Categories
AI Today in 5

AI Today in 5: September 29, 2026, The Risk Register Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Stale risk registers. (FinTech Global)
  2. What’s under your AI hood. (FinTech Futures)
  3. Nvidia releases SW to stop AI from ‘misbehaving’. (CNBC)
  4. Strengthening global trade compliance with AI. (CA&AS)
  5. US corps adopting cheaper IE, Chinese AI models. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Blog

De-Risking AI Adoption Through Accountability and Effective Governance

A company can publish thoughtful AI principles, appoint a governance committee, and still struggle to answer a basic question: who can stop an AI system when its behavior creates unacceptable business risk? For chief compliance officers and boards, that question reaches the heart of program effectiveness. Policies establish expectations. The real test comes when someone must decide, enforce a boundary, and show what happened.

Pamela Gupta addresses that challenge in De-Risking AI Adoption: The AI Trust Layer: An AI Governance Playbook. Her central argument is that trustworthy AI requires an operating model connecting ownership, controls, deployment decisions, monitoring, and evidence. The book provides a structure for translating responsible AI commitments into repeatable business practices. For compliance professionals, its value lies in explaining how governance can support adoption while keeping accountability attached to the people making consequential decisions.

Making Trust Operational

Gupta defines trustworthy AI through three practical capabilities: people can understand the behavior to expect and its limits, verify what actually occurred, and identify an accountable person when something goes wrong. This moves the discussion toward demonstrable performance.

That approach should resonate with any CCO who has examined the distance between a written procedure and actual business conduct. An AI policy may require human oversight. Whether that oversight works depends on the reviewer’s information, competence, time, and authority to intervene. A human approval step has limited value if the organization rewards automatic acceptance or discourages challenges.

The compliance application is straightforward. For each significant AI use case, identify the business purpose, potential harm, responsible owner, operating limits, and evidence needed to evaluate performance. These questions belong at the beginning of development and procurement, when the answers can still shape the system.

Eight Pillars of AI Governance

The book organizes its methodology around AI TIPS™, Gupta’s framework of eight interconnected pillars: cybersecurity, privacy, ethics and bias, transparency, explainability, regulations, audit, and accountability. Together, they address the different ways AI can create enterprise exposure.

The connections matter. Security controls may protect information against unauthorized access while leaving questions about discriminatory outcomes unresolved. Transparency can establish which data and processes a system uses, while explainability addresses whether people can understand and challenge a particular decision. Independent assurance requires evidence from across these activities.

Gupta also presents mappings to established frameworks and standards, including the NIST AI Risk Management Framework and ISO/IEC 42001. Her purpose is to connect enterprise controls and evidence across multiple governance expectations.

For a compliance team, the practical lesson is to coordinate existing expertise. Privacy, security, legal, risk, audit, and business leaders each hold part of the answer. The CCO can help connect their work through common requirements, escalation procedures, and documented decisions. Business owners must remain answerable for the systems they deploy.

Accountability Must Carry Authority

Accountability receives special treatment throughout the book. Under Gupta’s methodology, a critical accountability failure blocks deployment regardless of the aggregate governance score. A system needs a named owner with authority to accept risk and stop its operation. Consequential uses also require appropriate human override and redress mechanisms.

This is a useful challenge to governance committees that distribute responsibility so broadly that no individual can decide. Participation in a committee does not automatically establish authority over a business process.

CCOs should translate this principle into explicit decision rights. Who approves the use case? Who accepts the remaining risk? Who authorizes exceptions? Who can suspend operation? Who addresses harm to an affected customer or employee? Document and understand those answers before an incident forces the organization to discover whether its governance arrangements work.

Governance Throughout the Lifecycle

Gupta’s gated lifecycle makes these responsibilities actionable. It follows AI from concept and planning through data preparation, development, independent validation, deployment, continuing monitoring, and retirement. Decision gates establish criteria for moving forward and identify the people authorized to approve or refuse progression.

Independent validation is particularly important. The team building a system should face review capable of challenging its assumptions and testing whether performance meets the intended use. Deployment readiness also includes monitoring, incident response, rollback capability, and operational procedures.

For compliance professionals, the lesson extends beyond initial approval. A system’s exposure can change when it receives new data, serves a different population, gains additional permissions, or undergoes a material modification. Gupta calls for defined triggers that return systems to validation.

Apply the same discipline to exceptions. Record the rationale, compensating controls, approver, remediation owner, and expiration date. An exception should remain visible until it is resolved. Retirement deserves similar attention, including appropriate data disposition and preservation of evidence needed to explain earlier decisions.

Measuring Whether Controls Work

The Trust Index gives Gupta’s framework a common measurement approach. It combines control implementation, control effectiveness, residual risk exposure, and compliance status into pillar scores and an overall assessment. The methodology assigns the greatest combined emphasis to whether controls exist and whether they work.

For boards, this creates a way to discuss changes in governance performance and direct attention toward unresolved weaknesses. Gupta also distinguishes inherent risk from current risk after controls. An inherently consequential use case does not become inconsequential because its controls improve.

The compliance implication is to examine the evidence supporting the number. Directors should understand significant weaknesses, testing results, exceptions, and corrective actions. A dashboard becomes useful when it supports decisions about resources, restrictions, and remediation. The underlying assessment must remain open to challenge, especially where a favorable aggregate score could obscure a serious problem in one area.

Governing AI That Takes Action

The book’s treatment of agentic AI deserves senior executives’ attention. An AI system that can invoke tools, modify records, send communications, or initiate transactions introduces questions about delegated business authority. Evaluating the model’s outputs covers only part of that exposure.

Gupta describes an agentic control plane that governs identity, permissions, tools, memory, delegation, observation, and intervention. A central principle is that consequential boundaries must operate outside the agent’s own reasoning. Written instructions alone cannot reliably limit what credentials and connected tools permit.

Consider a compliance application: an agent assisting with third-party onboarding. Management should distinguish permission to summarize diligence materials from permission to approve a supplier, alter payment information, or release a blocked transaction. Each capability requires deliberate authorization and appropriate controls.

Internal controls professionals know this lesson. Delegated authority needs defined limits, traceable actions, and effective intervention. Automation increases the importance of those disciplines because actions can occur faster than a person can review them.

Data and Third Parties Remain Central

Gupta also emphasizes the information an AI system uses when it acts. Policies, customer records, retrieved documents, and stored memory shape its behavior. Even a system operating within its permissions can make a harmful decision when its information is outdated or inappropriate.

For compliance teams, this means governing the sources behind AI advice. An assistant answering employee questions should use approved, current policies with identifiable owners and version histories. Access restrictions should continue to apply when information enters a retrieval system.

Third-party oversight must also reach beyond the primary model provider. Gupta examines tools, connectors, and packaged agent capabilities as supply-chain dependencies. She adds a business continuity question: what happens if a critical model becomes unavailable? Organizations should identify affected processes, evaluate alternatives, and test fallback arrangements before disruption forces an improvised response.

Evidence the Board Can Use

Gupta’s evidence-by-design approach connects the entire operating model. Significant decisions and actions should generate records as work occurs: approvals, validation results, system versions, permissions, relevant context, interventions, and monitoring outcomes. Those records should support reconstruction of a consequential action.

For boards, reporting should connect this evidence to oversight. Which systems carry the greatest exposure? Which controls have failed testing? Which exceptions remain unresolved? What has management restricted, delayed, or rejected? What decisions require board attention?

The CCO’s contribution is to make this reporting actionable and consistent with operational reality. Evidence should reveal where management needs to intervene and whether previous corrective actions achieved their intended result.

A useful starting exercise is to select one consequential AI decision and trace it from initial authorization to its outcome. Ask the owner to produce the supporting evidence. Any missing link identifies a concrete improvement for the governance program to address.

Practical Steps for CCOs and Boards

Gupta recommends starting with an honest readiness assessment and a manageable set of high-impact use cases, then expanding proven governance practices. Apply that approach through five actions:

  1. Inventory consequential AI systems, their owners, permissions, and dependencies.
  2. Establish authority for approval, exceptions, escalation, and suspension.
  3. Test controls against actual business risks and affected populations.
  4. Capture decision evidence during ordinary operations.
  5. Give the board visibility into unresolved exposure and remediation.

The business lesson from De-Risking AI Adoption is that effective governance makes responsible adoption repeatable. For CCOs and boards, the immediate task is to make accountability observable in how AI is approved, operated, challenged, and improved.

Categories
Blog

Andrew McBride Does it Again: His New Guide on Buying Compliance Technology

Compliance technology has become the operational backbone of the modern ethics and compliance program. When technology works, it can make compliance faster, more consistent, measurable, and embedded in business operations. When it doesn’t, the consequences show up everywhere: spreadsheets, manual workarounds, disconnected data, frustrated employees, and compliance professionals spending time administering technology rather than managing risk.

That makes buying compliance technology more than an IT procurement exercise. It is a compliance program effectiveness issue. One commentator on this aspect of AI for compliance is Andrew McBride, founder of the consulting firm Integrity Bridge LLC. McBride recently released Recommended Practice for Buying & Selling Compliance Technology, based on surveys of compliance technology buyers and vendors. Its findings illuminate a fundamental imbalance in the marketplace. I can safely say this paper is the standard for compliance professionals evaluating and purchasing AI-based technology.

CCOs buy compliance technology infrequently. Vendors sell it every day. That imbalance matters. Compliance teams can be oversold on functionality. Vendors can become trapped in opaque procurement exercises. Business requirements can become disconnected from technical requirements. AI capabilities can be accepted without sufficient governance. Contracts can focus extensively on getting into a system while ignoring how the company will eventually get out. For the CCO, the lesson is straightforward. If you want to run compliance like a business, you must learn to buy compliance technology like a business. This is where McBride comes in.

Start With Strategy, Not Software

As a CCO, start with a documented compliance technology strategy aligned with business operations. McBride sees three operational layers for that strategy.

Compliance-owned technology includes platforms compliance directly manages, such as Codes of Conduct, training, whistleblower systems, investigation case management, and workflows for gifts, entertainment, and conflicts.

Compliance-shared technology includes systems operated across functions, such as third-party due diligence, transaction monitoring, and communications monitoring.

Enterprise dependency technology includes compliance systems that may not be owned but depend on ERP, CRM, HRIS, procurement, and financial platforms.

This third category is particularly important. A CCO may believe the company has a third-party risk problem when the real issue is poor vendor master data. Transaction monitoring may generate noise because underlying financial data is inconsistent. Technology strategy therefore begins with understanding the compliance program’s architecture.

Know What Compliance Really Costs

Here, McBride frames the question as, ‘What is the total cost of ownership? ‘How many screening tools are independently licensed by Compliance, Procurement, Finance, Credit, and Legal? How many employees maintain spreadsheets? How many hours are spent chasing approvals or reconciling systems? How much compliance talent is consumed by administration rather than risk management? Those costs matter because an inexpensive system can become extraordinarily expensive once you include the human infrastructure required to run it.

This leads to the recurring question: buy, build, or assemble? Internal IT may propose building custom tools. Sometimes that works, but the calculation must include maintenance, upgrades, staffing, cybersecurity, documentation, and key-person risk. Another option is configuring technology the company already owns. That may reduce licensing costs, but “we already own it” does not mean “it is free.” Configuration, integration, testing, administration, and support still cost money.

Commercial software offers established products and vendor-supported roadmaps, but buying software does not eliminate implementation challenges. Apply the same economic discipline to all three options. Don’t compare the sticker price of commercial software with an internal solution whose real costs have never been calculated.

AI Changes the Conversation

AI is moving into transaction analysis, investigation scoping, interview preparation, monitoring, and other compliance workflows. The opportunity is substantial. So is the governance challenge. The Integrity Bridge research presents an interesting picture. AI use appears widespread, but governance and confidence have not necessarily kept pace. Only about one in four compliance teams surveyed had established a formal governance framework. Fewer than half could articulate how AI demonstrably improved compliance outcomes. Only 41 percent of compliance leaders trusted AI-driven outputs for operational decisions.

At the same time, 84 percent reported efficiency gains, while fewer than half reported actual cost savings. That distinction between efficiency and effectiveness is critical. Doing something faster does not necessarily mean doing it better. The CCO should not simply ask, “Does this product use AI?” The better question is, “What compliance outcome does the AI improve, and how can we demonstrate it?”

AI Governance Starts Under the Hood

“AI-powered” is not a meaningful technical specification. McBride advises that compliance should understand what happens under the hood. Once again, he is spot on. Ask questions such as, “Which model is being used?” What information goes into it? What comes back? Is customer information retained? Can corporate data be used for training? Does a third-party model provider receive the information?

These are compliance governance questions because the data may include investigations, employee information, third-party records, or financial information. The contract should address how that information is handled and establish appropriate restrictions on the use of corporate data and queries.

Next, a series of questions about where the AI can fail. Here McBride suggests: How does the system prevent cross-tenant data leakage? How does it identify unsupported statements, hallucinations, or fabricated citations? What happens when malicious instructions are hidden inside uploaded documents? Most importantly, does the system recognize when it lacks sufficient confidence and escalate the matter to a human?

One of the most important characteristics of compliance AI may not be its ability to answer questions. It may be its ability to recognize when it should not answer them.

Keep Humans in the Control Environment

Agentic AI raises the stakes because technology moves from providing information to taking action. But this requires clear authority boundaries. What systems can the agent access? What records can it change? What decisions can it make? Which actions require approval?

Certain compliance decisions should remain subject to documented human authorization. Closing an investigation, changing third-party screening rules, or approving high-risk onboarding are obvious examples. This is where AI governance becomes internal controls. The organization should demonstrate not merely that humans are theoretically “in the loop,” but where human intervention occurs, who has authority, what approval evidence is retained, and what happens when the AI crosses a defined threshold.

CCOs must also understand AI economics. Traditional platforms may be priced by employees, users, or third parties. AI functionality can introduce consumption pricing tied to tokens, documents, searches, or API calls. Model realistic usage and negotiate appropriate spending caps, alerts, overage controls, and consumption rates.

Turn the RFP Into a Governance Exercise

A good RFP does more than collect vendor responses. It forces the organization to define what it actually needs. McBride highlights vendor frustration with “phantom RFPs,” where an incumbent has effectively been selected, or the process is used primarily to gain renewal leverage. A credible RFP must instead be transparent, disciplined, and operationally grounded.

Start with Procurement. Understand source-to-pay requirements, spending thresholds, cybersecurity reviews, privacy requirements, and contracting procedures before bringing vendors deep into the process. Then give vendors meaningful operational information: employee populations, transaction volumes, existing systems, data maturity, integrations, geographic requirements, and workflow constraints.

Most importantly, force precision into vendor answers. Require vendors to classify functionality as:

  1. Available out of the box.
  2. Available through configuration.
  3. Available through a named third-party integration.
  4. On the roadmap with a committed date.
  5. Not supported.

That discipline can dramatically improve an evaluation and create a record of what was actually promised.

Stop Buying Features. Test Controls.

Feature checklists have limits.

McBride suggests that a better test is a scenario. Suppose a critical third party is added to a sanctions list overnight. Ask the vendor to show exactly what happens. Ask questions such as, “How is the alert generated?” Who receives it? How is it prioritized? Who can override it? How is the matter escalated? What evidence is captured? What appears in the audit trail?

Now you are not evaluating a feature. You are evaluating a control. The same principle applies to sandboxes. A generic vendor sandbox tells you relatively little. Require a guided environment configured around your workflows using synthetic or anonymized data. Make users perform the work. That is where implementation problems begin to reveal themselves.

Look Under the Hood Before You Buy

A beautiful interface can be seductive, but buying compliance technology based primarily on user experience is like buying a house because you like the countertops without checking the plumbing. However, before you make a final selection, conduct due diligence around security controls, hosting, uptime, integrations, implementation resources, and data portability.

Review relevant SOC 2 Type II controls. Speak with peer customers. Consider asking to speak with a customer that recently left the platform. Just as importantly, interview the people who will actually implement the product. The team delivering the sales demonstration may not be the team handling implementation. Know who shows up after the contract is signed.

Begin the Relationship by Planning the Exit

Perhaps the most overlooked element of compliance technology contracting is the exit. Companies spend enormous time determining how information will enter a system and surprisingly little determining how they will get it back. A CSV containing basic fields may not recreate an investigation file or preserve the history of a third-party approval. It may not capture attachments, comments, timestamps, escalations, approvals, or audit trails.

Before signing, define export requirements. Ask questions such as: What formats will be provided? What metadata will be preserved? What happens to attachments? Will the audit trail survive? How long will migration assistance remain available? What will extraction cost? When will the vendor delete remaining copies? Understand how you will leave a compliance technology provider before deciding to join it.

The CCO’s Technology Mandate

Compliance technology doesn’t succeed or fail when Legal finishes negotiating the contract. The outcome is largely determined earlier. Did Compliance understand the business problem? Did it know the true cost of the existing process? Did it understand its data? Did it challenge AI claims? Did it test failure modes and workflows? Did it involve Procurement, IT, Privacy, Security, Legal, and the business at the right points? Did it negotiate for implementation, operation, and exit?

Those questions turn technology procurement into compliance governance. Compliance professionals spend their careers asking businesses to operate with transparency, accountability, documentation, fairness, and integrity. Compliance should bring those same principles into the technology marketplace.

Define what you need. Understand what it costs. Test what the vendor claims. Document what was promised. Build controls around AI. Measure whether the technology improves the program. Make sure you can get your data back when the relationship ends. That is what it means to run compliance like a business.

Practical Takeaways

For the CCO, the mandate is clear: build the strategy before selecting the technology; calculate the Total Cost of Ownership rather than the license cost; treat AI as a governance and internal controls issue; test workflows rather than watch demonstrations; diligence the implementation team; and negotiate data portability and exit before signing.

For boards and senior management, the oversight question is equally straightforward: What compliance risk is this technology addressing, how will management measure whether it improves program effectiveness, and what controls govern its use?

The answer tells you much more than whether Compliance has purchased the latest technology. It tells you whether the organization is building a technology architecture that can support an effective compliance program.

If you do not follow Andrew McBride on LinkedIn, you should. He is leading the discussion on the practical aspects of putting the right AI tool in place for you and your organization. His organization will be displaying at this week’s SCCE CEI, so drop by the Integrity Bridge and find out why I think he is the go-to guy in this area.

Categories
Daily Compliance News

Daily Compliance News: September 28, 2026,  The Falling Behind Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Foreign banks now after UBS. (Reuters)
  • Governments being left behind by AI. (NYT)
  • Former Indonesian Education Minister’s corruption conviction upheld. (Bloomberg)
  • Manchester City corruption hurting UK/UAE relations. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
AI Today in 5

AI Today in 5: September 28, 2026, The $1 Billion Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Governments being left behind by AI. (NYT)
  2. AI tools for employment raise privacy and compliance challenges. (Ogletree Deakins)
  3. Oz says AI will drive up healthcare costs. (Healthcare Dive)
  4. AI scams top Italian bank. (Reuters)
  5. Insurers say AI driving up hospital costs by nearly $1bn. (Reuters)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
2 Gurus Talk Compliance

2 Gurus Talk Compliance: The Slop Grenades Edition

What happens when two top compliance commentators get together? They talk compliance, of course. Join Tom Fox and Kristy Grant-Hart on 2 Gurus Talk Compliance as they discuss the latest compliance issues in this week’s episode!

Stories This Week Include:

  • Former Vitol trader Javier Aguilar sentenced to 4 years.   (Bloomberg)
  • Russia seizes control of Nestle operations.  (WSJ)
  • The Class ceiling in America.   (NYT)
  • SEC rollback puts audit fees at risk. (FT)
  • Must AI companies disclose ‘dangerous events’? (Reuters)
  • OpenAI Discloses Six New Incidents of ‘Concerning’ A.I. Behavior. (NYT)
  • Shopify CEO says employees’ ‘slop grenades’ are making more work for everyone else. (Fortune)
  • Payments Scandal Rocks LA Clippers. (Radical Compliance)
  • Florida man dressed in full jester costume arrested for pulling 12-inch dagger on landscaper over loud mowing. (AOL)
  • The EU AI Act Is No Longer Theoretical. (Volkov Law)

Resources:

Kristy

Kristy Grant-Hart on LinkedIn

Order Kristy’s updated 10-year new edition of How to Be a Wildly Effective Compliance Officer by clicking here.

Tom

Check out Tom on LinkedIn

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Daily Compliance News

Daily Compliance News: September 25, 2026, The PE and Law Firms Edition

Welcome to the Daily Compliance News. Each day, Tom Fox, the Voice of Compliance, brings you compliance-related stories to start your day. Sit back, enjoy a cup of morning coffee, and listen in to the Daily Compliance News. All from the Compliance Podcast Network. Each day, we consider four stories from the business world, compliance, ethics, risk management, leadership, or general interest for the compliance professional.

Top stories include:

  • Creating world AI controls via group chat. (WSJ)
  • Corruption shaking up the Brazilian Presidential election. (NYT)
  • The monster behind Russia sanctions evasion. (NYT)
  • Private Equity will pay out to lawyers. (FT)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.

Categories
Compliance and AI

Compliance and AI: SendSafely’s Brian Holyfield on Shrinking the Blast Radius

What is the intersection of AI and compliance? What about Machine Learning? Are you using ChatGPT? These questions are just three of the many we will explore in this cutting-edge podcast series, Compliance and AI, hosted by Tom Fox, the award-winning Voice of Compliance. In this episode, host Tom Fox visits Brian Holyfield, Co-Founder & Chief Product Officer at SendSafely.

Holyfield’s background in ethical hacking and real-world security testing shapes his practical view of cybersecurity. He believes compliance should reflect how breaches actually happen, especially through vendors and service providers, which means organizations must look beyond their own perimeter. For him, data minimization and retention controls are essential: companies should keep only the data they truly need, delete unnecessary copies, and limit where sensitive information lives. Holyfield also stresses reducing the blast radius, arguing that the best defense is to assume a breach will occur and design systems so attackers can access as little data as possible for as short a time as possible.

Key highlights:

  • Preventive AI governance through data minimization
  • Deliberate configuration choices that shrink breach blast radius
  • Aging Out Data Into Secure Backend Archives
  • Native end-to-end encrypted storage for regulated attachments
  • Trust Layer for End-to-End Encrypted Regulated Data

Resources:

SendSafely

Brian Holyfield on LinkedIn

Tom Fox

Instagram

Facebook

YouTube

Twitter

LinkedIn

Categories
Everything Compliance

Everything Compliance: The Conflicts of Interest, The False Claims Act, AI and More AI Edition

Welcome to a revamped Everything Compliance. We have a new host, Adam Turteltaub, and a new panelist, Rebecca Walker, who joins returning regulars Matt Kelly, Jonathan Armstrong, and Karen Moore for the next iteration of Everything Compliance. This episode features a cross-Atlantic discussion on emerging compliance issues. Fan favs Shout Outs and Rants end this week’s episode.

  • Karen Moore looks at the growing Federal trend of bringing False Act Claims against corporate DEI programs.
  • Jonathan Armstrong describes the first public GDPR report of an AI agent attack and offers nine responses.
  • Rebecca Walker reviews key data from Navex anonymized disclosures, including COIs.
  • Matt Kelly looks at recent guidance from the New York State Department of Financial Services on AI risk assessment.

The members of Everything Compliance are:

The award-winning Everything Compliance is a part of the Compliance Podcast Network.

Categories
AI Today in 5

AI Today in 5: September 24, 2026, The Complicating Compliance Edition

Welcome to AI Today in 5, the newest addition to the Compliance Podcast Network. Each day, Tom Fox will bring you 5 stories about AI to start your day. Sit back, enjoy a cup of morning coffee, and listen in to AI Today in 5. All from the Compliance Podcast Network. Each day, we consider five stories from the business world on compliance, ethics, risk management, leadership, or general interest in AI.

Top AI stories include:

  1. Flock says it will set limits. (WSJ)
  2. Mental health strains on AI workers. (FT)
  3. Does the EU AI Act complicate compliance? (IAPP)
  4. Boards say they need more from management on AI. (CCI)
  5. Compliance teams struggling with AI auditing. (FinTech Global)

My first work of general non-fiction is now out: Deluge Before Dawn, the story of the 2025 flood in Kerr County, Texas, which killed 119 people and devastated a county. It is a story of tragedy, heartbreak, survival, and resilience.

It is available on the following sites:

Amazon.com

Stoney Creek Publishing

Barnes and Noble

Texas A&M University Press

Bookshop.org

Google.Books

Walmart

This week only, the Kindle e-book version is available for $0.99 on Amazon.