AI Governance

Changing the Conditions of the Test: Command Judgment, the Digital Twin & the Next Frontier of GRC

In a recent piece on my site, I wrote about Captain Batel's digital twin, and about what I am calling GRC 7.0 — GRC Orchestrate. I made the case that the future of risk management is not another dashboard bolted onto yesterday's process, but a living model of the enterprise that senses, simulates, and orchestrates response. That piece generated more conversation than almost anything I have written this year, and one question kept surfacing in different forms, from different people, in different words. If the digital twin can model the scenario, simulate the intervention, and recommend the path . . . what is left for the human being standing on the bridge?

Trust Is Becoming the Real AI Battleground for Banks

Banks have spent centuries refining a single business model. They borrow trust, transform it into financial activity, and spend every day trying not to lose it. That is what makes a recent reflection from Bank of Ireland more interesting than it first appears. On its surface, it reads like another executive essay about artificial intelligence, full of familiar references to fraud detection, customer service, compliance monitoring, and operational efficiency. Those examples are almost expected now. Every large financial institution has a similar catalogue of use cases.

Dutch Privacy Regulator Draws GDPR Guardrails for Generative AI

The Dutch Data Protection Authority has published two documents on Monday. One provides GDPR guidance for developers of generative AI models. The other offers a practical checklist for organizations that want to purchase, implement and use the technology.

The Next Competitive Advantage in GRC Is No Longer Software

For much of the past twenty-five years, the GRC technology market rewarded providers for building broader platforms. New modules became competitive advantages. More configurable workflows became competitive advantages. Larger control libraries, deeper reporting, additional dashboards, more sophisticated risk quantification, and expanded third-party capabilities, with every release cycle promising another collection of features designed to distinguish one platform from another. Buyers responded in kind, and procurement teams assembled exhaustive requirements, while consultants developed detailed evaluation methodologies. Analysts compared products capability by capability until selection often resembled an exercise in accounting rather than strategy.

European Financial Regulators Back ESRB Warning on Frontier AI Cyber Risks

On Tuesday, Europe's three financial supervisory authorities publicly endorsed the European Systemic Risk Board's warning that frontier artificial intelligence models are creating systemic cyber risks for the financial sector, lending the combined authority of the continent's banking, insurance, and securities regulators to a concern that has been gathering force for months. Their message was not that artificial intelligence introduces a new category of risk. It was that the pace at which the technology is changing offensive cyber capabilities is beginning to test assumptions that were reasonable only yesterday.

FCA Says AI Will Fundamentally Reshape Retail Financial Services by 2030

Artificial intelligence is poised to become one of the defining forces in retail financial services over the next decade, according to a review published Monday by the UK's Financial Conduct Authority, which argues that regulators, industry and government must begin preparing now for a financial system increasingly shaped by autonomous AI.

Italian Competition Authority Investigates Microsoft Over Microsoft 365 AI-Linked Price Increase

The Italian Competition Authority has opened an investigation into Microsoft Ireland Operations and Microsoft, arguing that the company may have crossed that line when it increased the price of Microsoft 365 after incorporating its Copilot and Designer artificial intelligence services into the subscription.