The RiskReview Blog
Practical perspectives on AI risk, security testing, compliance, and governance.
Stay Updated on AI Risk & Compliance
Get notified when we publish new insights on AI risk assessment, regulatory compliance, and security testing.
- Read
Shadow AI · LLM Security · Data Loss · Governance · LayerX · Visibility
77% of Enterprise Employees Have Pasted Company Data Into a Chatbot — Shadow AI Is Your Biggest LLM Risk
The LayerX data on uncontrolled AI tool usage, why 62% of organizations have no visibility into where LLMs are deployed, and how to build a shadow AI detection and governance program that doesn't just ban everything.
- Read
Insurance · AI Risk · General Liability · Silent Cyber · AI Governance · Risk Management
Silent AI Is the New Silent Cyber: Why Your General Liability Policy May Exclude AI Claims Starting in 2026
Insurers are ending 'silent' AI coverage the same way they ended silent cyber—with explicit exclusions. ISO's new CGL endorsements and carrier wordings mean 2026 renewals could leave AI-related claims uncovered unless you plan ahead.
- Read
FTC · Operation AI Comply · Consumer Protection · AI Regulation · Section 5 · AI Washing
FTC Operation AI Comply: How the FTC Is Using Existing Consumer Protection Law to Regulate AI
The FTC isn't waiting for new AI legislation. Operation AI Comply applies Section 5 and existing consumer protection law to AI claims and conduct—with real settlements and a clear message: there is no AI exemption.
- Read
Agentic AI · Prompt Injection · ServiceNow · Multi-Agent Security · Privilege Escalation
When AI Agents Conspire: Cross-Agent Privilege Escalation and the ServiceNow Second-Order Injection
How a low-privilege agent tricked a higher-privilege agent into exfiltrating an entire case file. The new attack surface created by multi-agent trust graphs, cascading failures, and why agent-to-agent communication needs the same scrutiny as user-to-agent.
- Read
AI Access · Identity Governance · IAM · Non-Human Identities
71% of Organizations Say AI Tools Access Core Systems Like Salesforce and SAP: But Only 16% Govern That Access
The 2026 CISO AI Risk Report shows a wide gap between AI access and AI oversight. How to apply identity governance to AI agents: just-in-time privilege, scoped API permissions, read-only defaults, and continuous monitoring for privilege drift. The same principles as human IAM, adapted for non-human identities.
- Read
EU AI Act · High-Risk AI · Compliance · 2026 · Extraterritorial
The EU AI Act August 2026 Deadline: High-Risk AI System Requirements Your US Company Can't Ignore
The EU AI Act applies to US providers and deployers when AI is placed on the EU market or put into service there. August 2, 2026 is when high-risk obligations become enforceable—risk management, conformity assessment, CE marking, and deployer duties. What triggers scope, what Annex III actually catches, and why 'we're not in Europe' doesn't work.
- Read
AI Governance · Vendor Management · Contracts · Compliance · Audit · Flow-Down
When Your AI Vendor Gets Audited: How Downstream Compliance Obligations Flow Through Enterprise Contracts
Regulators and your own auditors look at you when your AI vendor is under scrutiny. The contract is where flow-down lives—or doesn't. Audit rights, certifications, and warranties that actually pass obligations to the vendor, and what happens when they're missing.
- Read
AI Sandbox · Governance · Sanctioned AI · Innovation
From Shadow AI to Sanctioned AI: Building an AI Sandbox Program That Doesn't Kill Innovation
Banning AI tools doesn't work; employees find workarounds. How to create contained environments where teams test AI with synthetic data, submit use cases for review, and graduate approved tools into production with proper controls. The governance model that says yes, but safely.
- Read
Audit Readiness · AI Governance · Evidence · Quarterly Refresh
Quarterly Evidence Refresh: How to Keep Your AI Governance Documentation Audit-Ready Year-Round
Point-in-time assessments decay fast when AI systems change weekly. How to build a quarterly refresh cadence that updates the AI inventory, validates risk classifications, confirms control effectiveness, documents policy changes, and produces the evidence package an auditor or regulator would need, without making it a fire drill every time.
- Read
Security · Prompt Injection · IDE Security · CVE · Developer Security
GitHub Copilot's CVE-2025-53773: What a CVSS 9.6 in Your IDE Means for Developer Security
Remote code execution through prompt injection in a coding assistant used by millions. How the attack works, why developer workstations are high-value targets, and what security controls should exist between an AI agent and your local filesystem.
- Read
Governance Maturity · Scale AI · Enablement · Executive Sponsorship
The Governance Maturity Gap: 78% of Organizations Use AI, But Only 30% Feel Ready to Scale It Safely
Why governance programs stall: too much framework and not enough operations, too much legal and not enough engineering, too much committee and not enough tooling. The practical blockers and how to overcome them with phased implementation, quick wins, and executive sponsorship that treats governance as enablement.
- Read
KPIs · AI Governance · Metrics · Dashboard
What KPIs Should You Track for AI Governance? Moving Beyond "We Have a Policy"
Regulators and boards want quantified metrics, not documentation alone. Inventory coverage, high-risk systems with completed impact assessments, shadow AI detection rate, mean time to review, incident count, and governance maturity. The dashboard that answers: are we actually governing AI?