compliance

50 States, 50 Different Ways: Who Owns AI Once It’s Deployed?

Most U.S. states have established AI governance frameworks with central technology teams setting initial policies and oversight, but responsibility often shifts to individual agencies once AI systems are deployed. This decentralized operational accountability requires agencies to monitor performance, manage risks, and address issues, while central offices provide standards and oversight, though variations exist across states like Maryland, California, and Pennsylvania. A key challenge remains in defining clear ownership and accountability for AI tools post-deployment, especially as AI increasingly appears embedded in existing software, complicating governance and requiring ongoing scrutiny during procurement and use.

https://www.govtech.com/spotlight/50-states-50-different-ways-who-owns-ai-once-its-deployed

Third-Party Risk Management: You Can Outsource the Task — Not the Risk

Third-Party Risk Management (TPRM) has evolved into a critical strategic capability as companies increasingly rely on third parties, exposing themselves to significant cybersecurity, compliance, supply chain, and sustainability risks. Regulatory bodies in the U.S., EU, Germany, and Brazil mandate that while companies may outsource tasks, they retain accountability for third-party failures, reinforcing the need for comprehensive, lifecycle-based risk programs integrated with broader enterprise risk management. Effective TPRM programs enable organizations to anticipate and mitigate risks through continuous monitoring, due diligence, contractual controls, and adaptability to emerging challenges such as AI, ultimately protecting operational resilience, regulatory compliance, and corporate value.

https://www.alvarezandmarsal.com/thought-leadership/third-party-risk-management-you-can-outsource-the-task-not-the-risk

EU AI Act for Boards: Timeline and Board Responsibilities

The EU Artificial Intelligence Act, effective from 2025 with phased deadlines through 2027, establishes a legal governance framework requiring boards of organizations deploying AI in the EU to oversee compliance, particularly for high-risk AI systems subject to strict documentation, human oversight, and conformity assessment obligations. Board responsibilities include ensuring accurate AI risk classification, implementing oversight structures, maintaining AI system inventories, and integrating AI governance within broader compliance frameworks to manage significant financial penalties and regulatory exposure. Structured governance supported by independent assurance and regular reporting is essential for boards to meet their non-delegable accountability under the Act’s evolving requirements.

https://www.nasdaq.com/articles/governance/eu-ai-act-boards

The Due Diligence Blind Spot Every Fintech Acquirer Should Worry About in 2026

Sergiy Fitsak highlights a critical blind spot in fintech acquisitions centered on insufficient due diligence regarding technology infrastructure and security vulnerabilities. He emphasizes that overlooking these technical risks can lead to operational disruptions, compliance failures, and financial losses post-acquisition. The article urges acquirers to integrate comprehensive technical assessments into their due diligence processes to safeguard long-term value and stability.

https://www.finextra.com/blogposting/32365/the-due-diligence-blind-spot-every-fintech-acquirer-should-worry-about-in-2026

Sharp Rise in AI Adoption for Cyber Defense Exposes Major Governance Gap

A recent SANS Institute survey reveals rapid AI adoption in enterprise cyber defense has outpaced the establishment of governance frameworks, with over 40% of practitioners reporting no formal AI policies and 60% lacking visibility into AI model use and data exposure. Despite 75% of security professionals holding governance roles, more than half indicate the absence of AI audit frameworks, highlighting a significant perception gap between security leaders and frontline staff regarding AI risk management programs. This governance shortfall raises concerns about protecting sensitive information amid expanding AI integration in cybersecurity operations.

https://www.ciodive.com/news/ai-adoption-cyber-defense-governance-gap/825462/

Shadow AI Is Really a Workflow Problem

As law firms integrate AI into legal work, the primary challenge is not just unauthorized technology use (“Shadow AI”) but inconsistent, unofficial workflows (“Shadow Workflows”) created by individual lawyers lacking firm-wide guidance. This leads to varied AI practices within the same firm, undermining governance, quality consistency, and institutional knowledge while exposing lawyers and clients to operational risks. Effective AI governance requires designing shared, scalable workflows and organizational capabilities that enable responsible, consistent AI use beyond mere technology approval.

https://aceds.org/shadow-ai-is-really-a-workflow-problem-ai-blog/

You Outsourced the AI—but You Still Own the Risk

As enterprises increasingly deploy AI systems developed by third parties, they remain legally and operationally responsible for the risks these systems pose, including discrimination, data mishandling, and customer harm. Despite limited visibility into the models’ training or updates, companies face scrutiny from regulators and courts when adverse outcomes occur, underscoring the need for robust AI risk management and governance even when AI is outsourced.

https://hbr.org/2026/07/you-outsourced-the-ai-but-you-still-own-the-risk

The New AI Trust Architecture: 5 Requirements for Agent-to-Agent Communication

Salesforce AI Research identifies a critical need for a new trust architecture to enable effective, reliable communication and negotiation between autonomous AI agents representing competing organizations. The framework requires five key elements: interpretable standards beyond fixed rules, persistent identity and reputation linked to principals, governance through boundaries rather than exhaustive scripting, structured accountability traceable to humans, and calibrated escalation to balance automation with liability. These principles aim to establish governance, legal, and ethical guardrails before AI agents handle consequential enterprise transactions at scale.

https://www.salesforce.com/blog/new-ai-trust-architecture/

Modernizing Legacy IT with AI Without Triggering Regulatory Risk

AI can accelerate the modernization of legacy IT systems, especially in regulated sectors with COBOL-based cores, but the main challenge lies in ensuring compliance and traceability to satisfy auditors and regulators. Key risks include undocumented business rules that AI may incorrectly interpret, leading to regulatory violations under frameworks like DORA, NIS2, and AI Regulation. Successful modernization requires thorough asset inventory, human validation of AI outputs, end-to-end traceability, strict data governance, and oversight of AI use to make transformations defensible and sustainable.

https://www.cio.com/article/4193445/modernizing-legacy-it-with-ai-without-increasing-regulatory-risk.html

5 AI Risk Management Frameworks for Shoring up Key Gaps

A new generation of AI-specific risk management frameworks has emerged to address gaps in traditional governance, security, and compliance models, helping organizations identify AI risks, implement controls, and demonstrate responsible AI use. Five notable frameworks include the ISO/IEC 42001 AI Management System, the NIST AI Risk Management Framework, ENISA’s AI Cybersecurity Practices, ISO/IEC 23894 guidance on AI risk, and Google’s Secure AI Framework (SAIF), each focusing on different aspects like governance, lifecycle risk management, cybersecurity, or operational security. These frameworks are complementary and vary in complexity and focus, with organizations advised to select ones that align best with their AI risk challenges and maturity level.

https://www.csoonline.com/article/4185917/5-ai-risk-management-frameworks-for-shoring-up-key-gaps.html

Scroll to Top