<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GRCIDE — Insights</title>
    <link>https://grcide.com/insights</link>
    <description>Reading notes, commentary and practice notes from the editors on AI, security practice, regulation and audit, and the craft of the work.</description>
    <language>en</language>
    <atom:link href="https://grcide.com/insights.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Mon, 07 Sep 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>For a bank's security AI, high risk begins where it can change state</title>
      <link>https://grcide.com/insights/security-ai-high-risk-changes-state</link>
      <guid isPermaLink="false">https://grcide.com/insights/security-ai-high-risk-changes-state</guid>
      <pubDate>Mon, 07 Sep 2026 00:00:00 +0000</pubDate>
      <description>An article reading China's AI guidance for banks and insurers puts the grading line at whether a security system can act, not at whether it touches money.</description>
    </item>
    <item>
      <title>Article 5 on 2 December 2026: the check a security function runs on its own tooling</title>
      <link>https://grcide.com/insights/ai-act-article-5-december</link>
      <guid isPermaLink="false">https://grcide.com/insights/ai-act-article-5-december</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>The prohibited-practice list reads as a product problem. A security function's own tooling touches three of its points, and two more start in December.</description>
    </item>
    <item>
      <title>The AI bill of materials is the next SBOM</title>
      <link>https://grcide.com/insights/ai-bom-is-the-next-sbom</link>
      <guid isPermaLink="false">https://grcide.com/insights/ai-bom-is-the-next-sbom</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>Three articles in one issue argue that the supply chain is now four chains. The bill of materials that stops at code no longer describes what ships.</description>
    </item>
    <item>
      <title>When agents deal with each other, the object is the connection</title>
      <link>https://grcide.com/insights/multi-agent-governance-is-the-connection</link>
      <guid isPermaLink="false">https://grcide.com/insights/multi-agent-governance-is-the-connection</guid>
      <pubDate>Sun, 06 Sep 2026 00:00:00 +0000</pubDate>
      <description>An Australian government report moves the governance object from the single agent to the relationship between them. The stop-point sits where control ends.</description>
    </item>
    <item>
      <title>Agent governance is a permissions problem before it is a model problem</title>
      <link>https://grcide.com/insights/agent-governance-is-a-permissions-problem</link>
      <guid isPermaLink="false">https://grcide.com/insights/agent-governance-is-a-permissions-problem</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Singapore's advisory on the OpenClaw agent platform moves AI risk from what a model says to what an agent can do. The controls it lists are identity controls.</description>
    </item>
    <item>
      <title>The permissions review that did not happen</title>
      <link>https://grcide.com/insights/agent-permissions-review</link>
      <guid isPermaLink="false">https://grcide.com/insights/agent-permissions-review</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>An agent reaches production on its installer's identity, holding every tool that person held. This is the review that should have run first.</description>
    </item>
    <item>
      <title>CRA in fifteen months: what to do first</title>
      <link>https://grcide.com/insights/cra-what-to-do-first</link>
      <guid isPermaLink="false">https://grcide.com/insights/cra-what-to-do-first</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Article 14 starts in September 2026 and the essential requirements in December 2027. The first quarter is three decisions, not a compliance programme.</description>
    </item>
    <item>
      <title>Open-source risk is a maintainer problem, not a CVE count</title>
      <link>https://grcide.com/insights/open-source-risk-is-a-maintainer-problem</link>
      <guid isPermaLink="false">https://grcide.com/insights/open-source-risk-is-a-maintainer-problem</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A Chinese-language piece argues that open-source risk lives in maintainers and funding, not in CVE queues. We agree, and add the control it implies.</description>
    </item>
    <item>
      <title>The board question is not the CVE count</title>
      <link>https://grcide.com/insights/the-board-question-is-not-the-cve-count</link>
      <guid isPermaLink="false">https://grcide.com/insights/the-board-question-is-not-the-cve-count</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.</description>
    </item>
  </channel>
</rss>
