Aeon AI Risk Management

AI Governance Insights

Thought leadership on AI implementation, cybersecurity, governance, regulatory frameworks, and defensible AI programs.

AI Governance - 7 min read

AI 2040 Plan A: Why Verifiable AI Governance Matters

AI 2040 Plan A proposes a verified slowdown to superintelligence. Aeon examines its compute controls, transparency regime, security assumptions, and immediate implications for boards and operators.

AI Research - 8 min read

Kimi K3 Looks Like a Cost-Frontier Break. The Asterisk Matters.

Kimi K3 appears near the coding frontier at less than USD 1 per task, while GLM-5.2 offers open weights and private deployment with weaker hosted task economics. Aeon separates comparable measurements from provisional cross-suite evidence.

AI Security - 4 min read

What Is an AI Agent Security Assessment?

An AI agent security assessment reviews what an agent can access, execute, or leak across tools, APIs, MCP servers, RAG systems, permissions, logs, and data paths. It is the missing security layer for teams moving agents from demo to production.

AI Security - 4 min read

RAG Security Assessment Checklist

A RAG security assessment reviews document access, tenant isolation, retrieval permissions, prompt injection, connector behavior, logging, and data leakage paths before sensitive context moves through an AI workflow.

AI Security - 4 min read

AI Security Evidence for SOC 2 Readiness

SOC 2 buyers ask for evidence, not claims. AI systems need tested security artifacts for agents, APIs, MCP tools, RAG, access control, logging, remediation, and retest evidence.

AI Governance - 5 min read

What the Fable 5 outage means for firms that rent their AI

Claude Fable 5 was released June 9, 2026, pulled offline June 12 under a US export directive, and restored July 1: three weeks of interruption on the newest frontier tier. It is not a one-off. The strategic issue is dependency, not villainy: rented AI capability changes on the vendor's schedule. What resilient firms do, and when to consider owned inference.

AI Security - 7 min read

The Agentic Harness Is Cutting Your Costs and Widening Your Blast Radius

Agentic harnesses (coding agents, MCP tool servers, multi-agent orchestration) are delivering real efficiency and cost savings. The four properties that make them efficient, autonomy, tool access, speed, and low marginal cost, are the same ones that widen the blast radius when something fails or is manipulated. The concrete failure classes, why workflow-era oversight does not fit, and how to capture the return without the exposure.

AI Governance - 10 min read

Shadow AI Is the AI on Your Network Right Now. We Built a Registry to Make It Visible.

Today Aeon AI Risk Management is launching the Shadow AI List, a maintained, risk-ranked registry of the 420 AI tools your employees and their agents are most likely using right now. Built to load into your firewall, SIEM, and DLP so the AI on your network stops being invisible. Inside: why classic shadow IT playbooks fail, the four risks regulated enterprises should track, and how the AI Exposure Index (AEX) ranks tools inside their category.

AI Disclosure Practice - 7 min read

We Built a Public Tracker for Canadian Listed-Issuer AI Disclosures. Here Is Why, and What It Will Tell You Every Week.

Today we are launching the Canada AI Disclosure Observatory, a public, weekly-refreshed tracker of how Canadian TSX and TSXV listed companies are disclosing their use of AI in issuer-hosted PDFs and filed annual reports. This is what it is, why we built it, what it surfaces, and how it pressure-tests the governance posture every regulated Canadian organization should already be developing.

Regulatory Compliance - 10 min read

The Three-Bloc World of AI Regulation Just Crystallized. Canadian Regulated Enterprises Sit at the Intersection.

On June 2, 2026, the United States signed an Executive Order requiring federal pre-deployment testing of frontier AI models. The EU's harmonized standard (prEN 18286) is in late-stage drafting. China's binding agentic AI rules continue to tighten. Within a single quarter, three regulatory blocs have all hardened. Canadian regulated enterprises - supplied by US vendors, selling to EU clients, governed by OSFI's principles-based posture - sit at the intersection. This article maps the new landscape and lays out five practical steps for the next two quarters.

AI Governance - 10 min read

Trust, but Verify: AI Assurance and Certification Are Becoming the Proof Regulators Ask For

As AI governance frameworks become widespread, the question regulators, boards, and counterparties ask is shifting from "do you have a governance program?" to "can you prove it works - independently?" This article maps the three layers of AI assurance - management-system certification (ISO 42001), AI system validation (EU conformity assessment, CSA Valid-AI-ted, OSFI model validation), and professional credentials - and lays out practical sequencing for regulated enterprises.

AI Governance - 10 min read

The Six Accountability Layers Every Enterprise AI Agent Needs - and the One Most Programs Are Missing

Most enterprise AI governance programs were designed for AI that recommends, not AI that acts. This six-layer accountability framework - identity, authorization, validation, runtime decisioning, audit, and responsibility - gives regulated enterprises a complete model for governing AI agents in production. The Responsibility Layer is the one most programs have not yet built.

Regulatory Compliance - 9 min read

prEN 18286: The European Harmonized Standard That Will Define EU AI Act Compliance

prEN 18286 is the draft European harmonized standard that will operationalize the EU AI Act. Once published by CEN-CENELEC, conformity with it grants a presumption of conformity with the Act - the strongest legal position an EU-facing organization can hold. Here is what Canadian regulated enterprises need to know.

Frameworks - 8 min read

Implementing NIST AI RMF: A Practical Guide

The NIST AI Risk Management Framework provides a comprehensive approach to managing AI risks. Learn how to implement it effectively in your organization.

Compliance - 7 min read

EU AI Act Compliance: What You Need to Know

The EU AI Act represents the world's first comprehensive AI regulation. Understand its requirements and how to prepare your organization for compliance.

Standards - 6 min read

ISO 42001: The New Standard for AI Management

ISO 42001 establishes the first international standard for AI management systems. Discover what it means for your organization and how to achieve certification.