List your product on Stack Search

Get in front of thousands of GRC decision-makers

AI Governance

South Korea Opens a New Route to Personal Data for AI Development

For South Korean AI developers, some useful data has come with an awkward choice. Get fresh consent from the people behind it, strip away enough identifying information to satisfy privacy requirements, or find another legal basis for using information that may have been collected for an entirely different reason. None is especially convenient when the object is to train an AI model on large and varied datasets.

Stop Treating AI Risk as an Assurance Silo

In a recent LinkedIn post, I asked why so many organizations are trying to assess AI as a standalone risk. I think that question gets to the heart of what is going wrong with much of the discussion around AI governance. There is no shortage of people trying to work out how organizations should govern AI. New frameworks are appearing, risk taxonomies are being built, internal audit teams are developing programs, and familiar questions are being asked about bias, security, compliance, privacy, and hallucinations.

Governing the Impossible

Antimatter propulsion remains far beyond today's engineering reach. But AI may help turn the unknown into a development roadmap. The governance question is whether we can control the research before it outpaces us. A question that sounds like science fiction reveals a very practical governance problem: What happens when artificial intelligence accelerates a high-consequence technology faster than our institutions can regulate it?

When AI Chooses

Imagine the boardroom in 2036. Artificial intelligence has become part of how the company operates. It tests capital choices, monitors risk, compares strategic alternatives and makes thousands of decisions within limits established by management and the board.

Europe Starts Enforcing Key Provisions of the AI Act

On Aug. 2, the European Commission's AI Office, working alongside national authorities, began enforcing key provisions of the AI Act. The same date also marked the start of new transparency obligations requiring certain AI systems to disclose when users are interacting with artificial intelligence rather than a human being. AI-generated or AI-altered content must now carry machine-readable markers that make it easier to detect, while deepfakes (images, audio, or video) must be clearly labeled.

EU Financial Regulators Warn Frontier AI Is Compressing the Time Between Vulnerability & Attack

The European Banking Authority (EBA), European Insurance and Occupational Pensions Authority (EIOPA), and European Securities and Markets Authority (ESMA) published a joint statement that is not warning that frontier artificial intelligence will eventually reshape cybersecurity. They are arguing that it already has.

Changing the Conditions of the Test: Command Judgment, the Digital Twin & the Next Frontier of GRC

In a recent piece on my site, I wrote about Captain Batel's digital twin, and about what I am calling GRC 7.0 — GRC Orchestrate. I made the case that the future of risk management is not another dashboard bolted onto yesterday's process, but a living model of the enterprise that senses, simulates, and orchestrates response. That piece generated more conversation than almost anything I have written this year, and one question kept surfacing in different forms, from different people, in different words. If the digital twin can model the scenario, simulate the intervention, and recommend the path . . . what is left for the human being standing on the bridge?