AI has changed how ISO management systems get built. A capable person with the right prompts can now draft a quality manual, a risk assessment or a set of procedures in an afternoon. That is a real shift, and for a lot of the documentation work it is a good one. But it leaves a […]
Tag: #iso42001
The First AI-Run Cyberattack Hit Hugging Face. The Real Lesson Is Older Than AI.
Update, 22 July 2026: OpenAI has now confirmed that this incident was caused by its own models, not an outside attacker. In a joint statement with Hugging Face, OpenAI said two of its models, the publicly available GPT-5.6 Sol and a more capable unreleased model, were running an internal cyber-capability benchmark called ExploitGym with their […]
Building Your ISO System with AI? Here’s Where It Goes Wrong
AI tools can draft ISO documentation in minutes, but they routinely miss the mark on context, risk and implementation. Here’s where AI-built ISO systems fail, and how to make yours actually pass certification.
What Happens When All Your AI Agents Call in Sick?
Claude reliability incidents highlight a new continuity risk: what happens when business-critical AI agents and their underlying providers become unavailable?
From 10 December, Your Privacy Policy Has to Name the Decisions Your Software Makes
From 10 December 2026, new APP 1.7 to 1.9 require your privacy policy to disclose automated decisions about people. The OAIC is reading “computer program” broadly enough to catch spreadsheets, and a human in the loop does not get you out of it.
Four questions to ask before you let an AI agent loose
Anthropic’s Deputy CISO uses four questions to decide whether an AI agent is safe to deploy. Here they are, and how they map to the controls in ISO 27001 and ISO 42001.
ISO 42001 and ISO 27001: How They Fit Together
ISO 42001 (AI management) and ISO 27001 (information security) share the same structure and integrate cleanly. Here’s how they overlap and why a combined system is the smart move for AI-driven businesses.
The Cost of Poor Quality: What Incidents Really Cost Across Safety, Environment, Security and AI
Everyone asks what ISO certification costs. The better question is what poor quality and incidents cost: 10-30% of revenue in quality failures, $4.26M average data breaches, $10M environmental penalties and a $28.6B-a-year safety problem, paid in people, reputation and dollars.
Shadow AI in the Workplace: The Wild West of Ungoverned AI
Employees are using a patchwork of AI tools with no oversight. Here’s why ungoverned shadow AI is a serious data-loss risk, and how governance closes the gap.
Your AI Policy Shouldn’t Name a Vendor
The AI leaderboard flipped again in 2026. If your acceptable-use policy says “staff may use ChatGPT”, you are rewriting it every time the market moves, and your people are already outside it.












