AI governance is often discussed through the lens of policies, frameworks, and responsible AI principles. Those tools matter, but they are not where many of the most important AI decisions are actually being made. In practice, AI governance is increasingly happening in contracts. Vendor agreements now decide who can use data, whether customer inputs may
AI tools
Privacy Tip #493 – Stop Using Shadow AI!
As you can tell, I am obsessed with Verizon’s Data Breach Investigations Report. It is worthy of full immersion, and I am picking it apart with precision (here and here). I always spend a lot of time delving into it as it informs and confirms strategies to assist others with prevention and resilience.…
Phishing Now Top Method for Initial Unauthorized Network Access
According to Cisco Talus researchers, phishing is the primary method threat actors use to gain unauthorized access to networks, accounting for more than one-third of all incidents in the first quarter of 2026. This increase is attributed to threat actors using legitimate AI tools to enhance phishing campaigns, particularly against health care and government sectors.…
Vetting AI for Government: California’s Executive Order Sets New Expectations
California Governor Gavin Newsom issued a new executive order aimed at tightening California’s procurement rules for artificial intelligence (AI) vendors and “raising the bar” for companies that want to sell AI tools to the state. The administration says the goal is to ensure contractors meet strong standards and can demonstrate responsible policies that prevent misuse…
AI Governance Programs Provide a Competitive Advantage
In an excellent blog post, “Avoiding AI Pitfalls in 2026: Lessons Learned from Top 2025 Incidents,” ISACA’s Mary Carmichael summarizes lessons learned from top incidents in 2025 using MIT’s AI Incident Database and risk domains. According to Carmichael, an analysis of the incidents showed recurring patterns across different risk domains, including privacy, security…
Privacy Tip #465 – Privacy Risks Associated with AI
The use of AI tools is revolutionizing our society. The efficiency it presents is like nothing we have ever experienced. That said, there are risks worth considering.
“AI poses risks including job loss, deepfakes, biased algorithms, privacy violations, weapons automation and social manipulation. Some experts and leaders are calling for stronger regulation and ethical…
Privacy Tip #454 – Students Sue Kansas School District Over AI Surveillance Tool
Current and former students at Lawrence High School and Free State High School, located in Lawrence, Kansas, have sued the school district, alleging that its use of an AI surveillance tool violates their privacy.
The allegations revolve around the school district’s use of Gaggle, which is an AI tool that mines the district’s Google…
Mastering Information Governance with the ARMA IGIM 2.1 Framework – Part 4: Sustaining and Evolving IG Practices
Finally, after providing the building blocks for strong Information Governance (IG) programs and operationalizing that framework, we discuss how to sustain your IG program in the last part of the series. An effective IG program powered by the ARMA IGIM framework isn’t static. To remain relevant in an AI-driven world, it must be scalable…
Mastering Information Governance with the ARMA IGIM 2.1 Framework – Part 3: Operationalizing the Framework
Last week, we outlined the building blocks for a strong IG program. Now that you’ve laid the groundwork, it’s time to bring your IG program to life. The ARMA IGIM framework emphasizes operational execution in three key areas:
- Procedural Framework
- Capabilities
- Information Lifecycle
These domains are where your framework tangibly interacts with AI systems…
Mastering Information Governance with the ARMA IGIM 2.1 Framework: Part 2 – Building the Foundation
Last week, we introduced you to the ARMA IGIM Framework. What’s next? Every successful Information Governance (IG) program starts with a strong base. The ARMA IGIM framework outlines three critical building blocks:
- Steering Committee
- Authorities
- Support Functions
Implementing these foundational pieces not only gets your IG program off the ground but also creates a…