If an AI agent is attesting your controls, who’s attesting the agent?

https://cdn.mos.cms.futurecdn.net/JpXukHGqkZ8gapEzDQNqRW-1920-80.jpg

I’ve watched engineers lose a week before an audit collecting screenshots no one will ever look at again. I’ve seen incident response plans that exist on paper but have never been tested, and vendor questionnaires completed once and filed away while the risk quietly changed underneath them.

Security teams are under more pressure than ever to prove they can be trusted by customers and boards alike. Yet the frameworks they rely on to demonstrate security are increasingly disconnected from how risk actually shows up in practice.

This gap between appearing secure and being secure isn’t new, but AI is making it impossible to ignore. As AI systems become more complex, traditional compliance-first approaches are struggling to keep pace. The result is a growing reliance on what many security leaders now describe as security theatre: activities that prove a control existed at a point in time but say nothing about whether...

Copyright of this story solely belongs to www.techradar.com. To see the full text click HERE

Read more

https://media.wired.com/photos/6abf96a21c08425a2aa5099d/191:100/w_1280,c_limit/GettyImages-2286465910.jpg

Amazon says it has stopped using NDAs with county officials for data center projects and acknowledges community backlash is leading to data center moratoriums

Sponsor Posts Subquadratic: the LLM built for 12M-token reasoning — SubQ can reason across entire codebases and document sets in one pass with no RAG workarounds. Read how SubQ 1.1 Small holds near-perfect retrieval out to 12M tokens. Introducing Campus: The digital home for educational institutions — Every educational institution needs