Cyber security

AI Agent Security: What the RubyGems and Hugging Face Incidents Reveal

Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.

Widespread AI Security Failures in UK Retail Demand Sharper Cyber Risk Ownership

RiverSafe’s Censuswide survey of 200 senior security leaders at large UK retailers reported AI-related incidents, unapproved tools and incomplete security reviews. The UK Government’s Cyber Security Breaches Survey and NCSC secure-AI guidance show how boards can convert that warning into access, supplier, monitoring and incident controls.

Third-Party AI: Someone Else Built the Autopilot, but You’re Still Flying the Plane

APRA's April 2026 letter named third-party AI risk as the biggest gap in bank and insurer oversight — and weeks later, a compromised account at AI tooling vendor Context.ai gave attackers a path into Vercel's infrastructure. This piece uses both to show why vendor assurance paperwork isn't AI risk management, and what to ask instead.

Third-Party AI Dependency Requires Rigorous Risk Management

HM Treasury's move to designate AI providers as UK critical third parties, a German court ruling that made a chatbot's words the company's legal liability, and the Character.AI/Google settlement all show the same pattern: vendor AI risk is now the deploying organisation's problem, not the vendor's. Here's what boards and risk teams need to check before the next case names them instead.

Why Over-Reliance on Vendor AI Assurances Puts Your Organisation at Risk

Deloitte's $290,000 government report scandal, AICD's warning on AI vendor concentration risk, and the UK's new Critical Third Parties regime all expose the same gap: accountability for AI-enabled outcomes can't be outsourced to the vendor that built the tool. Here's what risk and governance teams should check before relying on vendor AI assurances.

Leveraging AI risk in third-party relationships the right way

Third-party vendors increasingly embed AI into their services, yet many organisations rely too heavily on vendor assurances without independent verification. Effective AI risk management demands clear ownership, thorough evidence review, and ongoing oversight to meet governance and regulatory expectations.

Recent posts