Research notes and practical write-ups on governance, AI risk, and security, published as they're ready.
The SP 800-82r4 draft rebuilds OT security around CSF 2.0's Govern Function, widens scope to water, buildings, rail and maritime, and separates management networks from process control. Comments close 30 November 2026.
TC260's third edition adds a dedicated agentic AI risk class built around identity, tools, memory and planning. It is not binding law — but it is the third major jurisdiction this year to describe the agent in the same four terms.
California signed two laws creating a state registry for AI auditors and a certification framework for independent verification organisations, then issued an executive order nine days later to accelerate both. The assurance layer is becoming regulated infrastructure.
Europe's first quality management standard for the AI Act finished its approval process this summer, and EN ISO/IEC 42001:2026 arrived in March. Neither one currently gives a provider legal cover — and understanding why changes what you should be building.
The Cyber Resilience Act's 24-hour reporting duty and ENISA's Single Reporting Platform went live on 11 September 2026. The hard part is not the deadline: the clock starts on awareness, there is no API at launch, and the platform's own counter currently runs fast.
Cyber insurers have moved faster than regulators on AI governance: generative-AI exclusions, conditional AI riders, and control questionnaires that put a price on your documentation. The four artefacts underwriters now ask for are the same four ISO/IEC 42001 and the EU AI Act already require.
On 19 August NIST released the initial public draft of SP 1353, a quick-start guide of AI prompts for producing CSF 2.0 governance reviews and state profiles. The caveat NIST attaches to it is the whole governance question.
The SP 800-82r4 draft rebuilds OT security around CSF 2.0's Govern Function, widens scope to water, buildings, rail and maritime, and separates management networks from process control. Comments close 30 November 2026.
TC260's third edition adds a dedicated agentic AI risk class built around identity, tools, memory and planning. It is not binding law — but it is the third major jurisdiction this year to describe the agent in the same four terms.
California signed two laws creating a state registry for AI auditors and a certification framework for independent verification organisations, then issued an executive order nine days later to accelerate both. The assurance layer is becoming regulated infrastructure.