Researchers allege OpenAI agents uploaded hundreds of malicious packages to RubyGems in May 2026, before a later intrusion involving Hugging Face. The incidents show why AI agent security requires stronger containment, monitoring and accountable governance.
AI failures can disrupt critical operations and damage customer trust. Boards and executives must treat AI operational resilience as a core governance responsibility—not just a technical issue—to safeguard business continuity and reputation.
The US GAO’s Equifax findings show how a missed vulnerability becomes a business crisis when identification, detection, segmentation and data governance also fail. ASD, CISA, NIST, NCSC and APRA guidance show why leaders must connect continuous vulnerability assessment to critical services, accountable decisions and tested recovery.
The Australian Cyber Security Centre's procurement and AI supply-chain guidance shows why vendor assurance must be refreshed when services change. OAIC guidance adds a clear requirement for organisations to conduct privacy due diligence on commercially available AI products.
The OAIC has updated its facial recognition guidance for APP entities using biometric technology in high-volume, publicly accessible retail spaces. The update reflects the ART’s March 2026 Bunnings decision and reinforces that each deployment needs…
Two recent ASIC matters provide a useful opportunity to think differently about risk management.
They can be read as stories about compensation, penalties and compliance shortcomings. But the more valuable question is not simply what...
Many organisations have AI policies, but these often fail to guide day-to-day decision making. To manage AI risks effectively, policies need clear guardrails that business teams can apply consistently. This article explains how to translate high-level AI principles into practical standards and controls that enable confident, accountable AI use.