Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

OWASP Rebuilt Its LLM Top 10 Around 6,639 Real Incidents, and Excessive Agency Climbed to Third

OWASP published the 2026 edition of its Top 10 for LLM Applications on 3 August 2026. For the first time the ranking was set by two inputs rather than one: expert consensus carried 75% of the weight and 6,639 documented real-world incidents carried the remaining 25%. Excessive Agency climbed from sixth place to third. This walks the three entries that live on the request and response path, and names the entries a policy gateway has no claim on.

Platform & Architecturellm-securityai-securitypolicy-enforcementarchitectureagentic-ai
Read post →

Singapore MAS Wrote Down Three Runtime Questions for AI Agents in Finance

On 5 August 2026 the Monetary Authority of Singapore answered a parliamentary question on agentic AI in financial services, confirming that its proposed Guidelines on AI Risk Management cover all AI use cases at financial institutions including AI agents. The companion paper published on 3 July 2026, Safeguards for Agentic Finance at Runtime, sets out three questions: what the system is authorised to do, how proposed actions are assessed before execution, and what records are retained. Those three describe a policy decision point.

Industry Verticalsai-governanceai-complianceregulationagentic-aipolicy-enforcementaudit
Read post →

NIST SP 800-53 AI Controls Mapping: Control IDs an AI Gateway Answers

SP 800-53 Revision 5 organises its catalogue into 20 control families, and the COSAiS overlay work that will tailor it for AI is still in draft. An AI system inside an authorisation boundary is assessed today against control identifiers that already exist. This maps the specific controls an identity-aware gateway on AI traffic satisfies, at the AC-3, AC-4, AU-3, AU-9, IA-2, SC-7, SI-4 and SR-3 level, and names the ones it contributes nothing to.

Compliance & Regulationnistcomplianceai-governancearchitectureauditpolicy-enforcement
Read post →

NIST SP 800-53 AI Compliance Checklist: 12 Items to Close Before Assessment

An AI system inside an authorisation boundary gets assessed against SP 800-53 Revision 5 control identifiers that already exist, ahead of any COSAiS overlay being finalised. This is a sequenced checklist of 12 items, each written with the control it satisfies and an objective completion test an assessor could run. It starts with endpoint inventory and identity binding, because every later item inherits whatever those two produce.

Compliance & Regulationnistcomplianceai-governanceauditai-security
Read post →

NIST CSF 2.0 AI Controls Mapping: AI Traffic Across the Six Functions

NIST released Cybersecurity Framework 2.0 on 26 February 2024 with a sixth Function, GOVERN, sitting at the centre of the other five. AI traffic between authenticated callers and model endpoints falls across GV.SC, ID.AM, PR.AA, PR.DS, DE.CM and RS.AN without any AI-specific subcategory being written. This maps the categories an identity-aware gateway answers, the outcome each one expects, and the parts of the Framework it contributes nothing to.

Compliance & Regulationnistcomplianceai-governancearchitecturezero-trustpolicy-enforcement
Read post →

NIST CSF 2.0 AI Compliance Checklist: 10 Outcomes to Evidence for AI Traffic

CSF 2.0 states outcomes rather than requirements, so a Profile that claims AI coverage is only as good as the evidence behind it. This is a sequenced checklist of 10 items covering the categories AI traffic actually touches, from GV.SC through RC.RP. Each item names the category it serves and a completion test somebody outside the security team could run, and the ordering follows dependency rather than the Function wheel.

Compliance & Regulationnistcomplianceai-governanceauditzero-trust
Read post →

NIST CSF 2.0 AI Audit Evidence: The Artifacts an Assessor Reads Per Function

CSF 2.0 is written as outcomes rather than requirements, which makes an assessment a conversation about evidence rather than a checkbox exercise. When AI traffic sits in scope, the assessor asks who called which model, what the prompt carried, what rule governed the decision, and which record proves it. This walks the artifact each Function expects for AI traffic, and the property that decides whether an artifact counts.

Compliance & Regulationnistauditcomplianceai-governanceforensic-audit
Read post →

NYC Local Law 144 AI Compliance Checklist: 11 Items With an Objective Completion Test

Local Law 144 has been enforced since 5 July 2023, and a December 2025 New York State Comptroller audit found the enforcement ineffective and re-read 32 posted bias audits DCWP had cleared, identifying at least 17 potential issues. This is an 11-item checklist covering scoping, the annual bias audit, the published summary, candidate notice, and the invocation record underneath all of them, each with a test somebody outside HR could run.

Compliance & Regulationcomplianceregulationai-complianceai-governanceaudit
Read post →

NYC Local Law 144 AI Audit Evidence: What the Comptroller Found When It Re-Read 32 Bias Audits

In December 2025 the New York State Comptroller published an audit of how the Department of Consumer and Worker Protection enforces Local Law 144. DCWP had reviewed 32 published bias audits and found one non-compliance issue. The Comptroller re-read the same 32 and identified at least 17. That gap is a statement about evidence quality, and it changes what an employer should be able to produce about its own AEDT.

Compliance & Regulationcomplianceregulationauditai-governanceai-compliance
Read post →

OWASP Agentic Top 10 AI Audit Evidence: The Artifacts That Prove a Control Ran

OWASP released the Top 10 for Agentic Applications on 9 December 2025, built with more than 100 contributors. A framework tells an assurance function what to look for and stops short of telling it what a passing answer looks like on paper. This walks the evidence an auditor or a customer security review can actually inspect for each risk category, separates the categories that produce inspectable artifacts from the ones that do not, and names where the record has to come from.

Compliance & Regulationai-securityagentic-aiauditcomplianceai-governancepolicy-enforcement
Read post →

NYC Local Law 144 AI Controls Mapping: Each Obligation Against the Control That Satisfies It

Local Law 144 imposes four obligations on an employer using an automated employment decision tool: an annual bias audit by an independent auditor, publication of the results summary, candidate notice at least ten business days before use, and the record-keeping underneath all three. This maps each obligation to the control that satisfies it, names the owner, and states plainly which of the four an identity-aware gateway on the request path touches and which it contributes nothing to.

Compliance & Regulationcomplianceregulationai-governanceai-complianceauditpolicy-enforcement
Read post →

OWASP Agentic Top 10 AI Controls Mapping: Which Risks an Assurance Programme Can Actually Own

The OWASP Top 10 for Agentic Applications, published 9 December 2025 with more than 100 contributors, is a risk list rather than a control framework. An assurance function has to convert it into named controls with named owners before it can be used in an ISO 42001 statement of applicability or a customer security review. This maps each risk area to the control that addresses it, the function that owns that control, and the coverage verdict a reviewer should expect.

Compliance & Regulationai-securityagentic-aicomplianceai-governancearchitecturepolicy-enforcement
Read post →