risk management

Linux Foundation Report Finds Greatest Obstacle for AI Adoption and Innovation Is a Security Readiness Crisis

The Linux Foundation's 2026 State of Tech Talent Report identifies a security readiness crisis as the greatest obstacle to AI adoption and innovation, with security and privacy concerns rising sharply from 17% in 2024 to 48% in 2026. Despite these challenges and a significant capacity gap in AI security and risk management reported by 57% of organizations, AI is driving technical job growth and organizations are prioritizing upskilling existing employees to bridge talent gaps, yielding substantial business benefits over hiring new staff.

https://www.linuxfoundation.org/press/linux-foundation-report-finds-greatest-obstacle-for-ai-adoption-and-innovation-is-a-security-readiness-crisis

From Capabilities to Responsibilities

The article “From Capabilities to Responsibilities” by Artur Huk argues that in high-stakes AI agent systems—those that can affect finance, healthcare, or critical infrastructure—designing agents around explicit responsibilities rather than just capabilities is essential for governance and safety. It proposes a Responsibility-Oriented Agent (ROA) architecture where strict, code-enforced contracts define what an AI agent is authorized to do, separating intent generation from execution and enabling scalable, deterministic validation that escalates only true exceptions to humans, thus avoiding operational bottlenecks inherent in human-in-the-loop models.

https://www.oreilly.com/radar/from-capabilities-to-responsibilities/

Software Bill of Materials for AI – Minimum Elements

The Cybersecurity and Infrastructure Security Agency (CISA) outlines the minimum elements for a Software Bill of Materials (SBOM) specific to AI systems to enhance transparency and security. These elements include detailed information about the components, versions, and relationships within AI software to help identify vulnerabilities and manage risks effectively. This approach aims to improve trust and security in AI technologies by providing comprehensive visibility into their software components.

https://www.cisa.gov/resources-tools/resources/software-bill-materials-ai-minimum-elements

Risk Management Is Key in This Unpredictable Environment

Marco Saalfrank, head of merchant trading at Axpo, emphasizes the critical importance of risk management amid the current volatile energy markets shaped by geopolitical crises and global events. Axpo leverages its diversified presence across commodities and geographies to provide tailored risk management solutions, helping clients navigate uncertainty through customized hedging and flexible energy sourcing, while actively engaging in the energy transition through investments in renewables, low-carbon fuels, and innovative technologies.

https://www.risk.net/awards/7963498/risk-management-is-key-in-this-unpredictable-environment

Shadow AI Now Needs a Bill of Materials

Enterprises are adopting AI Bills of Materials (AI-BOMs) to manage the complexity of Shadow AI, including tracking AI models, datasets, prompts, agents, identities, and cloud infrastructure, beyond traditional software components. Companies like Cisco, Wiz, and Palo Alto Networks are developing tools to create detailed, machine-readable inventories of AI assets to improve security, governance, model provenance, and compliance with emerging regulations such as the EU AI Act.

https://techinformed.com/shadow-ai-now-needs-a-bill-of-materials/

The Ultimate Guide to Managing Third-Party Risk

Third-party risk management (TPRM) is the process of identifying, assessing, and mitigating risks associated with external third parties. TPRM programs are driven by regulatory requirements, cybersecurity risk, competitive advantages, and internal efficiency. The TPRM lifecycle includes sourcing and selection, intake and onboarding, inherent risk scoring, internal controls assessment, external risk monitoring, SLA and performance management, and offboarding and termination.

https://www.jdsupra.com/legalnews/the-ultimate-guide-to-managing-third-5033967/

How to Create an Effective Business Continuity Plan

A business continuity plan (BCP) is a strategic guide that helps organizations maintain or quickly resume operations during disruptions such as natural disasters, cyberattacks, or supply chain failures. It involves assessing critical business processes, setting recovery objectives, detailing roles and procedures, and regularly testing and updating the plan to address evolving risks, including those from AI and third-party dependencies. Effective BCPs, supported by senior management and enhanced by modern tools like AI, are vital for minimizing downtime and ensuring organizational resilience in an increasingly complex operating environment.

https://www.cio.com/article/4166194/how-to-create-an-effective-business-continuity-plan-3.html

AI Is Spreading Decision-Making, but Not Accountability

As AI systems become widely adopted in enterprises, decision-making responsibilities are distributed across various teams, but legal accountability tends to concentrate on the organizations deploying these systems and their executive leadership, particularly CIOs. While AI governance frameworks involve multiple functions like legal, risk, IT, and business, courts generally hold humans—especially those integrating AI into real-world decisions—responsible when failures occur, underscoring that AI spreads decision-making but does not absolve accountability.

https://www.cio.com/article/4160986/ai-is-spreading-decision-making-but-not-accountability.html

8 Best Practices for CISOs Conducting Risk Reviews

Rico Mariani, Deputy CISO at Microsoft Security, shares eight best practices for CISOs conducting risk reviews to proactively enhance security posture amid evolving cyberthreats driven by AI. His approach emphasizes identifying assets and applications, ensuring strong authentication and authorization, network isolation, effective detection and auditing, and not overlooking backup or development systems, thereby enabling structured conversations and informed risk management.

https://www.microsoft.com/en-us/security/blog/2026/04/29/8-best-practices-for-cisos-conducting-risk-reviews/

Why a ‘Risk Position’ Should Be The Next Big Thing In Business Leadership

Dr Emma Soane argues that an organization's “risk position”—its intentional stance on risk-taking and management—should be regarded as fundamental as its strategy, culture, and leadership. Highlighting examples like Netflix and The Royal Mint, she explains that a clear risk position enables organizations to align risk with strategic goals, foster open risk dialogue, and move beyond viewing risk solely as a compliance issue or threat.

https://www.lse.ac.uk/study-at-lse/executive-education/insights/articles/why-a-risk-position-should-be-the-next-big-thing-in-business-leadership

Scroll to Top