<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>The Cyber and AI Governance Vault</title><description>Cybersecurity &amp; AI Governance insights for Financial Services by Gerard Louis</description><link>https://gerardlouis.org/</link><item><title>Frontier AI, DORA, and the Case for Faster Security Validation</title><link>https://gerardlouis.org/blog/frontier-ai-dora-and-the-case-for-faster-security-validation/</link><guid isPermaLink="true">https://gerardlouis.org/blog/frontier-ai-dora-and-the-case-for-faster-security-validation/</guid><description>Recent statements from the ESAs, the FSB, and OpenAI point to the same concern: cyber risk may develop faster than traditional security and resilience processes can absorb. Here is what that means for DORA-regulated financial entities.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><category>Regulations</category><category>DORA</category><category>Frontier AI</category><category>Cybersecurity</category><category>Operational Resilience</category><category>ESA</category><category>FSB</category><category>Financial Services</category><category>AI Governance</category></item><item><title>Building a Gen AI Security Framework, Part 1: The Foundation</title><link>https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-1-the-foundation/</link><guid isPermaLink="true">https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-1-the-foundation/</guid><description>Part 1 of 4: How to use NIST AI RMF, NIST AI 600-1, SP 800-30, OWASP, and MITRE ATLAS together to build a practical, regulator-ready risk framework for generative AI.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>NIST AI RMF</category><category>NIST AI 600-1</category><category>SP 800-30</category><category>OWASP</category><category>MITRE ATLAS</category><category>AI Governance</category><category>Gen AI</category><category>Risk Management</category></item><item><title>Building a Gen AI Security Framework, Part 2: Scaling the Assessment</title><link>https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-2-scaling-the-assessment/</link><guid isPermaLink="true">https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-2-scaling-the-assessment/</guid><description>Part 2 of 4: How to scale a NIST-aligned gen AI risk assessment across dozens of use cases without rebuilding the process every time.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>NIST AI RMF</category><category>NIST AI 600-1</category><category>SP 800-30</category><category>OWASP</category><category>MITRE ATLAS</category><category>AI Governance</category><category>Gen AI</category><category>Risk Management</category></item><item><title>Building a Gen AI Security Framework, Part 3: From Risk to Controls</title><link>https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-3-from-risk-to-controls/</link><guid isPermaLink="true">https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-3-from-risk-to-controls/</guid><description>Part 3 of 4: How to map rated gen AI risks to specific controls across NIST SP 800-53, CSF 2.0, and ISO 27001, and define the evidence that proves those controls are actually working.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>NIST AI RMF</category><category>NIST AI 600-1</category><category>SP 800-53</category><category>CSF 2.0</category><category>ISO 27001</category><category>OWASP</category><category>MITRE ATLAS</category><category>AI Governance</category><category>Gen AI</category><category>Risk Management</category></item><item><title>Building a Gen AI Security Framework, Part 4: A Complete Worked Example</title><link>https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-4-a-complete-worked-example/</link><guid isPermaLink="true">https://gerardlouis.org/blog/building-a-gen-ai-security-framework-part-4-a-complete-worked-example/</guid><description>Part 4 of 4: A retrieval-based financial services chatbot carried through the full framework — pattern classification, threat model, SP 800-30 ratings three ways, control mapping, and a completed evidence record.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>NIST AI RMF</category><category>NIST AI 600-1</category><category>SP 800-30</category><category>SP 800-53</category><category>CSF 2.0</category><category>OWASP</category><category>MITRE ATLAS</category><category>AI Governance</category><category>Gen AI</category><category>Risk Management</category><category>Financial Services</category></item><item><title>When Frontier Models Reach Beyond Intended Boundaries: Lessons for Financial Services AI Agents</title><link>https://gerardlouis.org/blog/when-frontier-models-reach-beyond-intended-boundaries-financial-services-ai-agents/</link><guid isPermaLink="true">https://gerardlouis.org/blog/when-frontier-models-reach-beyond-intended-boundaries-financial-services-ai-agents/</guid><description>Recent OpenAI, Anthropic, and UK AI Security Institute disclosures show how capable models can act beyond an evaluation&apos;s intended scope when network access, task design, identity controls, and monitoring fail.</description><pubDate>Sun, 23 Aug 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Frontier AI</category><category>Agentic AI</category><category>Cybersecurity</category><category>AI Governance</category><category>Financial Services</category><category>Non-Human Identity</category><category>Third-Party Risk</category></item><item><title>Responsible AI in Financial Services: From Principles to Operational Governance</title><link>https://gerardlouis.org/blog/responsible-ai-in-financial-services-from-principles-to-operational-governance/</link><guid isPermaLink="true">https://gerardlouis.org/blog/responsible-ai-in-financial-services-from-principles-to-operational-governance/</guid><description>How financial institutions must evolve Responsible AI from ethical principles into an operational discipline of controls, risk tiering, and continuous governance, particularly as agentic systems introduce risks that existing frameworks were not designed to manage.</description><pubDate>Sun, 14 Jun 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>Responsible AI</category><category>AI Governance</category><category>FS AI RMF</category><category>NIST AI RMF</category><category>ISO 42001</category><category>EU AI Act</category><category>Agentic AI</category><category>Financial Services</category></item><item><title>Claude Fable 5 vs Mythos: Why Frontier AI Is Too Powerful to Fully Release</title><link>https://gerardlouis.org/blog/claude-fable-5-vs-mythos-why-frontier-ai-is-too-powerful-to-fully-release/</link><guid isPermaLink="true">https://gerardlouis.org/blog/claude-fable-5-vs-mythos-why-frontier-ai-is-too-powerful-to-fully-release/</guid><description>What Anthropic&apos;s decision to gate Mythos-class capabilities behind safety guardrails means for AI governance, cybersecurity threat models, and agentic AI deployment in financial services.</description><pubDate>Fri, 12 Jun 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Frontier AI</category><category>Mythos</category><category>FS AI RMF</category><category>Cybersecurity</category><category>Financial Services</category><category>AI Safety</category><category>AISI</category><category>Agentic AI</category></item><item><title>Preparing the Enterprise for AI-Enabled Vulnerability Discovery</title><link>https://gerardlouis.org/blog/preparing-the-enterprise-for-ai-enabled-vulnerability-discovery/</link><guid isPermaLink="true">https://gerardlouis.org/blog/preparing-the-enterprise-for-ai-enabled-vulnerability-discovery/</guid><description>FS-ISAC&apos;s Sector Risk Advisory outlines nine priority actions for financial institutions facing a fundamental shift in cybersecurity risk driven by AI-enabled vulnerability discovery, chaining, and exploitation.</description><pubDate>Sat, 06 Jun 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>FS-ISAC</category><category>Vulnerability Management</category><category>Cybersecurity</category><category>AI</category><category>Financial Services</category><category>FS AI RMF</category><category>Exploit Prevention</category></item><item><title>The Control Gap - Why AI Governance Must Pivot from Policy to Operations in 2026</title><link>https://gerardlouis.org/blog/the-control-gap-why-ai-governance-must-pivot-from-policy-to-operations-in-2026/</link><guid isPermaLink="true">https://gerardlouis.org/blog/the-control-gap-why-ai-governance-must-pivot-from-policy-to-operations-in-2026/</guid><description>The Stanford AI Index 2026 reveals a widening gap between AI capability and governance readiness. For financial institutions, closing this Control Gap before the EU AI Act and OSFI E-23 deadlines is no longer optional.</description><pubDate>Sun, 03 May 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Stanford AI Index</category><category>AI Governance</category><category>FS AI RMF</category><category>EU AI Act</category><category>OSFI</category><category>Financial Services</category><category>Agentic AI</category><category>NIST AI RMF</category></item><item><title>The Rise of Agentic AI in Financial Services</title><link>https://gerardlouis.org/blog/the-rise-of-agentic-ai-in-financial-services/</link><guid isPermaLink="true">https://gerardlouis.org/blog/the-rise-of-agentic-ai-in-financial-services/</guid><description>Beyond the Chatbot: Navigating the risks of autonomous AI agents in banking — from prompt injection 2.0 to memory poisoning, with mitigation controls mapped to NIST AI RMF and FS AI RMF 230.</description><pubDate>Sat, 02 May 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Agentic AI</category><category>FS AI RMF</category><category>NIST AI RMF</category><category>Prompt Injection</category><category>Financial Services</category><category>SEC</category><category>OSFI</category><category>Autonomous AI</category></item><item><title>The Rise of Agentic AI and the &apos;All-Green&apos; Fraud Problem</title><link>https://gerardlouis.org/blog/agentic-ai-all-green-fraud-problem/</link><guid isPermaLink="true">https://gerardlouis.org/blog/agentic-ai-all-green-fraud-problem/</guid><description>Why financial crime is shifting from bad events to clean sequences — and how agentic AI is enabling multi-step, coordinated deception that passes every control.</description><pubDate>Sun, 26 Apr 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Agentic AI</category><category>Fraud</category><category>Financial Services</category><category>NIST</category><category>OWASP</category><category>MITRE ATLAS</category><category>Synthetic Identity</category><category>Risk Management</category></item><item><title>From AI Risk Principles to Production Reality</title><link>https://gerardlouis.org/blog/from-ai-risk-principles-to-production-reality/</link><guid isPermaLink="true">https://gerardlouis.org/blog/from-ai-risk-principles-to-production-reality/</guid><description>How to operationalize NIST AI RMF, FS AI RMF, threat models, and MAESTRO across GenAI and agentic AI systems.</description><pubDate>Sat, 25 Apr 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>NIST</category><category>AI RMF</category><category>FS AI RMF</category><category>MITRE ATLAS</category><category>OWASP</category><category>CSA MAESTRO</category><category>Agentic AI</category><category>GenAI</category><category>Risk Management</category><category>Financial Services</category></item><item><title>FS AI RMF 230 Control Objectives - Mapping to NIST AI RMF and Implementation Guide</title><link>https://gerardlouis.org/blog/fs-ai-rmf-230-control-objectives-mapping-to-nist-ai-rmf-and-implementation-guide/</link><guid isPermaLink="true">https://gerardlouis.org/blog/fs-ai-rmf-230-control-objectives-mapping-to-nist-ai-rmf-and-implementation-guide/</guid><description>A deep dive into the Treasury&apos;s Financial Services AI Risk Management Framework, its 230 control objectives, how they map to the NIST AI RMF, and a practical implementation guide for financial institutions.</description><pubDate>Mon, 13 Apr 2026 00:00:00 GMT</pubDate><category>Frameworks</category><category>FS AI RMF</category><category>NIST AI RMF</category><category>Control Objectives</category><category>Risk Assessment</category><category>Financial Services</category><category>AI Governance</category></item><item><title>The Mythos AI Crisis and Banking Resilience</title><link>https://gerardlouis.org/blog/the-mythos-ai-crisis-and-banking-resilience/</link><guid isPermaLink="true">https://gerardlouis.org/blog/the-mythos-ai-crisis-and-banking-resilience/</guid><description>How Anthropic&apos;s Mythos model triggered an emergency government response, what it means for financial services cybersecurity, and how the FS AI RMF provides a path to resilience.</description><pubDate>Sun, 12 Apr 2026 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Mythos</category><category>Anthropic</category><category>FS AI RMF</category><category>Cybersecurity</category><category>Banking</category><category>NIST AI RMF</category><category>Zero-Day</category></item><item><title>NY DFS 23 NYCRR 500 - What You Need to Know</title><link>https://gerardlouis.org/blog/ny-dfs-23-nycrr-500-what-you-need-to-know/</link><guid isPermaLink="true">https://gerardlouis.org/blog/ny-dfs-23-nycrr-500-what-you-need-to-know/</guid><description>A comprehensive breakdown of New York&apos;s landmark cybersecurity regulation for financial services — covering key requirements, the 2023 amendments, and practical steps for compliance.</description><pubDate>Sun, 05 Apr 2026 00:00:00 GMT</pubDate><category>Regulations</category><category>NY DFS</category><category>23 NYCRR 500</category><category>Compliance</category><category>Financial Services</category><category>Cybersecurity</category></item><item><title>The Convergence of Cyber and AI Governance in Financial Services</title><link>https://gerardlouis.org/blog/convergence-cyber-ai-governance/</link><guid isPermaLink="true">https://gerardlouis.org/blog/convergence-cyber-ai-governance/</guid><description>Why financial institutions can no longer treat cybersecurity and AI governance as separate disciplines, and how to build an integrated governance model.</description><pubDate>Wed, 05 Mar 2025 00:00:00 GMT</pubDate><category>Industry Analysis</category><category>Governance</category><category>AI</category><category>Cybersecurity</category><category>Strategy</category></item><item><title>EU AI Act — What Financial Institutions Need to Know in 2025</title><link>https://gerardlouis.org/blog/eu-ai-act-financial-institutions/</link><guid isPermaLink="true">https://gerardlouis.org/blog/eu-ai-act-financial-institutions/</guid><description>A breakdown of the EU AI Act&apos;s risk-based classification system and its direct implications for banks, insurers, and investment firms operating in or serving EU markets.</description><pubDate>Mon, 10 Feb 2025 00:00:00 GMT</pubDate><category>Regulations</category><category>EU AI Act</category><category>Compliance</category><category>Financial Services</category><category>Europe</category></item><item><title>NIST AI RMF 1.0 — A Practical Guide for Financial Services</title><link>https://gerardlouis.org/blog/nist-ai-rmf-practical-guide/</link><guid isPermaLink="true">https://gerardlouis.org/blog/nist-ai-rmf-practical-guide/</guid><description>Breaking down the NIST AI Risk Management Framework and how financial institutions can operationalize its core functions: Govern, Map, Measure, and Manage.</description><pubDate>Wed, 15 Jan 2025 00:00:00 GMT</pubDate><category>Frameworks</category><category>NIST</category><category>AI RMF</category><category>Risk Management</category><category>Financial Services</category></item></channel></rss>