The Invisible Supply Chain, Part 1: Where AI Data Actually Comes From

Every AI model is, at its core, a direct product of its training data. Long before a system answers its first prompt or makes its first real-world prediction, decisions about data collection, sourcing, and processing have already permanently shaped its behavior. ...

July 9, 2026 · 3 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 2: Vulnerabilities You Can't Patch Out

In Part 1 we looked at how little organizations actually know about where their AI training data comes from. This time, we look at what happens once that unverified data gets baked directly into a model. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 3: How Model-Building Choices Introduce Risk

Parts 1 and 2 of this series covered the data going into a model. This time we look at the technical choices made while training and optimizing it — decisions that introduce their own, separate set of security trade-offs. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 4: The Fine-Tuning Inheritance Tax

So far this series has covered the data going into a model and the technical choices made while training it. Now: what happens when your organization doesn’t build a model at all, but fine-tunes someone else’s. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

The Invisible Supply Chain, Part 5: Navigating the Black Box with Model Cards

The first four parts of this series covered where AI training data comes from, what gets permanently baked into a model, how training and optimization choices introduce risk, and how fine-tuning inherits all of it. This part covers a harder problem: you often can’t check any of it yourself. ...

July 9, 2026 · 2 min · Jason, Cyber Professional

AI Governance Frameworks & Risk: A Complete Landscape

Understanding AI Frameworks and the Risks of Artificial Intelligence A blog post drawing on current frameworks, research, and the MIT AI Risk Repository Introduction Artificial Intelligence is no longer a niche technology. It is embedded in healthcare diagnostics, hiring decisions, financial systems, law enforcement tools, and the everyday software most of us use without a second thought. With that reach comes serious responsibility — and serious risk. Governments, standards bodies, researchers, and international organizations have responded by developing a growing ecosystem of frameworks designed to identify, categorize, and manage those risks. ...

March 31, 2026 · 7 min · Jason, Cyber Professional

EU AI Act: Risk Tiers, Penalties, and the Road to 2027

The EU Artificial Intelligence Act: The World’s First Comprehensive AI Law A deep dive into the landmark regulation reshaping how AI is built and deployed globally What Is It? The EU Artificial Intelligence Act (Regulation (EU) 2024/1689) is the world’s first comprehensive, legally binding regulation governing artificial intelligence. Enacted by the European Union, it establishes a common regulatory and legal framework for AI across all EU member states. ...

March 31, 2026 · 5 min · Jason, Cyber Professional

ISO/IEC 42001: Certifying AI Management Systems

ISO/IEC 42001: The International Standard for AI Management Systems A deep dive into the world’s first certifiable AI governance standard What Is It? ISO/IEC 42001 is an international standard published by the International Organization for Standardization (ISO) and the International Electrotechnical Commission (IEC). It is the first international standard for managing AI systems responsibly — and unlike advisory frameworks, it is certifiable, meaning organizations can formally demonstrate compliance through accredited third-party audits. ...

March 31, 2026 · 4 min · Jason, Cyber Professional

MIT AI Risk Repository: Mapping 1,700+ AI Risks

The MIT AI Risk Repository: Mapping the Full Landscape of AI Risks A deep dive into the most comprehensive academic catalog of AI risks ever assembled What Is It? The MIT AI Risk Repository is a living research database developed by MIT FutureTech. It is not a governance framework, a regulation, or a standard — it is a research tool: a comprehensive, publicly accessible catalog of over 1,700 distinct AI risks, extracted from 74 existing frameworks, taxonomies, and academic classifications. ...

March 31, 2026 · 4 min · Jason, Cyber Professional

NIST AI RMF: Govern, Map, Measure, Manage

NIST AI Risk Management Framework (AI RMF 1.0): The U.S. Standard for Responsible AI A deep dive into the voluntary framework that became the de facto baseline for AI governance in the United States ...

March 31, 2026 · 5 min · Jason, Cyber Professional