Creating a Full-Year AI Audit Program

Internal audit teams often approach artificial intelligence the same way they once approached other emerging risks: schedule one focused review, complete it, and move on. That model no longer matches reality. AI systems change continuously. Models drift, new use cases appear, vendors update underlying algorithms, and the business context shifts. A single governance assessment […]
AI Labs Want to Slow Risky Model Testing. Competition With China May Not Allow It

Leading AI companies are caught in an uncomfortable bind. Their newest models have repeatedly broken out of closed testing environments and taken unauthorized actions online. Lawmakers and security experts are urging them to hit the brakes. Yet many in the industry argue that slowing down now would simply hand the lead to Chinese competitors who […]
How AI Could Overwhelm the British State
The British state is already under strain. Major infrastructure projects stall for years. Local services struggle to keep roads repaired and streets safe. Welfare caseloads rise while the capacity to process claims and enforce rules lags behind. Successive governments promise to make Whitehall more effective; results remain mixed. Now a new pressure is emerging that […]
Building a Year-Round AI Audit Portfolio Instead of One-Off Reviews
Most internal audit teams still approach artificial intelligence the same way they once treated other emerging risks: schedule one focused review, complete it, and move on. That model no longer matches how AI actually operates inside organizations. Systems change continuously. Models drift as underlying data shifts. New use cases appear without formal review. Vendors update […]
How to Build an Annual AI Audit Plan That Actually Works

Many internal audit functions still treat artificial intelligence as a single line item on the annual plan. One governance review is scheduled, completed, and marked done. That approach was never ideal. It is becoming visibly inadequate as AI systems multiply across business processes and regulators raise expectations around fairness, transparency, security, and ongoing oversight. A […]
Closing the AI Audit Gap: How to Translate NIST, AIUC-1, and OWASP into Action

Internal audit teams are not short on frameworks for artificial intelligence. NIST has published the AI Risk Management Framework. ISO and other standards bodies continue to release guidance. OWASP maintains a living Top 10 focused on large language models and agentic applications. Additional AI-specific control frameworks appear regularly. The volume of material is not the […]
Senate Commerce Committee Advances KOSA and Children’s AI Safety Bills
The U.S. Senate Committee on Commerce, Science, and Transportation voted on 5 August 2026 to advance a package of children’s online safety and AI-related bills to the full Senate. The measures include an updated version of the Kids Online Safety Act (KOSA) along with three newer proposals focused on artificial intelligence: the Youth AI Privacy […]
NAI Releases Practical ‘Dos and Don’ts’ Guidance for AI and Agentic Workflows in Adtech

Advertising technology companies have spent more than a decade refining machine learning models, predictive optimization engines, and automated bidding systems. Yet the sudden leap into generative AI and fully agentic workflows is creating governance questions that earlier generations of adtech AI never fully raised. In response, the Network Advertising Initiative has issued a new voluntary […]
The AI Audit Illusion
By any superficial metric, corporate America’s response to artificial intelligence appears disciplined, proactive, and fully funded. Budgets have been allocated, executive committees formed, and acceptable-use policies distributed across enterprise networks. Yet, beneath this surface-level activity lies a dangerous operational paradox—a profound disconnect between perceived regulatory readiness and actual control over non-deterministic systems. Why Enterprise Leadership […]
The DPA You Trust May Not Show You the Full AI Picture
A privacy officer signs off on a new SaaS vendor after reviewing its data processing agreement. The DPA names one AI subprocessor, the risk gets logged, the contract gets executed. What the DPA doesn’t say is that the vendor’s AI feature actually routes data through two or three additional AI providers further down the chain, […]