Category

Business & Ethical AI

Pieces on AI’s impact on business processes, ROI, leadership decisions, plus the risks, ethics, and reliability of these technologies.

343 articles • Page 8 of 23

Enterprises Shift AI Procurement Focus to Security, Auditability Over Model Quality

Enterprises Shift AI Procurement Focus to Security, Auditability Over Model Quality

Enterprises now focus more on security and auditability when choosing AI vendors, since model quality is often similar across providers. Experts suggest that companies may need to check for strong data privacy, full conversation logging, and strict uptime rules. Buyers are advised to make sure vendors allow easy data export and give clear information about sub-processors and incidents. Using a step-by-step process with pilot testing might help find vendors that are reliable and safe. This approach appears to prevent hidden costs and risks for enterprises.

New Checklist Integrates AI Governance with Existing DevSecOps Pipelines

New Checklist Integrates AI Governance with Existing DevSecOps Pipelines

A new checklist may help companies better manage AI agents by adding governance controls to their current DevSecOps processes. This checklist suggests tracking each agent's identity, setting risk levels, adding checks before actions, keeping unchangeable logs, limiting spending, and retiring agents properly. These steps appear to match trusted frameworks like NIST AI RMF, which could help teams reuse existing policies. The checklist might help spot problems early and give proof for regulators when new laws like the EU AI Act start. Teams that use these controls may avoid unexpected costs and and better control their AI projects.

CTOs adopt agentic coding governance checklist to cut risk, cost

CTOs adopt agentic coding governance checklist to cut risk, cost

CTOs and security teams are starting to use a checklist to manage risks and costs when using autonomous coding agents. The checklist suggests naming a human responsible for each agent, setting clear rules on what agents can do, and keeping detailed logs that can be checked if problems happen. It also advises limiting agent access to only what they need, watching costs carefully, and always testing agents in safe environments before using them for real. These steps may help reduce risks but may not remove them completely.

Regulators worldwide adopt new rules for AI financial agents in 2026

Regulators worldwide adopt new rules for AI financial agents in 2026

Regulators around the world are bringing in new rules for AI agents that handle financial and identity actions starting in 2026. The European Union, the US, and other countries appear to be creating similar requirements, such as documentation and human oversight, but no single global rule exists. Experts say humans still hold responsibility for AI decisions, and keeping detailed logs may be required to prove accountability. Some recent incidents suggest that mistakes by these AI agents might cause big financial risks. Lawmakers may require safeguards like human checks, audit logs, and ways to quickly stop agents if needed.

Enterprises Adopt AI Agent Governance Checklist to Control Costs

Enterprises Adopt AI Agent Governance Checklist to Control Costs

Enterprises are adopting AI agent governance checklists to help control costs, data, and agent autonomy, especially after incidents of budget overruns and unauthorized actions. The checklist suggests tracking all agents, setting approval steps for risky actions, limiting access to only what is needed, and monitoring agent activities. Cost controls may include spend caps and usage tracking, while policy guidelines may be stored as code for easy review and updates. These practices aim to help companies avoid repeated mistakes and meet regulatory expectations, but some recommendations are based on recent guidance and reported trends, not guaranteed outcomes.

Investors demand new metrics for agentic coding ROI, costs

Investors demand new metrics for agentic coding ROI, costs

Investors are seeing many bold claims about agentic coding, but costs may rise quickly and are hard to predict. Field studies and reports suggest that most of the spending goes into input tokens and code reviews, with ratios as high as 25 input tokens for each output token. The best metrics for understanding value may include speed, quality, cost per feature, and business impact, but there are risks if companies cannot clearly explain costs and outcomes. Some signs of concern might be vague answers about token usage, no baseline data, or using only basic productivity measures.

New AI Agent Governance Checklist Updates Security, Cost Controls for CTOs

New AI Agent Governance Checklist Updates Security, Cost Controls for CTOs

The updated AI Agent Governance Checklist gives CTOs and security teams new ways to control security and costs as they use more autonomous coding agents. It suggests using strong tracking, clear agent identities, and real-time controls instead of only static policies. Studies point out that spending problems may happen quickly, so teams should set strict spending limits and alerts. The checklist also recommends regular reviews, strict data privacy measures, and careful management of agent permissions to prevent risks. Some risks, like personal data leaks or shared accounts, may still happen but can be reduced with these steps.

Anthropic, Parasoft guidance forms new enterprise AI code safety checklist

Anthropic, Parasoft guidance forms new enterprise AI code safety checklist

Enterprises using autonomous coding tools may need to follow a new checklist to make sure agent-written code is safe and meets legal and security standards. The checklist suggests steps like human review, layered testing, restricted agent permissions, and careful logging of changes. Legal and audit needs appear to require storing evidence for every action, and the rules for liability and copyright of AI-generated code are not fully settled yet. Pilot programs and graduated reviews might help reduce risk as organizations adopt these tools. These practices are meant as a starting point and can be adapted as needed.

Agentic AI shifts enterprises from SaaS seats to workflow platforms

Agentic AI shifts enterprises from SaaS seats to workflow platforms

Enterprises moving from seat-based SaaS to workflow platforms may face technical and organizational challenges. Agentic AI appears to work best in workflow systems that track and manage entire processes, which may explain why this shift is happening. Experts suggest starting with small, focused projects and measuring real business results early on. Good governance, careful integration planning, and clear communication with teams are recommended to avoid problems and support adoption. Studies suggest most agentic AI projects have not yet scaled fully, often due to gaps in process redesign and team alignment.

Executives Prioritize AI Inventory, Governance to Avoid Failure

Executives Prioritize AI Inventory, Governance to Avoid Failure

Executives may be focusing more on AI inventory and governance to prevent project failures. Interviews suggest that leaders now discuss the quality of training data first and follow steps like mapping use cases to business goals, assigning clear ownership, and keeping a register of all AI systems. Common governance frameworks mentioned are the NIST AI Risk Management Framework and ISO-IEC 42001:2023. Many failures appear to come from poor data, unclear ownership, or pilot projects that never scale. There may also be resistance from some managers, suggesting that responsible AI training for staff could be important.

Game studios face new AI agent copyright and liability risks

Game studios face new AI agent copyright and liability risks

Game studios may face new risks when using AI agents, including copyright and liability problems. AI systems might remix or copy original content without proper credit, and outputs made only by AI may not be protected by copyright. Legal experts warn that when AI uses large datasets, it becomes easier to accidentally copy parts of protected works. Because of these risks, studios are advised to use strong controls and human oversight when letting agents access curated data. Continued legal uncertainty suggests that studios should document human input and sources carefully to protect their work.

Enterprises build Codex playbooks for AI governance, compliance by 2026

Enterprises build Codex playbooks for AI governance, compliance by 2026

Companies using Codex agents may struggle because there is no clear guide for making governance playbooks. Sources suggest that a playbook helps link policy and controls directly into development, which might reduce risks and speed up audits. Most organizations use a mix of NIST AI RMF 1.0 and the EU AI Act for their oversight, and experts believe a playbook should cover areas like agent inventory, risk levels, and response steps. Guidelines recommend building oversight into existing pipelines and keeping logs for audits. Playbooks may need regular updates after incidents to stay effective and follow new rules.

Anthropic Urges Human Oversight, Layered Defenses for AI-Authored Code

Anthropic Urges Human Oversight, Layered Defenses for AI-Authored Code

Anthropic warns that current safety measures for AI-generated code may not be enough, and it urges companies to use human oversight with several layers of security. Its guidance suggests humans should review and approve all important changes, while keeping logs and following clear procedures in case of problems. Anthropic also recommends starting with small pilot projects, measuring risks, and only expanding once controls seem reliable. These steps may help organizations meet new laws in the EU and US that require detailed tracking and transparency for high-risk AI systems.

Enterprises Adopt AI Governance Playbooks to Manage LLM Risks

Enterprises Adopt AI Governance Playbooks to Manage LLM Risks

Enterprises are increasingly adopting AI governance playbooks to manage risks from large language models (LLMs), as they try to balance productivity and compliance. Only about 21 percent of firms reportedly had formal generative-AI policies by mid-2025, which suggests that many organizations may still need structured guidance. Best practices appear to include combining general standards like the NIST AI Risk Management Framework with specific controls for LLMs, such as prompt-injection defenses and artifact tracking. Playbooks often recommend careful review of generated code, control gates at each workflow step, and strong artifact management. Automation and visible governance may help organizations both improve compliance and make work easier for teams.

IBM and Northflank Detail Safe AI Code Deployment Checklist

IBM and Northflank Detail Safe AI Code Deployment Checklist

IBM and Northflank share advice for safely deploying AI-generated code in companies. They suggest starting with small pilot projects, using strict testing and security checks before expanding to more teams. Human oversight and clear tracking of code changes appear to be important for meeting legal rules and catching problems early. Teams may want to wait until defect and security rates are low before wider rollout. While this approach does not guarantee perfect results, experts suggest it may help make using AI-generated software safer and more reliable.