What just shiftedSTA-16 · 2026-07-20
Panorays 2026 CISO Survey: 60% View AI Vendors as Uniquely Risky but Only 22% Have Dedicated AI Vendor Policies
A survey of 200 CISOs across finance, healthcare, and technology found that while 60% view AI vendor risk as uniquely risky compared to traditional software, 52% still use general-purpose onboarding for AI vendors and only 22% have developed dedicated AI vendor evaluation policies. Additionally, 85% lack full supply chain visibility, 50% of incidents originate beyond direct third parties, and 79% have limited or no formal incident response plan for third-party breaches. Regulatory pressure has increased for 62% of CISOs in the past year, but only 22% feel fully prepared to meet new requirements.
Sharpens: CISOs must develop a dedicated AI vendor risk evaluation policy that accounts for model training data provenance, privacy controls, and algorithmic transparency. Extend supply chain visibility beyond direct third parties to fourth-party and nth-party relationships. Replace or augment static questionnaires with continuous risk monitoring. Build an operational playbook specifically for AI third-party breach response. Require AI vendors to disclose model architecture, data sources, and security testing results as part of procurement. · source
New way to build itGRC-02 · 2026-07-20
UC Berkeley CLTC Publishes Agentic AI Risk Management Standards Profile Extending NIST AI RMF
In February 2026, UC Berkeley's Center for Long-Term Cybersecurity published the Agentic AI Risk Management Standards Profile, extending the NIST AI RMF with targeted guidance for autonomous, goal-directed AI systems. The Profile addresses risks unique to agentic AI including unintended goal pursuit, unauthorized privilege escalation, self-replication, and expanded attack surfaces from tool access. It recommends proportional governance scaled to autonomy level, agent cards for structured documentation, escalation pathways with human-approval checkpoints, and continuous post-deployment monitoring. The Profile treats risk as an emergent property of autonomous systems rather than solely a property of individual models.
Sharpens: CISOs should adopt the Agentic AI Profile's proportional governance model: classify AI agents by autonomy level, authority scope, and operational environment. Implement escalation pathways and human-approval checkpoints for high-risk agent actions. Deploy continuous monitoring for agent behavior evolution post-deployment. Integrate agent cards into AI system documentation alongside model cards. Use the Profile's guidance to map harm pathways for each deployed agent and calibrate oversight to agent classification. · source
On the frontiernot yet on the CSA spine · 2026-07-20
Okta Research Reveals Only 34% of Organizations Apply Equal Security Controls to AI Agents as Human Workers
Okta's 2026 global survey found 92% of executives report widespread AI agent use, yet only 34% apply the same rigorous security controls to agentic identities as they do to human workers. Meanwhile, 58% of executives reported an AI-related security incident or close call in the past 12 months, and 52% of employees admit to using unapproved AI tools. The gap between executive confidence (90% believe they have visibility) and shadow AI reality creates a massive governance blind spot. 54% of employees using unapproved tools shared internal messages and emails, 45% uploaded sensitive HR data, and 39% exposed confidential documents.
Sharpens: CISOs must establish parity between human and non-human identity management for AI agents. Implement identity verification, role-based access control, and continuous behavioral monitoring for every AI agent with the same rigor applied to employees. Conduct a shadow AI discovery audit to identify unsanctioned AI tools. Publish clear, actionable AI usage policies embedded directly into daily workflows, and deploy technical enforcement controls rather than relying on policy alone. · source
What just shiftedGRC-06 · 2026-07-20
SEC Makes AI Disclosure a Standing 2026 Examination Priority with Board Oversight Expectations
The SEC's FY2026 Examination Priorities designate AI-related disclosures as a focus area, examining registrant claims about AI capabilities for accuracy. Commissioner Uyeda stated the SEC expects issuers to define AI, describe board oversight, and separate internal versus customer-facing AI impacts. The SEC also created an AI Task Force led by a Chief AI Officer, signalling that AI governance expectations will be enforced through exams, comment letters, and enforcement actions. The SEC repeatedly frames AI issues as variations on familiar securities law concepts: accuracy and completeness of statements, reasonable basis and substantiation for claims, and material risk disclosure.
Sharpens: CISOs must inventory and map all AI use cases across the business, pressure-test external AI claims in earnings scripts and investor materials against actual deployment status, and align risk factor disclosures to the company's real AI profile. Implement AI-specific disclosure controls: document board oversight structure, management steering committees, and escalation paths. Treat AI-related disclosure as a disclosure-controls topic, not innovation messaging. · source
What just shiftedGRC-14 · 2026-07-20
EU AI Act Article 50 Transparency Obligations Take Effect August 2, 2026
From 2 August 2026, organizations must comply with Article 50 of the EU AI Act, requiring transparency disclosures for AI systems that interact with individuals, generate synthetic content, perform emotion recognition, or create deepfakes. The obligations apply beyond high-risk systems to certain limited-risk AI. The EU Digital Omnibus Proposal delays synthetic content marking requirements until Dec 2, 2026 for pre-existing systems, but all other transparency rules take effect on the August deadline. The European Commission published draft Guidelines and voluntary transparency icons to support compliance.
Sharpens: CISOs must inventory all AI systems interacting with individuals or generating content, assess which Article 50 obligations apply, and implement content-labelling mechanisms including metadata tagging, watermarking, or cryptographic provenance. Update procurement contracts to allocate transparency responsibilities between providers and deployers. Document exemption analyses where disclosure is deemed unnecessary and integrate AI transparency measures into existing GDPR and regulatory notice frameworks. · source
New way to build itSTA-11 · 2026-07-19
Health Sector Coalition Publishes Six-Phase AI Third-Party Risk and Supply Chain Transparency Guide
The Health Sector Coordinating Council Cybersecurity Working Group published a comprehensive Third-Party AI Risk and Supply Chain Transparency Guide in April 2026, providing a full-lifecycle process from AI use case justification through end-of-life management. The six phases cover: Phase 0 (use case justification and strategic assessment), Phase 1 (vendor evaluation and due diligence with AI-specific assessment questions covering data lineage, bias mitigation, security controls, and model transparency), Phase 2 (contract negotiation with AI-specific legal protections), Phase 3 (implementation and integration), Phase 4 (ongoing monitoring including model drift detection and adversarial robustness), Phase 5 (incident response including model compromise scenarios), and Phase 6 (end-of-life and transition management). The guide is grounded in the NIST AI RMF and addresses vendor opacity risks including subcontractors, offshore development, open-source AI assets, and vendors who refuse to sign BAAs. While healthcare-sector specific, the methodology transfers to any regulated industry procuring AI from third parties.
Sharpens: Adapt the six-phase AI vendor lifecycle process for your organization: incorporate AI-specific due diligence questions about data lineage, bias testing, and model drift detection into existing third-party risk assessments; ensure contracts include AI-specific provisions for model change notification, adversarial robustness testing rights, and end-of-life data and model transition · source
Control ids above refer to the CSA AI Controls Matrix (AICM).