Skip to content

AI Governance

Shared AI workspaces need shared accountability

OpenAI's October 23 update introduces a company-knowledge capability that can assemble context from connected workplace systems. The company also announces the acquisition of the maker of Sky, a desktop interface that can understand what is on a user's screen and act through applications.

Artificial intelligence (AI) is moving closer to where organizational work actually lives: across documents, messages, tickets, code, and the desktop. That proximity makes context more useful. It also makes accountability harder to fake.

AI security overlays can connect two professions

The National Institute of Standards and Technology's (NIST) August 14 concept paper proposes security-control overlays tailored to artificial intelligence (AI) systems. The work adapts controls from NIST Special Publication 800-53 to generative, predictive, single-agent, multi-agent, and developer use cases.

The practical promise is not a new checklist. It is a better conversation between two professions that too often approach the same system with different maps.

The federal AI inventory is becoming an operating instrument

The United States Government Accountability Office's (GAO) July 29 report finds that generative artificial intelligence (AI) use cases at the federal agencies under review have increased nearly ninefold between 2023 and 2024, from 32 to 282. Across the same inventories, reported AI use cases of all kinds have nearly doubled.

That is more than a growth statistic. It is a warning about the management problem arriving behind the technology.

Capability releases need operational gates

Anthropic's May 22 release of Claude 4 comes with a less ordinary announcement: the company is activating stronger Artificial Intelligence Safety Level 3 (ASL-3) safeguards for Claude Opus 4 even though it has not concluded that the model definitively crosses the relevant capability threshold.

That provisional decision is worth examining. It treats uncertainty as a reason to strengthen a control, not as permission to continue under the old one.

Federal AI governance is moving into the operating model

Two April 3 Office of Management and Budget (OMB) memoranda make federal artificial intelligence (AI) policy more operational: M-25-21 on agency AI use and governance and M-25-22 on AI acquisition.

Policies change across administrations. The durable lesson in these documents is institutional: trustworthy use has to be built into roles, inventories, procurement, measurement, and delivery practice.

Frontier safety must be governed as a moving threshold

When a technology changes quickly, a fixed policy can be obsolete while everyone is still complying with it.

Google DeepMind's February update to its Frontier Safety Framework addresses that problem by linking stronger safeguards to capability thresholds in areas that could create severe harm. The details will continue to evolve. The organizational principle should endure: controls should respond to what a system can do, not only to the name or generation printed on it.

A management-system certificate is a beginning, not a verdict

Anthropic's January 13 announcement reports that the company has achieved International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 42001 certification, making it one of the first frontier-model companies to certify an artificial intelligence management system against the new international standard.

That is meaningful. It is also easy to misunderstand.

AI safety needs better questions before better rules

The National Institute of Standards and Technology (NIST) has issued a request for information (RFI) on the safe, secure, and trustworthy development and use of artificial intelligence. Responses will inform future guidance on evaluation, red teaming, risk management, and related measurement challenges.

The request arrives after a year of rapid capability releases and equally rapid calls for guardrails. Before guidance becomes more specific, the field needs to ask more precise questions about systems, evidence, and use.

READER-NEUTRAL SUBSCRIPTION

Follow Field Notes via RSS.

Copy this address into the RSS reader you already use. New notes will appear there automatically—no account, email address, or tracking required.