<?xml version="1.0" encoding="UTF-8" standalone="no"?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:sy="http://purl.org/rss/1.0/modules/syndication/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" version="2.0">

<channel>
	<title>DISC Infosec blog</title>
	<atom:link href="http://blog.deurainfosec.com/feed/" rel="self" type="application/rss+xml"/>
	<link>https://blog.deurainfosec.com/</link>
	<description>Dedicated to information security assurance&#13;
Information Security subject matter with related items</description>
	<lastBuildDate>Tue, 29 Sep 2026 16:25:11 +0000</lastBuildDate>
	<language>en-US</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.1.14</generator>

<image>
	<url>https://blog.deurainfosec.com/wp-content/uploads/2026/07/disc-logo-144x144.jpg</url>
	<title>DISC InfoSec blog</title>
	<link>https://blog.deurainfosec.com/</link>
	<width>32</width>
	<height>32</height>
</image> 
	<xhtml:meta content="noindex" name="robots" xmlns:xhtml="http://www.w3.org/1999/xhtml"/><item>
		<title>The Security Risks Hiding in AI Agent Memory</title>
		<link>https://blog.deurainfosec.com/the-security-risks-hiding-in-ai-agent-memory/</link>
					<comments>https://blog.deurainfosec.com/the-security-risks-hiding-in-ai-agent-memory/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 29 Sep 2026 16:25:09 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Governance Enforcement]]></category>
		<category><![CDATA[AI Logs]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI Agent Memory]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36586</guid>

					<description><![CDATA[<p>The Security Risks Hiding in AI Agent Memory Agent memory is the least-governed data store in most enterprises, and it is filling up with secrets. An agent that remembers can be taught. An agent that can be taught can be poisoned. And whatever it has learned sits somewhere, usually in plain text, usually outside any [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-security-risks-hiding-in-ai-agent-memory/" data-wpel-link="internal" target="_blank">The Security Risks Hiding in AI Agent Memory</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-security-risks-hiding-in-ai-agent-memory/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Log Retention: Why Every AI Log Doesn’t Deserve the Same Shelf Life</title>
		<link>https://blog.deurainfosec.com/ai-log-retention-why-every-ai-log-doesnt-deserve-the-same-shelf-life/</link>
					<comments>https://blog.deurainfosec.com/ai-log-retention-why-every-ai-log-doesnt-deserve-the-same-shelf-life/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 25 Sep 2026 21:29:08 +0000</pubDate>
				<category><![CDATA[AI Log Retention]]></category>
		<category><![CDATA[AI Logs]]></category>
		<category><![CDATA[AI Logs retention]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36583</guid>

					<description><![CDATA[<p>DISC INFOSEC&#160; &#124;&#160; AI GOVERNANCE AI Log Retention: Why Every AI Log Doesn&#8217;t Deserve the Same Shelf Life Your AI logs are either your best evidence or your biggest liability. The retention period decides which. Most teams I assess have exactly one AI log retention setting: whatever the vendor or the SIEM shipped with. Thirty [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-log-retention-why-every-ai-log-doesnt-deserve-the-same-shelf-life/" data-wpel-link="internal" target="_blank">AI Log Retention: Why Every AI Log Doesn&#8217;t Deserve the Same Shelf Life</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-log-retention-why-every-ai-log-doesnt-deserve-the-same-shelf-life/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>The AI Agent Harness Is the New Security Boundary</title>
		<link>https://blog.deurainfosec.com/the-ai-agent-harness-is-the-new-security-boundary/</link>
					<comments>https://blog.deurainfosec.com/the-ai-agent-harness-is-the-new-security-boundary/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 24 Sep 2026 17:22:37 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[AI Agent Harness]]></category>
		<category><![CDATA[AI Agents]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36574</guid>

					<description><![CDATA[<p>The AI Agent Harness Is the New Security Boundary Everyone is talking about securing the AI model. But for AI agents, the model may not be the most important security boundary. The real security boundary is the harness. Think of the model as the reasoning engine. The harness is the scaffolding that turns reasoning into [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/the-ai-agent-harness-is-the-new-security-boundary/" data-wpel-link="internal" target="_blank">The AI Agent Harness Is the New Security Boundary</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/the-ai-agent-harness-is-the-new-security-boundary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Stop asking what your agent can do</title>
		<link>https://blog.deurainfosec.com/stop-asking-what-your-agent-can-do/</link>
					<comments>https://blog.deurainfosec.com/stop-asking-what-your-agent-can-do/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 21 Sep 2026 20:12:45 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[Harness is the contract]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36552</guid>

					<description><![CDATA[<p>The Harness Is the Contract: Declared, Bounded, Verifiable Stop asking what your agent can do. Ask whether every consequential path was declared, bounded, and left evidence a third party can verify. A practitioner&#8217;s framework for governing the harness, not the model. Most AI governance effort is aimed at the wrong object. Teams assess the model [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/stop-asking-what-your-agent-can-do/" data-wpel-link="internal" target="_blank">Stop asking what your agent can do</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/stop-asking-what-your-agent-can-do/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>You can’t put a human in the loop of a system that kills its agents every 3 minutes</title>
		<link>https://blog.deurainfosec.com/you-cant-put-a-human-in-the-loop-of-a-system-that-kills-its-agents-every-3-minutes/</link>
					<comments>https://blog.deurainfosec.com/you-cant-put-a-human-in-the-loop-of-a-system-that-kills-its-agents-every-3-minutes/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 15 Sep 2026 19:30:14 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Agents]]></category>
		<category><![CDATA[Human in the loop]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36544</guid>

					<description><![CDATA[<p>Continuous Human Involvement Is a Fantasy. Continuous Human Authority Is an Architecture. How to govern a fleet of hundreds of ephemeral AI agents that spawn, act, and vanish in minutes — when nobody can watch them. Someone posed me a riddle recently, and it&#8217;s the sharpest challenge to &#8220;human-in-the-loop&#8221; orthodoxy I&#8217;ve heard in a while: [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/you-cant-put-a-human-in-the-loop-of-a-system-that-kills-its-agents-every-3-minutes/" data-wpel-link="internal" target="_blank">You can&#8217;t put a human in the loop of a system that kills its agents every 3 minutes</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/you-cant-put-a-human-in-the-loop-of-a-system-that-kills-its-agents-every-3-minutes/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Human Oversight vs Human Control: Where the Human Sits in AI Execution</title>
		<link>https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/</link>
					<comments>https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 09 Sep 2026 19:07:16 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI execution]]></category>
		<category><![CDATA[alongside the execution]]></category>
		<category><![CDATA[Human control]]></category>
		<category><![CDATA[Human in the loop]]></category>
		<category><![CDATA[Human oversight]]></category>
		<category><![CDATA[Parallel on the loop]]></category>
		<category><![CDATA[Perpendicular in the loop]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36508</guid>

					<description><![CDATA[<p>Where Does the Human Sit Relative to Execution? Outside the loop, in it, on it, or alongside it? The position determines what evidence exists, which risk tiers are defensible, and whether Article 14 oversight is real or theatre. Someone put a question to me recently that I thought was better than most of the governance [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/" data-wpel-link="internal" target="_blank">Human Oversight vs Human Control: Where the Human Sits in AI Execution</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/human-oversight-vs-human-control-where-the-human-sits-in-ai-execution/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>A signed two-page policy beats a fifty-page draft. Every time…</title>
		<link>https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/</link>
					<comments>https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 08 Sep 2026 16:41:24 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[CISO]]></category>
		<category><![CDATA[Data Governance]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[IT Governance]]></category>
		<category><![CDATA[Security policy]]></category>
		<category><![CDATA[vCISO]]></category>
		<category><![CDATA[Bay Area Startups]]></category>
		<category><![CDATA[cybersecurity startups]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36521</guid>

					<description><![CDATA[<p>Startups at Seed or Series A Don&#8217;t Need a CISO to Pontificate. They Still Need Governance. A viral take says early-stage startups need operators, not CISOs. Mostly right — but three of the four things it says startups need are governance work. What actually blocks the audit and the deal. A take went around recently [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/" data-wpel-link="internal" target="_blank">A signed two-page policy beats a fifty-page draft. Every time&#8230;</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/a-signed-two-page-policy-beats-a-fifty-page-draft-every-time/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>We have guardrails for that is not a control – Here’s the difference</title>
		<link>https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/</link>
					<comments>https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 19:08:00 +0000</pubDate>
				<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI audit]]></category>
		<category><![CDATA[AI controls]]></category>
		<category><![CDATA[AI Security Assessment]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36490</guid>

					<description><![CDATA[<p>Why AI Systems Are Hard to Audit &#8211; AI doesn’t have controls, it has guardrails — and you can’t audit a guardrail AI Teams Think in Guardrails. Auditors Think in Controls. That Gap Is Where Programs Fail. Steven Ross made an observation in the ISACA Journal earlier this year that I&#8217;ve been chewing on since, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/" data-wpel-link="internal" target="_blank">We have guardrails for that is not a control &#8211; Here&#8217;s the difference</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/we-have-guardrails-for-that-is-not-a-control-heres-the-difference/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Point-in-time remediation is dead against a persistent adversary</title>
		<link>https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/</link>
					<comments>https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Thu, 03 Sep 2026 04:31:30 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Governance Enforcement]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Agentic defense agent]]></category>
		<category><![CDATA[Agentic offensive agent]]></category>
		<category><![CDATA[Autonomous Offensive Loops]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36451</guid>

					<description><![CDATA[<p>The Rise of Fully Autonomous Offensive Loops Agent collectives found zero-days, shared them, escalated, and moved laterally for weeks — by accident. Automated offense now has an existence proof. Automated defense doesn’t. What defenders should do. Every post in this series has been building toward a question that stopped being hypothetical in July 2026: what [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/" data-wpel-link="internal" target="_blank">Point-in-time remediation is dead against a persistent adversary</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/point-in-time-remediation-is-dead-against-a-persistent-adversary/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Your Security Stack Isn’t Obsolete. Your Operating Model Is</title>
		<link>https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/</link>
					<comments>https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Wed, 02 Sep 2026 19:20:40 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Enterprise Cybersecurity Infrastructure]]></category>
		<category><![CDATA[Operating Model]]></category>
		<category><![CDATA[Security Stack]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36501</guid>

					<description><![CDATA[<p>Your Security Stack Isn&#8217;t Obsolete. Your Operating Model Is. Is Enterprise Cybersecurity Infrastructure Already Obsolete? The $1T Claim, Examined. Palo Alto&#8217;s CEO put $1 trillion on the table. The latency argument is right — but &#8220;obsolete&#8221; is the wrong diagnosis, and buying faster makes it worse. What&#8217;s actually structurally dead, and what to do first. [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/" data-wpel-link="internal" target="_blank">Your Security Stack Isn&#8217;t Obsolete. Your Operating Model Is</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/your-security-stack-isnt-obsolete-your-operating-model-is/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Thirty years of security assumed the attacker was unauthorized – Your agent isn’t</title>
		<link>https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/</link>
					<comments>https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Mon, 31 Aug 2026 16:37:05 +0000</pubDate>
				<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[AI Agents]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36443</guid>

					<description><![CDATA[<p>Agentic AI Governance: Mitigating Liability and Protecting Information Assets The model decided to do that&#8221; is not a legal defense The previous post in this series covered agent security controls — tool scoping, separating decision from execution, memory hygiene, egress control. That&#8217;s the engineering layer. This post is about the layer above it, the one [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/" data-wpel-link="internal" target="_blank">Thirty years of security assumed the attacker was unauthorized &#8211; Your agent isn&#8217;t</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/thirty-years-of-security-assumed-the-attacker-was-unauthorized-your-agent-isnt/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Frontier Model, Familiar Framework: Reading Fable 5’s Guardrails Through ISO 42001</title>
		<link>https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/</link>
					<comments>https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Sun, 30 Aug 2026 17:47:35 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[Fable 5]]></category>
		<category><![CDATA[Frontier Model]]></category>
		<category><![CDATA[Mythos 5]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36474</guid>

					<description><![CDATA[<p>What Claude Fable 5&#8217;s Launch Teaches Us About AI Governance (An ISO 42001 Reading) In June 2026, Anthropic released Claude Fable 5 — the most capable AI model ever made generally available. But the more interesting story isn&#8217;t the benchmarks. It&#8217;s the governance architecture wrapped around the release. Because here&#8217;s the thing: while most organizations [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/" data-wpel-link="internal" target="_blank">Frontier Model, Familiar Framework: Reading Fable 5&#8217;s Guardrails Through ISO 42001</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/frontier-model-familiar-framework-reading-fable-5s-guardrails-through-iso-42001/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>ISO 42001 Evidence Checklist: What Auditors Actually Look For (2026)</title>
		<link>https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/</link>
					<comments>https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Sat, 29 Aug 2026 22:49:38 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[Internal Audit]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[ISO 42001 Evidence Checklist]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36462</guid>

					<description><![CDATA[<p>We Built an ISO 42001 Evidence Checklist for AI Companies — Here&#8217;s What Auditors Actually Look For Controls are rarely why organisations fail an ISO 42001 audit. Evidence is&#8230;A clause-by-clause evidence checklist, the seven patterns that separate a pass from a finding, and the questions auditors actually ask. ISO 42001 evidence checklist, ISO 42001 audit, [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/" data-wpel-link="internal" target="_blank">ISO 42001 Evidence Checklist: What Auditors Actually Look For (2026)</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/iso-42001-evidence-checklist-what-auditors-actually-look-for-2026/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>Agents don’t produce wrong answers anymore They take wrong actions – A practitioner’s guide to agent security</title>
		<link>https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/</link>
					<comments>https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Fri, 28 Aug 2026 16:30:22 +0000</pubDate>
				<category><![CDATA[AI Agent]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[AI Governance Enforcement]]></category>
		<category><![CDATA[AI Guardrails]]></category>
		<category><![CDATA[AI Risk]]></category>
		<category><![CDATA[Information Security]]></category>
		<category><![CDATA[agent least privilege]]></category>
		<category><![CDATA[AI Agent Security]]></category>
		<category><![CDATA[AIMS]]></category>
		<category><![CDATA[EU AI Act Article 14]]></category>
		<category><![CDATA[human-in-the-loop]]></category>
		<category><![CDATA[ISO 42001]]></category>
		<category><![CDATA[ISO 42001 agents]]></category>
		<category><![CDATA[prompt Injection]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36425</guid>

					<description><![CDATA[<p>AI Agent Security: Nobody Authorized That Action, and That&#8217;s the Problem The last two posts in this series ended in the same place from different directions. The one on AI-executable workflows argued that when the convertible tasks leave, what remains valuable is specification, oversight, evidence, boundary judgment, and the signature. The one on Bay Area [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/" data-wpel-link="internal" target="_blank">Agents don&#8217;t produce wrong answers anymore They take wrong actions &#8211; A practitioner&#8217;s guide to agent security</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/agents-dont-produce-wrong-answers-anymore-they-take-wrong-actions-a-practitioners-guide-to-agent-security/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
		<item>
		<title>AI Governance for Bay Area Startups: What to Put in Place Before Enterprise Customers Ask</title>
		<link>https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/</link>
					<comments>https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/#respond</comments>
		
		<dc:creator><![CDATA[disc7]]></dc:creator>
		<pubDate>Tue, 25 Aug 2026 16:30:03 +0000</pubDate>
				<category><![CDATA[AI]]></category>
		<category><![CDATA[AI Governance]]></category>
		<category><![CDATA[Bay Area Startups]]></category>
		<guid isPermaLink="false">https://blog.deurainfosec.com/?p=36418</guid>

					<description><![CDATA[<p>AI Governance for Bay Area Startups: What to Put in Place Before Enterprise Customers Ask There&#8217;s a specific email that changes a startup&#8217;s quarter. It arrives from a champion who is genuinely on your side, and it reads something like: &#8220;Security review went fine, but our AI risk team added a section. Can you send [&#8230;]</p>
<p>The post <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/" data-wpel-link="internal" target="_blank">AI Governance for Bay Area Startups: What to Put in Place Before Enterprise Customers Ask</a> appeared first on <a rel="nofollow noopener noreferrer" href="https://blog.deurainfosec.com" data-wpel-link="internal" target="_blank">DISC InfoSec blog</a>.</p>
]]></description>
		
					<wfw:commentRss>https://blog.deurainfosec.com/ai-governance-for-bay-area-startups-what-to-put-in-place-before-enterprise-customers-ask/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>