<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>GRCIDE — Insights</title>
    <link>https://grcide.com/insights</link>
    <description>Reading notes, commentary and practice notes from the editors on AI, security practice, regulation and audit, and the craft of the work.</description>
    <language>en</language>
    <atom:link href="https://grcide.com/insights.xml" rel="self" type="application/rss+xml" />
    <lastBuildDate>Sat, 05 Sep 2026 00:00:00 +0000</lastBuildDate>
    <item>
      <title>Agent governance is a permissions problem before it is a model problem</title>
      <link>https://grcide.com/insights/agent-governance-is-a-permissions-problem</link>
      <guid isPermaLink="false">https://grcide.com/insights/agent-governance-is-a-permissions-problem</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>Singapore's advisory on the OpenClaw agent platform moves AI risk from what a model says to what an agent can do. The controls it lists are identity controls.</description>
    </item>
    <item>
      <title>Open-source risk is a maintainer problem, not a CVE count</title>
      <link>https://grcide.com/insights/open-source-risk-is-a-maintainer-problem</link>
      <guid isPermaLink="false">https://grcide.com/insights/open-source-risk-is-a-maintainer-problem</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A Chinese-language piece argues that open-source risk lives in maintainers and funding, not in CVE queues. We agree, and add the control it implies.</description>
    </item>
    <item>
      <title>The board question is not the CVE count</title>
      <link>https://grcide.com/insights/the-board-question-is-not-the-cve-count</link>
      <guid isPermaLink="false">https://grcide.com/insights/the-board-question-is-not-the-cve-count</guid>
      <pubDate>Sat, 05 Sep 2026 00:00:00 +0000</pubDate>
      <description>A vendor piece uses Anthropic's Mythos findings to argue that boards should hear attack paths and expected loss, not patch rates. Half of it holds.</description>
    </item>
  </channel>
</rss>
