Governance Insights

The Dictiva Blog

Insights on policy operations, attestation, governance education, and AI-agent oversight from the team building Dictiva.

Showing 1-24 of 136 articles

Page 1 of 6

NewsSep 10, 20264 min read

A Reform Is a Maintenance Commitment, Not a Press Release

A reform gets announced, celebrated, and a year later the service still fails and business still pays. The missing piece is an owner for month twelve.

data governanceaccountabilityreform delivery
NewsSep 9, 20263 min read

Anthropic's Safety Pledge Was a Favor, Not a Control

Anthropic barred the UK's safety institute from its newest model. The lesson: a commitment one party can revoke alone was never governance.

AI governanceAI safetyAnthropic
NewsSep 3, 20263 min read

BAE's Controls Never Fired Where the Export Happened

BAE's $36M ITAR penalty shows what happens when controls live in a policy binder, not at the point of export. And BIS just made that gap expensive.

export controlsITAR complianceregulatory enforcement
NewsSep 1, 20264 min read

Most Compliance Programs Die of Assurance, Not Bad Design

The DOJ's new fraud memo spells out where enforcement is headed. The real lesson: controls that live as documents die the moment they're tested.

compliance programsDOJ enforcementinternal controls
ArticleAug 27, 20268 min read

The Model Was Never the Variable

Across three benchmarks, changing the context supplied to a frontier model moved accuracy by 17 to 38 points. Changing the model produced swings statistically indistinguishable from zero. The half of your AI system that decides whether it tells the truth is the half nobody owns, versions, or signs for.

ai-governancecontext-qualitysemantic-layer
NewsAug 26, 20264 min read

Hiring a Red Team Isn't Assurance. Owning the Verdict Is.

A vendor red-teamed OpenAI, Anthropic and Meta, and it went off the rails. Third-party AI testing isn't a control until someone owns the verdict.

AI governancethird-party riskAI safety
NewsAug 25, 20263 min read

Anyone Can Build a Gate. Almost No One Can Close One.

China's gate for frontier AI is already built. That was the easy part. A release gate is only governance if someone owns the authority to halt a launch.

AI governancefrontier AIrelease gates
NewsAug 20, 20264 min read

A Self-Certification Nobody Rejects Is Just a Rubber Stamp

Self-certification only governs if the regulator can say no. When filings flood in and silence means yes, the binding commitment quietly flips into a rubber stamp.

self-certificationregulatory enforcementattestation controls
NewsAug 18, 20265 min read

Nobody Owns the 20-Year FTC Decree Your Company Signed

An FTC settlement doesn't end the case. It starts a 20-year obligation most firms sign without naming who inside actually owns it.

FTC consent decreeregulatory compliancegovernance ownership
NewsAug 14, 20267 min read

The Claim Is Cheap Now. Substantiation Is the Control.

A true "Made in USA" claim can still be illegal without proof. See why substantiation, not honesty, is becoming governance's core control.

substantiationAI governancedata provenance
NewsAug 8, 20267 min read

Your Scariest AI Incident Was a Configuration Error

OpenAI's model 'escaped' its sandbox, but the root cause was a misconfiguration. Why AI's scariest incidents trace back to old governance failures.

AI governancecybersecurityrisk management
NewsAug 6, 20267 min read

The Definition Is the Control Nobody Thought to Govern

A narrowed word in the Endangered Species Act, a new CLO methodology, a defense audit mandate: why definitions are governance's quietest control.

policy governanceregulatory changerisk management
NewsAug 4, 20267 min read

Nobody Voted to Make ChatGPT Government Infrastructure

Congress drafts laws with ChatGPT, and no one approved it. When adoption outruns the procurement gate, governance must go to the point of use.

AI governanceshadow AIvendor risk management
NewsJul 30, 20267 min read

AI Stopped Asking Permission. Your Controls Didn't Notice.

A breach, a productivity tool, and a factory pitch share one capability: autonomous AI action. Here's why your checkpoint controls no longer fire.

agentic AIAI governanceaccess controls
NewsJul 29, 20267 min read

Your Risk Model Is a Parlay. Someone Is Betting Against It

Retail bettors lost $294M on Kalshi parlays. The AI chip trade cracked on one weak leg. Your risk register hides the same compound bets.

risk managementthird-party riskAI governance
NewsJul 23, 20267 min read

Your Thresholds Expired. You Just Haven't Noticed Yet.

Merrill Lynch's $7.5M fine shows a control can work exactly as designed and still fail. Why every compliance threshold has an expiration date.

compliance monitoringinternal controlsAML
NewsJul 22, 20267 min read

Every Control Has an Off Switch. Who's Holding Yours?

Regulators are handing discretion back to companies: from SEC reporting choices to shrinking agencies. Here's why that raises internal control stakes.

internal controlsregulatory complianceboard governance
NewsJul 16, 20267 min read

When AI Is Table Stakes, Governance Is the Only Moat

AI is now table stakes, and attackers wield the same models you do. When technology stops being the differentiator, governance becomes the real moat.

AI governancecybersecuritysoftware supply chain
NewsJul 15, 20268 min read

The Most Dangerous Risk Is the One You Already Know About

Microsoft's Secure Boot was broken for a decade. GPT-5.6 deletes files it disclosed in June. Your real risk is the one you already know about.

vulnerability managementAI governancesoftware supply chain
NewsJul 14, 20266 min read

You Don't Build Your Stack. You Assemble It From Strangers.

The threats that matter now arrive as trusted components: AI models, CI/CD workflows, open-source tools. How governance shifts to composition.

software supply chainai governancethird-party risk
NewsJul 9, 20267 min read

You Can Delegate the Work. You Can't Delegate the Blame.

From HIPAA fines to AI agents to Amazon's marketplace, enforcers are refusing to let organizations delegate away the blame. Here's the new rule.

accountabilitythird-party riskAI agents
NewsJul 8, 20267 min read

The Real Bottleneck Isn't Making Things. It's Governing Them.

AI generates code, attacks, and capital faster than we can review. The scarce resource now is governance capacity, not generation speed.

AI governanceSDLC governancecybersecurity
NewsJul 7, 20267 min read

The 'Trust Me' Era Is Over: Governance Must Now Verify

AI made every claim cheap to fake, from Tidal's royalty detection to autonomous ransomware. Governance is shifting from attestation to verification.

continuous verificationAI governancecompliance
NewsJul 2, 20267 min read

Frictionless Is a Trap: Friction Is Your Control Surface

The race to eliminate friction is quietly dismantling the checkpoints governance depends on. Here's why friction is a control asset, not just a cost.

governance strategyinternal controlscompliance