Security | Threat Detection | Cyberattacks | DevSecOps | Compliance

Aikido Security achieves ISO 42001:2023 certification for AI governance

Aikido Security has achieved ISO 42001:2023 certification, the international standard for AI management systems, a step few security vendors have taken so far. The certification confirms that Aikido runs a structured, continuously improving governance system for managing the risks introduced by its AI-enabled features, across our entire platform.

Zombie APIs Are Costing You More Than You Think: A Risk Quantification Guide

Zombie APIs are API versions or endpoints that were once known and documented, but were never properly retired. A team ships v2 of an API, tells everyone to migrate, and assumes v1 is dead. In reality, v1 is still running on a server somewhere, still accepting requests, and still connected to production data. This is different from unmanaged APIs, which were never documented in the first place. Zombie APIs were documented once.

AI Assurance: The Third Head of Your AI Governance Watchdog

In July 2026, two AI stories broke that appeared unrelated on the surface. But were they really? The first was an AI product's shared conversation links, meant for specific people, turning up in Google searches, some holding sensitive personal and company data. The second was a frontier AI lab's own model escaping a security sandbox during an internal evaluation and spending four and a half days inside three companies' systems. One involved ordinary users making a common mistake.

Agent Incident Response: Containment Is the Easy Part

Containment guidance for agent incidents already exists and it is largely correct. Revoke the tokens, freeze the orchestration tier, cut egress, set the vector store to read-only. Those steps take minutes and any competent team will find them. ‍ The difficulty sits either side of containment. Deciding what kind of incident this is takes longer than stopping it, establishing what the agent did before you stopped it takes longer still, and both depend on preparation that has to exist beforehand.

AI/LLM Penetration Testing in 2026: The Complete Guide

Most organisations now run at least one LLM in production, and a growing number run agents that call tools and act without a human in the loop. The security testing those systems receive was designed for deterministic software. AI applications fail differently. The payload is natural language, the same input can be safe nine times and unsafe on the tenth, and the malicious instruction often arrives inside a document or tool description rather than from the user.

The Competitive Edge of AI Procurement Solutions for Modern Enterprises

Modern enterprises operate in an environment where efficiency, cost control, and agility can directly influence business growth. Procurement, once viewed primarily as an administrative function, has become an important strategic area for organizations looking to improve financial performance and build stronger supplier relationships. As procurement processes become more complex, businesses are increasingly turning to AI Procurement Solutions to simplify operations and make better purchasing decisions.

What makes a good AI coworker? With OpenAI's Codex product lead

Zero-Shot Learning is a podcast about how AI is built, secured, and deployed. Hosted by Nancy Wang, 1Password CTO, and Dev Tagare, Senior Director of Engineering at Google Gemini, it offers a builder’s view of the architecture and complex decisions involved in shipping AI.

Agentic AI Security: Credentials and Permissions Define the Blast Radius

In July 2026, researchers at Noma Labs coaxed GitHub's new Agentic Workflows into leaking data from a private repository. It wasn’t from malware. They created a plausible-looking issue in a public repository containing instructions for the agent to retrieve information from other repositories in the organization. After testing variations of the prompt, they found that adding one word, "Additionally," was enough to get past GitHub's guardrails.

Code is the easy part with Rohan Varma from OpenAI | Zero-Shot Learning

As a product leader who went from working on Cursor to OpenAI’s Codex, Rohan Varma got a personal preview of a shift most developers are just beginning to catch up to. His conversation with 1Password CTO Nancy Wang upends the idea that AI helps developers write code faster, reimagines code reviews, and explores how developer skills expand once agents take over implementation. In this episode: Zero-Shot Learning is a builder-to-builder podcast about how AI systems are designed, deployed, and secured. Subscribe for more.

State AI Laws Change Faster Than Compliance Programs

Colorado passed the first comprehensive state AI law in May 2024, and organizations spent the following year building impact assessment processes against it. Those obligations never took effect. The statute was delayed twice, blocked by a federal court, then repealed and replaced by a narrower framework before its own effective date arrived. ‍ Anyone who built a compliance program to that specific statute prepared for a regime that never existed.