The RiskReview Blog
Practical perspectives on AI risk, security testing, compliance, and governance.
Stay Updated on AI Risk & Compliance
Get notified when we publish new insights on AI risk assessment, regulatory compliance, and security testing.
- Read
Security · Prompt Injection · LLM Security · Indirect Prompt Injection · EchoLeak · Microsoft Copilot
Indirect Prompt Injection: The Attack Where Your User Never Touches the Prompt
How poisoned emails, PDFs, web pages, and calendar entries become executable instructions when an LLM ingests them. The EchoLeak CVE in Microsoft 365 Copilot, the zero-click exfiltration pattern, and why perimeter defenses don't apply.
- Read
Security · Prompt Injection · OWASP · LLM Security · Red Team · Testing
A Practical Prompt Injection Testing Playbook for Security Teams
How to red-team your own LLM applications: direct injection, indirect via external content, multi-turn escalation, encoding bypass, and cross-language attacks. Mapped to the OWASP Top 10 for LLM Applications 2025 with reproducible test patterns.
- Read
EU AI Act · Extraterritorial · SaaS · Compliance · Third Country
EU AI Act Compliance for American SaaS Companies: When Extraterritorial Reach Applies to You
The EU AI Act applies to providers and deployers outside the EU when AI output is used in the Union—no office in Brussels required. How to tell if your US-based SaaS is in scope and what that actually means.
- Read
AI Policy · Acceptable Use · Governance · Template
Writing an AI Acceptable Use Policy That People Actually Read: A Practitioner's Template
Most AI policies are copy-pasted legal boilerplate. What works: a tiered structure (prohibited / cautious / approved), plain-language rules mapped to real scenarios, and a one-page quick-reference card. What to include, what to skip, and how to enforce it.
- Read
SEC · Examination · AI Governance · Investment Advisers · Compliance
The SEC's 2026 Examination Priorities: AI Is on the List — Here's What Examiners Will Look For
The Division of Examinations named AI, automated investment tools, and trading algorithms as 2026 priorities. Not theory—what they'll actually ask for: representations vs. reality, supervision, data sources, and AI washing. Plus how the new 'gotcha' tone changes the game.
- Read
AI Governance · Competitive Advantage · Growth · Enterprise
AI Governance as Competitive Advantage: The Companies That Govern Best Will Scale Fastest
Governance isn't overhead. It's why enterprise deals close, insurance stays manageable, the board is satisfied, and regulators aren't investigating. The evidence that organizations with mature AI governance innovate faster, not slower, and how to position governance as a growth investment.
- Read
Security · MCP · AI Agents · Supply Chain · Tool Poisoning · Model Context Protocol
13,000 MCP Servers Launched on GitHub in 2025 — Your Security Team Can't Catalog Them Fast Enough
The Model Context Protocol is becoming the default integration layer for AI agents. Tool poisoning, schema manipulation, supply-chain compromise (the trojanized postmark-mcp package), and why 'it's just JSON-RPC' is a dangerous underestimation.
- Read
EU AI Act · Compliance · Regulation
The EU AI Act Is Now Enforceable: Here's What It Means for Your Business
The EU AI Act's key provisions are now in effect. We break down what regulated businesses need to know about compliance timelines, risk classifications, and mandatory reviews.
- Read
SEC · AI Disclosure · Investor Advisory Committee · Regulation S-K · AI Governance · Securities
The SEC's AI Disclosure Debate: What the Investor Advisory Committee's Recommendations Mean for You
The IAC voted to recommend AI disclosure guidance—define AI, board oversight, deployment reporting. The Commission may not adopt it. Here's what the debate actually turns on, why the 'define AI' question cuts both ways, and what to do regardless.
- Read
AI Governance · Inventory · Risk Management
You Can't Govern What You Can't See: How to Build a Living AI Inventory From Scratch
Most AI governance starts with a spreadsheet that goes stale in weeks. Here's how to build an inventory that stays current, surfaces shadow AI, and actually supports risk decisions.
- Read
RACI · AI Governance · Accountability · Risk Ownership
Who Owns AI Risk in Your Organization? The RACI Chart Nobody Has Built Yet
The AI system owner, compliance reviewer, security reviewer, data protection officer, business sponsor: most organizations haven't assigned clear accountability for AI decisions. A practical RACI model that maps every governance function to a named individual, with escalation paths and documented authority.
- Read
Incident Response · AI Governance · Risk Management · Playbook
Your AI Policy Needs an Incident Response Plan: What Happens When a Model Fails in Production
Most organizations have IR plans for data breaches but nothing for AI-specific failures: hallucinated outputs reaching customers, biased decisions flagged by regulators, prompt injection compromising an agent. How to build an AI incident response playbook with roles, escalation triggers, containment, and post-incident review.