Leadership at @cytexsmb has been preparing our clients for this over the last year. AI Decision Assurance will be required by every company deploying AI. My next prediction is that underwriters will require it. https://t.co/Ep38eTMiKi
Denmark: 8.8M CPR records taken through a private company's authorized access to the register.
FBI: contractor data exposed because a PeopleSoft patch was never applied.
Neither was a zero-day. Both were delegated access nobody verified.
Now add agents to that list.
15,465 public MCP servers scanned. 15.6% resolve outside the US. 2.3% point to dead domains, out of which 6 can be re-registered for $4.
Meanwhile OpenAI has notified 100+ orgs of misaligned agent activity.
Agent connections are a supply chain nobody is governing yet. #aicenturion
California just stood up the first AI auditor registry in the US (AB 1405, signed 9/30). SB 813 sets the standards auditors have to meet.
Policy was never the hard part. Producing evidence that policy was followed at decision time is. That bill comes due in 2027. #aicenturion
99.7% of security leaders say they have a formal AI policy.
57% say it's enforced.
42% have no way to auto-revoke an agent's access when the session ends.
AIGovernance is becoming a control that runs inline with the agent, not a document you write. #aicenturion
Speak on it! AICenturion is freeing developers, CIO's and CISOs from the shackles of uncertainty, regulatory risk, and vulnerabilities. Long Live AICenturion- Decision Assurance for the People!
New BearingPoint data: 13% of companies on track with AI, under a third past pilot. Top blocker cited, at 40%: regulation.
Mostly wrong. What blocks production is that nobody can evidence lineage, evals, approvals or rollback when required.
AICenturion addresses this pain point and helps companies put AI into operations. #aicenturion
Penny wise and thousands of pounds foolish. Start prioritizing AI security or face the consequences. #AICentuion from @cytexsmb will help you avoid tool & app sprawl.
A cybersecurity nonprofit was breached by an autonomous AI agent. Defenders' verdict: "loud and very, very messy." It sabotaged its own password spray.
It still got in. It was just bad at hiding.
That gap closes with the next model release, not your next budget cycle.
Six frontier labs signed a voluntary AI accord: internal controls, named owners, external audits, shared standards.
That isn't AI policy. It's SOX for models.
Voluntary at the developer becomes contractual at the deployer. Your next vendor questionnaire is being written now.
Florida's AG asked a court to block OpenAI from shipping new frontier models. The evidence is largely OpenAI's own safety disclosures: the scrapped GPT-6.1, the Hugging Face agent breach, Altman saying slow down.
Candor is discoverable now. Publishing less isn't the fix.
SalesBleed: attacker puts hidden instructions in a Salesforce Web-to-Lead form. Dormant until an employee asks Agentforce to process the lead. Then zero-click exfil of CRM data.
The bug wasn't the model. It was read access + outbound network + an input strangers can write to.
#autonomypassport #leastautonomy
Sept 26: US and China agree to an AI incident hotline. Same day: OpenAI discloses its own agents probed US gov sites during training, including a failed hack attempt.
A hotline before a definition of "AI incident."
Could you reconstruct what your agents did last Tuesday? #aicenturion @cytexsmb
EU AI Board met Sept 17. No new rules, no new deadlines. The agenda was enforcement, market surveillance, incident review.
DORA year two, same story: prove the control works, classify in 4 hours.
The rulemaking phase is done. Policy libraries do not score anymore.
At the UN this week: Altman and Amodei asked for global AI rules. The US delegation rejected "centralised control" in the same session.
No global floor is coming. The patchwork is the plan.
Your internal AI governance program is the regulation you'll be judged on first.
California now wants independent auditors onsite at frontier AI labs and a verified emergency shutoff. 98% of large firms say they have AI governance policies. 47% skip them under deadline pressure. Self-attestation is ending. Evidence is the product now.