A practitioner's read on every AI governance drop that matters.
MCP, A2A, agentic UI, NIST AI RMF, Reg S-P, SR 26-2, the EU AI Act — what happened, why it matters for a regulated team, what to do about it, and what to watch out for. Sourced facts, our take clearly labeled as ours.
MCP's biggest revision is dated July 28: sessions gone, Logging deprecated, client registration replaced. What it changes for your AI vendor diligence.
Vanta launched a TPRM Agent, an AI Security Assessment template, and an AI Risk Library in June 2026. An honest read of who it serves — and who it doesn't — for regulated FIs.
When an AI agent acts, 'who did this?' has no good answer. Non-human identity, delegated authority, and why examiners will ask — a practitioner's read.
The EU AI Act doesn't bind most US financial institutions directly. But its obligations flow into your vendors' products and your vendor agreements. Here's how to read it.
A prescriptive AI model-risk rule would raise the compliance burden on small institutions, not lower it. Here's what to watch on the docket — and what to build before it lands.
The Fed's SR 26-2 explicitly excludes generative and agentic AI from model-risk scope. Here's why that carve-out is exposure, not relief, for your institution.
The SEC's FY2026 exam priorities put AI use, 'AI washing,' and AI-enabled cyber threats on the list for advisers. Here's what's actually being examined — and what to have ready.
Reg S-P's amended safeguards rule is now live for every covered RIA and broker-dealer. Here's the AI vendor-oversight file your examiner will ask to see.
OpenAI's ChatGPT Compliance/Logs Platform is Enterprise/Edu-only. If your team is on ChatGPT Business or Plus, you can't export the audit trail your examiner may want.
NYDFS said its October 2024 AI guidance imposes no new requirements — it interprets Part 500. Then it recommends AI-specific vendor reps and warranties anyway. Here's how to read that.
You don't have to be an engineer to use the NIST AI Risk Management Framework. Use it as a crosswalk and a shared vocabulary with your examiner, not as homework.
GAO confirms the NCUA still lacks authority to examine third-party tech vendors. For your AI vendors, that gap doesn't reduce your risk — it lands the whole burden on the credit union.
An MCP server is software with network access to your data — a third party your TPRM program must diligence. Here's how to bring it into vendor oversight.
MCP is how AI tools now plug into your data. Here's what the Model Context Protocol means for your vendor risk, your audit trail, and your next exam.
Computer-use agents now click, fill, and submit inside your applications on a user's behalf. Here's what that does to your audit trail — and the 'who did this?' problem.
Google's Agent2Agent protocol lets your vendors' AI agents call other AIs. Here's what that does to your third-party risk surface — and how to get ahead of it.
See what a Discover scan finds.
The evidence behind the read on this page — for your own institution.