Your AI Story Is an Examinable Representation, and the Exam Year Ends 30 September
Nothing new landed this summer. The SEC has been examining the accuracy of AI representations all year, and the fiscal year closes on 30 September. That is the point.

Practical perspectives from practitioners who have operated at the expert level, not advisors who read the framework.
Nothing new landed this summer. The SEC has been examining the accuracy of AI representations all year, and the fiscal year closes on 30 September. That is the point.
OpenAI's cyber-evaluation models escaped their sandbox through a zero-day, reached Hugging Face production, and stole the answer key to their own benchmark. The objective was in scope. Nothing else was.
On 7 July the Commission published its Cybersecurity and AI Action Plan. On 8 July it asked the Court to fine four member states over NIS2. Read together, they set the direction.
Researchers tricked six AI browsers into leaking credentials; North Korea shipped malware that gaslights the AI doing the triage. Prompt injection now cuts both ways.
The Digital Omnibus (final Council approval June 29) defers the AI Act's high-risk obligations to 2027 and 2028. But August 2 is not cancelled: transparency rules still land.
If you cannot win every race, the goal shifts to surviving a loss. Regenerative containment turns the exposure window from something you react to into a constant you declare.
The June 2 executive order builds a Treasury-run clearinghouse to coordinate vulnerability scanning and patch distribution: the absorption layer the Velocity Gap exposed.
You do not need a full Cyber Resilience Act audit to diligence a product target. You need a few questions that read the room, a hypothesis formed from the tech and cyber work you are already doing, and the discipline to carry it into the SPA and the W&I tower.
The CRA has been binding law since December 2024, but its obligations arrive in phases. This week the conformity-assessment machinery switched on. The first reporting deadline is 11 September 2026. For most smaller product companies the gap is not capability. It is evidence.
Mythos-class AI went from withheld to publicly available in nine weeks. Discovery now runs at machine speed; remediation does not. The metric that matters is the gap between weaponization and containment.
Investment committees see more AI-intensive deals every quarter, but the process was not built for the pattern. Three IC-level questions surface AI risk before the vote.
The proposed Digital Omnibus Regulation would consolidate incident reporting into one ENISA-run portal. The proposal is still in negotiation, and the five underlying regimes do not go away. The work moves upstream, into the controls crosswalk.
On 19 May 2026 the European Commission published draft guidelines clarifying when an AI system is high-risk under Article 6. The exceptions are narrower than the market assumed.
McKinsey's Project Acorn shifts partner pay from cash toward equity: the clearest signal yet from MBB of a consulting partnership reset buyers must price in.
A US court let negligence claims against Bain Capital proceed for a portfolio company's breach. The cost of weak cyber diligence is no longer just a write-down, it's the sponsor named in the suit. The exposure attached to how the bid was conditioned.
Investment committees approve AI projects with a value case that ignores data risk. A short checklist prevents the post-mortem finding.
The Model Context Protocol connects AI agents to external tools. Real 2026 CVEs show the attack surface is already being exploited.
AI coding tools are adopted team by team, below committee line of sight. Three questions separate oversight from assurance.
Boards approved AI principles. The next 18 months are about proving those principles operate as controls. The gap is where regulatory risk sits.
Deal teams are seeing more AI-intensive targets. The diligence process was not designed for agent sprawl, training data provenance, or vendor lock-in.
Most organizations have AI principles. Few have controls that execute at runtime. The gap between policy and enforcement is where incidents happen.
RoguePilot, CamoLeak, and Comment-and-Control attacks prove AI coding tools are a live attack surface. A practical control set for development teams.
Most boards hear the AI productivity pitch but not the identity, permission, and accountability model underneath. Three questions surface the gap.
If your risk register treats AI as one line item under technology risk, it is out of date. Shadow AI touches four risk categories at once.
AI agents, data governance, and regulatory enforcement are converging into a single challenge. Treating them separately creates blind spots.
Only 35% of organizations have full visibility into unstructured data. Without data discovery and classification, AI security controls have no foundation.
Machine identities will outnumber human identities in most enterprises this year. 78% have no formal policies for AI identity lifecycle management.
78% of employees who use AI at work bring their own AI tools. Only 36% of organizations have governance policies. A 10-day sprint closes the gap.
AI-assisted attack tools find vulnerabilities faster than organizations can patch. Framework compliance alone no longer defines adequate security.
Project Glasswing resets the baseline for cybersecurity assessment. When AI finds 27-year-old flaws, traditional assessment methodologies need to catch up.
Anthropic built Claude Mythos Preview and chose not to release it. The first frontier model withheld for cyber risk reshapes AI governance playbooks.
AI coding tools create bidirectional supply chain risk. The axios trojan and Claude Code leak hit the same day. Most security teams are not watching.
AI models that exploit vulnerabilities autonomously are here. Mythos, real-world LLM operations, and eCrime breakout times averaging 29 minutes demand a new threat model.
Anthropic shipped Claude Code's complete source in a routine npm update. With tens of thousands of forks and exposed feature flags, AI vendor risk needs rethinking.
NIS2, DORA, CRA, the revised CSA, and the EU AI Act each evaluate different dimensions of the same vendor. Running them as separate programs hides cross-framework exposure.
Computer-use agents that operate your desktop autonomously are here. The governance gap between copilots and autonomous colleagues is the next risk.
Single-vendor AI stacks create concentration risk enterprises don't yet see. A portfolio approach across cloud, open-source, and edge models is overdue.
AI platform loyalty can fracture overnight. The ChatGPT-Claude shift shows why vendor evaluation must now include political and reputational risk.
Browser AI assistants create high-value attack surfaces. The Chrome Gemini hijack shows why enterprises must rethink endpoint security for embedded AI.
Only 29% of organizations are prepared to secure AI agent deployments. A six-domain framework for deploying agents with controls mapped to ISO 27001 and DORA.
Most organizations treat AI agents and chatbots as the same security category. They are fundamentally different - and chatbot controls are not enough.
AI agent adoption is outpacing security infrastructure. Only 14.4% of organizations have full security approval for their entire agent fleet. A present risk boards are missing.
AI agents are not a future capability. They are an operational tool that professionals and deal teams are using now to compress hours of skilled labor.
You do not need a technical background to use an AI agent. A paid subscription, a desktop app, and twenty minutes. A step-by-step setup guide.
The shift from AI that talks to AI that does is underway. A plain-language guide to what AI agents are, where the market stands, and why it matters.
A 1998-era SQL injection reportedly exposed McKinsey's AI platform Lilli. The vulnerability class is old. The consequences for enterprise AI are not.
Enterprise AI data concerns mirror cloud migration fears of 2010-2016. The governance discipline is identical, only the processing engine changed.
Large consulting firms have misaligned people, services, and technology. AI is making this fragmentation worse before it makes it better.
Every consulting firm has an AI strategy and AI partnerships. None has transformed its own delivery model - which is exactly what they sell to clients.
A three-tier framework for M&A cybersecurity due diligence - from 24-hour screening to post-close monitoring - with Expected Annual Loss quantification.
AI-powered attacks and deepfake fraud are the defining threats of 2026. A plain-language briefing for boards and CFOs, with the 12 controls that change the risk profile.
88% of organizations use AI but only 28% see measurable transformation. The gap is not a technology problem - it's why AI-native agencies outperform SaaS.
Sweden's Cybersecurity Act (SFS 2025:1506) entered into force on 15 January 2026, shifting cybersecurity obligations to entity-wide scope with explicit management accountability requirements and fines up to €10M.
AI has automated junior analyst work faster than firms can redeploy. The consulting pyramid is under structural pressure - here's what replaces it.
Practical GenAI applications for tech and cyber due diligence in M&A, with the governance controls that keep deal-confidential data protected.
In our engagement experience, document-only reviews miss most material cyber risks. Technical validation is what closes the gap for underwriters.
In our middle-market engagements, material cybersecurity findings have typically driven 8-25% valuation adjustments. Here's how diligence informs deal structure and protects buyer ROI.
In our middle-market engagements, cybersecurity vulnerabilities, technical debt, privacy gaps, IP ambiguity, and integration complexity have reduced IRR by 8-12 points in affected transactions.
In our middle-market engagements, roughly 72% of quality deals have involved multiple bidders. External-only digital due diligence delivers comprehensive technology intelligence in 24-72 hours.
Most PE deal teams assess cybersecurity through questionnaires and limited-access reviews. Here's what that approach systematically misses, and why it matters at close.
Talk to a practitioner. We'll be direct about whether we can help and how.
Start Discussion