Note 05
The risk of catastrophic harm from AI remains, despite the countermeasures.
MIT's June 2026 Delphi study of 272 experts finds the risk of catastrophic harm from AI remains despite countermeasures: five of 24 domains hold at 1 in 10 or worse by 2030. Until governance instruments exist, the control gap sits with deployers.
July 2026
Note 04
The control is not the deliverable.
Most AI frameworks hand organizations a list of controls and stop there. A recent CSET reference guide traces every control back to the principle it implements, and that lineage, not the checklist, is what survives diligence.
July 2026
Note 03
Adoption Is Outrunning Control.
Incidents up 55%, response confidence down, and most organizations still integrating governance practices rather than operating them.
July 2026
Note 02
Governance is part of rebuilding around AI, not a layer on top.
The organizations pulling ahead didn't bolt AI onto existing workflows; they rebuilt around it. Governance added on top doesn't survive a system that runs the business.
June 2026
Note 01
From Possible Threats to Production Incidents.
Only 37% of organizations have policies to manage AI or detect Shadow AI. What OWASP's latest report means once agents start acting on production systems, and why insurers are now paying attention.
June 2026