Secure Runtime Evolution for AI Coding Agents
What is the logical progression in AI (Artificial Intelligence) coding-agent runtime design from local process/Operating System (OS) sandboxes, through shared Continuous Integration (CI)/cloud develop…
Privacy-preserving long-term memory for Artificial Intelligence agents
How can Artificial Intelligence (AI) agents preserve the utility of long-term memory for personalisation and historical context while enforcing privacy, security, and data-sovereignty controls strong…
What benefits, risks, and lifecycle costs of shadow Information Technology (IT)…
What benefits, risks, and lifecycle costs of shadow Information Technology (IT) and custom local tooling are documented, and which governance approaches successfully transition covert local solutions…
State Space Explosion and Deterministic Chaos
How do state space explosion in concurrent systems and chaos theory, especially sensitive dependence on initial conditions, mirror the fragility of machine learning models when subjected to minor inpu…
The Halting Problem and Rice's Theorem
How do the Halting Problem (Turing) and Rice's Theorem formalise the absolute boundary of static analysis, proving that it is mathematically impossible to write a general algorithm to verify whether a…
Stochastic LLM Agent vs. Deterministic Coded System
How do the failure modes of a stochastic multi-step Large Language Model (LLM) agent, meaning a tool-using system whose action path can vary across runs, differ fundamentally from the failure modes of…
Structural Stability vs. Predictive Fragility
Using dynamical systems theory, how does the fragility of a purely predictive model under input noise or system drift differ from the local qualitative stability of a model whose governing equations p…
Failure Modes of Instrumentalist Epistemology When Applied to Complex Dynamic…
What are the operational failure modes of an epistemic framework that prioritises instrumentalism, treating predictive performance as the primary criterion, over explanatory reach when applied to comp…
Visibility and exit outcomes
How often does vendor-supplied temporary operational automation produce materially worse visibility and exit outcomes than internally governed temporary operational automation?
Policy Quality Degradation and Cross-Institution Blind Spots When New Policy…
What policy-quality degradation and systemic blind-spot risks emerge when organisations draft new policy versions from Large Language Model (LLM) interpretations of previous policy versions?
LLM Response Style and Confidence Signalling
How do Large Language Model (LLM) response style and self-reported confidence change how accurately users judge uncertainty and downstream risk when interpreting ambiguous policy and compliance requir…
LLM Training Prior Contamination in Compliance Interpretation
What failure modes emerge when Large Language Models (LLMs) combine generic public legal knowledge with proprietary organisational policy in compliance interpretation tasks?
Cognitive Closure Under Ambiguity and Confirmation Bias
How do pressures to reach a quick, definite answer under ambiguity and iterative prompt refinement influence acceptance of flawed Large Language Model (LLM) policy interpretations?
De Facto Policy Drift From Repeated Unverified LLM Interpretations
How quickly do repeated unverified Large Language Model (LLM) interpretations create de facto policy norms that diverge from executive intent and board-level risk appetite?
Adversarial prompting risks in policy assistants
How vulnerable are corporate compliance Large Language Models (LLMs) to adversarial prompting that reframes restrictive policy as permissive guidance, and which controls detect or contain deliberate m…
AI-Assisted Policy Interpretation and Accountability Displacement
How does integration of Large Language Models (LLMs) into policy-ambiguity resolution change liability allocation, escalation behaviour, and an organisation's ability to justify the resulting decision…
ServiceNow Artificial Intelligence (AI) Control Tower
What is the complete set of features, functions, and capabilities offered by ServiceNow AI Control Tower, and how do those capabilities address enterprise Artificial Intelligence (AI) governance, obse…
Governance structures that support investment in delivery capability without…
Under what governance conditions can investment in building durable delivery capability be made reliably without placing risk, cost, and benefits accountability under one owner, and what minimum autho…
External Dependency Surface Taxonomy for Production LLM Agents
What is the complete taxonomy of external dependencies for a production Large Language Model (LLM)-based agent, how does each dependency class fail, what is the blast radius of each failure class, and…
Universal Entity Lifecycle Governance Framework (UELGF) 8-layer organisational…
What is the most suitable knowledge representation architecture for evolving the Universal Entity Lifecycle Governance Framework (UELGF) 8-layer organisational context model from static classification…
Declaration of the Independence of Cyberspace
What are the historical origins and core claims of John Perry Barlow's *Declaration of the Independence of Cyberspace*, how have those claims influenced modern research and technology governance, and…
Vendor Non-Compliance With or Absence of Implementation Standards
What failure modes have been empirically observed in organisations where vendors do not comply with established implementation standards, or where implementation standards are absent or insufficiently…
Separated Risk, Cost, and Benefits Accountability Across Business Units
What failure modes have been empirically observed in organisations where accountability for risk, operational cost, and benefits realisation are held in separate business units (BUs) rather than co-lo…
International Organization for Standardization (ISO) and International…
What is International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 for an Artificial Intelligence Management System (AIMS), and which specific…
Security, Compliance, and Governance Risks of Using Generative AI (GenAI) Tools…
What are the documented security, compliance, and governance risks of using Generative Artificial Intelligence (GenAI) tools such as Microsoft 365 (M365) Copilot for drafting memos, reports, and other…
Control deficiencies from bypassing designated workforce record platforms
What control deficiencies are most common when designated workforce record platforms are bypassed by spreadsheet, presentation, and list-based shadow workflows?
Taxonomy criteria: process inefficiency versus hidden control and dependency…
Which explicit criteria best distinguish ordinary process inefficiency from hidden control and dependency risk in workforce-capacity and skill-tracking workflows?
Process-Risk-Control (PRC) scoring impacts from unstandardized workforce…
How should inherent risk, meaning exposure before relying on controls, and control effectiveness, meaning the demonstrated reliability of the mitigating control, scores in a PRC library change when wo…
Language Server Protocol (LSP)-style policy surfaces and workforce taxonomies…
How can workforce-capacity and skills-taxonomy structures integrate with a Language Server Protocol (LSP)-style policy diagnostic surface to detect persistent capability mismatches automatically in en…
National Institute of Standards and Technology (NIST) Special Publication (SP)…
How do missing provenance, lineage, and change-history controls in Microsoft Lists, Excel, and PowerPoint workforce artifacts conflict with NIST SP 800-53 Rev. 5 integrity-related controls?
Key-person dependency and Basel execution, delivery, and process-management…
How should key-person dependency in workforce-critical processes be mapped to execution, delivery, and process-management risk categories in Basel Committee framing?
Control Objectives for Information and Related Technologies (COBIT) and…
What minimum process-definition conditions do COBIT 2019 and CMMI require before mitigation of workforce-process risk can be considered effective and sustainable?
Basel Committee on Banking Supervision (BCBS), International Organization for…
How do Basel Committee on Banking Supervision (BCBS), International Organization for Standardization (ISO) 31000, and National Institute of Standards and Technology (NIST) frameworks classify risk whe…
Implementation Patterns for Regulatory Compliance in Artificial…
What specific implementation patterns, including externalized machine-executable policy rules (Policy-as-Code (PaC)), rules engines, input, tool-use, and output safety controls (guardrails), output va…
Extending Traditional Data Governance Frameworks to Address Large Language…
How can traditional data governance frameworks be extended or mapped to address the inherent non-determinism and uncertainty about whether deployed behavior remains aligned with intended use in modern…
Compliance Risks of Relying on Stochastic Large Language Model (LLM) Outputs…
What evidence or guidance exists on the compliance risks of relying primarily on stochastic Large Language Model (LLM) outputs for governance, privacy, or regulatory decisions?
Orthogonality thesis under modern Large Language Model (LLM) training and…
How should the orthogonality thesis be interpreted for modern Large Language Models (LLMs) given current pre-training and post-training methods, and what does that imply for enterprise risk when agent…
What are the primary behavioural and structural drivers of unsanctioned AI…
What are the primary behavioural and structural drivers of shadow Artificial Intelligence (AI) adoption, meaning unsanctioned use of AI tools without formal approval or oversight, in enterprises after…
How do coupled enterprise risks manifest differently in agentic Artificial…synthesis
How do the coupled enterprise risks, capability debt, incentive-driven shadow Artificial Intelligence (AI) adoption, skill decay, and oversight failure, manifest differently in agentic AI, meaning aut…
How can organisational capability debt be rigorously defined and measured as a…
How can capability debt, the accumulated organisational deficit in review quality, judgment, process maturity, and skill inventory, be rigorously defined, measured, and tracked as a leading indicator…
Updating the enterprise Artificial Intelligence ecosystem capability reference…synthesis
How should the enterprise Artificial Intelligence (AI) ecosystem capability reference architecture (as expressed in `2026-04-22-enterprise-ai-capability-model`, `2026-05-05-enterprise-ai-capability-st…
Production incidents linked to Artificial Intelligence systems
What documented production incidents over the last five years were caused or materially contributed to by Artificial Intelligence (AI) systems, and what recurring failure modes and mitigations were id…
Artificial Intelligence (AI) regulatory guidance delta checksynthesis
Since the completion of `2026-04-24-ai-agent-regulation-global-financial-services`, what newly issued regulatory advice, policy, guidance, or supervisory statements have been published on Artificial I…
Five Eyes stance on Artificial Intelligence risk and policy advice
What is the current stance of the Five Eyes intelligence alliance (Australia, Canada, New Zealand, United Kingdom, United States) on Artificial Intelligence (AI) risks, and what concrete policy and op…
Integrating 2026-05 security and supply chain findings into the enterprise…synthesis
How should the enterprise Artificial Intelligence (AI) ecosystem capability reference architecture (as expressed in `2026-04-22-enterprise-ai-capability-model` and the `2026-05-05-enterprise-ai-capabi…
How do open-weight policy enforcement reasoning models, exemplified by OpenAI's…
How do open-weight, meaning released-weight and self-hostable, policy enforcement reasoning models, exemplified by OpenAI's gpt-oss-safeguard, classify text against strict, customizable policies, and…
What is the minimal viable schema for an Artificial Intelligence bill of…
What is the minimal viable set of schema properties required to describe Artificial Intelligence (AI) system dependencies for systems that use prompts, retrieval knowledge bases, memory, and tools in…
Why does Software Bill of Materials (SBOM) fail as a complete inventory model…
Why do traditional Software Bill of Materials (SBOM) concepts fail to adequately describe the dependency, provenance, and runtime composition of agentic Artificial Intelligence (AI) systems, and what…
How do you capture a runtime-observed Artificial Intelligence Bill of Materials…
How do you instrument a real agentic Artificial Intelligence workload, meaning a tool-using workload that plans or acts across multiple steps, to capture a runtime-observed Artificial Intelligence Bil…
How does the European Union (EU) AI Act and related international AI governance…
- [fact; source: https://owaspaibom.org/] Artificial Intelligence Bill of Materials (AIBOM) is used here in the Open Worldwide Application Security Project (OWASP) sense of an artifact intended to mak…
How should identity, delegation chains, and permission scopes be formally…
How should identity, delegation, and permission scopes be formally represented in an Artificial Intelligence Bill of Materials (AIBOM) schema to enable end-to-end attribution, "who authorized what", a…
How do OAuth 2.0, OpenID Connect, and SPIFFE token propagation work in real…
How do OAuth 2.0 (Open Authorisation), OpenID Connect (OIDC), and SPIFFE (Secure Production Identity Framework for Everyone) token propagation mechanisms work in real multi-agent Artificial Intelligen…
What security and governance risks can a declared and runtime-observed…synthesis
What categories of security and governance risk can an Artificial Intelligence Bill of Materials (AIBOM), an artifact intended to make artificial intelligence systems transparent, auditable, and secur…
How do you construct a declared design-time Artificial Intelligence Bill of…
How do you extract and construct a declared design-time Artificial Intelligence Bill of Materials (AIBOM), covering model, prompt or system instruction, tools, Retrieval-Augmented Generation (RAG) kno…
What adversarial review and red-teaming methods are most effective for…
What adversarial review and red-teaming methods, drawn from Artificial Intelligence (AI) safety research, debate-based evaluation, formal argumentation theory, and scientific peer review practice, are…
What security capabilities are required in an enterprise Artificial…
What security capabilities are required in an enterprise Artificial Intelligence (AI) system, beyond basic Application Programming Interface (API) access controls and audit logging, to address prompt…
How do errors compound in Artificial Intelligence (AI)-agent-heavy codebases,…
How do errors ("boooos") compound in codebases developed with high volumes of AI agent-generated code, including how local patches cause global regressions, and what review and governance strategies c…
What criteria define tasks where Artificial Intelligence (AI) coding agents…
What empirically grounded criteria define the characteristics of software development tasks where Artificial Intelligence (AI) coding agents reliably add value, versus tasks where agent autonomy intro…
Deterministic weighted scoring models for customer risk rating under MLR 2017
To what extent do deterministic weighted scoring models (based on the four main risk factors: customer, geographic, product/service, and delivery channel) effectively support a proportionate risk-base…
Anthropic Claude Teams or Enterprise vs Microsoft 365 Copilot Coworksynthesis
How do Anthropic Claude, specifically the Team and Enterprise plans, and Microsoft 365 (M365) Copilot Cowork compare across capability, pricing, user experience, and guardrails, and what are the secur…
Explainable Artificial Intelligence (XAI)
What is the current state of Explainable Artificial Intelligence (XAI) research, who leads it and what are the primary techniques, and how does XAI intersect with regulatory obligations, audit require…
Universal Entity Lifecycle Governance Framework (UELGF) extension
What concrete reference architecture and tooling specification, covering policy-as-code engines such as Open Policy Agent (OPA) and Cedar, observability pipelines such as OpenTelemetry (OTel), and mod…
Universal Entity Lifecycle Governance Framework (UELGF) extension
What explicit human oversight and accountability requirements, covering named human owners for every governed entity, defined escalation paths for high-risk autonomous actions, accountability designat…
Universal Entity Lifecycle Governance Framework (UELGF) extension
What agentic Artificial Intelligence (AI)-specific risk categories, specifically emergent behaviour, goal misalignment, multi-agent interaction failures, and hallucinations in decision loops, are insu…
Universal Entity Lifecycle Governance Framework (UELGF)
What is the complete specification of the Universal Entity Lifecycle Governance Framework (UELGF), integrating foundational definitions and principles, entity taxonomy and Confidentiality, Integrity,…
Universal Entity Lifecycle Governance Framework (UELGF)
What policy architecture, covering Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP), and what 8-layer organisational c…
Universal Entity Lifecycle Governance Framework (UELGF)
What canonical entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification system should the UELGF use to determine governance intensity, ensuring that every entity type, fro…
Universal Entity Lifecycle Governance Framework (UELGF)
How should the UELGF formally specify the decommission lifecycle, including a complete trigger taxonomy, procedural requirements differentiated by CIA tier, a ghost-entity detection and remediation me…
Invariant-based anomaly detection in the Policy Information Point (PIP)
How can the Policy Information Point (PIP) detect when a governed asset's transient operating context is being used, intentionally or through task creep, to suppress or obscure a permanent invariant,…
Policy Administration Point (PAP) dynamic policy profiling and proportionality
How can a Policy Administration Point (PAP) dynamically map a governed asset's metadata, specifically its invariants and Confidentiality, Integrity, and Availability (CIA) ratings, to a proportional a…
Out-of-band policy invalidation and remediation
What consistency model governs [Policy Administration Point (PAP)](https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html)-to-[Policy Enforcement Point (PEP)](https://docs.oasis-open.org…
What is the precise technical distinction between code generation and other…
What is the precise technical distinction between code generation and other Large Language Model (LLM)-generated outputs in terms of external verifiability, specifically, that code operates in a forma…
What constraints do vendor platforms impose on governance, and how should…
What governance constraints are imposed by major vendor Artificial Intelligence (AI) and low-code platforms, specifically, what governance capabilities are natively supported versus where external con…
How can enterprise data governance frameworks be consistently enforced within…
How can enterprise data governance frameworks be consistently enforced within Artificial Intelligence (AI) and visual, minimal-code application environments, specifically, how should data classificati…
How should Artificial Intelligence (AI) and low-code use cases be classified…
What structured risk classification framework is appropriate for AI and low-code use cases in enterprise environments, specifically, how should categories such as informational, decision-support, and…
How can enterprise Artificial Intelligence (AI) and low-code governance…
How can enterprise Artificial Intelligence (AI) and low-code governance frameworks be aligned with external regulatory and compliance obligations, specifically, what is the mapping between governance…
What maturity model best describes the evolution of governance capabilities for…
What maturity model best describes the evolution of governance capabilities for AI and low-code in enterprises, specifically, what are the clearly defined maturity stages, capability benchmarks, and p…
Where should governance enforcement points be implemented within enterprise…
Where should governance enforcement points be implemented within enterprise architecture for Artificial Intelligence (AI) and low-code systems, specifically, at which architectural layers (Application…
What are the primary failure modes in enterprise Artificial Intelligence (AI)…
What are the primary failure modes in enterprise Artificial Intelligence (AI) and low-code deployments, including data leakage, conflicting automations, unintended actions by AI agents, and loss of au…
How should decision rights, accountability, and liability be structured for…
How should decision rights, accountability, and liability be structured for AI systems and low-code applications in enterprise environments, specifically, who should be empowered to approve new use ca…
How do organisational incentives, culture, and behaviour influence adherence to…
How do organisational incentives, culture, and behaviour influence adherence to governance in Artificial Intelligence (AI) and low-code environments, specifically, what conditions drive teams to bypas…
What identity and access management model is required for Artificial…
What identity and access management (IAM) model is required for non-human actors, AI agents and low-code artefacts, operating within enterprise systems, specifically: how should machine identities be…
Implicit rate-limiting controls removed by agentic Artificial Intelligence (AI)
Prior to agentic Artificial Intelligence (AI), the blast radius of ungoverned citizen development was implicitly bounded by human speed, attention, fatigue, and working hours, controls that are not do…
Access control amplification under agentic operations
Agents do not inherit a user's typical behaviour, they inherit the worst-case interpretation of that user's full permission set, because they operate without fatigue, attention limits, or working hour…
Permission-safe Retrieval-Augmented Generation (RAG) in enterprise information…
What are the technical constraints on permission-safe Retrieval-Augmented Generation (RAG) in an enterprise information architecture with incoherent access controls, collaboration groups created ad ho…
Dependency ordering of foundational conditions for safe agentic Artificial…
The foundational conditions for safe agentic AI deployment in a regulated financial institution are not independent, they form a dependency graph in which policy coherence is a prerequisite for inform…
Systems capability debt as the root cause of citizen development
What empirical evidence exists that systems capability debt, the accumulated gap between what people need from their systems and what those systems deliver across integration, functionality, data acce…
Systems capability debt, citizen development, and agentic AI risk
Does the synthesis of technical debt literature (Cunningham, Kruchten), systems capability research, transaction cost economics (Coase, Williamson), operational risk frameworks (Basel III/IV, Risk and…
Regulatory and standards preconditions for deployment of Artificial…
Under applicable regulatory and standards frameworks, including Australian Prudential Regulation Authority (APRA) CPS 230, the European Union (EU) Digital Operational Resilience Act (DORA), Payment Ca…
Multi-provider AI control planes
Which platforms or architectural designs provide multi-provider Artificial Intelligence (AI) control planes that unify discoverability, oversight, logging, security, data-access control, Financial Ope…
What is Microsoft 365 Copilot Cowork and what are its enterprise governance…
What is Microsoft 365 (M365) Copilot Cowork, how does it technically differ from custom Microsoft Copilot Skills, and what are the governance, legal, and shadow Information Technology (IT) risks it in…
Global artificial intelligence agent regulation in financial services
What regulatory obligations do financial-services regulators globally, including the European Union (EU), Australia, New Zealand (NZ), the United States (US), and the United Kingdom (UK), impose on Ar…
Business-led low-code agent governance
Under what conditions does business-led low-code Artificial Intelligence (AI) agent creation produce durable organisational value versus technical debt and governance fragmentation, and what foundatio…
Knowledge curation governance as an enterprise AI capability in regulated…
What operational models exist for governing authoritative knowledge as a managed enterprise capability for Artificial Intelligence (AI) consumption in regulated financial institutions, covering domain…
Enterprise AI use-case routing frameworks
What decision frameworks do enterprises use to route Artificial Intelligence (AI) use cases to the appropriate platform, implementation pattern, and risk tier, distinguishing low-code business-led, pr…
Anthropic Claude Code leak
What does the accidental March 2026 leak of Anthropic's Claude Code source code reveal about: (1) the codebase architecture, (2) how key engineering problems are solved, (3) the prompting and instruct…
Claude Code npm Source Map Leak
How did the March 2026 accidental leak of Anthropic's Claude Code source code via an npm (Node Package Manager) package occur, and what processes and protections can organisations adopt to prevent sim…
Large Language Models as offensive security tools
What is the current state of Large Language Model (LLM)-driven offensive security capability: can LLMs autonomously discover and exploit zero-day (0-day) vulnerabilities, what does the empirical evide…
Claude Code on the web
Does Claude Code on the web automatically initialise git submodules when cloning a repository, and if so, can it access private submodules (such as `davidamitchell/Skills` referenced at `.github/skill…
Public sentiment on AI in banking and high-trust institutions
What does current (2024–2025) survey data reveal about customer sentiment toward Artificial Intelligence (AI) in banking and high-trust Financial Services (FS) institutions — in Australia, across Asia…
Cross-Scanner Compliance Evidence and Waiver Normalisation in GitHub Actions
How should an organisation running multiple compliance scanners in GitHub Actions normalise evidence, severity, waiver handling, and developer-facing output so that heterogeneous tools behave like one…
Compliance Scanning via GitHub Actions — Broad Policy as Code Across a…
How can GitHub Actions (with GitHub Advanced Security (GHAS) and CodeQL already enabled) be extended to enforce a broad, organisation-wide compliance policy — covering naming conventions, architectura…
Adaptive Policy-Based Authorization (APBA)
How does Adaptive Policy-Based Authorization (APBA) align with the dynamic access-control requirements of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and ISO/…
Trusting Trust and AI Corpus Contamination
Ken Thompson's "Trusting Trust" argument shows that you cannot verify a compiler by reading its source code if the compiler was compiled by a compromised toolchain — the contamination lives in the bin…
Prompt injection threat landscape
What is the current state of the prompt injection threat in agentic artificial intelligence (AI) systems: who is exploiting it, who is defending against it, and what does the research community consid…
Failure mode taxonomy
The five-layer failure mode taxonomy established in `2026-03-10-ai-concept-classification-taxonomy.md` (Q5) provides a structurally sound classification, but leaves three empirical gaps unanswered: (1…
Adversarial agents with shared goals
What is the design pattern for a system of agents — human or AI — that share a common goal but deliberately occupy different competency domains and time horizons? How does "adversarial collaboration"…
Guiding Headless Agents via LSP-Like Mechanisms for Org Policy Conformance
Who is building solutions that allow headless autonomous coding agents to be guided in real time by LSP-like mechanisms — rather than CI gates or pre-commit hooks — to conform to an organisation's sec…
RBNZ AI Supervisory Expectations
What are the Reserve Bank of New Zealand's specific supervisory expectations for AI use by regulated entities, and how do these align with or diverge from the expectations of comparator regulators (AP…
Pre-Training Origins of Hallucination-Associated Neurons — Implications for LLM…
Given that Hallucination-Associated Neurons (H-Neurons) emerge during pre-training rather than instruction tuning or RLHF, what does this reveal about how hallucination-prone behaviour is encoded duri…
Over-Compliance in LLMs — How H-Neurons Drive Sycophancy and What Interventions…
What exactly is over-compliance behaviour in LLMs, how do Hallucination-Associated Neurons (H-Neurons) cause it, and what neuron-level and inference-time interventions are feasible to reduce it withou…
H-Neurons Synthesis — From Hallucination Mechanisms to Actionable LLM…
Across all four preceding research items — the macroscopic hallucination landscape, the H-Neurons paper, over-compliance interventions, and pre-training origins — what is the unified, actionable pictu…
Hallucination-Associated Neurons (H-Neurons) in LLMs — Identification,…
What are Hallucination-Associated Neurons (H-Neurons) in large language models, how can they be identified, what behaviours do they cause, where do they come from, and what do these findings imply for…
LLM Hallucinations — Types, Causes, and Current Mitigation Approaches
What are the established types, root causes, and current mitigation strategies for hallucinations in large language models, and what does the macroscopic (training-level) view leave unexplained that m…
Artificial Intelligence (AI) security strategy
Which organisations have developed coherent AI strategies with security as the primary objective — either using AI to enhance security posture or governing the security risks that AI systems themselve…
Artificial Intelligence (AI) risk-reduction deployments in financial services
Which organisations have developed AI strategies explicitly framed around risk reduction — operational risk, credit risk, fraud, compliance, model risk — and what governance structures, outcome metric…
Artificial Intelligence (AI) agents in financial services line 1 and line 2…
Who is currently building or deploying AI agents specifically positioned to operate within the three lines of defence model — line 1 (business/operational risk management) and line 2 (risk and complia…
AI for Control Testing, Gap Identification, and Policies/Standards Reviews
Which organisations are using AI to automate control testing, identify control gaps, or conduct policies and standards reviews — and what does the current vendor, practitioner, and regulatory landscap…
AI Strategy: global and NZ examples, policy frameworks, regulations, and…
What do leading global AI strategies look like, how does New Zealand's regulatory and policy landscape (RBNZ, DIA, MBIE, and others) compare, and what use-case typology — from human augmentation throu…