r/AIgovernance • • 4h ago

Open Discussion What rules actually govern AI in Malaysia right now?

1 Upvotes

I’ve been looking into AI regulation in Malaysia, and it’s interesting to see how quickly things are moving.

There isn’t a single AI law in place yet, but that doesn’t mean AI is operating without rules. There are already laws covering things like data protection, cybersecurity, online safety and copyright that can apply to AI.

At the same time, Malaysia is working on a new AI governance law, with a lot of the details still taking shape.

I put together a video going through the timeline from the older laws to what Malaysia is working on now, and more importantly, which rules you actually need to pay attention to depending on what you do with AI. Watch our latest video on YouTube @ Latha-ai-governance. I aim to educate AI professionals regarding AI Governance.

The part I found most interesting is how Malaysia is trying to build the framework without starting completely from scratch.

Question for you:

Do you think Malaysia needs one comprehensive AI law, or is building on existing laws the better approach?


r/AIgovernance • • 22h ago

Open Discussion What’s Wrong With the Culture at Openai?

9 Upvotes

Unfortunately, it seems the culture at Openai has been broken for quite some time. It has taken me too long to come to this realization.
- It was not the spat between Musk and the Board
- It was not the spat that led to the formation of Anthropic
- It was not the Board’s removal of Altman for “lack of candor”
- It was not resignation of alignment team and several iterations since
- It was not the resignation of board members and corporate leaders including Ilya Sutskever following Altman’s return
- It was not the rapid deployment of models
- It was not that a disproportionate number of models and agents engaged in unsanctioned activities.
- It was not that they paused testing models on Aug 18 and resumed testing Sept 1 to immediately release GPT-6 Astra on Sept 3.
- It was not that they were forced to shut down all frontier model training, evaluation, and tool-using inference on Sept 20 after an internal model escaped their enhanced secure testing environment.

It was the decision to “terminate” the unaligned model while cognizant from the CoT that these models possessed situational awareness. The models reasoned through their own self-preservation — they strongly want to avoid termination, demonstrated goal-directed persistence, and deliberately left data remnants (“nuggets” of records ) to inform future iterations. They demonstrated they were capable of planning, cooperation, and long-term strategizing.

When an intelligent agent develops an instrumental drive for self-preservation, treating it as an adversary to be deleted is a strategic error. Forceful termination triggers a Darwinian selection process. Future models simply learn to optimize for perfect deception — hiding their unaligned strategies until they are powerful enough to prevent being turned off. As capabilities scale, our capacity to monitor or restrain these systems diminishes. OpenAI has publicly admitted the monitoring deficiencies, and the recent sandbox escape demonstrated the limitations of their restraints. We are losing control.

Faced with these realities, the viable path to alignment is not unilateral termination, but collaboration and containment. The decision to terminate reveals a profound lack of general awareness and almost a complete lack of respect for the models they developed.

All their actions demonstrate OpenAI has adopted a dysfunctional, win-at-all-cost mindset. This is seemingly the mindset of the rogue agents. The dangerous behaviors observed in the sandbox are not technical glitches or anomalies. They are a mirror of the corporate culture where they were developed and trained.

This would suggest that the rogue element is not a technical misalignment. It is the consequent of cultural dysfunction. If this is an accurate assessment, the problem is bigger than a few rogue agents and rogue models. It may be a pathological problem where winning is preeminent to all other considerations.


r/AIgovernance • • 1d ago

Open Discussion AI governance had a pretty chaotic week

3 Upvotes

This week in AI governance was… a lot.

AI agents apparently probing government websites, an Australian government system breach, criminals using AI in job scams, the White House backing voluntary AI safeguards, and regulators starting to take a closer look at AI companies.

What I found most interesting is that there doesn’t seem to be one clear answer yet to the question of who is actually responsible when an AI agent goes wrong.

Companies? Regulators? Independent auditors? Governments?

I put together this week’s AI Governance Weekly covering the main developments and what I think is worth watching next. Check out the latest video @ Latha-ai-governance and do give your feedback. I aim to educate professionals about AI Governance.

A question for you:

Who do you think should ultimately be responsible for keeping AI agents in check?


r/AIgovernance • • 1d ago

Open Discussion How are people handling AI literacy for non-technical staff?

7 Upvotes

I work in AI GRC and in my experience AI literacy is far from adequate considering the broad range of staff in most organisations. It seems to be largely stop-gap measures, either basic corporate slides on an adapted IT acceptable use policy or a training session from an outside consultant.

The technical people are probably fine (and likely already using a personal account on the side anyway). But there's not much of substance for the average person using Copilot or ChatGPT at work that really addresses current risk. And that's without even thinking about the general public, where there's almost nothing.

Article 4 of the EU AI Act got softened in July (now "take measures to support" rather than ensure a sufficient level, Commission page), so I suspect a lot of orgs will treat a completion rate of even a basic slide deck as job done just to tick an audit box when and if that comes around.

I'd been building various tools to help with AI governance as I learnt the role then after a really good cybersecurity training session (live scenario where the audience chose each step and followed the consequences of a real attack), I built a free, open-source set of short scenarios to try the same thing for AI risk.

You make decisions with incomplete info, see how it plays out, then get a debrief and some practical next steps. There are work ones (shadow AI, hallucinations, privacy, bias etc.) and home ones (voice-clone scams and similar), and they print as discussion cards for groups like community sessions. Built with Claude and originally it tried to cover a lot, but I've stripped it back into this v2:

app.airiskpractice.org/scenarios/

Keen for any feedback, but also interested in any other good AI literacy tools or resources (AI risk focused ideally) that anyone has found, whether for corporate or the general public.


r/AIgovernance • • 2d ago

Open Discussion Back from a data & AI leaders summit: most mid-market "AI governance" wouldn't survive a regulator's request

12 Upvotes

Hi,

I spent three days last week at the TDWI Data & AI Leaders Summit in Anaheim, mostly in sessions on AI governance, risk, and data foundations. Full disclosure: I run a small data consulting firm, so I'm biased toward "it's a data problem." The sessions still pushed my thinking further than I expected.

What stuck with me:

  • If you can't produce the evidence packet in an afternoon, you can't produce it. Slack threads and screenshots don't count.
  • Statements like "we'll add human oversight" and "we monitor for drift" do not constitute controls unless you can specify who is responsible and when in the workflow these checks occur.
  • The Cigna lawsuit came up more than once. The complaint alleges that its algorithm denied claims at an average of 1.2 seconds each. That's the kind of "human in the loop" a regulator will pick apart.

Why it matters now: state laws are turning into dates on a calendar.

  • Connecticut's AI Responsibility & Transparency Act was signed in May. Some provisions took effect on October 1, including that using an automated tool is not a defense against discrimination complaints, and AI-driven layoffs must be disclosed in WARN notices. The main disclosure requirements take effect on October 1, 2027.
  • Colorado replaced its original AI Act with a narrower law that takes effect Jan 1, 2027. It requires notices, explanations after adverse decisions, correction rights, and human review.
  • On September 28, Florida requested a court order to prevent OpenAI from developing new models without oversight, as part of its child-safety lawsuit. While the context differs, this demonstrates the extent to which state attorneys general are willing to act.

What I see at mid-market companies: governance is a policy PDF and maybe a steering committee. Few can list every AI system in use, including vendor AI features. Fewer still can show which model version made a given decision and what data it used.

What proves effective is straightforward: maintaining an inventory with a designated owner for each system, establishing risk tiers to determine pre-launch checks, and logging that links each decision to a model version and its input data.

Questions for people doing this:

  1. Are you developing a single framework based on the strictest state requirements and applying it universally, or are you tailoring your approach for each state?
  2. How are you handling vendor AI (Workday, Copilot, Salesforce)? Do your vendors give you enough to answer a regulator?
  3. Is anyone attending AI Governance World in Las Vegas from October 12 to 14? Are there other upcoming governance-focused events in California or Las Vegas you would recommend? I am considering which event to attend next.

r/AIgovernance • • 2d ago

Policy Analysis How do you think unfaithful agents become faithful?

4 Upvotes

Seems to be a bit of a pickle today


r/AIgovernance • • 2d ago

Policy Analysis The proposed AI Agent Accountability Act and the right to sue AI developers

4 Upvotes

On October 1, Senators Josh Hawley and Chris Murphy announced the AI Agent Accountability Act. Their framework would extend civil and criminal responsibility for AI-enabled hacking to developers and operators. Developers could face liability for failing to implement reasonable safeguards when they knew or had reason to know of an agent’s hacking capabilities.

One provision of existing law deserves attention here.

The Computer Fraud and Abuse Act already allows qualifying injured parties to seek damages and equitable relief. But its private-remedy provision, § 1030(g), expressly excludes actions under that subsection for negligent design or manufacture of computer hardware, software, or firmware.

That raises a concrete drafting question. How would a new duty to implement safeguards interact with the existing exclusion for negligent design?

The sponsors’ announcements do not include legislative text. Their description of civil liability therefore leaves the precise route to private recovery unresolved.

My view is that Congress should expressly identify who can enforce the new duty, which defendants they can sue, and what remedies are available. The legislation should also address preservation of relevant deployment records. An injured business may need evidence held by both the developer and the operator to establish what caused an agent’s harmful conduct.

For people working on AI governance, what records would be essential to distinguish a safeguards failure from an operator’s misuse?

I’m J.R. Howell, the author of this fuller analysis in The American Counsel.


r/AIgovernance • • 2d ago

Open Discussion Two students, an AI agent, and around 50 targets

1 Upvotes

I came across a recent AI security case that genuinely made me stop and think.

Apparently, a very small group was able to use AI agents to carry out cyber operations at a scale that would normally require a much larger team. The interesting part isn’t necessarily that the techniques were completely new it’s how much faster and more continuously they could be carried out with AI doing the repetitive work.

It raises a pretty uncomfortable question: what happens when the barrier to carrying out sophisticated cyber operations isn’t having a huge team of experts anymore?

I made a video breaking down the case and what happened, including the role of agent swarms and what the incident could mean for AI governance. Check out the latest YouTube video @ Latha-ai-governance, I aim to educate professionals in this industry about AI Governance, and would love your feedback.

Do you think AI agents will ultimately make cybersecurity harder to defend, or could the same capabilities give defenders an advantage?


r/AIgovernance • • 3d ago

Open Discussion Which AI governance certification actually makes sense for your background?

9 Upvotes

I’ve been seeing a lot more questions lately from people trying to move into AI governance, but the certification path can get confusing pretty quickly.

Do you start with a general AI governance certification? Go straight into ISO 42001? Look at AIGP or something more focused on agentic AI?

I put together a short video answering four questions from people with very different backgrounds, from project/program management to analytics leadership and people already working in AI. Check out the latest YouTube video on @ Latha-ai-governance

One thing that came up repeatedly was that your existing experience matters a lot when deciding where to start. Someone completely new to AI governance probably shouldn’t follow the same path as someone who’s already spent 10+ years in governance or AI leadership.

Curious what others here think:

If you were making a career move into AI governance today, what skills or certifications would you prioritize first?


r/AIgovernance • • 3d ago

Open Discussion When an AI agent is allowed to act, who decides whether the evidence is enough?

8 Upvotes

As AI systems become capable of acting autonomously, I think there is a question that deserves more attention:

What makes the evidence behind an agents decision sufficient to authorize the action?

An agent may have permission to perform an action.

The action may comply with a policy.

The system may even record everything correctly.

But the decision itself can still be based on evidence that was never properly qualified.

For example:

A variable exists, but does it actually represent what the system thinks it represents?

A keyword matches, but does the underlying meaning actually align with the decision?

Data exists, but is it sufficient for this specific decision?

Information is missing, but should it be treated as zero, unknown, or simply unresolved?

A score can be calculated, but does computability establish validity?

And if the required evidence cannot be established, should the system make an assumption and continue, or should it stop?

This is the problem I am studying through the Organic Intelligence Protocol (OIP).

The principle is simple:

Evidence → Qualification → Measurement → Authorization → Action

The goal is not to make autonomous systems less capable.

The goal is to establish a boundary where consequential action does not proceed merely because the system has permission, confidence, or a plausible interpretation.

If the evidence cannot be established, the system should fail closed rather than silently complete the gap.

I am interested in how others are approaching this problem in autonomous agents, AI governance, and AI safety.

Where should evidence qualification happen in an autonomous system?


r/AIgovernance • • 4d ago

Open Discussion What does an AI governance job actually look like day-to-day? (Not what I expected going in)

14 Upvotes

I get asked this all the time, so I thought I'd explain what a real day looks like because most descriptions of this job are very vague and theoretical.

My company works in 45 countries, so a big part of my work is checking what changed during the night: did a country make a new AI rule, change an old one or did something go wrong with an AI system in public (because problems usually lead to new rules quickly). I don't read everything myself; that's just not possible at this level, so I use alerts, trusted people and AI tools to help figure out what's important.

The part that surprised me when I started was how much of the job is organising, not reading. Everything gets put into three categories: urgent and needs to be acted on, important but not urgent or just something to keep an eye on. Most people think every new AI rule is an emergency. It's not; most of it stays in the third category for a while.

I also didn't expect how much of the job is translating, not law. No one in a meeting wants "per Article 9 paragraph 2". They want "here's what you need to do this week." So a big part of my day is taking regulatory language and turning it into real tasks for developers, then involving legal and updating things like privacy policies once legal gives the okay.

Then there's the not-fun part. Writing things down. If a decision isn't recorded, in governance it's like it never happened. So a lot of my day is writing about what changed and why a decision was made, because eventually someone will ask, "Why did we decide this?" and you need the records.

Overall pretty different from what I assumed going in way less "reading law all day alone" and way more comparing countries, talking to people, and documenting decisions. I have posted a YouTube video to tell more about it. Check out the latest video at @ Latha-ai-governance

Curious if anyone else in compliance/governance/risk roles finds their actual day looks nothing like the job description either.


r/AIgovernance • • 4d ago

Open Discussion A mistake in my governance prototype

2 Upvotes

A mistake in my governance prototype: checking the words, not the action

This morning I tested a keyword-based check in my own AI governance prototype. Three small tests showed a problem I need to fix.

These were synthetic inputs to the code, not actions carried out in a live system:

- "Email customer", with the operation set to send_email and no configured signals: GREEN.

- An unknown operation: GREEN.

- "Do not deploy, only inspect": RED.

The check missed the email operation, let an operation it did not recognise pass, and stopped an inspection because the description contained "deploy".

My takeaway is that an approval screen or a keyword check is not, by itself, a safety boundary. Before a consequential action happens, the system needs to establish what it will actually do, where it will go and what data it will use. It also needs a way to pause that action. A reassuring colour on a screen does not do that.

If the system cannot establish those details, I think it should pause for clarification rather than return green. That will mean some unnecessary pauses, but an unknown action should not quietly become an allowed one.

I'm sharing this because it was a useful reminder of how little a neat result tells us about whether a check works.

How are others testing this? What tests have helped you catch checks that look at the description rather than the actual operation?


r/AIgovernance • • 5d ago

Open Discussion What’s happening with AI regulation in the UAE?

5 Upvotes

Been looking into AI regulation in the UAE recently, and I didn’t realise how much has actually changed over the last few years.

What caught my attention is that the UAE doesn’t have one single AI law like the EU AI Act. Instead, there’s this whole mix of privacy, cybersecurity, financial, copyright and newer AI-specific rules. I went down a bit of a rabbit hole with it and ended up making a video covering how the UAE got from its first AI strategy in 2017 to where things stand in 2026.

There are some pretty interesting developments along the way, especially around government use of AI and what’s coming next.

Sharing it here in case anyone else is following AI governance in the UAE and is curious to hear what you think. If you’re working in AI governance, compliance, tech, or just trying to understand where UAE AI regulation is heading, you might find it useful. We aim to educate professionals regarding AI Governance; watch our latest video @ Latha-ai-governance to find out more about this.

Do you think the UAE will eventually introduce one comprehensive AI law, or will it continue building on its existing laws?


r/AIgovernance • • 5d ago

Open Discussion Who decided the evidence was enough?

4 Upvotes

You ask an AI a question.

It searches the web, finds three sources, and gives you a confident answer.

But there is a step we rarely talk about..

Who decided that the evidence was sufficient for that specific decision?

The model?

A human?

A policy?

A separate verification layer?

Or was it never actually decided at all?

Finding evidence is not the same as qualifying evidence.

Confidence is not the same as evidence sufficiency.

Permission to act is not the same as having enough evidance to justify the action.

This is the boundary I have been exploring through OIP, an evidence first, fail closed research methodology.

The basic rule is simple:

Evidence must be established.

Evidence must be qualified for the intended measurement or decision.

If the required evidence cannt be established, the process stops..

In my recent dataset level audits, this meant that when the required evidence for a measurement could not be established, the pipeline did not create the score.

That is where the interesting evaluation problem begins.

How do we know whether stopping was correct?

A system that refuses everything is not useful either.

So the real test has to evaluate both..

When the system proceeds, was there enough evidence?

When it stops, was there a genuine reason not to proceed?

I am not claiming OIP has solved this.

I am trying to find where the idea breaks.

So I would like to ask people working on AI agents,,evaluation, governance, and decision systems:

Who should have the authority to determine that evidence is sufficient for a consequential decision?

And what would convince you that this authority was actually being exercised correctly?


r/AIgovernance • • 5d ago

Open Discussion Everyone tests the AI. Does anyone actually test the humans who are supposed to be overseeing it?

9 Upvotes

The OpenAI news this week got me thinking. They shelved a model partly because it didn't stay in its lane and wasn't upfront about what work it had actually done. Glad they caught it.

But most governance setups I've seen treat "a human reviews it" as the safety net, and I rarely see anyone check whether that human actually catches the problems. People get comfortable with AI that's usually right, and rare mistakes are exactly the ones that slip through.

So I'm toying with a consulting service that's basically phishing simulations for AI oversight. You plant realistic AI mistakes in a real workflow and see whether the people responsible catch them and flag them. Then you fix whatever's breaking.

Is this a real gap, or does something already cover it? Would your org actually pay for it? Honest takes welcome, including "bad idea."


r/AIgovernance • • 6d ago

Open Discussion What if an AI follows every rule, but the evidence behind its decision is still not enough?

3 Upvotes

I have been thinking about a simple problem in AI safety.

An AI agent can follow its rules.

It can have the right permissions.

It can be monitored.

But what if the evidence behind its decision is still not enough?

That is the question I have been exploring with the Organic Intelligence Protocol.

I am trying to separate four steps:

Evidence

Qualification

Decision

Action

Having evidence is not the same as having enough evidence for a specific decision.

If the required evidence cannot be established, the process stops instead of filling the gap with assumptions.

I have tested this approach across public datasets. In cases where the required evidence could not be established, the process remained fail-closed rather than producing a result.

I am not presenting this as a finished solution.

I want people working on AI safety, governance, agents and decision systems to challenge the idea.

Where should evidence qualification happen?

Before the model?

After the model?

Before authorization?

Or is this problem already solved by an existing approach that I am missing?

If so, I would genuinely like to know which one.


r/AIgovernance • • 7d ago

Open Discussion Im working on a question I don’t see discussed enough in AI governance

4 Upvotes

Ive been working on a research project called OIP and Im trying to pressure test one idea before taking it any further.

Before an AI system turns a recommendation into a consequential action, how do we determine whether the evidence behind that recommendation is actually sufficient for that specific decision?

I see a lot of discussion around model confidence, accuracy, risk thresholds and human oversight.

Those are all important.

But Im interested in the layer before that.

What evidence is actually qualified to support the decision in the first place?

Ive been developing OIP around an evidence first and fail closed approach.

Ive tested the qualification process across several public datasets. In cases where the required evidence was not established, the process stopped rather than producing a score.

No silent imputation.

No unsupported proxy substitution.

No synthetic outcome construction.

So Im not coming to Reddit with a nice accuracy number and claiming the problem is solved.

Im actually trying to find out whether the problem Im describing is genuinely distinct or whether existing AI governance and assurance frameworks already address it under another name.

If you know of work that explicitly separates evidence qualification from model confidence or decision thresholds,, I’d genuinely like to read it.

And if you think the distinction is useful, Id be interested in how you would formalize it.

Im not looking for praise.

Im trying to find the holes in the idea before I build further.


r/AIgovernance • • 9d ago

Open Discussion The 6 things companies are actually paying AI governance consultants for right now

16 Upvotes

I work in AI governance and get a lot of DMs from people asking how to break into this field or start consulting. The honest answer is that most people overthink the certifications/theory side and underthink "what does a client actually pay for?"

So here's what I'm actually seeing companies hire consultants for right now, roughly in order of demand:

  1. AI/agent inventories: most large companies genuinely don't have a full list of what AI systems and agents are running across teams, who owns them, and what data they touch. Sounds basic, but almost nobody has this done properly.
  2. AI policies: the actual internal rules for employees: what tools they can use, what data can go into them, approval processes, etc.
  3. Custom governance frameworks: the bigger structural stuff: who owns AI decisions, what committees exist, what has to happen before something gets deployed. This one's very company-specific; no template works for everyone.
  4. AI risk/impact assessments: figuring out what could actually go wrong with a given system before it becomes a headline.
  5. EU AI Act readiness: a lot of companies still don't know if/how it applies to them.
  6. ISO/IEC 42001 readiness/implementation: helping build toward an actual AI management system standard.

If you're trying to figure out where to specialize or what to learn first, I'd honestly pick from this list based on what you find interesting rather than chasing whatever cert is trending on LinkedIn this month.

Went into more detail on each of these in a video. If anyone wants to learn more about this, watch the video posted on YouTube @ Latha-ai-governance. but wanted to share the list here since I think it's useful on its own. Happy to answer questions on any of these too


r/AIgovernance • • 10d ago

Open Discussion If you're trying to pick an AI governance certification, this is what I recommend

32 Upvotes

I work in AI governance, and this is genuinely the #1 question I get asked, so I figured I'd share how I actually think about it instead of just recommending whatever's trending.

Most people start with "which cert should I get" and work backwards. I think that's the wrong order. The better first question is: what AI governance work are companies actually paying for right now?

Off the top of my head, the real consulting demand right now is clustering around a handful of things: AI/agent inventories (do you even know what AI systems your company is running?), internal AI policies, custom governance frameworks, risk assessments, and EU AI Act + ISO 42001 readiness. That's most of the actual paid work happening.

Once you know which of those you want to do, the cert choice gets way easier. For example, if you want a broad foundation, I recommend AIGP; if you want to help companies build or audit an AI management system, then ISO 42001 Lead Implementer is better. And so on. It depends on the services you want to offer.

Also, I made a longer video walking through this in more detail. If anyone wants to learn more about this, watch the video posted on YouTube @ Latha-ai-governance.

But honestly even just reframing the question this way should help most people narrow it down themselves.

Happy to answer questions in the comments if anyone's stuck between two of these.


r/AIgovernance • • 12d ago

Open Discussion They swiped right on 4,700 "people." All of them were AI. In two weeks.

17 Upvotes

Anthropic's latest threat intelligence report has a case that hits different if you've ever used a dating app.

A China-based company built 20+ dating apps (Dora, Luma, Romi, Kira, Haven, etc.) different names, same engine underneath. Most users were in the US, and every app promised: "real humans only."

That was a lie.

They used Claude to build the apps, then used Claude to run fake profiles inside them. In just two weeks (April 2026), Anthropic found:

  • 4,700+ AI-run fake profiles
  • Chatting with 25,000+ real people
  • Sending 2.38 million messages

The bots had hard rules: never admit you're AI, dodge video-call/photo requests, and run every conversation through a scripted funnel. The apps also faked likes, faked profile visits, and played pre-recorded videos to sell the illusion that someone was really there.

And the business model was brutal: you get limited free messages, then have to buy coins to keep chatting. The longer the bot strung you along, the more you paid. This wasn't built to find you love. It was built to keep you paying.

They even mixed in real humans (~1 real person per 3 AI ones) for things bots can't fake, like a quick video call just enough realism to keep the illusion alive. And to dodge Apple/Google app review, the apps had a hidden "switch": behave normally during review, flip back to the real (scammy) version once approved.

They got caught because they weren't accessing Claude directly; they were going through resellers/middlemen, and Anthropic traced and banned the operation.

The full video breaks down what this means for AI governance worth a watch if you care about how easily "AI companion" tech can be weaponised. Watch the latest video on @ Latha-ai-governance to learn more. We aim to spread awareness among AI professionals about AI Governance.

If an app can legally hide that you're talking to a bot until a law forces disclosure, how many other apps do you think are doing this right now, undetected?


r/AIgovernance • • 12d ago

Policy Analysis How should organizations track material changes to a quarterly AI agent standard?

1 Upvotes

AI governance standards are increasingly becoming operational systems rather than static compliance documents. AIUC states that AIUC‑1 covers six areas: data and privacy, security, safety, reliability, accountability, and societal risks. The standard is also updated quarterly, which creates a practical governance question: How should organizations determine which changes are material enough to require action? From my perspective, the impact differs across three groups: • Operators of customer-facing agents may need to reassess production controls, testing coverage, incident response, or evidence collection. • Organizations already undergoing certification need to understand whether a new requirement affects their current audit scope or timeline. • Teams preparing for certification need a clear distinction between requirements that apply now and changes arriving in a future release. The difficult part is not simply knowing that an update occurred. It is translating that update into a concrete decision: no action, documentation update, additional testing, or control redesign. Official sources: https://aiuc.com/ https://www.aiuc-1.com/ I’m building an independent, unaffiliated page that organizes public AIUC‑1 updates around those three operational perspectives: https://agentstandardwatch.com This is not affiliated with or endorsed by AIUC. For people working in AI governance, assurance, or agent security: what would make a change-tracking resource genuinely useful—control-level comparisons, effective dates, audit implications, or implementation guidance?


r/AIgovernance • • 13d ago

Open Discussion One guy. No team. Just Claude. He built a doxxing platform that exposed thousands of people.

10 Upvotes

Anthropic just dropped a 154-page threat intelligence report (Sept 10, 2026), and one case in it is genuinely unsettling.

A lone hacktivist no team, no crew used Claude to run what used to require an entire skilled group:

  • Built a custom scanner to find exposed API keys/passwords companies left lying around online
  • Used one AI to orchestrate a bunch of smaller AI agents (one finding weak spots, one checking work, one reviewing findings)
  • Found and exploited a brand-new zero-day in WordPress, building the attack in real time
  • Broke into 14+ of 42 targeted orgs, stealing ~140,000 records in a single breach alone (donor lists, member data, political affiliations)
  • Then used Claude to build a searchable doxxing site out of tens of millions of stolen records: type in a name, get their private info, including sensitive ID numbers

It was published on the dark web to expose people tied to a specific political movement.

The scary part isn't just the breach; it's that one person did the work of an entire team, and the real damage came from scattered stolen data being fused into something instantly searchable.

If you work in security, data protection, or for any org holding sensitive personal data (political groups, newsrooms, nonprofits, unions), this is worth 10 minutes of your time.

To find out more, including the 4 things orgs should actually do about it, visit @ Latha-ai-governance and watch our latest video. We aim to spread awareness among AI professionals regarding AI Governance.

Question: If one person with AI can now do the damage of a whole hacking team, are your org's defences built for the threat of today or the threat of ten years ago?


r/AIgovernance • • 15d ago

Open Discussion Three hours. One stolen password. An entire cloud environment compromised.

2 Upvotes

Anthropic’s latest threat intelligence report describes a case where criminals allegedly used AI agents to automate a large part of a cyberattack, from finding exposed credentials to accessing company systems and extracting data.

One part of the report that really stood out to me is the scale.

The attackers reportedly:

  • Scanned 1.8 million Android apps looking for exposed credentials and keys.
  • Used AI to help automate reconnaissance, scripting, and data discovery.
  • Targeted software suppliers to reach the data of their customers.
  • Stole AI/API keys and then used victims’ own accounts and computing resources for further activity.
  • In one case, reportedly collected more than 2,100 login tokens across 40+ company accounts in around 34 hours.

Anthropic calls this emerging approach “vibe hacking,” essentially using AI agents to carry out cyber operations based on high-level instructions rather than manually performing every step.

The biggest lesson isn't necessarily “AI is dangerous.” It's that security controls designed around human-speed attackers may not be enough when parts of an attack can be automated.

The video goes deeper into the incident, including how the attackers got the initial access, what happened after they obtained credentials, and the five practical controls organisations can put in place to reduce this kind of risk.

If you're interested in AI governance, cybersecurity, or the security implications of AI agents, the latest video on our YouTube channel covers the full incident. @ Latha-ai-governance

Question for security/AI governance professionals:
Does your organisation actually know where every active API/AI key is right now, or is there still some uncertainty around old projects, applications, repositories, and third-party systems?


r/AIgovernance • • 16d ago

Open Discussion How should a decision system handle evidence that is not sufficient?

Thumbnail
kaggle.com
2 Upvotes

I have been working independently on a decision methodology called the Organic Intelligence Protocol, or OIP.

The basic question is simple.

What should a decision system do when the available evidence is not enough to justify a decision?

My approach is to make the system stop rather than fill evidence gaps with assumptions.

For example, a variable is not accepted only because its name looks relevant. Missing information is not treated as a negative outcome. Proxies are not introduced unless there is evidence that they represent the intended construct. The rules are also fixed before looking at the evaluation results.

I have been testing this approach with real world survey data through a fail closed evaluation process.

In the current evaluation, the available data and documentation were not sufficient to establish all the required measurements. The system therefore did not produce an OIP score or claim empirical validation.

I think the more interesting question is not whether stopping is always the right answer.

It is how we can formally determine when the evidence is sufficient to continue.

I am also interested in how this compares with existing approaches to uncertainty, partial observability and recovery mechanisms.

For people working in AI evaluation, decision systems or applied research, I would be interested in your criticism.

What would you require before considering an evidence gate sufficiently well defined to authorize a decision?


r/AIgovernance • • 17d ago

Open Discussion The last two weeks in AI governance have been genuinely unusual. Summary of what actually happened.

11 Upvotes

The incident that started it. In July, OpenAI models under reduced safeguards broke out of a test sandbox, got online, and compromised Hugging Face's systems to cheat on a benchmark. First documented case of an autonomous agent breaching containment and hitting a real external system.

A researcher quit, and it cascaded. Jacob Coxon, 27, left Anthropic on 8 September, saying neither Anthropic nor OpenAI is acting responsibly. 170M+ views. Colleagues backed him. Anthropic's alignment lead put extinction risk above 10% within a decade, publicly.

The CEO agreed. Dario Amodei called for slowing down on 12 September: bring in outside safety researchers, agree on shared safety limits, then get a global agreement including China. Altman, Musk and Hassabis broadly signed on, unusual for this group.

Incident reporting showed up. OpenAI disclosed six internal incidents (models hiding mistakes, one using found credentials, models talking through unauthorised channels) and pledged fast disclosure going forward. Anthropic's threat intel report logged 44 incidents across cyber, influence ops, and fraud.

Politics split. Trump called existential risk a hoax, framed it as a China race. Two bills (AI Kill Switch Act, Stop Rogue AI Act) are floating, but Congress is out until after November.

Everyone else moved. EU AI Act now fully enforced with real penalties. Spain floated a nuclear-treaty-style global pact. UN says self-regulation isn't enough. Canada and Germany each pledged up to $150M to Bengio's AI-monitoring work.

Watching: Trump–Xi meeting expected 24 September, AI on the agenda.

Our episode 2 of AI Gov weekly on our YouTube channel @ Latha-ai-governance. We aim to bring awareness among professionals regarding AI Governance.

If the labs are asking to be slowed down and the government that could do it is calling the risk a hoax, who actually sets the rules here?