Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

Shadow AI in the Enterprise: Definition, Mechanism, and the Architecture That Closes the Gap

Shadow AI is the unauthorized use of AI tools by employees, agents, and embedded vendor features inside an enterprise. IBM Cost of Data Breach finds one in five breached organizations had shadow AI exposure, with $670,000 in incremental cost per incident. Cloud Radix puts unauthorized AI usage at 78% of employees. This pillar walks through what shadow AI is, why traditional DLP cannot see it, and the architecture that contains the blast radius.

Problem-Awareshadow-aiai-securitydlpai-governancecisoenterprise
Read post →

EU AI Act News Today: Live Tracker for Enforcement, Guidelines, and Member-State Implementation

Live tracker for EU AI Act enforcement actions, Commission guidelines, AI Office decisions, member-state designations, Code of Practice updates, and major court rulings. Updated as developments land. Current entries through June 2026 cover the GPAI guidelines, the Article 5 prohibited-practices enforcement, and the August 2 high-risk system deadline countdown.

Compliance & Regulationeu-ai-actregulationcompliancenewstrackerai-governance
Read post →

EU AI Act Compliance: What the Regulation Requires from Enterprise AI Architecture

The EU AI Act enters force in stages from February 2025 through August 2027. The August 2, 2026 deadline brings high-risk system obligations into effect for most enterprise AI deployments in the EU market. Penalties under Article 99 reach €35 million or 7% of global annual turnover. This pillar walks through what the Act actually mandates, where most architectures fall short, and the infrastructure pattern that satisfies the obligations at scale.

Compliance & Regulationeu-ai-actcomplianceai-governanceauditregulationhigh-risk-ai
Read post →

Databricks Buys Panther: What the Security Lakehouse Race Means for Teams Weighing AI Detection Against Inline Enforcement

On June 16, 2026, Databricks announced its intent to acquire Panther, its third security acquisition after Antimatter and SiftD.ai. The deal extends Databricks security lakehouse with an agentic SOC. Detection of AI-driven attacks sits in one architectural place. Per-decision enforcement on AI traffic sits in another. The two are not interchangeable.

Comparisons & Alternativesai-control-planeai-securityinline-enforcementsocdatabrickspanther
Read post →

NIST AI Risk Management Framework: GOVERN, MAP, MEASURE, MANAGE at the request layer

The NIST AI Risk Management Framework organizes AI risk into four functions: GOVERN, MAP, MEASURE, MANAGE. The framework is voluntary in name and effectively mandatory for federal contractors, critical infrastructure operators, and any organization whose AI program will be measured against US guidance. The text reads at a higher level of abstraction than implementation. This piece walks through each function with the artifact a real organization has to produce, then maps the artifacts to the request-layer architecture that produces them.

Compliance & Regulationnistai-rmfai-governancecomplianceauditrisk-management
Read post →

HIPAA-compliant LLMs: what the deployer has to produce when OCR shows up

HIPAA does not approve LLMs. HIPAA places obligations on covered entities and business associates around how PHI gets used, accessed, and audited. When OCR opens a complaint review of a clinical AI deployment, the questions are specific: who accessed PHI in what context, with what authorization, with what evidence. This piece walks through what HIPAA actually requires from an AI deployment, what a Business Associate Agreement does and does not cover, and the architecture that produces the audit artifact OCR will ask for.

Compliance & Regulationhipaahealthcarephicomplianceauditclinical-ai
Read post →

DORA and AI: what EU financial entities have to map by January 2027

The EU Digital Operational Resilience Act took effect January 17, 2025 and treats LLM vendors as critical ICT third parties at scale. By January 2027, EU financial entities have to maintain a Register of Information covering ICT third-party arrangements, run exit-strategy testing for material providers, manage concentration risk, and produce per-decision audit trails for AI-influenced decisions. This piece walks through what DORA actually requires from an AI program and the architecture that satisfies it.

Compliance & Regulationdorafinancial-servicesai-governanceeu-regulationauditbanking
Read post →

NIST AI agent identity Pillars 2 and 3: authorization and audit at the request layer

NIST has framed AI agent identity and authorization around three pillars. Pillar 1 is identification at the request boundary. Pillar 2 is authorization tied to the resolved identity. Pillar 3 is audit and accountability across the request lifecycle. The public comment window on the NIST draft closed April 2, 2026. This piece walks through what Pillars 2 and 3 actually require at the architecture layer and where most enterprise AI deployments fall short.

Platform & Architecturenistai-agent-identityauthorizationauditzero-trust-ai
Read post →

Fannie Mae LL-2026-04: the first sector-specific AI governance mandate for lenders

Fannie Mae Lender Letter LL-2026-04 was issued April 8, 2026 and takes effect August 8, 2026. It is the first sector-specific AI governance mandate in US mortgage lending. The Letter requires lenders to inventory AI usage, document data classification, attach identity context, and produce audit records for AI-influenced credit decisions. Freddie Mac Section 1302.8 has been enforced since March 3, 2026. This piece walks through the requirements, what they mean for the lender stack, and the architecture that satisfies them.

Compliance & Regulationfannie-maemortgageai-governancelendingcomplianceaudit
Read post →

AI vendor liability: you own it, the vendor will not

Microsoft, SAP, Oracle, Salesforce, ServiceNow, and Workday all sell AI agents under enterprise contracts. When The Register asked who is liable for the decisions those agents make, Microsoft and SAP declined to comment and the other four did not respond. The contract language already places the risk on the deployer. This piece walks through what the regulators say, what the contracts say, and what a deployer must produce on its own to discharge the obligation.

Compliance & Regulationai-vendor-liabilityeu-ai-actcomplianceauditai-governance
Read post →

Credal alternatives: where the portal pattern stops working

Credal gives employees a sanctioned internal AI portal. The pattern works when employee AI usage is the entire scope. The pattern stops working when machine-to-machine, agent-driven, or vendor-embedded AI traffic must be covered by the same policy and the same audit trail. This piece walks through where the portal stops and what fills the gap.

Comparisons & Alternativesalternativescredalai-portalai-gatewayenforcement
Read post →