Daily Cyber & AI Briefing with Michael Housch. This episode was published automatically and includes the assembled audio plus full transcript. TranscriptToday’s cyber risk landscape is in a state of rapid evolution, shaped by the relentless integration of artificial intelligence into both defense and attack strategies. We’re seeing AI not just as a tool for defenders, but also as a new surface for attackers. Identity security and operational readiness are now front and center, with organizations under pressure to demonstrate that their policies aren’t just words on paper, but are actually being put into practice and can be proven when regulators or customers demand it. Let’s start by looking at the dual-edged nature of AI in cybersecurity. On one hand, AI is enabling organizations to automate risk management, monitor controls in real time, and respond to threats faster than ever before. On the other, attackers are increasingly targeting AI platforms themselves, exploiting their integration into business operations and the sensitive data they process. A clear example of this comes from Anthropic’s recent warning to users of its Claude AI platform. They’ve identified active infostealer malware campaigns targeting Claude users, aiming to steal credentials and sensitive data. As businesses rely more on AI tools like Claude for core operations, these platforms become high-value targets. The practical implication is that organizations need to treat their AI platforms with the same—if not greater—scrutiny as their traditional IT assets. That means robust endpoint security, ongoing user education, and continuous monitoring of AI-integrated environments. This isn’t just a theoretical risk. Infostealer malware is designed to quietly siphon off credentials, session tokens, and other sensitive information, often before anyone notices. If those credentials unlock access to AI tools that are deeply embedded in business processes, the impact can be significant—ranging from data theft to manipulation of AI outputs. For CISOs, this is a call to action: review your endpoint security controls, ensure your detection and response capabilities are up to date, and make sure users understand the risks of phishing and malware in the context of AI. Shifting gears, let’s talk about the persistent threat to critical infrastructure. Just recently, a cyber extortion group claimed responsibility for a breach at Manchester Airports Group, reportedly exfiltrating sensitive data. While details are still emerging, this incident highlights the ongoing risks facing critical infrastructure operators—not just from ransomware, but from extortion groups that are willing to disrupt operations or leak sensitive data to achieve their goals. What does this mean for risk leaders? First, it’s a reminder that supply chain security is only as strong as your weakest link. Airports, utilities, and other critical sectors are attractive targets because of their operational importance and the sensitive data they hold. Second, incident response readiness is essential. Organizations need to have layered defenses, clear playbooks, and the ability to quickly contain and investigate breaches. And third, the risk isn’t just about data loss—it’s about operational disruption, reputational damage, and regulatory consequences. Now, let’s look at how AI is being used to automate cybersecurity risk management in highly sensitive environments. Telos Corporation has secured a $34.3 million contract to deploy AI-driven automation for cybersecurity risk management within the Air Force intelligence community. The goal is to streamline compliance, threat detection, and risk assessment processes—essentially automating the tedious, error-prone parts of risk management so that human analysts can focus on higher-value tasks. This is part of a broader trend: AI isn’t just about detecting threats, it’s about automating the entire risk management lifecycle. For CISOs, the takeaway is clear. If you’re still relying on manual processes for risk assessments, compliance monitoring, or controls testing, you’re falling behind. Automation can reduce human error, increase efficiency, and provide continuous assurance that controls are working as intended. It’s time to evaluate where AI and automation can add value in your own risk management workflows. Identity security is also evolving rapidly in the age of AI. LastPass, for example, has rolled out new secure access capabilities designed to strengthen identity security against AI-driven threats. These enhancements focus on adaptive authentication, improved user experience, and integration with AI-powered risk analytics. The idea is to make it harder for attackers to exploit stolen credentials, while making it easier for legitimate users to access what they need. Credential-based attacks remain one of the most common and damaging threats. As AI platforms become more deeply integrated into business processes, the value of a compromised credential goes up. Adaptive authentication—using context and behavioral analytics to assess risk in real time—can help mitigate these risks. For organizations, this is a proactive step toward aligning identity governance with the evolving threat landscape. On the compliance front, Anthropic is rolling out a compliance API and enhanced local visibility features for its Claude platform. This is a response to growing regulatory and governance requirements. The new tools provide granular access controls, audit trails, and improved identity governance, supporting both compliance and operational transparency. For CISOs, this is a development worth watching. Compliance APIs can be leveraged to provide real-time evidence of compliance, integrate with broader governance, risk, and compliance (GRC) frameworks, and automate the production of audit trails. This is especially important as regulators and customers increasingly expect organizations to demonstrate—not just declare—their adherence to security and privacy controls. But there’s a bigger issue at play here: the accountability gap for CIOs and CISOs. As organizations adopt distributed and AI-enabled technologies, the complexity of managing risk, compliance, and security across hybrid environments is outpacing traditional governance models. A new analysis highlights the need for updated accountability frameworks, clearer lines of responsibility, and increased board-level engagement on technology risk. What does this look like in practice? It means that leadership can no longer delegate cyber and AI risk to a single function or team. Instead, there needs to be cross-functional coordination, with clear ownership of risks, controls, and reporting. Boards are increasingly asking tough questions about operational readiness, resilience, and the ability to produce evidence of compliance on demand. This brings us to the evolving security concerns around agentic, or autonomous, AI. In 2026, AI systems aren’t just assisting—they’re making decisions, accessing sensitive data, and interacting with critical business processes. This increased autonomy brings new risks. Without robust guardrails, continuous monitoring, and transparent governance, agentic AI can introduce vulnerabilities that are hard to detect and even harder to remediate. For CISOs, this means re-evaluating risk assessments and controls for AI systems that act independently. It’s not enough to secure the data going in and out; you need to understand how AI systems are making decisions, what data they’re accessing, and how they’re interacting with other systems. Continuous monitoring and transparent governance are key to ensuring trustworthy AI operations. A related challenge is the gap between policy and practice in AI governance. Having a policy on the books isn’t enough—regulators and stakeholders now expect organizations to produce evidence of compliance on demand. This means investing in tooling, documentation, and process automation to ensure auditability and defensibility. This shift is being driven by increasing regulatory scrutiny, especially in sectors like finance, healthcare, and critical infrastructure. Demonstrable, auditable evidence of AI and cybersecurity governance is becoming a baseline expectation—not just for regulators, but for boards and customers as well. Let’s talk about data sovereignty and localized security solutions. Horizon3 has launched a sovereign, Sydney-hosted instance of its NodeZero penetration testing platform. This move addresses data residency and sovereignty requirements for organizations operating in regulated jurisdictions. For CISOs, sovereign cloud and testing solutions are becoming essential for meeting local regulatory mandates and reducing cross-border data risk. Data sovereignty isn’t just a compliance checkbox—it’s a strategic consideration. Organizations need to know where their data is stored, who has access to it, and how it’s being protected. Sovereign cloud solutions can help address these concerns, but they also require careful integration with existing security and compliance frameworks. Finally, a recent report has emphasized that AI-native success depends on operational readiness—not just adoption. It’s not enough to implement AI tools; organizations need the processes, controls, and cultural alignment to ensure secure, resilient deployments. This includes security, compliance, and risk management capabilities tailored to the unique challenges of AI. For CISOs, this means prioritizing readiness assessments and cross-functional collaboration. Security teams need to work closely with IT, legal, compliance, and business units to ensure that AI deployments are not only effective, but also secure and compliant. Let’s pull these threads together and look at the strategic implications for organizations today.