The RiskReview Blog
Practical perspectives on AI risk, security testing, compliance, and governance.
Stay Updated on AI Risk & Compliance
Get notified when we publish new insights on AI risk assessment, regulatory compliance, and security testing.
- Read
Colorado AI Act · High-Risk AI · Compliance · SB 24-205 · Regulation
The Colorado AI Act Takes Effect in June 2026: What "High-Risk" Means for Your Product
Colorado's SB 24-205 is the first comprehensive state AI law in the U.S. The trigger isn't 'we use AI'—it's whether your system makes or substantially influences a consequential decision. How to tell if you're in scope, what deployers vs developers must do, and where teams keep getting the definition wrong.
- Read
Security · Text-to-SQL · LLM Security · SQL Injection
Text-to-SQL Is a SQL Injection Vulnerability You Built on Purpose
When your LLM converts natural language to database queries, it can hallucinate destructive commands or be manipulated into data exfiltration. Why read-only credentials, query allowlisting, and result-size limits are non-negotiable.
- Read
Training · AI Risk · Culture · Compliance
Training Employees on AI Risk Without Turning It Into a Checkbox Exercise
Annual compliance training doesn't change behavior. What does: role-specific training for engineers, business users, and leadership; real-world simulations of what goes wrong; clear escalation paths; and a culture where reporting shadow AI is rewarded, not punished.
- Read
AI Governance · Committee · RACI · Operating Model
How to Stand Up an AI Governance Committee Without Creating a Bureaucracy
Cross-functional representation from IT, legal, compliance, security, and the business, but a committee that actually moves. Meeting cadence, decision rights, RACI assignments, escalation rules, and how to avoid the trap where governance slows everything down.
- Read
Legal Ethics · AI Governance · State Bar · Research · Discovery · Privilege · Compliance
State Bar AI Ethics Rules Are Tightening: What Law Firms Using AI for Research and Discovery Need to Know
Bar associations are applying existing ethics rules to generative AI—and courts are ruling on privilege and sanctions. For firms using AI in research and discovery, the gap between 'allowed' and 'safe' is narrowing fast.
- Read
Agentic AI · Least Privilege · Output Validation · Tool Security · Audit Logging
Securing Agentic AI: Least Privilege, Output Validation, and the Controls That Actually Matter
Move beyond 'don't use AI agents' to practical engineering: scoped tool permissions, human-in-the-loop for destructive actions, deterministic output validation, sandboxed execution, and audit logging for every tool invocation.
- Read
State AI Laws · Compliance · AI Governance · Multi-State · Regulatory Patchwork
38 States, 100+ AI Measures: How to Build a Compliance Program When Every State Has Different Rules
The state AI patchwork isn't going away. How to build one compliance program that holds up when 38 states have adopted 100+ AI measures—without running 38 separate playbooks or waiting for Washington to sort it out.
- Read
AI Governance · Insurance · Cyber Insurance · Underwriting · Risk Management
AI Governance as an Insurance Prerequisite: How Carriers Are Borrowing the Cyber Underwriting Playbook
Cyber insurers learned the hard way: soft questions and hope don't limit losses. They tightened underwriting around controls and evidence. The same shift is happening for AI—governance is becoming a condition of coverage. What carriers are asking for, why, and how to be ready.
- Read
LLM Observability · Data Privacy · Compliance · PII · Redaction
Your AI Is Logging Sensitive Data You Didn't Know About: The Plumbing Problem in LLM Observability
Prompt-response logging, RAG context capture, embedding storage, and agent action traces all create data leakage vectors. How to build observability without creating a compliance incident — classification, minimization, redaction, and access control at every layer.
- Read
Identity Verification · Deepfakes · BEC · Voice Spoofing · Security
AI Deepfakes Are Breaking Your Identity Verification: Voice Spoofing, Video Impersonation, and What to Do About It
AI-generated deepfakes are supercharging social engineering and BEC attacks. Why voice-only and video-only authentication is no longer sufficient, and how to redesign verification protocols for the deepfake era.
- Read
AI Access · RBAC · Sensitivity Labels · Microsoft Purview · Least Privilege
The Access Control Gap in AI Systems: Why Your LLM Operates With More Permissions Than Any Employee
Most AI agents inherit the permissions of the user or a broad service account. How to implement fine-grained RBAC for AI systems, sensitivity labels for AI-accessible data, and why Microsoft Purview's approach matters.
- Read
Risk Assessment · Framework · AI Governance
Building an AI Risk Assessment Framework That Actually Works
Most AI risk frameworks are compliance theater. Here's how to build one that produces real, actionable findings, drawn from our experience reviewing AI systems across regulated industries.