Skip to content

2026

Capability gating is a cybersecurity control

OpenAI has introduced Trusted Access for Cyber, an approach intended to expand advanced cybersecurity capabilities for legitimate defenders while placing additional controls around uses that could create harm.

The initiative highlights a problem that every organization deploying powerful artificial intelligence now faces: access control cannot stop at whether somebody may use a model. It has to consider which capabilities they may invoke, under what conditions, with what evidence, and through which escalation path.

A benchmark needs a theory of use

The National Institute of Standards and Technology (NIST) has released draft guidance on best practices for automated benchmark evaluations. The subject sounds technical, but it reaches directly into strategy and procurement. Organizations routinely use benchmark results to choose models, justify investment, and communicate readiness.

A benchmark can support those decisions. It can also lend numerical confidence to a question it was never designed to answer.

A model constitution is an operating artifact

Anthropic has published a new constitution for Claude. The document is intended to shape how the model understands its role, weighs competing considerations, and behaves when a simple rule does not resolve the situation.

The interesting idea is not that an artificial intelligence system has a constitution. It is that governance becomes more useful when principles are written to support reasoning, implementation, testing, and revision—not merely to announce values.

Agent security starts before the agent acts

The National Institute of Standards and Technology (NIST) has opened a request for information on securing artificial intelligence agent systems. The timing is right. Organizations are moving from systems that generate suggestions toward systems that can call tools, manipulate records, send messages, and coordinate multi-step work.

The security question is no longer only what a model might say. It is what the complete system is allowed to do—and whether the organization can reconstruct what happened afterward.

Healthcare AI enters through the workflow

OpenAI has introduced OpenAI for Healthcare, bringing its models and products into an environment where information is sensitive, time is scarce, and an apparently useful answer can shape a consequential decision.

The announcement emphasizes administrative and clinical work as well as support for obligations under the Health Insurance Portability and Accountability Act (HIPAA). Those are important foundations. They do not, by themselves, make an artificial intelligence system fit for a particular healthcare decision.

Governance needs an evidence system

The new year has opened with a practical test for artificial intelligence governance. California's Transparency in Frontier Artificial Intelligence Act (TFAIA), enacted through Senate Bill 53 (SB 53), is now operative. It asks covered frontier developers for published frameworks, safety reporting, incident processes, and protections for employees who raise serious concerns.

The particulars apply to a defined group of companies. The lesson travels much further: a governance commitment is only as real as the evidence an organization can produce when somebody asks how the commitment works.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.