AI Compliance & Cyber · Week of July 24, 2026

AI Compliance & Cyber Brief

ISO 42001 turns into a procurement gate, NIST moves toward sector-specific profiles, shadow AI stays invisible, and DoCRA gives boards a defensible answer to “did we do enough?”

The 30-second version

ISO 42001 has quietly become an AI vendor credibility gate

Talking point

ISO 42001 certification is showing up in roughly 40% of enterprise AI vendor RFPs in the EU and about 25% in North America — AWS, Anthropic, and Microsoft already hold it. Vendors without it are losing deals on paperwork, not technical merit.

Content angle

The 5-question ISO 42001 gut check: walk a board through what the standard actually requires versus what most companies assume their existing AI policy already covers.

Question to ask in the room

If I asked your top three AI vendors for their ISO 42001 certificate today, how many could produce one — and do you know what you’d do if none of them could?

Lens: Methodology and technology — not legal analysis. This is orientation on frameworks, tooling, and methodology for AI risk and security conversations with executives. It is not legal advice and not a compliance certification.

NIST AI RMF & ISO 42001 Maturity

How the two dominant AI governance frameworks are maturing from voluntary guidance into procurement and audit expectations.

ISO 42001 has quietly become an AI vendor credibility gate

Talking point

ISO 42001 certification is showing up in roughly 40% of enterprise AI vendor RFPs in the EU and about 25% in North America — AWS, Anthropic, and Microsoft already hold it. Vendors without it are losing deals on paperwork, not technical merit.

Content angle

The 5-question ISO 42001 gut check: walk a board through what the standard actually requires versus what most companies assume their existing AI policy already covers.

Question to ask

If I asked your top three AI vendors for their ISO 42001 certificate today, how many could produce one — and do you know what you’d do if none of them could?

NIST is moving from general framework to sector-specific profiles

Talking point

NIST released a concept note in April 2026 for an AI RMF Profile on Trustworthy AI in Critical Infrastructure (energy, water, healthcare, financial services). It’s early-stage, but it signals where the standard of care is headed for every sector — profiles, not just principles.

Content angle

NIST AI RMF isn’t finished — here’s what the next chapter looks like, and why your industry’s profile is probably next.

Question to ask

Of the four NIST AI RMF functions — govern, map, measure, manage — which one does your organization actually have a named owner for today?

Technical Governance & Controls

Where the actual attack surface and testing discipline stand right now — red teaming, shadow AI, and prompt injection.

AI red teaming has become a measurable line item, not a nice-to-have

Talking point

Mature programs now map red-teaming against three overlapping frameworks — NIST AI RMF, OWASP’s LLM Top 10, and MITRE ATLAS — and organizations with mature AI security testing report roughly $1.9M lower cost per incident. Testing has demonstrable ROI now, not just a compliance checkbox.

Content angle

Your AI pilot needs a red team before it needs a rollout plan — most pilots skip adversarial testing entirely.

Question to ask

Has anyone actually tried to break your AI system on purpose — or is “testing” still just checking that it gives the right answer?

Shadow AI is the biggest technical blind spot in most organizations

Talking point

98% of organizations report employees using unsanctioned AI tools, yet only 37% have any policy to even detect it. Gartner expects task-specific AI agents in 40% of enterprise applications by year-end, up from under 5% a year ago. Visibility isn’t keeping pace with adoption.

Content angle

The AI tool your team is already using without telling you — how employees quietly adopt technology under the radar.

Question to ask

If I asked three random employees what AI tools they used this week that IT doesn’t know about, what would they tell me?

Prompt injection remains the #1 technical risk in production AI

Talking point

OWASP still ranks prompt injection as the top risk to AI systems, and it’s now the leading cause of failures in production agentic AI — systems that don’t just answer questions but take actions. Every agent you deploy is a new door.

Content angle

What prompt injection actually is, in one page — a leave-behind that bridges engineer-to-executive translation.

Question to ask

Does anyone on your team know the difference between an AI chatbot that answers questions and an AI agent that can take actions on your systems — and which one you’ve actually deployed?

DoCRA — Duty of Care Risk Analysis

The emerging methodology for proving “we did enough” on AI security, in a language regulators, insurers, and boards all accept.

DoCRA gives boards a defensible way to justify AI security spend

Talking point

DoCRA is becoming the go-to methodology behind “reasonable security.” It forces a documented, harm-based justification for which AI controls get funded and which don’t, instead of a gut-feel best-practices list. Courts, regulators, and insurers increasingly expect to see that reasoning, not just a policy binder.

Content angle

How to answer “did we do enough?” before anyone asks it — AI readiness as a repeatable methodology, not a feeling.

Question to ask

If your AI program were investigated tomorrow, could you show the math behind why you chose the controls you chose — or would it just be “this felt reasonable”?

Bottom line

What I’d say if asked this week

  1. Shadow AI: 98% of your people are already using AI tools you can’t see. That’s the conversation to open with, because it’s true of almost every room you’re in.
  2. ISO 42001 as a gate, not a badge: this stopped being a nice-to-have cert and started being a deal-blocker in procurement — worth knowing before a vendor conversation, not after.
  3. DoCRA as the defensibility answer: when a CEO asks how much security is enough, this is the methodology that answers it in a way that holds up later.

Worth a second technical opinion

Keep reading

Next briefs

Get the briefs in your inbox

AI in the News, Legal Signal, Security & Compliance, and ROI briefs — written for executives in regulated industries. No spam, unsubscribe anytime.