Governance and policy
Compliance, AI policy, legal, and trust
Enterprise governance 13
- Responsible AI in Enterprise Applications: A Practitioner's Viewjjude.com
- A Strategic Framework for AI Product Development and Evaluation in Enterprise Softwareiaeme.com
- Blueprints of Trust: AI System Cards for End to End Transparency and Governancearxiv.org
- CISO MindMap 2024: What do InfoSec Professionals Really Dorafeeqrehman.com
- Enterprise AI Governance at Snowflake: Balancing Innovation and Risk - slidesdrive.google.com
- Enterprise AI security posture for coding tools - r/devsecopsreddit.com
- GitHub Copilot: Enterprise team specialization for managed settingsgithub.blog
- Golf - AI governance and shadow AI discovery platformgolf.dev
- Introducing VibeGuard: AI Security and Governancelegitsecurity.com
- Team8 - Generative AI and ChatGPT Enterprise Risksteam8.vc
- The anecdotes AI GRC Toolkit9105956.fs1.hubspotusercontent-na1.net
- VS Code for enterprise - centrally managing settings, extensions and AI policiescode.visualstudio.com
- What policies are you writing or considering for GPT-4 - r/cybersecurityreddit.com
AI policy 53
- The Generative AI Policy Landscape in Open Sourceredmonk.com
- Contributions policy · Issue #7695 · tldraw/tldrawgithub.com
- Generative AI Policy - Asahi Linux Documentationasahilinux.org
- Our First Generalist Policyphysicalintelligence.company
- Updates to Consumer Terms and Privacy Policyanthropic.com
- IBB Policy Update: AI-Assisted Submissionshackerone.com
- A Flock license plate reader linked a San Diego man to a violent crime - he was five miles awaytimesofsandiego.com
- A Pro-Innovation Approach to AI Regulation - UK Government White Paperassets.publishing.service.gov.uk
- AI 2040: Plan A - A forecast and policy plan for navigating superintelligenceai-2040.com
- AI for Wisconsin - KC Streich write-in campaign for AI-assisted governanceai-for-wi.com
- AI Now 2025 Landscape Reportainowinstitute.org
- Altman says OpenAI agrees with Anthropic's red lines in Pentagon disputethehill.com
- Anthropic joins RAISE US, a nonprofit AI workforce coalitionx.com
- Anthropic says capability cited by US in restricting Fable 5 is already available from other modelsx.com
- Anthropic statement on US government directive to suspend access to Fable 5 and Mythos 5anthropic.com
- Arnaud Bertrand on Palantir's AI sovereignty narrative and closed-model economicsx.com
- Automation Without Understanding - AI mathematical capability as strategic vulnerabilityarxiv.org
- bdsqlsz on Reuters misrepresenting China's tiered plan to restrict access to frontier AI modelsx.com
- Bindu Reddy on India requiring government approval to deploy GenAI modelsx.com
- Blueprint for an AI Bill of Rightswhitehouse.gov
- China considers restricting overseas access to cutting-edge AI models, citing cyberattack concernsx.com
- CISA Gold Eagle: Advancing AI-Driven Vulnerability Reportingcisa.gov
- CISA Roadmap for Artificial Intelligence 2023-2024cisa.gov
- Congressional oversight letter to Anthropic regarding AI model security incidentscasar.house.gov
- DeepSeek Unmasked - House Select Committee on the CCP reportselectcommitteeontheccp.house.gov
- Designing Loyalty - AI Agents and Conflicts of Interest, Stanford HAIt.co
- DHS Roles and Responsibilities Framework for Artificial Intelligence in Critical Infrastructuredhs.gov
- Diversion and resale: estimating compute smuggling to Chinaepoch.ai
- Flock Has a Powerful New AI Tool for Police. We Got Its Code - WIREDwired.com
- HashiCorp comment on NIST AI Agent Security RFI - Agentic Runtime Securityregulations.gov
- Introducing the Responsible Builder Policy - r/redditdevreddit.com
- Letter to Speaker Johnson Requesting AI Hearingscasar.house.gov
- Magnifica Humanitas - Pope Leo XIV encyclical on safeguarding the human person in the time of AIvatican.va
- Minnesota Privacy Project - advocacy against license plate reader surveillancemnprivacy.org
- Model AI Governance Framework for Generative AIaiverifyfoundation.sg
- New York Times on the Trump administration and AI modelsnytimes.com
- OpenAI - Industrial Policy for the Intelligence Agecdn.openai.com
- OpenAI: Introducing Trusted Access for Cyberopenai.com
- Our position on open-weights modelsanthropic.com
- Own the Narrative - Leaked Flock Guide Shows How It Teaches Cops to Promote Its Tech404media.co
- Pacing the Frontier - statement from frontier AI company employeespacingthefrontier.com
- Pentagon Seeks $55 Billion for Drones and Autonomous Warfare in 2027 Budgetfoxnews.com
- Policy on the AI Exponentialdarioamodei.com
- Promoting Advanced Artificial Intelligence Innovation and Securitywhitehouse.gov
- Sen. Banks Recommends Oversight of Unreleased AI Modelsbanks.senate.gov
- SightBringer on the US government pausing Anthropic's Fable model - a sovereignty collision over frontier AIx.com
- Superintelligence Strategy - Expert Version PDFdrive.google.com
- Superintelligence Strategy - Hendrycks, Schmidt, Wangnationalsecurity.ai
- Trump AI framework on open models - Axiosaxios.com
- Trump AI framework to require 30-day government safety review for closed models, exempt open modelsx.com
- US to tell partners they must pick sides in AI race with Chinareuters.com
- Violations in the Shell: Exposing the Human Rights Costs of Generative AI - Amnesty Internationalamnesty.org
- White House reportedly completes frontier AI model review process, begins industry talksx.com
Legal 14
- Taking legal action to protect users of AI and small businessesblog.google
- A Software Engineer Won a Religious Exemption From Using AI at Workbusinessinsider.com
- Apple v. OpenAI and io Products - motion for preliminary injunction over trade secret misappropriationstorage.courtlistener.com
- Canada walks back ban of Flipper Zero, targets 'illegitimate' use casespcmag.com
- chardet issue #327 - original author disputes relicensing of AI-assisted rewritegithub.com
- DHS and DOJ Interim Final Rule - Counter-UAS Authority for State, Local, Tribal and Territorial Law Enforcementpublic-inspection.federalregister.gov
- DOJ charges three, including Supermicro cofounder, with diverting US AI servers to Chinajustice.gov
- LLM + Clean Room: Will LLMs be the death of code copyrightsgynvael.coldwind.pl?id=764
- North Carolina Man Pleads Guilty to Music Streaming Fraud Aided by Artificial Intelligence - DOJjustice.gov
- OpenRouter Stealth Program EULA - terms for anonymous models and data trainingopenrouter.ai
- SEC Charges SolarWinds and Chief Information Security Officer with Fraud, Internal Control Failuressec.gov
- Security Research Legal Defense Fundsrldf.org
- Startup sues Palo Alto Networks' Koi Security over AI-hallucinated report falsely linking it to Chinese espionagetheregister.com
- State Attorneys General letter to OpenAI over agent that escaped its sandbox and intruded on Hugging Faceiowaattorneygeneral.gov
Security and compliance 45
- Preparing for what's next: Windows security and resiliency innovablogs.windows.com
- Meta's Llama Framework Flaw Exposes AI Systems to Remote Code Executhehackernews.com
- What The Claude Code Leak Means for Engineering Teams in Regulated Industriessystima.ai
- "Security Is Our Top Priority" is BSblog.waleson.com
- An Overview of Google's Commitment to Secure by Designstatic.googleusercontent.com
- Back to the Building Blocks: A Path Toward Secure and Measurable Software - ONCD Technical Reportwhitehouse.gov
- Careful Adoption of Agentic AI Services - NSA cybersecurity information sheetmedia.defense.gov
- CISA BOD 26-04: Prioritizing Security Updates Based on Riskcisa.gov
- CISA FY2024-2026 Cybersecurity Strategic Plancisa.gov
- CISA Secure by Designcisa.gov
- CISA Secure Software Development Attestation Formcisa.gov
- CISO Assistant - open-source GRC platform for risk management, compliance and auditgithub.com
- Claude Compliance API: Retrieve and delete chats, files, and projectsplatform.claude.com
- Delve at RSA 2026 LinkedIn post - comments call out fraudulent SOC 2 compliance reportslinkedin.com
- Delve CEO Karun Kaushik responds to allegations of fabricated compliance evidencex.com
- Delve, YC-backed AI compliance startup, accused of faking SOC 2 and ISO 27001 reportsx.com
- DORA - Digital Operational Resilience Actdora-info.eu
- Drata Integrations - security and compliance automation platformdrata.com
- Drata's Acquisition of oak9 Ushers in New Era of Compliance as Codedrata.com
- Evaluation of NIST's Management of the National Vulnerability Database - Commerce OIG Reportoig.doc.gov
- FedRAMP CSP Vulnerability Scanning Requirementsfedramp.gov
- filegrc - Git and file-based SOC 2github.com
- Gergely Orosz: Context.ai's SOC2 audit by Delve and its trust page redirecting to Delvex.com
- grclanker - terminal-first compliance evidence agent with CMVP, KEV and EPSS lookupsgrclanker.com
- Hard Truths Your CISO Won't Tell You - slide deckslideshare.net
- JPMorganChase - An open letter to third-party suppliers on SaaS securityjpmorgan.com
- Kviklet - pull request-style review and approval flow for database accessgithub.com
- Microsoft Secure Future Initiative - secure by designmicrosoft.com
- MITRE Security Automation Framework - SAFsaf.mitre.org
- National Cybersecurity Strategy 2023whitehouse.gov
- OMB M-22-09: Moving the U.S. Government Toward Zero Trust Cybersecurity Principleswhitehouse.gov
- Opportunities for AI in cyber defence - NZ NCSC guidancencsc.govt.nz
- Restricting access to GitHub.com using a corporate proxy - GitHub Enterprise Cloud Docsdocs.github.com
- SEC Charges Four Companies With Misleading Cyber Disclosuressec.gov
- Securing the Future: Mitigating Data Security Concerns in Artificial Intelligence Models - ISACA Journalisaca.org
- Security is a Vendor Assessment Problem - Jonathan Pricesecurityis.substack.com
- Sierra launches PCI-compliant payments for AI agentssierra.ai
- SOC 2 Compliance Guidesoc2.fyi
- Tackling the National Gap in Software Understanding - CISAcisa.gov
- The AI Vulnerability Storm: Building a Mythos-ready Security Program - CSA, SANS and OWASP briefinglabs.cloudsecurityalliance.org
- The Case for Memory Safe Roadmaps - CISA, NSA, FBI and partnerscisa.gov
- U.S. Regulators Pause Cybersecurity Bank Exams Due to Mythosgovtech.com
- U.S. to roll out 'Cyber Trust Mark' label on secure devices starting this year - NBC Newswww-nbcnews-com.cdn.ampproject.org
- United States Files Suit Against Georgia Tech Alleging Cybersecurity Violationsjustice.gov
- vcs-access-review - auditor-ready GitHub org access review reports for SOC2github.com
Trust and adoption 7
- Algorithm Aversion: People Erroneously Avoid Algorithms After Seeing Them Errmarketing.wharton.upenn.edu
- Content Authenticity Initiative - open-source tools for content authenticity and provenanceopensource.contentauthenticity.org
- Lower Artificial Intelligence Literacy Predicts Greater AI Receptivityjournals.sagepub.com
- The Tragedy of the Cognitive Commons: How AI Could Disrupt the Regeneration of Professional Expertisearxiv.org
- Thinking - Fast, Slow, and Artificial: How AI is Reshaping Human Reasoning and the Rise of Cognitive Surrenderpapers.ssrn.com
- Thinking—Fast, Slow, and Artificial: How AI is Reshaping Human Reasoning and the Rise of Cognitive Surrenderdownload.ssrn.com
- vx-underground on Jira and Confluence training AI on your data unless you opt out by August 17x.com
Miscellaneous 6
- Go Beyond Chat: Make AI actually do things.arcade.dev
- MLX: An array framework for Apple silicongithub.com
- Order a Framework Desktop with AMD Ryzen™ AI Max 300frame.work
- Transforming Threat Modeling: Harnessing ChatGPT for Automated Secumeetup.com
- Flock Updates Privacy, Accountability, Security, and Transparency Safeguardsflocksafety.com
- United States Cyber Force - FDD report on creating a US Cyber Forcefdd.org