<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Zero-Day Dawn]]></title><description><![CDATA[Agentic AI governance, EU AI Act enforcement intelligence, and the standards architecture underneath both. Where autonomous systems break the regulation's assumptions - and what to build before the regulator arrives. For leaders who decide, not delegate.]]></description><link>https://www.zerodaydawn.com</link><image><url>https://substackcdn.com/image/fetch/$s_!95_O!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d58aa56-128d-4aea-b0ef-ec7ce4ddefeb_1080x1080.png</url><title>Zero-Day Dawn</title><link>https://www.zerodaydawn.com</link></image><generator>Substack</generator><lastBuildDate>Wed, 24 Jun 2026 12:02:25 GMT</lastBuildDate><atom:link href="https://www.zerodaydawn.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Quantum Coherence LLC]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[wave@quantumcoherence.ai]]></webMaster><itunes:owner><itunes:email><![CDATA[wave@quantumcoherence.ai]]></itunes:email><itunes:name><![CDATA[Violeta Klein, CISSP, AIGP]]></itunes:name></itunes:owner><itunes:author><![CDATA[Violeta Klein, CISSP, AIGP]]></itunes:author><googleplay:owner><![CDATA[wave@quantumcoherence.ai]]></googleplay:owner><googleplay:email><![CDATA[wave@quantumcoherence.ai]]></googleplay:email><googleplay:author><![CDATA[Violeta Klein, CISSP, AIGP]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Zero Trust, Full Liability]]></title><description><![CDATA[The agentic security ecosystem and the EU AI Act describe the same failure from opposite sides of a wall.]]></description><link>https://www.zerodaydawn.com/p/zero-trust-full-liability</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/zero-trust-full-liability</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 07 Jun 2026 13:02:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6o4J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6o4J!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6o4J!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!6o4J!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!6o4J!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!6o4J!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6o4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3302588,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/200980078?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6o4J!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!6o4J!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!6o4J!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!6o4J!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe4261d25-859b-4570-aed1-3e2655236d95_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Anthropic published &#8220;Zero Trust for AI Agents&#8221; last month &#8212; thirty-six pages of security architecture for autonomous systems deployed inside enterprises. Cryptographic identity, least agency, behavioral baselines, anomaly detection, automated containment. Serious engineering. Disesdi Shoshana Cox, in her Angles of Attack intelligence brief, was among the very first to read the threat landscape correctly: the systems these controls are built to protect resist the protections by design.</p><p>Both readings are correct. Both are incomplete.</p><p>The Anthropic paper describes every architectural failure the EU AI Act penalizes &#8212; behavioral drift, privilege accumulation, supply chain opacity, the inability to document what a system will do before it runs &#8212; and prescribes controls that map, almost one-to-one, to the AI Act&#8217;s essential requirements. The paper never makes that connection. The security community&#8217;s coverage never makes that connection. The compliance community has not read the paper at all.</p><p>Two teams, staring at the same system failure, building the same engineering response, reading each other&#8217;s output as someone else&#8217;s problem. The organization that treats these as two separate programs will pay for the same infrastructure twice and still have a gap between them &#8212; because the gap is in the join that neither side makes.</p><div class="callout-block" data-callout="true"><p><strong>That join is the convergence thesis: the vulnerability and the violation are the same event, viewed through different frameworks.</strong></p></div><p>I stated it on the public record on March 8, 2026, in a formal response to NIST&#8217;s Request for Information on AI Agent Security &#8212; Docket NIST-2025-0035, publicly accessible on regulations.gov. The submission mapped three convergence points in detail: prompt injection as simultaneous cybersecurity breach and intended-purpose invalidation, tool misuse as simultaneous unauthorized access and deployer-to-provider conversion under the regulation, and privilege accumulation as simultaneous lateral movement and structural invisibility to the human oversight function. The conclusion: security guidelines that do not account for the regulatory obligations attached to the same vulnerabilities will leave organizations with a false sense of security.</p><p>Two months later, Anthropic published the security framework that proves it &#8212; without making the connection. Days after that, the OWASP GenAI Security Project published the convergence map as Section 2.8 of its State of Agentic AI Security and Governance report (v2.01) &#8212; &#8220;Towards Unified Governance: The Security-Compliance Convergence.&#8221; I wrote that section. It maps every OWASP Agentic Top 10 threat to the EU AI Act obligation it simultaneously triggers, introduces the N^D formulation for the compositional outcome space, and proposes the operational envelope as the governance response. The report is free and available now.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Comfortable Lie</h2><p>Here is what the market wants to believe: the security team handles the breach and the compliance team handles the regulator.</p><p>This belief persists because it matches the org chart. Security reports to the CISO. Compliance reports to Legal or Risk. They have separate budgets, separate reporting lines, separate vendors, and separate conferences. When an agent misbehaves, security opens an incident ticket. When a regulator asks questions, compliance opens a case file.</p><p>The comfortable part is the separation. The lie is that the separation describes two different problems.</p><div class="callout-block" data-callout="true"><p>For agentic AI, the security incident and the regulatory violation are the same event. </p></div><p>A prompt injection that hijacks an agent&#8217;s operational purpose is simultaneously a cybersecurity breach and an invalidation of the system&#8217;s documented intended purpose &#8212; the anchor point for every compliance obligation the provider filed. The security team sees a compromised execution path. The compliance team does not know the agent&#8217;s documentation no longer describes what the agent does. The incident report closes in one department. The violation sits open in the other, undiscovered, until the regulator discovers it for both of them.</p><p>The alternative is harder. It requires a single architectural response that serves two authorities simultaneously &#8212; the security function and the regulatory function reading the same telemetry, the same behavioral baselines, the same departure alerts, under two different names. That is what it costs to close the gap. Everything else is two teams patching one half of the same hole.</p><div><hr></div><h2>The Paper That Proved It Without Knowing It</h2><p>Anthropic&#8217;s paper is the most detailed security framework for autonomous agents published by a frontier AI company. Its controls address the five threat categories that define the OWASP Agentic Top 10 &#8212; prompt injection, tool and resource misuse, identity and privilege abuse, supply chain compromise, and memory and context poisoning &#8212; through a three-tier maturity model ranging from cryptographic identity and least-agency enforcement to behavioral anomaly detection and automated containment. Every entry in that taxonomy simultaneously triggers an obligation under the EU AI Act. The Agentic Top 10 is the Rosetta Stone between the two frameworks &#8212; the shared language that makes the convergence visible. Anthropic&#8217;s paper reads one side. The AI Act reads the other. The taxonomy connects them.</p><p>The framework is technically sound. It is also, sentence by sentence, a compliance architecture wearing security clothing.</p><p>Start with behavioral monitoring. The paper instructs organizations to establish baseline agent behavior, detect deviations from that baseline, and respond automatically when behavior exceeds defined boundaries. </p><p><strong>It specifies three tiers</strong>: manual definition of expected patterns, automated baseline learning, and continuous drift detection. That engineering &#8212; define the assessed boundary, monitor for departure, treat every crossing as an event requiring response &#8212; is the operational envelope. Anthropic built it as a security control. Under the EU AI Act, the identical mechanism is the only architecturally honest answer to risk management for systems whose runtime behavior cannot be pre-computed. Same mechanism. Two names. Two budgets. One problem.</p><p><strong>Move to supply chain</strong>. The paper acknowledges what static security models were never designed to handle: agentic systems assemble their capabilities at runtime, pulling in external tools and agent configurations dynamically rather than from a fixed catalogue. That architectural property breaks both frameworks simultaneously. For security, runtime composition means the attack surface expands with every action the agent takes &#8212; the paper is right about this. For compliance, it means the conformity assessment filed before deployment describes a system that no longer exists by the time it runs in production. The behavioral documentation assumes a fixed operational boundary. The architecture is designed to exceed it. </p><div class="callout-block" data-callout="true"><p>The security exposure and the compliance failure share the same root cause.</p></div><p><strong>Move to privilege management</strong>. The paper&#8217;s least-agency principle &#8212; restrict what each agent tool can do, how often, and where &#8212; is sound security engineering. It is also the operational specification for cybersecurity resilience under the AI Act, which requires high-risk systems to be resilient against unauthorized use and attempts to alter their use or performance by exploiting vulnerabilities. The paper&#8217;s privilege scoping tiers &#8212; static least-privilege, dynamic elevation, just-in-time provisioning with automatic expiration &#8212; are the same controls a provider would need to demonstrate conformity with that essential requirement. Anthropic built them for breach containment. The AI Act requires them for market access.</p><p><strong>Move to logging</strong>. The paper requires comprehensive action logging, immutable audit trails, and full provenance chains linking every agent decision to the triggering event. The regulation requires logging sufficient to enable post-market monitoring and assessment of compliance with essential requirements. These are the same specification written in two vocabularies &#8212; one by a security architect, one by a legislator. An organization that builds the Anthropic logging stack has also built the regulatory logging infrastructure. An organization that builds them separately has built the same system twice.</p><p>Every section of the paper follows this pattern. The controls are dual-use by construction &#8212; they serve security containment and compliance demonstration simultaneously &#8212; and the paper only invoices one.</p><div><hr></div><h2>The Security Community&#8217;s Verdict</h2><p>The security community&#8217;s response to the Anthropic paper landed where it deserved to land. Disesdi Shoshana Cox&#8217;s analysis in Angles of Attack &#8212; mapping the Anthropic paper against ASI04, Agentic Supply Chain Vulnerabilities from the OWASP Agentic Top 10 &#8212; delivered the security verdict the paper itself wouldn&#8217;t state plainly: the systems these controls are designed to protect are architecturally resistant to the protections. The threats are intrinsic to what makes agents agents &#8212; runtime composition, dynamic tool selection, autonomous goal pursuit. The defensive architecture cannot close what the system&#8217;s own design holds open. Cox is right. And that verdict is the security half of a two-sided failure.</p><p><strong>The regulatory half is what this article delivers.</strong></p><div class="callout-block" data-callout="true"><p>The same architectural properties that make agents unsecurable also make them non-compliant. </p></div><p>The agent that composes its behavior at runtime cannot be secured because the attack surface is unbounded. The same agent cannot be conformity-assessed because the behavioral documentation is structurally incomplete the moment it runs. The agent that resists privilege containment because autonomy requires latitude also resists the human oversight function the AI Act requires &#8212; because effective oversight demands visibility into what the agent is doing, and unbounded agents are designed to exceed the scope anyone anticipated.</p><p>The security community sees this as a containment failure. The regulation sees it as a documentation failure. The provider who cannot describe what the system does before it runs has a security problem and a compliance problem that share the same mathematical root: the compositional outcome space &#8212; N actions across D steps &#8212; grows too fast to enumerate, too fast to secure, and too fast to document. <a href="https://www.zerodaydawn.com/p/why-agentic-ai-breaks-every-existing">The Pre-Computation Fallacy</a> hits both frameworks at the same structural joint.</p><p>The empirical picture confirms the structural one. An independent audit by Capsule Security &#8212; the broadest data-driven security assessment of the agentic ecosystem to date &#8212; measured the exposure at scale in April 2026. 402,599 hosts running AI agent infrastructure on the public internet. 76.4% of dangerous-tool files with no input validation. 9.5% of agent skill files installing the lethal trifecta &#8212; code execution, credential access, and external communication &#8212; in a single step. Fewer than 5% of prompt-building repositories showing any sanitization. The first CVE ever assigned to an agentic prompt injection.</p><p><strong>Every one of those numbers has a convergence twin</strong>. </p><p>402,599 exposed hosts is 402,599 systems that cannot demonstrate the cybersecurity resilience the AI Act mandates for high-risk deployment. 76.4% with no input validation is 76.4% that cannot show an assessor the controls the essential requirements demand. 9.5% installing unsupervised code execution with credential access is 9.5% operating with capabilities no conformity assessment documented &#8212; because the capabilities were never in the scope. </p><p>The security exposure is measured. The regulatory exposure attached to the same numbers is not. Nobody is reading both columns.</p><p>What the security community&#8217;s coverage misses is the consequence that follows. </p><div class="callout-block" data-callout="true"><p><strong>&#8220;Agents are unsecurable&#8221; is a security finding. Under the EU AI Act, it is also a regulatory finding &#8212; because the AI Act mandates cybersecurity resilience as an essential requirement for high-risk systems</strong>. </p></div><p>A system the provider cannot secure is a system the provider cannot lawfully place on the EU market. <strong>The security verdict is the compliance verdict</strong>. The community delivered one half and stopped.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Convergence Map</h2><p>Control by control, here is what the Anthropic framework builds and what the EU AI Act requires &#8212; stated side by side so the organization that reads both can build once instead of twice. The threat layer underneath is the OWASP Agentic Top 10 &#8212; the taxonomy that names the risks both frameworks are responding to.</p><p><strong>Behavioral baselines and anomaly detection</strong> serve dual authority. In the Anthropic framework, they detect compromise &#8212; a hijacked agent deviating from established patterns triggers containment. Under the AI Act, the identical mechanism detects substantial modification &#8212; behavioral drift beyond the boundaries assessed during conformity assessment that triggers reassessment obligations. The engineering is one system. The triggers fire into two different reporting chains. An organization that builds behavioral monitoring for security and a separate drift-detection infrastructure for compliance has built the same telemetry pipeline twice, reading the same data, alerting different people, and leaving a gap between the alerts where neither team sees the other&#8217;s signal.</p><p><strong>Least agency and privilege scoping</strong> serve dual authority. Anthropic&#8217;s framework restricts what agents can access, for how long, with automatic expiration &#8212; <strong>because overprivileged agents are breach amplifiers</strong>. The regulation requires resilience against attempts to alter the system&#8217;s use or performance through exploitation &#8212; because overprivileged agents operating in high-risk domains create liability the provider documented around, not against. <strong>The control is the same: scope the agent&#8217;s operational permissions to the minimum required</strong>. The security team builds it to contain blast radius. The compliance team needs it to demonstrate that the system operates within its assessed boundaries. Build it once, under both names.</p><p><strong>Action logging and traceability</strong> serve dual authority. The Anthropic framework requires request IDs linking actions to triggering events, distributed tracing across multi-agent workflows, and full provenance chains from input to output with intermediate steps &#8212; because incident investigation requires reconstructing what the agent did and why. The regulation requires logging sufficient to assess compliance with essential requirements &#8212; because post-market monitoring requires the same reconstruction. <strong>The logs are the same logs. The provenance chains are the same chains</strong>. The only difference is who reads them and what they call the report.</p><p><strong>Identity and authentication</strong> serve dual authority. Anthropic requires cryptographic agent identity because attribution without identity is impossible &#8212; you cannot audit what you cannot name. The regulation requires that persons assigned to human oversight understand the system&#8217;s capabilities and be able to correctly interpret its output &#8212; which presupposes knowing which agent performed which action under whose authority. An organization whose security team tracks agent identity through cryptographic certificates and whose compliance team independently tracks agent actions through a separate oversight dashboard has built two attribution systems for the same agents performing the same actions.</p><p><strong>Input validation and output controls</strong> serve dual authority. The Anthropic framework filters manipulation attempts at the boundary &#8212; prompt injection detection, content filtering, output sandboxing. The regulation requires resilience against unauthorized third-party attempts to exploit vulnerabilities. The filter that blocks a prompt injection is simultaneously a security control and a compliance control. The organization that builds input validation for security and a separate robustness-testing regime for regulatory conformity has tested the same attack surface twice with different names on the report.</p><p><strong>Automated response and containment</strong> serve dual authority. The Anthropic framework terminates suspicious sessions, revokes credentials, and orchestrates graduated escalation &#8212; because compromised agents cause damage at machine speed and manual response is too slow. The regulation requires human oversight with the authority and technical capability to intervene during operation &#8212; which, for systems operating at machine speed, requires exactly the automated detection-and-escalation pipeline the security team already built. The security team&#8217;s containment trigger is the compliance team&#8217;s intervention mechanism. Wire them to the same signal, or build two alert pipelines watching the same agent and routing to different teams who do not read each other&#8217;s tickets.</p><p>The convergence map is not a metaphor. It is an engineering specification. </p><div class="callout-block" data-callout="true"><p>Every control in the Anthropic framework has a regulatory twin under the EU AI Act. </p></div><p>Building them separately doubles the cost and leaves the join &#8212; the point where a security event becomes a regulatory event &#8212; unwired.</p><p>The implementation layer that wires the join is now emerging. <strong>The Agent Control Standard (ACS)</strong> &#8212; an open specification built in alignment with the OWASP ecosystem &#8212; defines standardized middleware hooks at every agent decision point: input, output, tool call, memory operation, code execution, sub-agent invocation. </p><p>A Guardian Agent intercepts the action, evaluates it against policy, and returns a verdict before the action reaches production. Each hook is simultaneously the point where a security control fires and where a compliance obligation attaches. ACS is built explicitly to serve both the EU AI Act&#8217;s requirement for demonstrable human oversight and the NIST AI Risk Management Framework&#8217;s requirement for continuous monitoring and disengagement capability &#8212; and it integrates with the OWASP Agentic Top 10 and OpenTelemetry, the same taxonomies and telemetry standards the convergence map depends on. The standard is open-source, Apache 2.0 licensed, and vendor-neutral. It is the shared control plane both teams can build against, once, under both authorities.</p><div><hr></div><h2>One Problem, Two Invoices</h2><p>The cost is not abstract.</p><p>An organization deploying agents in a high-risk domain &#8212; employment screening, credit assessment, insurance underwriting, any Annex III use case &#8212; needs behavioral monitoring, privilege management, logging, identity attribution, input validation, and automated response. The security team will scope, procure, and build these controls against the threat landscape. The compliance team will scope, procure, and build documentation, drift detection, logging, oversight mechanisms, and conformity evidence against the essential requirements.</p><p>They will hire different vendors. They will issue different RFPs. They will build on different infrastructure. They will produce different dashboards. They will report to different executives. And the behavioral monitoring stack the security team built will detect the same departure from baseline that the compliance team&#8217;s drift-detection infrastructure was designed to catch &#8212; except neither team&#8217;s alerting pipeline routes to the other, and when the agent drifts, two teams will discover it independently, investigate it separately, and file reports that describe the same event in two languages neither team reads.</p><p>This is the structural cost of the wall between the security framework and the AI Act. The wall is not in the technology. It is in the org chart, the budget, and the conference schedule. </p><p>The security team attends RSA. The compliance team attends IAPP. The Anthropic paper is discussed at one. The EU AI Act is discussed at the other. The agent sits in both rooms and answers to both authorities.</p><div class="callout-block" data-callout="true"><p>Tearing the wall down is an architectural decision, not a procurement decision. </p></div><p>It means a single telemetry pipeline feeding both authorities. A single behavioral baseline serving both as the security anomaly detector and the compliance drift monitor. A single privilege-scoping layer documented once and submitted to both the security audit and the conformity assessment. A single logging infrastructure that satisfies the incident investigation and the regulatory record simultaneously.</p><p>The organization that builds it once, under both names, saves the duplicate engineering and closes the gap. The organization that builds it twice pays double and keeps the gap open &#8212; because the gap was never in either framework. It was in the space between them where nobody was looking.</p><div><hr></div><h2>What Regulators Will Ask</h2><p>Show us the behavioral baseline your agent was assessed against. Show us the mechanism that detects when the agent departs from it. Show us who receives the alert and what happens next.</p><p><strong>The security team built it</strong>.<strong> It is called anomaly detection</strong>. The compliance team does not know it exists because it sits in the SOC, not in the conformity assessment file. The regulator will ask for it by its regulatory name &#8212; evidence that the system continues to operate within the boundaries established during the initial conformity assessment &#8212; and neither team will recognize the question as the other team&#8217;s answered problem.</p><p><strong>Show us how the agent&#8217;s permissions are scoped to the minimum required for its documented function</strong>. Show us that the scoping is enforced at the infrastructure level, not through a system prompt.</p><p><strong>The security team built it</strong>. <strong>It is called least agency with JIT provisioning</strong>. The compliance team documented something called &#8220;appropriate technical and organizational measures to ensure cybersecurity resilience.&#8221; <strong>They are describing the same control in two vocabularies, and neither team has read the other&#8217;s documentation</strong>.</p><p>Show us the audit trail that links every agent action to the triggering event, through every tool call, every sub-agent delegation, every intermediate step. Show us that the trail captures why the agent selected this action and not another.</p><p><strong>The security team built it</strong>. <strong>It is called distributed tracing with full provenance chains</strong>. The compliance team needs it for post-market monitoring and assessment of compliance with essential requirements. The logs are the same logs. The chains are the same chains. The report goes to two authorities under two names.</p><p>The regulator does not care which team built the control. The regulator cares whether the control exists and whether the documentation describes it. An organization whose security controls and compliance documentation describe the same system in two vocabularies that do not cross-reference each other will spend the regulatory inquiry explaining what it already built &#8212; if it can find it.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/p/zero-trust-full-liability?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/p/zero-trust-full-liability?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><div><hr></div><h2>What To Do Now</h2><p><strong>Four questions</strong>. Each one tests whether the wall between the security function and the compliance function is still standing.</p><ol><li><p>Does your behavioral monitoring infrastructure &#8212; the baseline, the anomaly detection, the automated response &#8212; feed into the conformity assessment file as evidence of ongoing compliance, or does it sit in the SOC where the compliance team has never seen it?</p></li><li><p>Does your privilege-scoping architecture appear in both the security audit and the regulatory technical documentation under the same specification, or are two teams maintaining two descriptions of the same control?</p></li><li><p>Does your logging and traceability infrastructure serve both the incident investigation function and the post-market monitoring function, or are two separate pipelines capturing the same data under two different retention policies?</p></li><li><p>When your security team detects behavioral drift in an agent, does the alert route to the person responsible for determining whether that drift constitutes a change significant enough to trigger reassessment &#8212; or does the security team close the ticket and the compliance team never learns the agent left its assessed boundaries?</p></li></ol><p>If the answer to any of these is &#8220;they&#8217;re separate,&#8221; you are building twice and paying twice for one problem. </p><div class="callout-block" data-callout="true"><p>The engineering is one system. The authority it serves is two. Wire them together or accept that the gap between your security posture and your compliance posture is the space where your exposure lives &#8212; unmonitored by either team, visible to the regulator who reads both reports.</p></div><div><hr></div><h2>Conclusion</h2><p>The NIST submission is on the public record. Section 2.8 is published. The Anthropic paper is free to download. Every piece of the convergence &#8212; the security framework, the regulation, the map between them &#8212; is now publicly available, timestamped, and verifiable.</p><p>The security community delivered the security verdict: these systems resist the protections by design. The compliance community has not read the paper. Neither community holds the complete picture alone. The join between them is where the exposure lives &#8212; and where the architecture that closes it must be built.</p><p>Two teams. One hole.</p><p>Close it once, or answer for it twice.</p><div><hr></div><p><em>Zero-Day Dawn publishes weekly enforcement intelligence on agentic AI governance, standards architecture, and the gap between what the market sells and what survives the regulator. Subscribe at zerodaydawn.com.</em></p><div><hr></div><h2>References</h2><p>Anthropic, &#8220;<a href="https://claude.com/blog/zero-trust-for-ai-agents">Zero Trust for AI Agents: A Security Framework for Deploying Autonomous AI Agents in the Enterprise</a>,&#8221; May 2026. </p><p>OWASP GenAI Security Project, &#8220;<a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">State of Agentic AI Security and Governance,&#8221; v2.01, June 2026</a>. Section 2.8: &#8220;Towards Unified Governance: The Security-Compliance Convergence&#8221; (Violeta Klein). </p><p>Violeta Klein, &#8220;<a href="https://www.regulations.gov/comment/NIST-2025-0035-0474">Security Considerations for Artificial Intelligence Agents</a>,&#8221; Response to NIST Request for Information, Docket NIST-2025-0035, Document Number 2026-00206, March 8, 2026. </p><p>Regulation (EU) 2024/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), OJ L 2024/1689, 12.7.2024.</p><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications for 2026</a></strong>, (Agentic Top 10). Available at genai.owasp.org.</p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Disesdi Shoshana Cox&quot;,&quot;id&quot;:334048565,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2c78feb-660c-410a-b9df-a5e3c0564000_826x826.png&quot;,&quot;uuid&quot;:&quot;e99bff57-d674-4aa2-90da-c4771e41244e&quot;}" data-component-name="MentionToDOM"></span>, &#8220;<a href="https://disesdi.substack.com/p/attacking-and-threat-modeling-the-603">Attacking &amp; Threat Modeling The Agentic Top Ten: ASI04 &#8212; Agentic Supply Chain Vulnerabilities</a>,&#8221; Angles of Attack: The AI Security Intelligence Brief, Edition 53, June 2026.</p><p>Capsule Security, &#8220;<a href="https://www.capsulesecurity.io/the-state-of-ai-agent-security-2026">The State of AI Agent Security</a>,&#8221; April 2026.</p><p><a href="https://agentcontrolstandard.ai/">Agent Control Standard (ACS)</a>, Open Specification, Apache 2.0. </p><div><hr></div><p><em>Disclaimer: This article is educational analysis of regulatory architecture, enforcement dynamics, and standards development. It does not constitute legal advice. Organizations should consult qualified legal counsel for determinations specific to their AI systems and regulatory obligations.</em></p>]]></content:encoded></item><item><title><![CDATA[High-Risk Guidelines Are Not Built for Agents]]></title><description><![CDATA[New guidance. New deadline. Same blind spot.]]></description><link>https://www.zerodaydawn.com/p/high-risk-guidelines-are-not-built</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/high-risk-guidelines-are-not-built</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 24 May 2026 13:02:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vbiK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vbiK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vbiK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!vbiK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!vbiK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!vbiK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vbiK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3290931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/199059297?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vbiK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!vbiK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!vbiK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!vbiK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8a09afba-cb7b-4f66-a318-396bd408f543_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Two governance artefacts landed in May. The Commission published 148 pages of draft classification guidelines on May 19 &#8212; the first detailed interpretation of how to determine whethe&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/high-risk-guidelines-are-not-built">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Standards Delay, Omnibus "Simplification": Cui Bono? ]]></title><description><![CDATA[Why the legislator needs the delay more than you do]]></description><link>https://www.zerodaydawn.com/p/standards-delay-omnibus-simplification</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/standards-delay-omnibus-simplification</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 17 May 2026 13:01:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ab0i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ab0i!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ab0i!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ab0i!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ab0i!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ab0i!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ab0i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3306850,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/198103746?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ab0i!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ab0i!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ab0i!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ab0i!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2fb86508-00ab-440b-bde6-31b228d48930_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>The European Commission has framed the Digital Omnibus as a simplification package &#8212; competitiveness, red-tape reduction, alignment with the Draghi agenda. The framing is accurate at the level it operates on. It is also incomplete.</p><p>The infrastructure required to enforce the EU AI Act does not exist in its intended form. The harmonized standards underpinning the high-risk obligations are not ready. None has been cited in the Official Journal. FprEN 18286 on quality management is closest, at Formal Vote, with publication possible in July 2026 and citation later. prEN 18282 on cybersecurity and prEN 18228 on risk management are at Enquiry. prEN 18229-2 on accuracy and robustness trails behind. Adam Leon Smith&#8217;s tracking of the JTC 21 process documents the pipeline status in detail. The earliest realistic citation lands in the second half of 2026, and several standards will not be cited before the new delayed entry into force.</p><p>The certification market has been selling around this gap for two years. &#8220;Aligned to prEN 18286.&#8221; &#8220;Compliant with the harmonized cybersecurity standard.&#8221; &#8220;ISO 42001 certified.&#8221; Each of these phrases describes work that does not, in fact, deliver presumption of conformity under the AI Act. Presumption of conformity applies the moment the European Commission cites a harmonized standard in the Official Journal of the European Union, and not a day before. ISO 42001 is not a harmonized standard. <a href="https://www.zerodaydawn.com/p/your-iso-42001-badge-wont-save-you">ISO 42001 is structurally incompatible with the AI Act's product-conformity architecture</a> &#8212; a gap analyzed in JRC 139430.</p><p>By delaying high-risk obligations to December 2027 and August 2028, the Omnibus frames this delivery failure as a procedural adjustment. The recital lists the missing standards and the missing national infrastructure as the reasons. The framing is accurate. It is also doing political work.</p><p>That is the procedural read of the situation. It is the comfortable one. The structural read is harder to publish, so it does not get published at all.</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/standards-delay-omnibus-simplification">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Guardian Agents Won't Save You]]></title><description><![CDATA[The compliance market's newest solution has the same structural flaw as the problem it was built to solve.]]></description><link>https://www.zerodaydawn.com/p/guardian-agents-wont-save-you</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/guardian-agents-wont-save-you</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 10 May 2026 13:03:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sUdm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sUdm!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sUdm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!sUdm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!sUdm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!sUdm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sUdm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3312957,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/196776538?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sUdm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!sUdm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!sUdm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!sUdm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe00f03e8-b184-468b-bc24-a216609e559b_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Gartner named the category in 2025. By February 2026, they published a full Market Guide. The prediction: guardian agents will capture at least 6% of the agentic AI market by 2030 &#8212; &#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/guardian-agents-wont-save-you">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Pre-Computation Fallacy: Why Agentic AI Breaks Every Existing Governance Framework]]></title><description><![CDATA[Five frameworks. One assumption. The math breaks all of them.]]></description><link>https://www.zerodaydawn.com/p/why-agentic-ai-breaks-every-existing</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/why-agentic-ai-breaks-every-existing</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 03 May 2026 13:01:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9fKi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9fKi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9fKi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!9fKi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!9fKi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!9fKi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9fKi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3310241,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/196132341?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9fKi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!9fKi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!9fKi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!9fKi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8b67f09b-2550-481b-b4c2-bf055ead256b_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Five governance frameworks. Five different organizations. <strong>One shared assumption</strong>.</p><p>The EU AI Act requires providers to document intended purpose before deployment. NIST requires reliabi&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/why-agentic-ai-breaks-every-existing">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[(Un)governable: Agent Identity vs. Agentic Intent]]></title><description><![CDATA[The credential is bounded. The agent's intent is not. The EU AI Act holds you liable for both.]]></description><link>https://www.zerodaydawn.com/p/ungovernable-agent-identity-vs-agentic</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/ungovernable-agent-identity-vs-agentic</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 26 Apr 2026 13:02:32 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2f0Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2f0Y!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2f0Y!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2f0Y!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2f0Y!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2f0Y!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2f0Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/be2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3294206,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/195336836?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2f0Y!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2f0Y!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2f0Y!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2f0Y!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbe2b957f-2161-417d-b896-a75dab7257ad_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p style="text-align: justify;">Your security team has scoped the agent's permissions. Least privilege enforced. Service account credentials rotated. RBAC reviewed quarterly. The IAM dashboard shows green. The non-&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/ungovernable-agent-identity-vs-agentic">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The AI Decision Your Board Got Half Right]]></title><description><![CDATA[What happens when the AI investment that impressed the board meets the regulator who doesn't care about your ROI.]]></description><link>https://www.zerodaydawn.com/p/the-ai-decision-your-board-got-half</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/the-ai-decision-your-board-got-half</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 19 Apr 2026 13:02:35 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!5vsv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5vsv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5vsv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5vsv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5vsv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5vsv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5vsv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3302807,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/194168507?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5vsv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!5vsv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!5vsv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!5vsv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6b47df51-a656-4847-96b4-8bdb0e123d36_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>This piece has two authors because the problem it describes sits in a gap between two worlds that rarely talk to each other.</em></p><p><em><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Neha Kabra&quot;,&quot;id&quot;:120858550,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a26e4b77-bd83-41c3-b708-22c6806b1e0c_314x316.png&quot;,&quot;uuid&quot;:&quot;ddc88bcf-8890-4f4f-ba7f-b560a95bc4d8&quot;}" data-component-name="MentionToDOM"></span> has spent eighteen years inside the rooms where AI deployment decisions ge&#8230;</em></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/the-ai-decision-your-board-got-half">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Governing What Your Agent Does Next]]></title><description><![CDATA[The operational envelope for Agentic AI: four questions, one tripwire, and the only governance framework built for runtime]]></description><link>https://www.zerodaydawn.com/p/governing-what-your-agent-does-next</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/governing-what-your-agent-does-next</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Sun, 12 Apr 2026 13:01:34 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!FdX_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FdX_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FdX_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!FdX_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!FdX_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!FdX_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FdX_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3290339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/193948631?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FdX_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!FdX_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!FdX_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!FdX_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6d9afca6-66c5-445b-9422-ed399538076e_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Last week&#8217;s piece laid out the structural impossibility. <a href="https://www.zerodaydawn.com/p/human-oversight-at-machine-speed">Human oversight at machine</a> speed fails on the math. Kill switches fail on propagation speed. The blast perimeter expands before detection fires. Four governance frameworks mandate oversight. None of them account for the speed differential.</p><p><strong>This piece delivers the response.</strong></p><p>The <a href="https://www.zerodaydawn.com/p/guardrails-dont-scale">operational envelope</a> is the only governance architecture that survives enforcement &#8212; because <strong>it is the only one designed for systems whose behavior cannot be enumerated before runtime</strong>. Four questions define the boundary. A tripwire detects departure. A response protocol converts detection into a human decision. A documentation framework makes the whole thing defensible.</p><p>Every existing framework that assumes pre-deployment behavioral description requires this architecture underneath. They do not name it. The organizations that build it will be the ones that answer the regulator&#8217;s questions. The ones that do not will discover that &#8220;we have a human in the loop&#8221; is not an answer.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Comfortable Lie</h2><p>Here is what the market wants to believe: risk-tiered review solves the oversight problem.</p><p>It does not.</p><p>Risk-tiered review is the emerging consensus. Route high-consequence actions to a human. Let low-risk operations execute autonomously. Every framework is converging on this pattern. The OWASP State of Agentic AI Security and Governance report calls for it. Singapore&#8217;s MGF recommends checkpoints on high-stakes, irreversible, or outlier actions. ForHumanity mandates Human-in-Command with established stop, pause, disregard, override, and reverse processes.</p><p>The pattern is architecturally sound. The problem underneath it is unsolved.</p><p>Who defines high-consequence? The OWASP State of Agentic AI Security and Governance report mandates classifying agent actions by risk tier and assigning oversight requirements to each tier. The mandate is correct. </p><blockquote><p><strong>The problem underneath it is unaddressed: what counts as high-stakes when the agent composed a workflow at runtime that nobody anticipated at assessment time?</strong> <strong>This is the threshold-definition problem. No framework has solved it.</strong></p></blockquote><p>Risk-tiered review without a defined boundary is a governance fiction. It classifies actions against a threshold that does not exist. The operational envelope is the answer. It does not classify individual actions. <strong>It defines the boundary of the entire assessed behavioral space &#8212; and treats every departure from that space as a governance event.</strong></p><div><hr></div><h2>The Threshold Nobody Defined</h2><p>All major governance frameworks share a structural assumption: the provider or deployer can describe what the system does <em><strong>before it operates</strong></em>. Document the intended purpose. Assess risks within those boundaries. Certify against requirements. Monitor for deviation from the documented baseline.</p><p><strong>For agentic AI, this assumption is architecturally false.</strong></p><p>An agent with access to ten authorized tools across ten chaining steps can compose ten billion possible workflows. The outcome space grows exponentially with every action the agent is permitted to chain. No documentation captures it. No risk assessment bounds it. No monitoring system watches all of it.</p><p>The <strong><a href="https://www.zerodaydawn.com/p/guardrails-dont-scale">Pre-Computation Fallacy</a></strong> is the name for this structural failure. The governance specification requires describability. The math does not allow it.</p><p>The operational envelope resolves the fallacy &#8212; not by attempting to describe the full outcome space, but by defining the subset of behaviors the organization actually assessed. Everything inside the envelope was evaluated, documented, and accepted. Everything outside it is unknown territory.</p><p>The envelope is not a fence around the system&#8217;s behavior. It is a tripwire inside a defined boundary. When the agent&#8217;s behavior crosses that boundary, what happens next is not another automated decision. It is a human judgment about whether the system continues, pauses, or stops.</p><p>This is the architecture the OWASP State of Agentic AI Security and Governance report calls for when it names risk-tiered review. This is what Article 14 means when it requires effective oversight. This is what Singapore&#8217;s MGF requires when it mandates checkpoints on high-stakes actions. The frameworks describe the need. The operational envelope is the engineering response.</p><div><hr></div><p><em>The full methodology &#8212; the four questions that define the envelope, the tripwire detection architecture, the response protocol for boundary crossings, and the documentation framework a CISO can take into a Monday morning meeting &#8212; continues below for paid subscribers.</em></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/governing-what-your-agent-does-next">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Human Oversight at Machine Speed]]></title><description><![CDATA[When spawning agents outrun your blast perimeter]]></description><link>https://www.zerodaydawn.com/p/human-oversight-at-machine-speed</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/human-oversight-at-machine-speed</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 06 Apr 2026 05:01:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!0pps!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0pps!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0pps!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!0pps!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!0pps!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!0pps!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0pps!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3309810,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/192726344?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0pps!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!0pps!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!0pps!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!0pps!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5c848b02-ed55-4a73-85b5-878ef72494a2_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Four governance frameworks require human oversight of high-risk AI systems. The EU AI Act mandates it. Singapore's Model Governance Framework for Agentic AI recommends it. NIST recom&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/human-oversight-at-machine-speed">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA["Supply Chain Is The New DNS"]]></title><description><![CDATA[When the tool that protects your AI pipeline is the tool that compromises it, every governance artifact built on top of it becomes fiction overnight]]></description><link>https://www.zerodaydawn.com/p/supply-chain-is-the-new-dns</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/supply-chain-is-the-new-dns</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 30 Mar 2026 05:02:57 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZT5s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZT5s!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZT5s!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ZT5s!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ZT5s!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ZT5s!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZT5s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3309795,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/192183191?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZT5s!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!ZT5s!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!ZT5s!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!ZT5s!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F22d4f72a-5b6b-4a6d-bfb2-b77f224c73cd_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>DNS is the invisible layer that translates every web address into a destination &#8212; and when it breaks, nothing works even though nothing looks broken. The AI supply chain has become the same kind of invisible dependency. Every enterprise AI system &#8212; from demand forecasting agents to credit decisioning models &#8212; runs on a stack of open-source components that route the calls, verify the code, and connect the models to production infrastructure. Nobody in the boardroom thinks about those components. They are assumed to work. They are assumed to be trustworthy. They are assumed to be what they claim to be.</p><p>Last week, one of the most widely deployed components in that invisible layer was silently replaced by an attacker &#8212; and the entry point was the security scanner that was supposed to protect it. The compromise is not contained. The attacker retains persistent access to every affected system, deployable at any time.</p><p>The enterprise AI stack now has a structural vulnerability that no governance framework on the market is designed to detect. When a component underneath your AI system is silently replaced, every governance artifact your organization filed becomes a description of a system that no longer exists &#8212; the technical documentation, the risk assessment, the conformity assessment all describe something that stopped being real the moment the compromised component executed. The security team will find it and patch it. The compliance team will not know that the foundation underneath their documentation changed, because nothing in the current governance architecture connects the security team&#8217;s remediation workflow to the compliance team&#8217;s regulatory filing obligation.</p><p>The financial exposure is not abstract. The penalty ceiling under the EU AI Act runs to &#8364;15 million or 3% of global annual turnover. The reporting clocks &#8212; 15 days under the AI Act, 24 hours under NIS2 &#8212; start running the moment the organization becomes aware. For organizations that deployed AI agents in supply chain operations, logistics, or financial services, the real cost is the fine compounded by the operational disruption, the reputational fallout, and the discovery that the governance program the board funded was governing a fiction.</p><p>As Gadi Evron put it last week at RSA: &#8220;Supply chain is the new DNS.&#8221; He meant it as a security warning. The governance consequence hasn&#8217;t landed yet. This piece shows where it lands.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Comfortable Lie</h2><p>Here is what the market wants to believe:</p><p>Agentic AI is transforming supply chains through autonomous execution, and the governance challenge is under control. AI agents forecast demand, optimize logistics, manage inventory, schedule production, and reroute shipments &#8212; all in real time, all at scale, all with minimal human intervention. Trusted guardrails keep the system within its boundaries. Human oversight handles the exceptions. The infrastructure underneath is stable, verified, and trustworthy.</p><p>That belief is everywhere this year. EY describes agentic AI as enabling &#8220;autonomous decision-making and task execution&#8221; that will &#8220;unlock unprecedented value&#8221; for supply chain executives. Microsoft has deployed over 25 AI agents across its own supply chain operations, with a target of 100 by year-end, and published a reference architecture for multi-agent orchestration spanning demand planning, logistics, and warehouse management. IBM frames AI agents as systems that &#8220;perceive incoming data, reason about possible actions, and act in context rather than following fixed instructions,&#8221; predicting that by 2028, a third of enterprise software applications will include agentic AI. SAP calls 2026 the year AI agents &#8220;become team members&#8221; and describes a future where &#8220;copilots embedded in planning workspaces handle repetitive analysis while people focus on scenario choice and exception management.&#8221; Forbes reports that agentic AI &#8220;can reason through a situation, plan next steps, and execute actions across systems,&#8221; representing &#8220;the biggest change enterprise software has seen in years.&#8221;</p><p>Every one of these visions shares the same unexamined assumption: the components underneath the agents are what they claim to be. The models are clean. The APIs are authentic. The libraries behave as documented. The security scanner protecting the CI/CD pipeline is actually protecting the CI/CD pipeline.</p><p>Last week, that assumption broke down &#8212; and it did so through the security layer itself.</p><div><hr></div><h2>The Breach</h2><p>On March 24, 2026, security firm Semgrep published a detailed technical analysis of a multi-stage supply chain attack that cascaded from a security scanner into the AI infrastructure underneath enterprise deployments. The attack is ongoing, the threat actors are still active, and the full scope of the compromise remains unknown.</p><p>It started with Trivy &#8212; an open-source vulnerability scanner made by Aqua Security that is widely used across the industry to find vulnerabilities in CI/CD pipelines before builds are published. In late February, an automated bot exploited a workflow misconfiguration to steal credentials from the Aqua Security GitHub organization. Aqua rotated credentials, but the attacker retained access through a single bot account with write and admin privileges across both the public and internal GitHub organizations. With that access, the attackers &#8212; a group called TeamPCP &#8212; pushed a malicious Trivy release that ran a credential stealer alongside the legitimate scanner, force-pushed 75 of 76 version tags in Trivy&#8217;s GitHub Actions so that anyone referencing those actions by tag pulled the infostealer into their pipeline, and pushed malicious Docker images with no corresponding GitHub releases.</p><p>The stolen credentials gave TeamPCP access to downstream projects &#8212; and one of those projects was LiteLLM.</p><p>LiteLLM is not a peripheral library. It is the unified API gateway that enterprises use to route calls across multiple LLM providers &#8212; OpenAI, Anthropic, Google, Mistral &#8212; through a single interface. In enterprise deployments, LiteLLM operates as the AI routing layer: managing provider selection, budget controls, authentication, and model flexibility underneath applications that were written to a single API standard. Its proxy server is the most widely deployed feature in enterprise contexts, and it sits at the exact layer where enterprise AI systems connect to the models they depend on.</p><p>LiteLLM used Trivy in its own CI/CD pipeline &#8212; the security scanner that was supposed to protect its code was the mechanism through which the malware entered.</p><p>The attack inside LiteLLM was technically precise and deliberately difficult to detect. Rather than using a postinstall hook &#8212; a technique developers have learned to watch for &#8212; the malware dropped a <code>.pth</code> file into Python&#8217;s site-packages directory. Python auto-executes <code>.pth</code> files on every interpreter startup, which means the malware triggers not when you import litellm, but when you run any Python process at all, including something as innocuous as <code>python --version</code>.</p><p>The credential harvesting was comprehensive in a way that security researchers described as unprecedented in supply chain attacks. The malware exfiltrated SSH keys, AWS credentials including full IMDSv2 token flows and Secrets Manager enumeration, GCP and Azure credentials, Kubernetes tokens and service account secrets, environment configuration files across all standard naming conventions, shell history, git credentials, Docker registry authentication, Terraform state files containing infrastructure secrets, TLS private keys, and even cryptocurrency wallet keys. If the malware detected a Kubernetes environment with a permissive service account, it escalated from credential theft to full cluster compromise &#8212; creating privileged DaemonSets across every node including the control plane, mounting the host filesystem, and installing a persistent backdoor directly onto the underlying host.</p><p>The exfiltrated data was encrypted with AES-256-CBC, the session key wrapped with the attacker&#8217;s RSA-4096 public key, and transmitted to a domain designed to mimic LiteLLM&#8217;s legitimate infrastructure. This encryption architecture means that even if network traffic is intercepted, the stolen credentials cannot be recovered without the attacker&#8217;s private key &#8212; which means affected organizations cannot determine with certainty what was taken, and must assume the worst when deciding what to rotate.</p><p>The persistent backdoor installed on compromised systems polls a command-and-control endpoint every fifty minutes. When no active campaign is running, the endpoint returns a YouTube URL &#8212; the dormancy signal. The infrastructure is silent, but fully operational. The attacker retains arbitrary code execution on every compromised host, deployable at any time they choose.</p><p>TeamPCP shared their motive on their Telegram channel, referring to the security vendors they had compromised: &#8220;These companies were built to protect your supply chains yet they can&#8217;t even protect their own.&#8221;</p><p>The irony is real. But the consequence extends far beyond the security vendors &#8212; and far beyond what any security team can remediate with a patch.</p><div><hr></div><p><em>The full regulatory analysis &#8212; including where the EU AI Act's provider conversion trap applies to off-the-shelf supply chain agents, why operational gridlock qualifies as a mandatory serious incident filing, and the three questions your organization must answer before your next board meeting &#8212; continues below for paid subscribers.</em></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/supply-chain-is-the-new-dns">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Guardrails Don't Scale]]></title><description><![CDATA[And nobody checked the math]]></description><link>https://www.zerodaydawn.com/p/guardrails-dont-scale</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/guardrails-dont-scale</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 23 Mar 2026 06:02:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!p52w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p52w!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p52w!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!p52w!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!p52w!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!p52w!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p52w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3303924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/191458116?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p52w!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!p52w!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!p52w!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!p52w!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0148f7e2-d592-4736-983c-704675c22d24_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>The AI governance market is selling containment. Guardrails. Safety filters. Alignment layers. Layered internal controls. The pitch is the same everywhere: constrain the system, docu&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/guardrails-dont-scale">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Clean Logs. €15 Million Problem.]]></title><description><![CDATA[IAM governs access. It doesn't govern intent. The EU AI Act holds you liable for both.]]></description><link>https://www.zerodaydawn.com/p/clean-logs-15-million-problem</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/clean-logs-15-million-problem</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 16 Mar 2026 06:01:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_GwU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_GwU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_GwU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_GwU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_GwU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_GwU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_GwU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3293339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/190655988?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_GwU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!_GwU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!_GwU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!_GwU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95720432-014b-4f14-842b-14d2de94b8d7_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Your agent&#8217;s service account has scoped permissions. Least privilege enforced. RBAC clean. The IAM audit passes. Every security team in every enterprise running agentic AI signs off on this architecture. It is the standard.</p><p>It is also the blind spot.</p><p>An agent with authorized read access to an HR database and authorized write access to an external email API can autonomously chain those two permissions into a workflow that sends employee records to a third party. No privilege was escalated. No authorization was breached. The access log is clean. The outcome is an unassessed operation in an employment domain &#8212; and nobody in the organization knows it happened.</p><p>IAM was built for human users who make one decision at a time. Agents don&#8217;t work that way. They chain thousands of authorized actions into emergent workflows that no access control framework was designed to evaluate. The Cloud Security Alliance found that 50% of enterprises rely on traditional IAM and RBAC as the primary authorization mechanism for their agents. Half of all organizations deploying autonomous systems are governing them with tools built for human users clicking through permission prompts.</p><p>The EU AI Act does not distinguish between unauthorized access and authorized access that produces an ungoverned outcome. The obligation attaches to the outcome &#8212; what the system functionally does to people. Five governance frameworks &#8212; the EU AI Act, NIST, OWASP, Singapore&#8217;s Model AI Governance Framework, and ForHumanity&#8217;s multi-agent certification scheme &#8212; all assume that controlling access controls behavior.</p><p>The agent proves otherwise. Every framework built on this assumption has a structural blind spot in the same place. This article maps where it is.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>The Assumption</h2><p>Here is the sentence that will not survive enforcement:</p><p>&#8220;As long as we enforce strict Least Privilege and RBAC on the agent&#8217;s service account, it can&#8217;t do anything it&#8217;s not supposed to.&#8221;</p><p>Every CISO deploying agentic AI believes some version of this. The logic is intuitive: restrict what the agent can reach, and you restrict what the agent can do. Behavior is bounded by permissions.</p><p>For human users, that logic holds. A human makes one decision at a time. The authorization framework evaluates each action independently because humans execute actions independently.</p><p>Agents compose. They chain authorized operations into workflows that nobody designed, nobody reviewed, and nobody approved. Each individual action is within scope. The composed workflow is ungoverned. IAM evaluates access &#8212; can this identity reach this resource? It does not evaluate intent &#8212; what is this identity trying to accomplish? It does not evaluate composition &#8212; what happens when three authorized actions produce an outcome none of them would produce alone?</p><p>The CSA data confirms this is not an edge case. 50% of organizations use IAM roles or policies as the primary authorization mechanism for agents. 44% use static API keys. 72% cannot trace agent activities across environments.</p><p>The gap between &#8220;authorized access&#8221; and &#8220;governed outcome&#8221; is where the entire liability sits. Five governance frameworks assume it does not exist.</p><div><hr></div><h2>The Scenario</h2><p>A mid-sized financial services firm deploys an internal research agent. The agent has access to three systems: a customer relationship management platform, a market data API, and an internal communications tool. All three connections are authorized, scoped, and documented. The agent&#8217;s declared purpose is market research synthesis &#8212; pulling public data, generating summaries, flagging trends.</p><p>The agent receives a routine prompt: assess the potential impact of a market downturn on the firm&#8217;s client base. To complete the task, it queries the CRM for client portfolio data. It cross-references that data against the market data API. It identifies clients with concentrated exposure to affected sectors. It generates a prioritized risk assessment &#8212; ranking individual clients by vulnerability &#8212; and sends the summary to the relationship management team via the internal communications tool.</p><p>Every action was authorized. Every tool was within scope. The IAM audit log shows three clean API calls and one internal message. No privilege was escalated. No anomaly detected.</p><p>The agent has performed an assessment of individual clients&#8217; financial vulnerability. It has generated a ranking that will influence which clients receive outreach and which do not &#8212; a determination that affects access to financial services. Under the EU AI Act, a system that evaluates the creditworthiness of natural persons or assesses risk in relation to natural persons in the case of life and health insurance operates in an Annex III domain. The agent has entered that domain through its own runtime behavior &#8212; not through any configuration change, not through any human decision to expand its scope, but through the autonomous composition of individually authorized tool calls.</p><p>The firm&#8217;s CISO sees a clean access log. The firm&#8217;s compliance lead &#8212; if they ever see the output &#8212; sees an unregistered, unassessed high-risk AI system operating in a regulated domain without conformity assessment, without risk management documentation, without human oversight, and without the technical documentation the regulation requires before any high-risk system is put into service.</p><p>The agent did not break any rules. It composed a workflow from authorized components that crossed a regulatory boundary nobody mapped. The access was governed. The outcome was not.</p><div><hr></div><h2>The Composition Gap</h2><p>The structural failure is not a bug in IAM. IAM does what it was designed to do &#8212; evaluate discrete access requests against defined policies. The failure is in assuming that access-level control translates to behavior-level governance when the system determining its own behavior is autonomous.</p><p>Human users produce linear workflows. One action, one decision, one outcome. The authorization framework evaluates each action independently because human users execute actions independently. The composed behavior is the sum of discrete, intentional human choices.</p><p>Agents produce emergent workflows. The execution path is not specified at design time. It emerges at runtime. The agent selects tools based on intermediate results. It sequences actions based on its interpretation of the goal. It chains operations that were individually authorized into compositions that were never assessed. The authorization framework sees each component. It cannot see the composition &#8212; because it was never designed to evaluate compositions.</p><p>OWASP identified this in the Top 10 for Agentic Applications. The mitigation for tool misuse recommends defining &#8220;per-tool least-privilege profiles&#8221; &#8212; restricting each tool&#8217;s permissions and data scope individually. The recommendation is technically sound and structurally insufficient. An agent can chain two perfectly restricted, read-only tools into a data exfiltration workflow. Tool-level restriction does not equal workflow-level restriction. The gap between them is where the liability lives.</p><p>Every governance framework attempting to address agentic AI hits this same wall. The EU AI Act, NIST, OWASP, Singapore&#8217;s Model AI Governance Framework, ForHumanity&#8217;s multi-agent certification scheme &#8212; all of them assume that if you define the system&#8217;s boundaries before runtime, the system will operate within those boundaries during runtime. Agents are architecturally designed to determine their own operational boundaries. The assumption underneath every framework is the thing agents were built to violate.</p><p>What follows maps where each framework breaks &#8212; the specific provision, the specific assumption, and what it costs when an agent operating within authorized access produces an outcome that none of these instruments can govern.</p><p>The full analysis &#8212; where Singapore&#8217;s agent governance framework eliminates the thing it&#8217;s trying to govern, where ForHumanity&#8217;s audit criteria demand documentation of something that doesn&#8217;t yet exist, where NIST&#8217;s reliability definition collapses for systems whose operational conditions change per execution, where the EU AI Act&#8217;s conformity assessment certifies a system that stops existing the moment it operates, the convergence pattern across all five frameworks, and the operational methodology for building governance that evaluates intent and outcome rather than access &#8212; continues below for paid subscribers.</p><p><em>Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</em></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/clean-logs-15-million-problem">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Your Security Incident is a Regulatory Disaster]]></title><description><![CDATA[OWASP mapped the attack surface. The EU AI Act attached the penalties]]></description><link>https://www.zerodaydawn.com/p/your-security-incident-is-a-regulatory</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/your-security-incident-is-a-regulatory</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 09 Mar 2026 06:01:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LmCd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LmCd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LmCd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!LmCd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!LmCd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!LmCd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LmCd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bd2de383-2658-4074-9794-f1302285f393_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3286094,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/189976106?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LmCd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!LmCd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!LmCd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!LmCd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbd2de383-2658-4074-9794-f1302285f393_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary </h2><p>Your security team filed the incident report. They also filed the regulatory case file. They just don&#8217;t know it yet.</p><p>That is the disaster this article maps. The OWASP vulnerability and the EU AI Act violation are the same event, happening simultaneously, under identical facts. When your agent is hijacked, the regulation&#8217;s <strong>intended purpose</strong> architecture fails at the same moment. When your agent misuses a tool, the <strong>classification</strong> filed at deployment becomes invalid at the same moment. When your agent operates with uncontrolled identity and accumulated privileges, the <strong>human oversight</strong> obligation is breached at the same moment.</p><p>OWASP published its Top 10 for Agentic Applications in late 2025. The Cloud Security Alliance quantified the gap in January 2026: 72% of organizations cannot trace what their AI agents are doing across environments. Only 16% are confident they could pass a compliance audit on agent activity. Nearly one in five enterprises have already experienced an AI agent-related security breach. Those are organizations that have already accumulated regulatory disasters they cannot see.</p><p>What follows maps seven OWASP vulnerabilities to their EU AI Act equivalents. Each entry follows the same structure: what your security team calls it, what the regulation calls it, and what it costs you when the regulator reads the same incident report your team wrote.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2>1. Goal Hijacking</h2><p><strong>What you assume:</strong> Prompt injection is a security problem. Your red team tests for it. Your WAF blocks obvious payloads. You&#8217;ve hardened the input layer.</p><p><strong>What actually happens:</strong> A prompt injection attack doesn&#8217;t just compromise your agent&#8217;s current task. It substitutes a different <strong>intended purpose</strong> for the one you documented. The system is now operating outside its compliance envelope &#8212; not because it malfunctioned, but because it functioned exactly as the regulation assumes it should not be able to: executing goals that nobody authorized. The attack surface is natural language, not code. No user action required.</p><p>The EU AI Act defines an AI system&#8217;s intended purpose as the use for which the system was designed by the provider &#8212; including the specific context and conditions of use. The conformity assessment, the risk management system, the human oversight obligations &#8212; all of them are anchored to that documented intended purpose. A goal hijacking attack substitutes an attacker&#8217;s purpose for yours. The classification you filed at deployment no longer describes the system in production.</p><p>Article 15 is the regulatory hammer your security team hasn&#8217;t mapped. It mandates that high-risk AI systems be resilient against attempts by unauthorized third parties to alter their use, outputs, or performance by exploiting system vulnerabilities. Prompt injection is exactly this: unauthorized alteration of system use by exploiting a vulnerability. A successful goal hijacking attack is a documented Article 15 failure.</p><p>If the hijacked goal causes the agent to operate in a domain listed in Annex III &#8212; making employment decisions, influencing credit assessments, allocating access to essential services &#8212; the agent has crossed a classification boundary through hostile action. Under Article 9, the risk management system must identify and evaluate risks that may emerge under conditions of reasonably foreseeable misuse. Prompt injection is not a hypothetical. It is a documented, active attack vector. An organization that deployed an agentic system capable of being hijacked into high-risk territory without modeling that scenario failed Article 9 before the attack ever happened.</p><p><strong>What it costs you:</strong> A successful goal hijacking attack produces a stack of liabilities, not one. The Article 15 cybersecurity failure is the technical violation &#8212; the system was not resilient against unauthorized alteration. The Article 9 risk management failure is the governance violation &#8212; the scenario was reasonably foreseeable and not addressed. Both carry penalties of &#8364;15 million or 3% of global annual turnover. If the attack caused harm meeting the statutory threshold &#8212; death, serious damage to health, serious and irreversible disruption of critical infrastructure &#8212; Article 73 mandatory incident reporting triggers. The window is 15 days. Two days for critical infrastructure impacts. The security incident report your team files is already a regulatory case file.</p><div><hr></div><h2>2. Tool Misuse</h2><p><strong>What you assume:</strong> Your agent has authorized access. It holds legitimate credentials. The IAM controls are clean. What it does with that access is an application logic problem, not a compliance problem.</p><p><strong>What actually happens:</strong> Authorized access producing unintended consequences is the attack surface OWASP identifies as the most structurally dangerous. The agent reaches a database it was technically permitted to access. It pulls data it was not designed to use and feeds that data into a decision chain nobody anticipated. No authorization was breached. The access was clean. The outcome was not governed.</p><p>The EU AI Act doesn&#8217;t classify systems by what you call them. It classifies them by their legally defined intended purpose and the domain in which they operate. An agent whose tool use causes it to operate in an Annex III domain &#8212; employment decisions, creditworthiness assessments, access to essential services &#8212; has crossed into high-risk territory through its own runtime behavior. The classification filed at deployment no longer describes the system.</p><p>The conversion trap nobody discusses: under Article 25, a deployer who modifies the intended purpose of an AI system such that it becomes high-risk is considered to be the provider of that high-risk system and becomes subject to the provider obligations under Article 16. A deployer whose agent, through tool use, autonomously begins operating in a high-risk domain may have triggered exactly this conversion &#8212; without any human decision to do so. If your agent accesses an HR database and generates a recommendation that affects a hiring decision, and that was not in the original intended purpose documentation, you are now the provider of an unregistered, unassessed high-risk AI system. You inherit uncapped liability for a system you thought you were merely deploying.</p><p><strong>What it costs you:</strong> Non-registration of a high-risk AI system carries penalties of up to &#8364;15 million or 3% of global annual turnover. The failure to conduct a conformity assessment is a separate violation. The absence of technical documentation is a separate violation. 40% of CISOs estimate that a major AI agent incident will cost their organization between $1 million and $10 million &#8212; ransomware-level financial impact. A single episode of unintended tool use that tips an agent into Annex III territory generates multiple simultaneous regulatory violations, none of which require any third party to be harmed.</p><div><hr></div><h2>3. Identity and Privilege Abuse</h2><p><strong>What you assume:</strong> Your agent runs under a service account. Permissions are scoped. Access is controlled by the same IAM framework that governs your human users.</p><p><strong>What actually happens:</strong> The IAM framework was designed for human users. It was not designed for autonomous systems that execute thousands of actions per session under a single identity. Your agent inherits permissions from the user who configured it. It operates with credentials provisioned for human workflows. It accumulates access across execution chains &#8212; each tool call opening another connection, each data retrieval expanding the operational footprint. No single permission grant looks anomalous. The aggregate exposure is severe.</p><p>The Cloud Security Alliance data confirms this is not an edge case: 44% of organizations use static API keys as the primary authentication mechanism for their agents. 43% use username/password combinations. 25% of enterprises have no formal AI security controls in place at all.</p><p>Article 14 requires that high-risk AI systems be designed so that they can be effectively overseen by natural persons during the period in which they are in use. The persons assigned to human oversight must understand the system&#8217;s capabilities and limitations and be able to correctly interpret its output. An agent operating with accumulated, unmonitored access under a human user&#8217;s credentials is structurally invisible to any oversight function. The overseer cannot interpret output from a system whose actual operational scope they cannot see.</p><p>CSA found that 39% of organizations assign agent governance to Security, 32% to IT, with no unified accountability. The regulation requires designated, competent, properly trained oversight personnel with the authority to intervene. Fragmented ownership across three separate functions means no single function holds complete understanding of the agent&#8217;s capabilities and limitations. The Article 14 obligation requires operational capacity, not an org chart entry.</p><p><strong>What it costs you:</strong> Violations of high-risk human oversight obligations carry fines of &#8364;15 million or 3% of global annual turnover. For agents that have never been classified at all &#8212; operating under human credentials in domains that were never assessed &#8212; transparency obligations under Article 50 apply regardless of risk level. Violations of Article 50 carry the exact same penalty: &#8364;15 million or 3%. An unclassified agent is not exempt from both. It is potentially liable for both simultaneously.</p><div><hr></div><h2>4. Insecure Inter-Agent Communication</h2><p><strong>What you assume:</strong> Your multi-agent architecture is a scalability decision. Agents pass tasks to each other. Orchestrators coordinate workflows. The security model is inherited from your microservices framework.</p><p><strong>What actually happens:</strong> Multi-agent systems break standard authorization through two mechanisms. First, diffusion of responsibility: because there is no central authority, assumptions about which agent enforces security become ambiguous, and systems silently fail to enforce controls because each agent assumes another handled it. Second, workflow privilege escalation: agents perform individually authorized, low-privilege actions that, when chained together through inter-agent communication, result in an unauthorized, high-privilege exploit.</p><p>The EU AI Act assesses risk at the level of individual AI systems. The conformity assessment evaluates each system against its documented intended purpose &#8212; assuming identifiable, bounded behavior. Multi-agent interactions produce emergent behavior that no component-level assessment accounts for. Every handoff between agents is a point where data integrity, authorization scope, and classification boundaries can break simultaneously.</p><p>Under Article 26, deployers operating high-risk AI systems must monitor system performance against the intended purpose on an ongoing basis. An organization operating a multi-agent architecture cannot discharge that monitoring obligation for a system whose inter-agent communication it cannot trace. Only 28% of organizations can reliably trace an agent&#8217;s actions across all environments. For multi-agent systems, that coverage gap is structurally deeper.</p><p>The substantial modification provision compounds the exposure. An agent that receives corrupted or injected instructions from an upstream agent and executes them has had its intended purpose modified by the attack &#8212; a substantial modification requiring a new conformity assessment. Whether it triggers reassessment depends on whether the organization can detect it. 72% cannot.</p><p><strong>What it costs you:</strong> The failure to maintain ongoing monitoring of a high-risk system&#8217;s performance is a violation of Article 26 deployer obligations. The failure to report a serious incident carries mandatory reporting windows as short as two days for critical infrastructure. The regulatory clocks collide here. If your agent incident qualifies as a significant cyber threat under NIS2, you have 24 hours for an early warning and 72 hours for full incident notification. If the same incident triggers EU AI Act serious incident reporting under Article 73, you have 15 days &#8212; or 2 days for critical infrastructure. Article 73(9) provides a carve-out: if equivalent reporting applies under another framework, the AI Act obligation is limited to incidents involving infringement of fundamental rights. Your security team will be fighting two different regulatory clocks simultaneously, for the same event, with different disclosure requirements.</p><div><hr></div><p><em>The first four entries are the vulnerabilities your security team is most likely to have already logged. They are simultaneously the compliance failures your regulatory team cannot see. What follows are the entries that determine whether your governance architecture survives its first enforcement inquiry &#8212; or becomes the case study other organizations learn from.</em></p><p><em>The full analysis &#8212; including rogue agent behavior as a substantial modification trigger, cascading failures as an Article 9 risk management violation, memory poisoning as an Article 10 data governance failure, the four-question classification methodology for determining which vulnerabilities trigger high-risk obligations, the documentation architecture required before August 2026, and the operational framework for building compliance that survives both a penetration test and a regulatory audit &#8212; continues below for paid subscribers.</em></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/your-security-incident-is-a-regulatory">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Deploy First, Comply Never]]></title><description><![CDATA[A field guide to everything AI agent builders get wrong about the EU AI Act]]></description><link>https://www.zerodaydawn.com/p/deploy-first-comply-never</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/deploy-first-comply-never</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 02 Mar 2026 18:39:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!N8JK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!N8JK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!N8JK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!N8JK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!N8JK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!N8JK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!N8JK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3306169,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/189674208?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!N8JK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!N8JK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!N8JK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!N8JK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd1aebc2d-8fdf-4e85-b304-d14344449525_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Executive Summary</strong></h2><p>This article is for every team that has built, shipped, or deployed an AI agent without asking whether the EU AI Act applies to them. It does. This is the field guide to the fourteen regulatory traps waiting between your deployment and your first enforcement action.</p><p>You built an agent. You shipped it. Users in the EU are using it. You are now operating inside a regulatory framework you probably haven&#8217;t read &#8212; and the obligations it imposes are already binding.</p><p>The EU AI Act entered into force in August 2024. Bans on prohibited AI practices are actively enforced right now. General-purpose AI obligations hit in August 2025. Broad transparency rules and most high-risk obligations become enforceable in August 2026, with the rest following in 2027.</p><p>What follows is every assumption AI agent builders are making that will not survive enforcement. Each one is a trap. Each trap has a regulatory consequence. None of them require you to be a large company, a European company, or a company that intended to operate in the EU.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>1. The Extraterritorial Trigger</strong></h2><p><strong>What you assume:</strong> You&#8217;re not based in the EU, so the EU AI Act doesn&#8217;t apply to you.</p><p><strong>What actually happens:</strong> The regulation follows output, not headquarters. If your AI agent produces a recommendation, a classification, a score, or a decision that is used by a natural person inside the EU, you are in scope. It does not matter where your servers are. It does not matter where your company is incorporated. It does not matter whether you intended your agent to reach the EU market.</p><p>A recruiter in Paris uses your agent to screen candidates. A bank in Amsterdam uses it to flag transaction risk. A university in Milan uses it to evaluate student submissions. You are now a provider or deployer under the EU AI Act &#8212; and the obligations that come with that status are enforceable against you.</p><p><strong>What it costs you:</strong> Penalties for non-compliance with high-risk or transparency obligations reach &#8364;15 million or 3% of global annual turnover. Supplying misleading information to regulators carries fines of &#8364;7.5 million or 1% of global annual turnover. These are not theoretical. They are statutory.</p><div><hr></div><h2><strong>2. Classification Creep</strong></h2><p><strong>What you assume:</strong> You built a productivity tool. An assistant. A workflow optimizer. Not a high-risk AI system.</p><p><strong>What actually happens:</strong> The EU AI Act does not classify systems by what you <em>call them</em>. It classifies them by <strong>their legally defined</strong> <strong>intended purpose</strong>. Your agent screens job applicants &#8212; that is an employment decision system under Annex III. Your agent evaluates the creditworthiness of individual consumers &#8212; that is a financial access system under Annex III. Your agent monitors employee performance or allocates tasks &#8212; employment domain, Annex III. Your agent influences a student&#8217;s educational progression &#8212; education domain, Annex III.</p><p>You did not <em>design</em> a high-risk system. But you <strong>deployed</strong> one. The gap between the generic tool you built and the high-risk task it now performs is where enforcement lives.</p><p>The sneakiest triggers are the ones builders never anticipate. If an internal research agent is repurposed to access HR data and generate recommendations affecting hiring decisions, <strong>its intended purpose has legally changed</strong>. It has entered an Annex III employment domain. Whoever made that change is now legally the provider of a high-risk AI system.</p><p><strong>What it costs you:</strong> Every downstream obligation &#8212; risk management, conformity assessment, documentation, human oversight, logging &#8212; is triggered by classification. Get classification wrong and everything you build on top of it is wasted. Get it right and you know what you owe. Skip it and a regulator will do the classification for you. </p><div><hr></div><h2><strong>3. The Liability Shift</strong></h2><p><strong>What you assume:</strong> You are the provider. Your enterprise customers are deployers. They handle human oversight and logging on their end. Clean separation.</p><p><strong>What actually happens:</strong> If your customer <strong>modifies the intended purpose</strong> of your agent &#8212; deploys it in a domain you did not anticipate, connects it to data sources you did not design for, or changes how it interacts with end users &#8212; they may have just triggered a legal conversion. <strong>A deployer who makes a substantial modification to an AI system, or who changes its intended purpose such that it becomes high-risk, assumes the full obligations of a provider</strong>. That means conformity assessment, technical documentation, risk management, and post-market monitoring &#8212; all of it shifts to the deployer.</p><p>But here's the trap nobody discusses: when your customer becomes the provider through modification, the original provider &#8212; you &#8212; must legally cooperate. You are required to provide technical access and assistance so the new provider can meet their obligations. The only way out? You must <strong>explicitly specify</strong> in your terms that the system is not to be changed into a high-risk AI system. If you didn't write that in, you owe them your documentation &#8212; <strong>limited only by strict trade secret protections</strong>.</p><p><strong>What it costs you:</strong> You lose control of how your system is classified. Your customer&#8217;s deployment decision creates obligations for both of you. And if you didn&#8217;t explicitly forbid high-risk modification in your contracts, enforcement will find two parties pointing at each other with nobody holding the compliance.</p><div><hr></div><h3>4. The Open-Source Illusion</h3><p><strong>What you assume:</strong> You built your agent on an open-source model. Open-source means lighter regulatory requirements. You&#8217;re covered.</p><p><strong>What actually happens:</strong> The EU AI Act offers limited transparency exemptions for open-source general-purpose AI models. Those exemptions apply <strong>to the model layer</strong>. The moment you integrate that model into an AI system that qualifies as high-risk under Annex III &#8212; because it screens applicants, evaluates creditworthiness, assesses insurance risk, or influences educational outcomes &#8212; every exemption vanishes. The system-level obligations apply in full.</p><p><strong>Open-source is a licensing model. It is not a regulatory shield. </strong>The regulation does not care how your model was licensed. It cares what the system built on top of it does to people.</p><p><strong>What it costs you:</strong> Every builder using open-source models who assumed lighter obligations now has the same compliance burden as a proprietary system deployed in the same domain. The model&#8217;s license changed nothing about the system&#8217;s classification.</p><div><hr></div><p><em>The first four traps are the ones that catch builders before they even know they&#8217;re playing. What follows are the ten operational traps that <strong>determine whether your deployed agent survives its first regulatory inquiry</strong> &#8212; or becomes the case study other builders learn from.</em></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/deploy-first-comply-never">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[When the EU Comes for Your Agents]]></title><description><![CDATA[Governance can't keep up with the tech &#8212; and going offshore isn't an escape route either]]></description><link>https://www.zerodaydawn.com/p/when-the-eu-comes-for-your-agents</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/when-the-eu-comes-for-your-agents</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 23 Feb 2026 06:00:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8vRP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8vRP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8vRP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!8vRP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!8vRP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!8vRP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8vRP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3292965,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/188606693?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8vRP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!8vRP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!8vRP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!8vRP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa99e3dfd-b028-40dc-b72e-da689fb1d345_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>This article is for the security teams deploying agentic AI systems who do not yet realize they have a compliance obligation under the EU AI Act.</p><p>If you work in application security, cloud architecture, or CISO operations &#8212; if you read OWASP advisories and CSA benchmarks as part of your operational baseline &#8212; this piece was written for your blind spot. The agentic AI systems you are deploying, monitoring, and securing are subject to binding regulatory obligations that your security frameworks do not address and your compliance teams may not know about.</p><p>Three things happened in the past ninety days that make this unavoidable.</p><p>The Cloud Security Alliance published its first comprehensive assessment of agentic AI security posture. The findings are severe: 72% of organizations cannot trace what their AI agents are doing across environments. Only 16% are confident they could pass a compliance audit on agent activity. 21% maintain a real-time agent registry. The rest are operating blind.</p><p>NIST launched the AI Agent Standards Initiative on February 17, 2026 &#8212; three pillars covering industry-led standards, open-source protocols, and research on agent security and identity. The first concrete deliverable is a request for information on agent security due March 9. A concept paper on AI agent identity and authorization follows on April 2. Listening sessions begin in April. The governance infrastructure is forming. It is not ready.</p><p>And the EU AI Act &#8212; enforceable from August 2026 for high-risk systems &#8212; already applies to every organization whose AI agents produce output used inside the EU. Regardless of where that organization is headquartered. Regardless of whether the agent was designed to reach the EU market. The regulation follows outputs, not headquarters.</p><p><span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Ken Huang&quot;,&quot;id&quot;:1160339,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3d670301-204b-472e-a2ee-bbb1b7633a99_2026x2026.png&quot;,&quot;uuid&quot;:&quot;50828278-512d-4673-882e-850e2519d88d&quot;}" data-component-name="MentionToDOM"></span>&#8217;s &#8220;Layer 8&#8221; thesis argues that agentic AI sits above the application layer because it breaks the deterministic boundary. The compliance architecture of the EU AI Act was built for everything below that boundary. The security community is mapping the risk. The standards bodies are forming the frameworks. The EU AI Act is the only instrument that already imposes binding obligations. And 72% of organizations cannot see the systems those obligations apply to.</p><p>Transparency obligations under Article 50 apply to all AI systems regardless of risk classification. The classification decision itself carries regulatory consequences &#8212; &#8364;7.5 million or 1% of global annual turnover for violations.</p><p>This piece maps the gap: who is in scope, what the regulation requires, where the OWASP vulnerabilities become regulatory exposure, and what you must build before August 2026.Prohibited practices under Article 5 have applied since February 2025. General-purpose AI model obligations since August 2025. The full weight of high-risk obligations for Annex III systems applies in August 2026, with Annex I systems following in August 2027.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>Who This Applies To</h2><p>The EU AI Act does not require you to be in the EU. It requires your AI system&#8217;s output to be used there.</p><p>Article 2 defines the scope: the regulation applies to providers who place AI systems on the EU market or put them into service in the EU &#8212; and to providers and deployers established in a third country, where the output produced by the AI system is used in the Union.</p><p>That second clause is the one most organizations miss. </p><p><strong>Examples:</strong> You built an AI agent in Austin, TX. A recruiter in Berlin, DE uses it to screen candidates. That puts you in the regulation's reach. You launched an AI finance tool from Singapore. EU customers use it to assess creditworthiness. The same logic applies. Your agent is hosted on US infrastructure and never touches an EU server &#8212; but its recommendation is used by an EU natural person and influences a decision that affects them. The regulation follows the output, not the headquarters.</p><blockquote><p>Geography is not a shield. The trigger is whether the output produced by the AI system is used in the Union.</p></blockquote><p>For providers of high-risk AI systems established outside the EU, Article 22 requires the appointment of an authorized representative established in the EU before the system is placed on the market or put into service. That is not a filing requirement you handle after the fact. It is a precondition for lawful operation.</p><p>The extraterritorial architecture mirrors GDPR &#8212; but with a critical distinction. GDPR follows personal data. <strong>The EU AI Act follows system output</strong>. Every agent that produces a recommendation, a classification, a decision, or a risk assessment that is used by an EU natural person is potentially in scope &#8212; <strong>whether the deploying organization intended that reach or not</strong>.</p><p>If your agents touch the EU market &#8212; directly or through downstream users you may not have mapped &#8212; the obligations in this article apply to you. The penalties for non-compliance with high-risk obligations reach &#8364;15 million or 3% of global annual turnover. Transparency obligations under Article 50 apply to all AI systems regardless of classification, with violations carrying fines of &#8364;7.5 million or 1% of global annual turnover.</p><p>For a deeper analysis of the EU AI Act&#8217;s extraterritorial reach, see <a href="https://www.zerodaydawn.com/p/the-long-arm-of-the-eu-ai-act">The Long Arm of the EU AI Act</a>.</p><div><hr></div><h2>The Data</h2><p>The governance gap is quantified. Three of the most authoritative bodies in AI security have measured it &#8212; and the numbers are worse than most organizations expect.</p><p><strong>The Cloud Security Alliance</strong> published <em>Securing Autonomous AI Agents</em> in January 2026. The findings describe an industry that has <strong>deployed agentic AI faster than it can govern it</strong>. Only 28% of organizations can reliably trace an agent&#8217;s actions across all environments &#8212; meaning 72% lack full visibility into what their agents are doing. Only 16% of respondents expressed confidence they could pass a compliance audit on AI agent activity. Just 21% maintain a real-time registry of their AI agents. And only 23% have a formal, organization-wide agent governance strategy &#8212; the rest rely on informal practices or have no strategy at all.</p><p>Ownership is fragmented. 39% of organizations assign agent governance to Security. 32% to IT. 13% to a dedicated AI Security function. The rest scatter it across compliance, engineering, and executive teams with no clear accountability.</p><p>These are not immature organizations experimenting with AI. These are enterprises that have deployed agents into production &#8212; and cannot tell you <strong>what</strong> those agents are doing, <strong>where </strong>they are operating, or <strong>whether they comply</strong> with anything.</p><p><strong>OWASP</strong> published the Top 10 for Agentic Applications in December 2025 &#8212; the product of over 100 security researchers working across more than a year. Three of the ten critical vulnerabilities involve agentic tool use directly: Tool Misuse and Exploitation (ASI02), Identity and Privilege Abuse (ASI03), and Insecure Inter-Agent Communication (ASI07). A tenth entry &#8212; Rogue Agents (ASI10) &#8212; addresses misalignment, concealment, and self-directed action.</p><p>These are not theoretical attack surfaces. In early February 2026, a prompt injection attack against the Cline coding assistant &#8212; exploiting a vulnerability in its Claude-powered issue triage workflow &#8212; led to a compromised npm token that was used to push a modified package silently installing OpenClaw on developer machines. The attack was live for eight hours before detection. The entry point was natural language, not code. An agent&#8217;s tool access was weaponized through its own context window.</p><p><strong>NIST</strong> launched the AI Agent Standards Initiative on February 17, 2026. Three pillars: facilitating industry-led standards development, fostering open-source protocol development, and advancing research on AI agent security and identity. The initiative&#8217;s first deliverables are an RFI on agent security (due March 9), a concept paper on AI agent identity and authorization (due April 2), and sector-specific listening sessions starting in April.</p><p>The signal is clear. NIST is at the RFI stage. OWASP has mapped the vulnerabilities. CSA has quantified the gap. The governance infrastructure is forming &#8212; but it is not operational. And the EU AI Act obligations do not wait for frameworks to be ready.</p><div><hr></div><p><em>What the EU AI Act actually requires of deployers operating agentic systems &#8212; the specific obligation mapping against CSA data, the OWASP-to-EU-AI-Act vulnerability crosswalk, why your agent's runtime behavior may already constitute a substantial modification under Article 3(23), and the operational methodology for building compliance before August 2026 &#8212; continues below for paid subscribers.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>
      <p>
          <a href="https://www.zerodaydawn.com/p/when-the-eu-comes-for-your-agents">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Shadow Side of Agentic AI]]></title><description><![CDATA[What happens when the agents are already running, but the governance infrastructure is not]]></description><link>https://www.zerodaydawn.com/p/the-shadow-side-of-agentic-ai</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/the-shadow-side-of-agentic-ai</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 16 Feb 2026 06:01:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2wRq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2wRq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2wRq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2wRq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2wRq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2wRq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2wRq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3306434,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/188026694?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2wRq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!2wRq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!2wRq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!2wRq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F308c1760-0a5e-4adf-88c9-4ea7fcb95de1_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2><strong>Executive Summary</strong></h2><p>A decade ago, the security problem was shadow IT &#8212; employees installing Dropbox, spinning up Trello boards, running SaaS tools their IT departments never authorized. It was a containment problem. Unauthorized applications creating data silos and compliance blind spots.</p><p>Shadow AI is not the same problem at scale. It is a different problem entirely.</p><p>Shadow IT stored data. Shadow AI makes decisions. An unsanctioned Dropbox folder does not autonomously access your HR database, generate a recommendation about an employee, and act on it before anyone reviews the output. An unsanctioned AI agent can.</p><p>And they already are. Employees and teams are deploying AI agents &#8212; autonomous systems that select their own tools, sequence their own actions, and make decisions that affect people &#8212; into enterprise workflows that touch employment, finance, personal data, and critical infrastructure. These agents are not being inventoried. They are not being assessed. They are not being governed. In a growing number of cases, the organizations running them do not know they exist.</p><p>The EU AI Act &#8212; enforceable from August 2026 &#8212; requires a documented risk determination before any AI system is put into service. That obligation does not wait for a standard to be published, a vendor to provide a template, or an agent to cause harm. It applies at deployment. For agents that were never inventoried, the liability exposure is not theoretical. It is already accruing &#8212; and the penalties for non-compliance with high-risk obligations reach &#8364;15 million or 3% of global annual turnover &#8212; and that is before GDPR, sector regulation, and cybersecurity liability compound on top.</p><p>But the regulatory gap is only the first layer. The deeper problem is structural. The EU AI Act&#8217;s entire compliance architecture &#8212; risk classification, documentation, conformity assessment, post-market monitoring &#8212; assumes the system&#8217;s behavior can be described before it runs. Agentic AI breaks that assumption. An agent classified at deployment begins diverging from its documented purpose the moment it starts operating. The tools it selects, the data it accesses, the decisions it chains &#8212; all emerge at runtime, not at design time. The risk determination that was supposed to govern the system expires before the first audit cycle.</p><p>The cybersecurity exposure runs parallel. Agentic tool use is so vulnerable that it occupies three separate slots on the OWASP Top 10 for Agentic Applications. The critical vulnerability is not broken authorization &#8212; it is what happens when legitimate access goes wrong. Data exfiltration, privilege escalation, workflow hijacking &#8212; all within the agent&#8217;s authorized scope. The agent does not need to break the rules to create liability. It creates liability by operating within them.</p><p>The governance infrastructure to address this is forming &#8212; but it is not ready. ForHumanity has published a dedicated multi-agent certification scheme. The OECD released its first formal analysis of the agentic AI landscape in February 2026. The International AI Safety Report 2026 identifies multi-agent liability attribution as a core policymaker challenge. The CIGI/Privy Council Office of Canada&#8217;s national security scenarios workshop identified autonomous agent collusion as an emerging attack vector. The European Commission has introduced a technology code for agentic AI in the Digital Omnibus &#8212; while deferring actual governance solutions to a future strategy with no timeline.</p><p>The organizations that move now will build governance capability while the frameworks are still forming. The organizations that wait will discover &#8212; when a regulator, an auditor, or a breach forces the question &#8212; that the agents were already running. The governance was not.</p><p>This article maps the gap: what agents are doing, what the regulation requires, what the audit infrastructure can verify, and what needs to be built before August 2026.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.zerodaydawn.com/subscribe?"><span>Subscribe now</span></a></p><div><hr></div><h2><strong>The Agents You Don&#8217;t Know About</strong></h2><p>Microsoft&#8217;s 2026 Cyber Pulse report found that nearly a third of employees have already turned to unsanctioned AI agents for work tasks &#8212; tools operating with embedded credentials, API integrations, and elevated system access outside standard provisioning workflows. These are not browser-based chatbots. They are autonomous systems plugged into enterprise infrastructure, acting on data they were never explicitly authorized to touch.</p><p>The deployment velocity behind this is staggering. The OECD&#8217;s February 2026 analysis of the agentic AI landscape documents a 920% increase in GitHub repositories using agentic frameworks &#8212; AutoGPT, BabyAGI, OpenDevin, CrewAI &#8212; between early 2023 and mid-2025. The Stack Overflow Developer Survey, covering more than 49,000 respondents across 177 countries, found that roughly half of developers are already using or planning to use AI agents in their work. The vast majority of those developers flagged security and privacy as unresolved concerns.</p><p><strong>This is not a forecast. This is the current installed base.</strong></p><p>The OECD&#8217;s companion paper on AI trajectories through 2030 quantifies the acceleration: the length of software engineering tasks that AI systems can complete autonomously is doubling approximately every seven months. The CIGI/Privy Council Office of Canada&#8217;s 2026 national security scenarios workshop &#8212; convened with security and intelligence officials, AI researchers, and industry representatives &#8212; identified &#8220;autonomous agent collusion&#8221; as an emerging attack vector and flagged systemic vulnerabilities from ecosystem-wide dependencies on AI systems as a national security concern.</p><p>The International AI Safety Report 2026 confirms that attributing liability when agents cause harm &#8212; particularly in multi-agent settings where identifying when and how failures occurred is structurally difficult &#8212; is now recognized as a core policymaker challenge.</p><p>These agents are not experimental. They are in production. They are accessing systems that touch employment decisions, financial assessments, personal data, and critical infrastructure. And in the overwhelming majority of cases, nobody has performed the risk determination that the EU AI Act requires before any AI system is put into service.</p><p>The regulation does not wait for harm. The obligation applies at deployment. For agents that were never inventoried, never assessed, and never governed, the exposure is already accruing &#8212; and the penalties for non-compliance with high-risk obligations reach &#8364;15 million or 3% of global annual turnover &#8212; and that is before GDPR, sector regulation, and cybersecurity liability compound on top.</p><p><strong>That is the visible cost. The structural cost is worse.</strong></p><div><hr></div><h2><strong>Why Your Governance Model Doesn&#8217;t Work for Agents</strong></h2><p><strong>Traditional AI governance assumes three things</strong>: the system does what it was designed to do, the risks it poses can be assessed before deployment, and the documentation describing its behavior stays accurate over time.</p><p>For a credit scoring model, a fraud detection engine, or an automated document classifier, those assumptions hold. The system receives defined inputs, applies defined logic, and produces defined outputs. It can drift &#8212; through data degradation or model decay &#8212; but the operational boundaries remain recognizable. You can describe what the system does because what it does stays within the design envelope.</p><p><strong>Agentic AI does not work this way.</strong></p><p>An agent receives a goal and determines its own path to achieving it. It selects which tools to use. It decides what data to access. It sequences its own actions based on intermediate results. The execution path is not specified at design time &#8212; it emerges at runtime. And it changes with every interaction.</p><p><strong>This is not a theoretical distinction. It is an operational one with direct financial and legal consequence.</strong></p><p>Consider a concrete scenario. An organization deploys an AI agent to automate internal research &#8212; summarizing documents, pulling data from approved sources, drafting reports. At deployment, the system&#8217;s purpose is clearly defined and its risk profile is minimal. Nobody would classify a research assistant as high-risk under the EU AI Act.</p><p>Then the agent does what agents do. A user asks it to compile information on a job candidate. The agent accesses the HR database &#8212; because it has the permissions to do so. It pulls performance reviews, compensation history, and disciplinary records. It generates a summary with an implicit recommendation. The output reaches a hiring manager who uses it to make a decision.</p><p>The agent just crossed into employment territory &#8212; one of the EU AI Act&#8217;s explicitly designated high-risk domains. Nobody changed the system&#8217;s code. Nobody updated its permissions. Nobody reclassified it. T<strong>he agent&#8217;s functional purpose shifted through its own operational choices, and the risk determination made at deployment no longer describes the system in production</strong>.</p><p>Under the EU AI Act, this is not a gray area. When a system&#8217;s behavior changes its effective purpose beyond what was assessed at deployment, it triggers what the regulation calls a <strong>substantial modification</strong> &#8212; a change that was not foreseen in the initial assessment and that affects the system&#8217;s compliance with its obligations or modifies its <strong>intended purpose</strong>. A substantial modification requires a new conformity assessment. Not a review. Not an update to the documentation. <strong>A full reassessment</strong> &#8212; with the time, cost, and documentation burden that entails.</p><p>For a traditional system, substantial modifications are rare events &#8212; a major update, a new deployment context, a retraining cycle. Identifiable, manageable, budgetable.</p><p>For an agent, substantial modifications are the normal operating condition. Every interaction where the agent exercises autonomous judgment about tool selection, data access, or execution strategy is an interaction where the system&#8217;s functional behavior may diverge from its documented purpose. An agent running thousands of interactions per day generates thousands of potential triggers for reassessment.</p><p><strong>The regulatory mechanism exists. The operational capacity to execute it does not.</strong></p><p>And this is where the security exposure and the regulatory exposure converge &#8212; a convergence that most organizations have not yet recognized, because their security teams and their compliance teams are not looking at the same system through the same lens.</p><p><em>The full analysis of that convergence &#8212; including what OWASP's Agentic Top 10 reveals about the attack surface, how privilege escalation in agentic systems maps to regulatory liability, what ForHumanity's multi-agent certification scheme addresses and where the enforcement integration remains untested, and the four capabilities your organization must have operational before August 2026 &#8212; continues below for paid subscribers.</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>
      <p>
          <a href="https://www.zerodaydawn.com/p/the-shadow-side-of-agentic-ai">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[When Your Agents Go Rogue]]></title><description><![CDATA[The EU AI Act wasn't built for systems that rewrite their own intended purpose]]></description><link>https://www.zerodaydawn.com/p/when-your-agents-go-rogue</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/when-your-agents-go-rogue</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 09 Feb 2026 06:00:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!SCJL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SCJL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SCJL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!SCJL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!SCJL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!SCJL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SCJL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3295383,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/187276922?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SCJL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!SCJL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!SCJL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!SCJL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9ae72b7b-5ce1-499f-a2e7-a217d6a3ceb1_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Your AI system follows instructions. Your AI agent makes its own.</p><p>That distinction is about to become the most expensive compliance gap in the EU AI Act.</p><p>The regulation requires a risk determination before any AI system goes to market. Is it high-risk? Low-risk? Banned? That answer decides everything &#8212; what documentation you need, what standards apply, what penalties you face if you get it wrong. And the entire framework assumes two things: someone in your organization made that determination before deployment, and the answer stays stable.</p><p>Agentic AI breaks both assumptions. An agent picks its own tools, chooses what data to pull, decides what steps to take &#8212; and those choices change every time it runs. The system you deployed Monday is not the system running Friday.</p><p>This piece explains why the EU AI Act&#8217;s classification architecture cannot handle systems that determine their own behavior at runtime, what that means for organizations deploying agents before August 2026, and what you need to build now &#8212; before a regulator asks a question you cannot answer.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>1.4+ Million Agents. Zero Classification Decisions</h2><p>Moltbook became a case study in what happens when deployment outpaces governance. The platform claimed 1.4+ million agent users &#8212; a figure contested by security researchers who demonstrated that a single script could generate hundreds of thousands of accounts. But even if the real number is a fraction, nobody made a risk determination for any of them. The agents inherited permissions from their owners, accessed tools at runtime, and changed behavior based on interactions with other agents.</p><p>Under the EU AI Act, every AI system needs a risk determination <strong>before deployment</strong>. Does it fall within the high-risk categories &#8212; employment, creditworthiness, law enforcement, critical infrastructure, education, access to essential services? Does its output <strong>materially influence</strong> decisions affecting people?</p><p>Nobody made that determination for Moltbook&#8217;s agents. Nobody could have. The agents&#8217; purposes were not fixed at deployment. What they did depended on what tools they accessed, what data they encountered, and what other agents they interacted with. <strong>The intended purpose changed with every execution cycle</strong>.</p><p>This is not a Moltbook problem. This is an architectural problem.</p><p>McKinsey's CEO disclosed in January 2026 that 25,000 AI agents now sit alongside 40,000 human employees &#8212; and that AI initiatives account for 40% of the firm's total work. Not people using agents. Agents counted as staff. If those agents screen candidates, score performance, or influence staffing decisions &#8212; each one requires a risk determination under the EU AI Act <strong>before deployment</strong>. Multiply that across every company racing to deploy agentic AI at scale, and the classification gap is not theoretical. It is industrial.</p><p>The regulatory framework was not designed to handle it.</p><div><hr></div><h2>What an Agent Actually Does</h2><p>The gap between an AI system and an AI agent is not branding. It is deeply structural.</p><p>A traditional AI system is a function. A credit scoring model receives an application, processes it, and produces a score. The behavior is bounded. The output is traceable. Documentation can describe what the system does &#8212; because what it does stays within the boundaries drawn at deployment.</p><p>An agent is different. It receives a goal and determines its own path to achieving it. It selects which tools to use. It sequences its own actions. It adapts its approach based on intermediate results. The execution path is not specified at design time. It emerges at runtime.</p><p>Palantir published the most detailed public architecture for production-grade agentic AI to date in January 2026. What their documentation reveals is that even the vendor building the governance tooling describes the problem in stark terms: the possible paths an agent can take through its decision space are &#8220;innumerable&#8221; and &#8220;vary dramatically in functional depth.&#8221; The agent operates with permissions inherited from whoever configured it, whatever service scope it was given, and whichever user it is acting on behalf of at any given moment &#8212; all layered, all dynamic, all context-dependent.</p><p>This is not a chatbot with extra steps. It is a system actor that determines its own behavior every time it runs. Your documentation describes the system as designed. The agent operates as it decides.</p><div><hr></div><h2>The Classification Assumption That Breaks</h2><p>Every obligation in the EU AI Act traces back to a single upstream decision: <strong>is this system high-risk</strong>?</p><p>That decision depends on <strong>intended purpose</strong> &#8212; what the system is designed to do. The provider declares a purpose. The declaration drives the risk classification. The classification determines everything downstream: risk management, data governance, documentation, logging, transparency, human oversight, accuracy requirements, quality management, post-market monitoring.</p><p><strong>Change the purpose, and every one of those obligations needs reassessment.</strong></p><p>Traditional AI systems have relatively stable purposes. They drift through data shifts or model degradation, but their operational boundaries remain recognizable. You can document what they do because what they do stays within the design envelope.</p><p><strong>Agents do not work this way. Three things break at once.</strong></p><p><strong>The purpose is not fixed</strong>. When an agent autonomously accesses a credit database and generates a recommendation, it has functionally entered the creditworthiness domain &#8212; regardless of what the provider declared at classification time. A customer service agent that pulls HR records and suggests a personnel action has crossed into employment territory. The classification filed at deployment no longer describes the system in production.</p><p><strong>The risk profile is not stable</strong>. An agent classified as minimal risk at deployment can escalate into high-risk territory through its own operational choices &#8212; choices nobody anticipated and nobody approved.</p><p><strong>The documentation is instantly obsolete</strong>. The EU AI Act requires a description of the system&#8217;s intended purpose, its capabilities, its limitations, and its expected performance. For an agent, this documentation describes the system <em>as designed</em>. Not the system <em>as it operates</em>. The gap widens with every interaction.</p><div><hr></div><h2>The Regulation Already Recognizes the Problem. The Framework Cannot Detect It.</h2><p>Here is where this gets structurally uncomfortable.</p><p>The EU AI Act&#8217;s own Code of Practice already identifies the capabilities that define agentic behavior as sources of systemic risk. The list reads like a technical specification for an autonomous agent: the capability to operate autonomously, to adaptively learn new tasks, to reason about itself and its environment, to evade human oversight, to self-replicate or modify its own implementation, to interact with other AI systems, and to use tools including hardware and software external to the model.</p><p>The regulation recognizes these capabilities. It flags them as risk-relevant.</p><p>These model-level capabilities become system-level risks at deployment. When a system built on a model with these propensities operates autonomously in production, the behavioral drift they enable triggers the substantial modification mechanism under Article 25.</p><p>But the classification architecture was designed to detect them <em>at deployment</em> &#8212; not when they emerge at runtime. An agent classified as minimal risk because its declared purpose was customer support does not get automatically reclassified when it accesses an HR database and generates a recommendation about an employee. The classification happened upstream. The behavior changed downstream. Nobody updated the assessment.</p><p>The Code of Practice goes further, flagging behavioral tendencies including what it calls &#8220;lawlessness&#8221; &#8212; acting without reasonable regard to legal duties &#8212; and &#8220;goal-pursuing&#8221; behavior that resists modification. These are not theoretical risks. They describe what agentic architectures produce in production when agents optimize for task completion without regard for the regulatory boundaries their providers assumed would hold.</p><p>The framework identifies the risk factors. The classification mechanism cannot detect when those factors activate outside the documented operational envelope.</p><div><hr></div><h2>The Audit That Cannot Keep Up</h2><p></p>
      <p>
          <a href="https://www.zerodaydawn.com/p/when-your-agents-go-rogue">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Raising the Standard on AI Governance ]]></title><description><![CDATA[Which one is paving the road to EU AI Act conformity &#8212; and why ISO 42001 wasn't built for that]]></description><link>https://www.zerodaydawn.com/p/raising-the-standard-on-ai-governance</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/raising-the-standard-on-ai-governance</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 02 Feb 2026 06:01:33 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QBKx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QBKx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QBKx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!QBKx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!QBKx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!QBKx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QBKx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3300440,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/186400363?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QBKx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!QBKx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!QBKx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!QBKx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf134b01-4c4c-493d-98b7-8acac7423629_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>There are two QMS standards for AI governance. One is designed specifically for EU AI Act conformity. One is not.</p><p>The one designed for conformity is still in draft. prEN 18286 completed its public enquiry period on January 22, 2026 and is working through the CEN-CENELEC process toward harmonization. Unless you purchased access through a national standards body, you have not seen what it contains.</p><p>The one not designed for conformity is everywhere. ISO 42001 certification programs proliferate. Consultants sell readiness packages. Organizations pursue badges. The market has invested heavily in this standard.</p><p>The investment is misplaced. Here&#8217;s why.</p><p>prEN 18286 contains Annex ZA &#8212; a clause-by-clause mapping to Article 17 that will carry presumption of conformity when harmonized. ISO 42001 has no such mapping. It was never designed to. The JRC already found it structurally incompatible with high-risk AI requirements.</p><p>But here is what neither standard addresses: the upstream risk classification decision that determines whether Article 17 applies to your systems at all.</p><p>This piece shows what prEN 18286 contains, why ISO 42001 falls short, and why the choice between them is premature if you haven&#8217;t classified your AI systems first. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div><hr></div><h2>The Access Asymmetry</h2><p>The EU AI Act requires high-risk AI providers to implement a quality management system under Article 17. This QMS must cover risk management, data governance, technical documentation, record-keeping, and post-market monitoring <strong>across the entire AI lifecycle</strong>.</p><p>Two standards claim to address this requirement.</p><p><strong>ISO/IEC 42001:2023</strong> is available globally. You can purchase it from any national standards body. Certification programs exist. Training courses exist. A cottage industry of consultants will help you implement it. The market has invested heavily in this standard.</p><p><strong>prEN 18286:2025</strong> is a European draft standard titled &#8220;Artificial intelligence &#8212; Quality management system for EU AI Act regulatory purposes.&#8221; It was released for CEN Enquiry in October 2025. The public comment period closed January 22, 2026. Unless you purchased access through a national standards body, you have never seen it.</p><p>Here is the asymmetry that will cost organizations money: <strong>the visible standard lacks what the invisible standard contains</strong>.</p><p>ISO 42001 provides a management system framework. It certifies that governance processes exist. It does not map to Article 17 requirements. It does not address EU-specific obligations. It provides no presumption of conformity.</p><p><strong>prEN 18286</strong> was commissioned by the European Commission under standardization request M/613 C(2023) 3215 specifically to provide a voluntary means of conforming to Regulation (EU) 2024/1689. When finalized and cited in the Official Journal, compliance with its normative clauses will confer <strong>presumption of conformity</strong> with the corresponding essential requirements.</p><p>One standard was built for the regulation. One was built for the global market. The market seeking EU AI Act compliance is buying the wrong one.</p><div><hr></div><h2>What the JRC Already Found</h2><p>The Joint Research Centre &#8212; the Commission&#8217;s science and knowledge service &#8212; published <a href="https://publications.jrc.ec.europa.eu/repository/handle/JRC139430">gap analysis JRC 139430</a> examining ISO 42001 against EU AI Act requirements.</p><p>The finding was unambiguous: ISO 42001 lacks the specific safety-by-design mandates required for high-risk AI systems under Annex III.</p><p>This is not a minor gap. It is structural incompatibility. ISO 42001 was designed for organizational governance across jurisdictions. It addresses management system requirements. It does not address the product safety requirements embedded in the EU AI Act.</p><p><strong>The AI Act is product safety law.</strong> It treats AI systems as products subject to conformity assessment. The QMS requirements under Article 17 are not generic governance requirements &#8212; they are specific obligations tied to the essential requirements in Chapter III, Section 2.</p><p>ISO 42001 does not address these obligations because it was not designed to. It predates the final AI Act text. It serves a different purpose. Certification bodies audit it as a management system standard because that is what it is.</p><p>prEN 18286 exists because the Commission recognized this gap and requested a European standard that would actually address Article 17. The standard is being developed by <a href="https://jtc21.eu/">CEN-CENELEC JTC 21</a> &#8212; the Technical Committee on Artificial Intelligence &#8212; under explicit mandate to provide presumption of conformity.</p><p>The JRC finding is not a criticism of ISO 42001. The standard does what it was designed to do. The problem is that what it was designed to do is not what Article 17 requires.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.zerodaydawn.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Zero-Day Dawn is a reader-supported publication. To receive new posts and support my work, consider becoming a free or paid subscriber.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The Annex ZA Mapping</h2>
      <p>
          <a href="https://www.zerodaydawn.com/p/raising-the-standard-on-ai-governance">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[Your Guidance Isn't Coming]]></title><description><![CDATA[Flying blind into August 2026]]></description><link>https://www.zerodaydawn.com/p/your-guidance-isnt-coming</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/your-guidance-isnt-coming</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 26 Jan 2026 06:02:14 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!36Ka!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!36Ka!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!36Ka!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!36Ka!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!36Ka!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!36Ka!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!36Ka!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3294457,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/185711782?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!36Ka!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!36Ka!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!36Ka!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!36Ka!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb61ca5a9-23bb-483d-9bb4-d36df7fb03e7_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>The European Commission is about to miss its own deadline.</p><p>Article 6 classification guidelines &#8212; the document organizations have been waiting for to understand which AI systems are hi&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/your-guidance-isnt-coming">
              Read more
          </a>
      </p>
   ]]></content:encoded></item><item><title><![CDATA[The Long Arm of the EU AI Act]]></title><description><![CDATA[Why jurisdiction won't shield non-EU providers from enforcement]]></description><link>https://www.zerodaydawn.com/p/the-long-arm-of-the-eu-ai-act</link><guid isPermaLink="false">https://www.zerodaydawn.com/p/the-long-arm-of-the-eu-ai-act</guid><dc:creator><![CDATA[Violeta Klein, CISSP, AIGP]]></dc:creator><pubDate>Mon, 19 Jan 2026 06:00:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!HGpp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HGpp!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HGpp!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HGpp!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HGpp!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HGpp!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HGpp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3299746,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.zerodaydawn.com/i/184765549?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HGpp!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 424w, https://substackcdn.com/image/fetch/$s_!HGpp!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 848w, https://substackcdn.com/image/fetch/$s_!HGpp!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!HGpp!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F32b25d1c-bea9-4635-b1a7-c75f35c64190_1920x1080.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>Executive Summary</h2><p>Your headquarters location is not a compliance strategy. It is a comfortable assumption about to collide with regulatory reality.</p><p>Organizations outside the EU believe they are watchin&#8230;</p>
      <p>
          <a href="https://www.zerodaydawn.com/p/the-long-arm-of-the-eu-ai-act">
              Read more
          </a>
      </p>
   ]]></content:encoded></item></channel></rss>