175 practitioner articles on where governance programs look complete and are not, and what to do about it. From the author of the #DoNotBeLarry series.
The forensic analysis determined that data had been leaving the environment since the previous March. Not in bulk transfers that would have triggered volume-based alerts.
The data classification program is complete. Every data store has been assessed. Labels have been applied: public, internal, confidential, restricted.
The data security program that was mature eighteen months ago may be significantly less capable today if the organization went through a major reorganization, acquired a…
APIs are how personal data moves between systems today. The customer data that leaves the CRM for the marketing platform leaves through an API.
The encryption is strong. AES-256 at rest, TLS 1.3 in transit, end-to-end for sensitive communications. The cryptographic standards are current.
Container security is a well-developed discipline. Images are scanned for vulnerabilities. Runtime behavior is monitored. Network policies restrict container-to-container…
The developer needed realistic data to reproduce a bug that only appeared with production-scale record volumes and production-specific data patterns.
The backup job had been completing successfully for two years. The monitoring dashboard showed green every morning. The storage utilization reports confirmed that backup…
The integration was straightforward: the new analytics vendor's API received event data from the organization's mobile application. The API call was a standard HTTP reque…
Twenty states have enacted comprehensive consumer privacy laws. More are in progress. The laws share a common conceptual architecture: consumer rights, controller and pro…
The breach affected customer data across fourteen countries. The incident response team started the 72-hour GDPR notification clock from the moment awareness was establis…
Data sovereignty is the principle that data is subject to the laws and governance of the jurisdiction in which it is located. For organizations operating globally, data s…
Privacy policies describe how the organization handles personal data. They describe the purposes of processing, the legal bases, the rights individuals can exercise, and…
Schrems II was decided in July 2020. Standard contractual clauses were updated in June 2021. Transfer impact assessments were introduced as a requirement for demonstratin…
Data localization requirements tell organizations where data must be stored. They are legal requirements created by legislators. The compliance response to data localizat…
Answer the question precisely. Not in general terms — not 'primarily in the EU' or 'stored in our cloud provider's data centers.' Name the countries.
The proposition has intuitive appeal: if AI systems are too complex and too fast-moving for human governance processes to keep pace with, use AI to govern them.
Prompt injection is an attack technique in which malicious instructions are embedded in content that an AI system reads and processes, causing the system to follow the ma…
Third-party risk management was built around a manageable abstraction: the vendor has access to data or systems, the vendor's security practices affect the organization's…
Privacy law is built around data. Personal data is collected, processed, stored, and shared — and each of these activities creates obligations.
The EU AI Act came into force in August 2024. Its first wave of obligations — prohibitions on unacceptable-risk AI systems — applied from February 2025.
AI vendor safety claims are expressed as general properties: the model has been red teamed, content safety filters are applied, the model has been evaluated on standard b…
Model risk management was developed in financial services to govern the quantitative models used in credit scoring, trading, and risk calculation.
AI agents are not chatbots. They are autonomous systems that plan multi-step tasks, use tools to interact with external systems, make decisions without human approval at…