Research notes and practical write-ups on governance, AI risk, and security, published as they're ready.
TC260's third edition adds a dedicated agentic AI risk class built around identity, tools, memory and planning. It is not binding law — but it is the third major jurisdiction this year to describe the agent in the same four terms.
California signed two laws creating a state registry for AI auditors and a certification framework for independent verification organisations, then issued an executive order nine days later to accelerate both. The assurance layer is becoming regulated infrastructure.
Europe's first quality management standard for the AI Act finished its approval process this summer, and EN ISO/IEC 42001:2026 arrived in March. Neither one currently gives a provider legal cover — and understanding why changes what you should be building.
The Cyber Resilience Act's 24-hour reporting duty and ENISA's Single Reporting Platform went live on 11 September 2026. The hard part is not the deadline: the clock starts on awareness, there is no API at launch, and the platform's own counter currently runs fast.
Cyber insurers have moved faster than regulators on AI governance: generative-AI exclusions, conditional AI riders, and control questionnaires that put a price on your documentation. The four artefacts underwriters now ask for are the same four ISO/IEC 42001 and the EU AI Act already require.
On 19 August NIST released the initial public draft of SP 1353, a quick-start guide of AI prompts for producing CSF 2.0 governance reviews and state profiles. The caveat NIST attaches to it is the whole governance question.
DORA's second Register of Information cycle closed in April and NIS2 audit programmes are running across most of the EU. In both regimes, supervisors are now testing the completeness of your third-party record rather than the quality of your judgement.
TC260's third edition adds a dedicated agentic AI risk class built around identity, tools, memory and planning. It is not binding law — but it is the third major jurisdiction this year to describe the agent in the same four terms.
California signed two laws creating a state registry for AI auditors and a certification framework for independent verification organisations, then issued an executive order nine days later to accelerate both. The assurance layer is becoming regulated infrastructure.
Europe's first quality management standard for the AI Act finished its approval process this summer, and EN ISO/IEC 42001:2026 arrived in March. Neither one currently gives a provider legal cover — and understanding why changes what you should be building.