AI is reshaping both sides of the security equation, attack capability and defence capability scale in parallel. The CISO's mandate now includes governing AI systems they don't own.
For: Chief Information Security Officers, security architects, security operations
For CISOs, AI presents three converging challenges. First, AI capabilities are reshaping the threat landscape, phishing, social engineering, and vulnerability discovery are all being augmented by AI. Second, frontier AI systems are dual-use: the same capability that enables defence enables attack (Anthropic's Project Glasswing exists precisely because of this). Third, the security implications of AI adoption inside the enterprise, Microsoft Agent 365, ChatGPT Enterprise, Claude, custom agents, create attack surfaces that traditional controls don't cover. The Five Eyes agentic AI guidance (1 May 2026) and ASIC's 8 May 2026 cyber resilience letter are the most directly applicable references for this work.
The substantive AI governance responsibilities that fall to this role under current Australian and global expectations.
Curated coverage selected for this role, frameworks, regulatory developments, and operational guidance you can act on.
EchoLeak, EDP, Purview controls, and the AI attack surface of Copilot.
Security controls for autonomous AI operating across enterprise systems.
Detection, prevention, and policy for unauthorised AI use.
Security architecture of the major enterprise AI platforms.
Comparative security analysis of the four major enterprise AI platforms.
CAISI pre-deployment evaluation, Project Glasswing, and the dual-use frontier AI landscape.
The regulatory frameworks, standards, and guidance documents most relevant to this role.
Joint guidance from ASD ACSC, CISA, NSA, CCCS, NZ NCSC, UK NCSC.
Security and incident management for AI systems.
Frontier AI changing the cyber risk landscape, board implications.
Application security framework for LLM-integrated systems.
Threat modelling templates, AI security policies, incident response procedures.
ContinueSecurity-specific guidance for financial services, healthcare, public sector, and 13 other sectors.
ContinueOngoing coverage of Five Eyes guidance, ASIC cyber expectations, and global AI security policy.
Continue