The Human Take
AI Governance Frameworks attempt to tame and navigate the rapidly changing nature of AI integration and adoption. Rebecca put AI integration under her keen flashlight this week.
There are three frameworks helpful to guide your use of AI.
- EU AI Act
- NIST AI RMF
- ISO / IEC 42001
Let me share a bit of my experience with preparing the EU AI Act for a leading global payment processor in 2025-6. It was a significant lift – over 1,000 hours from our team. The EU AI Act sets the requirements for AI uses. Our bank payments and fraud fell into a higher risk category. They’re not excluded, but require policies, inspection and due diligence. We accomplished the attestation and the effort was well worth it.
What I discovered. Preparing for AI adoption is a daunting task, begin with ensuring the essentials:
- Identify where the human-in-the-loop occurs
- Ensure explainability of your AI use
- Ensure traceability of your AI use
- Document and learn.
Now enjoy what Rebecca has for you. She’s our most trusted AI partner!
Bonus. This is a wonderful article that addresses all three frameworks Global AI Governance Comparison 2026: EU AI Act vs NIST AI RMF vs ISO/IEC 42001
– David Kohrell, GRC Professor
Rebecca’s Intelligence Gathering – 20AUG2026

- Shadow Campaigns are hitting ministries and suppliers across Europe and Asia-Pacific.
- AI is rapidly being integrated into both offensive attack techniques and defensive detection systems.
- A surge of 44 zero-day exploits in one week overwhelms enterprise defenses worldwide.
Regional Campaigns
Global espionage operation “Shadow Campaigns” breaches 70 …
The “Shadow Campaigns” are a coordinated and deliberate espionage operation that has successfully breached numerous organizations across dozens of countries.
The campaign’s targets include critical ministries such as finance, foreign affairs, trade, and interior, alongside national law enforcement bodies and parliaments.
These targeted attacks demonstrate a clear focus on specific regions and economic partnerships.
Victims span Europe, the Americas, Asia-Pacific, and Africa, with one notable victim being a major Taiwanese power equipment supplier, illustrating how these campaigns prioritize strategic geopolitical interests.
Sources:
Cyberinsider (Shadow Campaigns): https://cyberinsider.com/global-espionage-operation-shadow-campaigns-breaches-70-orgs-in-37-countries/
Unit42 (Shadow Campaigns): https://unit42.paloaltonetworks.com/shadow-campaigns-uncovering-global-espionage/
AI Integration
Guide to AI in Cybersecurity: 7 Use Cases of AI Automation
AI agents are revolutionizing cybersecurity by optimizing SecOps workflows and maximizing return on investment across various functions.
Use cases include automating threat hunting, classifying vulnerabilities, and integrating human intelligence with machine learning to handle complex security tasks.
In defense applications, AI is crucial for real-time monitoring and detection; one specific example involves the Automated Indicator Sharing (AIS) service using an AI decision tree to assign a Confidence Score to incoming cyber threat indicators.
Offensively, attackers are leveraging AI at unprecedented speed to bypass traditional security measures.
Sources:
Swimlane (AI Use Cases): https://swimlane.com/blog/how-is-ai-used-in-cybersecurity/
CISA (AI Use Cases): https://www.cisa.gov/ai/cisa-use-cases
Zero-Day Exploits/CVEs
44 Zero-Days in One Week: The Exploitation Surge Overwhelming Enterprise Defenses
A massive surge of vulnerabilities has hit the industry, with 44 zero-day exploits being reported in a single week.
These flaws affect widely used enterprise software, including Microsoft Defender, VMware vCenter, and SAP Commerce Cloud, putting organizations under intense pressure to patch.
One specific critical finding involves Windows vulnerability CVE-2024-43461, which was exploited using the Atlantida info-stealer.
This exploit allows attackers to infect devices by abusing braille “spaces,” stealing passwords and authentication cookies from infected systems.
Sources:
Defend Edge (Exploit Surge): https://www.defendedge.com/zero-day-exploit-surge-2026-enterprise-defenses-overwhelmed/
BleepingComputer (Windows Zero-Day): https://www.bleepingcomputer.com/news/security/windows-vulnerability-abused-braille-spaces-in-zero-day-attacks/