Zan Digital › Topics
Security & Governance
Rules, risk and what regulation actually requires.
- 001Agent Credentials vs Impersonation: The Audit VerdictMachine identities outnumber humans 109 to 1. Impersonation ships faster; dedicated agent credentials survive an audit. The decision, the costs, the migration.109:1
- 002Agent Identity: 109 Machine Accounts Per Human UserMachine identities outnumber humans 109 to 1, and 41% of identity breaches trace to weak non-human identity management. Here is what actually works.109:1
- 003AI Agent Liability: Authority Clauses for 2026 DealsAir Canada paid CA$812.02 for a promise its chatbot invented. Attribution is already settled law. The unsettled part is which clause moves the liability.CA$812.02
- 004AI Audit Log Design: 12 Fields Agents Must RecordOnly 21% of enterprises can see what their agents do at runtime. Here is a 12-field minimum audit record for AI agents, and what each field has to prove.21%
- 005AI Bill of Materials: 7 Clusters, Zero ObligationThe G7 published 7 minimum AI SBOM clusters in May 2026 and made them voluntary. What an AI bill of materials should contain, and 12 fields to ship first.7
- 006AI Copyright Lawsuits: The $1.5B Repricing of Training DataAnthropic paid $1.5 billion, about $3,000 a book, to settle. Here is what the live AI copyright cases could do to model economics and licensing prices.$1.5B
- 007AI Cybercrime: 55% in Africa, 2% in FBI ComplaintsINTERPOL attributes 55% of reported African cybercrime to AI. The FBI's 2025 complaint data puts it near 2%. Why both are right, and which controls follow.55%
- 008AI Data Residency: What EU and India Buyers Demand51% of firms now rate data sovereignty as very important. What EU and Indian buyers actually demand, and where vendor residency claims stop short.51%
- 009AI Employee Monitoring: The €32M Line Nobody Agreed OnAI now scores messages, code and meetings. One regulator fined 32 million euros for it. What is permitted in 5 jurisdictions, and what breaks trust anywhere.€32M
- 010AI Export Controls: The 19 Days Claude Went DarkUS export controls pulled Claude Fable 5 offline worldwide for 19 days in June 2026. The order, the reversal, and the precedent it set for your stack.19 days
- 011AI Governance Maturity: Only 21% Are Ready for AgentsDeloitte surveyed 3,235 leaders and found 21% have mature agent governance. Here is a 5-level maturity model and a self-assessment you can score today.21%
- 012AI Insurance Is Real Now: What Underwriters AskInsurers now write affirmative AI liability cover, and standard policies exclude it. Deloitte sees $4.7bn of AI premiums by 2032. What underwriters ask.$4.7B
- 013AI Red Teaming for Agents: Building a Real ProgrammeNIST red teamers raised agent hijacking success from 11% to 81%. Here is how to scope, staff, run and report an AI red teaming programme for agents.81%
- 014Data Processing Agreement Gaps: 7 Clauses to RewriteMost DPAs predate agent tooling and model updates. Here are the 7 clauses to rewrite, with the EDPB findings and vendor terms that made them stale.38%
- 015Deepfake CFO Fraud: Why Process Beats DetectionBusiness email compromise cost $3.05 billion in 2025 and open source deepfake detectors lose about half their accuracy in the wild. Fix the payment process.$3.05B
- 016EU AI Act Transparency Rules: The 2 August ChecklistArticle 50 transparency duties applied from 2 August 2026, with fines to €15M or 3% of turnover. Only 9 of 27 member states have both enforcers named.€15M or 3%
- 017HIPAA, DORA and AI Controls: Evidence, Not IntentOnly 6.5% of DORA registers passed every data quality check. Here are the HIPAA and DORA control mappings for AI agents, and the evidence each one needs.6.5%
- 018MCP Security: 200,000 Servers Exposed by One Design FlawOX Security found one MCP design flaw exposing up to 200,000 instances across 150 million downloads. Here is how to vet a connector before you trust it.200,000
- 019Open Source AI Licence: The 4 Clauses Nobody ReadsMost open weight models are not open source. 4 clause types decide commercial use, from Llama's 700 million user cap to terms you must pass downstream.700M
- 020Personal AI Accounts: 67% of AI Use Is Off Your BooksVerizon's 2026 DBIR found 45% of employees now use AI on corporate devices, and 67% of them sign in with personal accounts. Source code leads the leak.67%
- 021Prompt Injection: 12 Defences Broken Above 90%Researchers broke 12 published prompt injection defences with attack success above 90%. Why the SQL injection fix has no equivalent, and what actually works.Above 90%
- 022Prompt Injection: 4 of 26 Models Paid the AttackerZscaler ran 26 models against live injected pages and 4 paid the attacker. Why prompt injection is the agent era's SQL injection, and what contains it.4 of 26
- 023Shadow AI Breaches Doubled to 43% and Cost $5.39MShadow AI appeared in 43% of breached organisations in 2026, up from 20% a year earlier, at $5.39M average cost. How to find it, and what to fix first.43%
- 024SOC 2 AI Questions: 9 Artefacts Auditors Now WantThe AICPA has issued no AI-specific SOC 2 criteria. The 2017 trust services criteria already cover AI tooling. Here are the 9 artefacts auditors ask for.0