SOC-2
-
Shadow AI Is Now Hiding Inside the Tools You Approved
Shadow AI used to mean pasting company data into an unapproved chatbot. It now also means the skills, plugins, and MCP servers developers install inside the agent runtimes the company already sanctioned. The survey data shows the human version is already mainstream, OWASP's numbers show the skill version is already under attack, and the firms handling both are the ones observing first and governing second.
-
NIST's GenAI Profile Is Voluntary. Your Customers Didn't Get the Memo.
NIST's Generative AI Profile is the most concrete control content we have for GenAI risk, but it is voluntary, and the attestation regimes buyers actually enforce have no native GenAI language. The fix for mid-sized firms is to feed the profile's controls into the SOC 2 machinery they already run, not to build a parallel governance program.