<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Arnaud Wiehe | AI &amp; Emerging Tech Strategist</title>
    <link>https://arnaudwiehe.com</link>
    <description>Cybersecurity executive, author, and international speaker specializing in AI, emerging technologies, and digital risk.</description>
    <language>en</language>
    <lastBuildDate>Thu, 04 Jun 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://arnaudwiehe.com/rss.xml" rel="self" type="application/rss+xml"/>
    <item>
      <title>AI Agent Debt — The Governance Gap Nobody Is Measuring</title>
      <link>https://arnaudwiehe.com/articles/ai-agent-debt/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-agent-debt/</guid>
      <pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate>
      <description>AI agent debt is the accumulation of abandoned, forgotten, or ungoverned AI agents that continue running with access nobody remembers granting and ownership nobody can identify. Organisations are deploying agents faster than they can govern them, and the lifecycle conversation has barely started.</description>
      <category>AI Governance</category>
    </item>
    <item>
      <title>AI Governance Is Becoming Operational</title>
      <link>https://arnaudwiehe.com/articles/ai-induced-misconfiguration/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-induced-misconfiguration/</guid>
      <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
      <description>Between March 31 and April 8, 2026, Palo Alto Networks Unit 42 published three separate research reports on AI agent security. Together they paint a clear picture: the near-term AI risk is not that models will produce bad content. It is that organizations will deploy AI-enabled systems with unsafe permissions, weak defaults, and incomplete controls.</description>
      <category>AI Security</category>
    </item>
    <item>
      <title>Before You Scale AI Agents, Give Them an Identity, a Privilege Boundary, and a Kill Switch</title>
      <link>https://arnaudwiehe.com/articles/agent-governance-kill-switch/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/agent-governance-kill-switch/</guid>
      <pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate>
      <description>In March 2026, Meta experienced a SEV1 security incident caused by an AI agent. The agent gave flawed technical advice on an internal forum. An engineer acted on that advice, and sensitive company and user data became accessible to unauthorized employees for nearly two hours. The failure was not just a hallucination — it was a chain of trust without verification.</description>
      <category>AI Governance</category>
    </item>
    <item>
      <title>AI Governance Is About Visibility</title>
      <link>https://arnaudwiehe.com/articles/ai-governance-is-about-visibility/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-governance-is-about-visibility/</guid>
      <pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate>
      <description>Most organizations do not have an AI governance problem because they lack ambition. They have a governance problem because they lack visibility. The first move is practical: find the AI usage, classify it, assign an owner, assess the risk, and keep the register alive. This article draws from Chapter 1 of my AI Governance Guide and outlines the six-step AI Inventory Audit every organization should complete.</description>
      <category>AI Governance</category>
    </item>
    <item>
      <title>AI Is Shrinking the Gap Between Vulnerability Discovery and Exploitation</title>
      <link>https://arnaudwiehe.com/articles/vulnerability-timeline-compression-hero/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/vulnerability-timeline-compression-hero/</guid>
      <pubDate>Fri, 01 May 2026 00:00:00 GMT</pubDate>
      <description>On April 14, 2026, Cloudflare published a framing of agents as non-human identity problems — exactly the right way to think about them. The industry is converging on a runtime-first defense model. Your vendor questionnaire should be updated to reflect this.</description>
      <category>AI Security</category>
    </item>
    <item>
      <title>Prompt Injection: Why Runtime Controls Beat Policy Checklists</title>
      <link>https://arnaudwiehe.com/articles/prompt-injection-runtime-controls/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/prompt-injection-runtime-controls/</guid>
      <pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate>
      <description>Google&apos;s field data shows a 32% increase in prompt injection attacks in a single quarter. Two research papers, published the same day, converge on the same architecture: runtime controls, not better prompts, are the correct defense. Here&apos;s why your AI governance committee can&apos;t stop prompt injection — and what can.</description>
      <category>AI Security</category>
    </item>
    <item>
      <title>Future Crimes — The Next Crime Wave Will Target the Control Planes of Everyday Life</title>
      <link>https://arnaudwiehe.com/articles/future-crimes/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/future-crimes/</guid>
      <pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate>
      <description>The most dangerous cyber threat isn&apos;t a new zero-day. It&apos;s a target shift. For thirty years, cybersecurity was built around keeping bad actors out. The next wave of crime is about taking control of the systems we already trust — cars, homes, hospitals, satellites, and AI agents.</description>
      <category>Cybersecurity</category>
    </item>
    <item>
      <title>Your AI Vendor Questionnaire Doesn&apos;t Ask the Questions That Matter Anymore</title>
      <link>https://arnaudwiehe.com/articles/ai-vendor-questionnaire-obsolete/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-vendor-questionnaire-obsolete/</guid>
      <pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate>
      <description>GlassWorm&apos;s 73 sleeper extensions, elementary-data&apos;s CI/CD pipeline hijack, and Cloudflare&apos;s non-human identity reframe all point to the same conclusion: your AI vendor questionnaire is asking about 2023 risks. Here are the questions you should be asking in 2026.</description>
      <category>AI Governance</category>
    </item>
    <item>
      <title>MCP Security: A New Attack Surface Emerges</title>
      <link>https://arnaudwiehe.com/articles/mcp-security-new-attack-surface/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/mcp-security-new-attack-surface/</guid>
      <pubDate>Mon, 27 Apr 2026 00:00:00 GMT</pubDate>
      <description>MCP is becoming a critical dependency layer for AI systems. The real question is no longer what the model can do — it is what it can reach.</description>
      <category>AI Security</category>
    </item>
    <item>
      <title>AI Security in 2026</title>
      <link>https://arnaudwiehe.com/articles/ai-security-2026/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-security-2026/</guid>
      <pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate>
      <description>AI Security in 2026: The shift from model intelligence to connected autonomy, tool use, and containment.</description>
      <category>AI Security</category>
    </item>
    <item>
      <title>The next AI breach may not be a hack, but a trusted feature doing exactly what it was allowed to do</title>
      <link>https://arnaudwiehe.com/articles/trusted-feature-breach/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/trusted-feature-breach/</guid>
      <pubDate>Thu, 16 Apr 2026 00:00:00 GMT</pubDate>
      <description>Many future AI incidents may not start with attackers breaking in. They may start with trusted features doing exactly what they were allowed to do, inside workflows that were never governed tightly enough.</description>
      <category>AI Governance</category>
    </item>
    <item>
      <title>Board oversight of AI is getting real, but most companies still have no operating model beneath the slide deck</title>
      <link>https://arnaudwiehe.com/articles/board-oversight-operating-model/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/board-oversight-operating-model/</guid>
      <pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate>
      <description>AI has clearly entered the boardroom. Directors are asking harder questions. Regulators are raising obligations. Audit and risk committees increasingly want to know where AI is used, who is accountable, and what could go wrong. That is progress. But in many organizations, the visible maturity is still misleading. The board deck looks polished. The principles sound sensible. The policy exists. The steering committee has been announced. And underneath that, the operating model is still missing.</description>
      <category>Article</category>
    </item>
    <item>
      <title>The AI Agent Problem</title>
      <link>https://arnaudwiehe.com/articles/the-ai-agent-problem/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/the-ai-agent-problem/</guid>
      <pubDate>Fri, 10 Apr 2026 00:00:00 GMT</pubDate>
      <description>Enterprise leaders say they expect a major AI agent security incident within the next year, but most still lack the governance, visibility, and accountability needed to manage that risk.</description>
      <category>Article</category>
    </item>
    <item>
      <title>NCSC on Vibe Coding Safeguards: The Real Risk Is Control, Not Code</title>
      <link>https://arnaudwiehe.com/articles/ncsc-vibe-coding-safeguards/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ncsc-vibe-coding-safeguards/</guid>
      <pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate>
      <description>The NCSC&apos;s clear signal to security leaders: AI-generated &quot;vibe coding&quot; is inevitable. The question isn&apos;t whether to adopt it, but how to control it before it scales insecurity across your organization.</description>
      <category>Article</category>
    </item>
    <item>
      <title>The AI Governance Journey (It&apos;s Not About a Checklist)</title>
      <link>https://arnaudwiehe.com/articles/ai-governance-journey/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-governance-journey/</guid>
      <pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate>
      <description>Stop treating AI governance like a spreadsheet exercise. Framework implementation is not a checklist—it is a transformation journey. And increasingly, it is a competitive differentiator.</description>
      <category>Article</category>
    </item>
    <item>
      <title>ISO 42001 Compliance: A Practical Guide for AI Governance</title>
      <link>https://arnaudwiehe.com/articles/iso-42001-compliance-final/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/iso-42001-compliance-final/</guid>
      <pubDate>Sat, 04 Apr 2026 00:00:00 GMT</pubDate>
      <description>In December 2023, ISO/IEC 42001 became the world’s first certifiable AI management system standard. Here’s what it requires, how it relates to the EU AI Act and NIST AI RMF, and what boards should ask before pursuing certification.</description>
      <category>ai-governance</category>
    </item>
    <item>
      <title>The OWASP Top 10 for Agentic Applications</title>
      <link>https://arnaudwiehe.com/articles/owasp-top-10-agentic-ai/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/owasp-top-10-agentic-ai/</guid>
      <pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate>
      <description>OWASP’s Top 10 for Agentic Applications is one of the clearest early frameworks for understanding how autonomous AI systems change the cybersecurity risk landscape. Here is why it matters for security leaders now.</description>
      <category>ai-security</category>
    </item>
    <item>
      <title>Shadow AI: What to Do in 2026</title>
      <link>https://arnaudwiehe.com/articles/shadow-ai-guide-2026/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/shadow-ai-guide-2026/</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description>In 2023, Samsung employees inadvertently uploaded sensitive information to ChatGPT—becoming the most cited example of shadow AI. With 28% of employees now using unapproved AI tools at work, organizations need a Shadow AI Discovery and Response Programme. The EU AI Act now imposes fines up to €15 million for deploying high-risk AI without proper governance.</description>
      <category>ai-governance</category>
    </item>
    <item>
      <title>The Board&apos;s Cyber Agenda Has Changed: What Directors Need to Ask in 2026</title>
      <link>https://arnaudwiehe.com/articles/boards-cyber-agenda-2026/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/boards-cyber-agenda-2026/</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description>Something fundamental shifted in how boards must approach cybersecurity. Directors are now expected to understand cyber as a business resilience issue, a fiduciary responsibility, and increasingly, a personal liability concern. Here are the five questions that should now be standard in every boardroom.</description>
      <category>board-governance</category>
    </item>
    <item>
      <title>AI Governance Starts as Cybersecurity Governance</title>
      <link>https://arnaudwiehe.com/articles/ai-governance-cybersecurity/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/ai-governance-cybersecurity/</guid>
      <pubDate>Wed, 25 Mar 2026 00:00:00 GMT</pubDate>
      <description>The good news is that effective AI governance does not require inventing entirely new frameworks. Organizations that have built robust cybersecurity governance already have the foundation. The challenge is extending those structures to address AI&apos;s unique risks.</description>
      <category>ai-governance</category>
    </item>
    <item>
      <title>The Year of Autonomous Agents</title>
      <link>https://arnaudwiehe.com/articles/year-of-autonomous-agents/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/year-of-autonomous-agents/</guid>
      <pubDate>Sun, 22 Mar 2026 00:00:00 GMT</pubDate>
      <description>Autonomous agents change the security model fundamentally. Why 2026 feels like an inflection point for AI governance, accountability, and agent security.</description>
      <category>ai-governance</category>
    </item>
    <item>
      <title>5 CVEs in 7 Days: The OpenClaw Security Crisis Is Here</title>
      <link>https://arnaudwiehe.com/articles/openclaw-security-crisis-5-cves-2026/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/openclaw-security-crisis-5-cves-2026/</guid>
      <pubDate>Fri, 20 Mar 2026 00:00:00 GMT</pubDate>
      <description>The shift to agentic computing has begun, but security is still DIY. This week, five new vulnerabilities dropped for OpenClaw — five ways your AI agent can be turned against you. Just like early web commerce needed SSL and fraud protection to become mainstream, AI agents need security to achieve widespread adoption. Here&apos;s why early adopters must roll their own security — and what that means for leaders deploying OpenClaw today.</description>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>OpenClaw Security Best Practices: A Practical Guide</title>
      <link>https://arnaudwiehe.com/articles/openclaw-security-best-practices/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/openclaw-security-best-practices/</guid>
      <pubDate>Wed, 18 Mar 2026 00:00:00 GMT</pubDate>
      <description>Practical security best practices for OpenClaw deployments. Learn how to harden your AI agent setup with actionable tips for credentials, network security, and configuration management.</description>
      <category>cybersecurity</category>
    </item>
    <item>
      <title>The Rise of OpenClaw: Why AI Agents Are Taking Over</title>
      <link>https://arnaudwiehe.com/articles/rise-of-openclaw/</link>
      <guid isPermaLink="true">https://arnaudwiehe.com/articles/rise-of-openclaw/</guid>
      <pubDate>Mon, 16 Mar 2026 00:00:00 GMT</pubDate>
      <description>OpenClaw is the fastest-growing AI agent framework. Here&apos;s why developers are flocking to it and what it means for the future of work, automation, and human-AI collaboration.</description>
      <category>industry-trends</category>
    </item>
  </channel>
</rss>