Is AI Use a CMMC Violation?

Is AI Use a CMMC Violation? Picture this: an employee pastes Controlled Unclassified Information (CUI) into ChatGPT to “clean up a report.” No new AI law was needed for that to become a compliance problem , under CMMC and DFARS, it may already be one. So when defense contractors ask “is there an AI law

Is AI Use a CMMC Violation? Read More »

How to Conduct an AI Security Risk Assessment: A Practical Guide for Organizations

AI security isn’t about replacing your existing cybersecurity program. It’s about extending governance, risk management, and security practices to address the unique risks introduced by artificial intelligence. Over the past few years, nearly every conversation I’ve had with organizations about AI adoption eventually lands on the same question: how do we actually know our AI

How to Conduct an AI Security Risk Assessment: A Practical Guide for Organizations Read More »

What Can We Learn from OpenAI, Anthropic, and Google’s Approach to AI Governance?

Over the last year, I’ve noticed something interesting. Whether I’m speaking with executives, board members, cybersecurity professionals, or risk teams, the conversation eventually comes back to the same question: How do we govern AI without slowing down innovation? Everyone wants to take advantage of AI. Organizations see the opportunities. They see the productivity gains, the

What Can We Learn from OpenAI, Anthropic, and Google’s Approach to AI Governance? Read More »