This website uses cookies

Read our Privacy policy and Terms of use for more information.

ITRADE works with STEM organizations to close Technology, Talent, & Security gaps. See how →

The ITRADE Dispatch Issue #8 · August 25, 2026
ITRADE
The Dispatch · Intelligence for STEM Leaders
Security · Week 8
87% Have AI Governance. 22% Say It Works.
The American Arbitration Association surveyed 500 senior legal and executive leaders in May 2026. The gap they found is exactly what the NIST AI Risk Management Framework was built to close.
AI Governance Cybersecurity NIST RMF Compliance
The Lead

A director in operations wires a model into a workflow on a Thursday afternoon, because a vendor made it a checkbox. Legal doesn't hear about it. Security doesn't hear about it. The AI policy sits in a shared drive with a version number, untouched.

That gap has a number. The American Arbitration Association surveyed 500 senior legal and executive leaders at large U.S. and Canadian organizations: 87% say they have AI governance in place. 22% say it works (AAA, "From Principles to Practice," May 2026). The breaks cluster in escalation, audit readiness, and how late legal gets pulled in.

The clock already started. EU AI Act enforcement began 2 August 2026 - prohibited practices, Article 50 transparency, AI literacy, general-purpose AI models - with Annex III high-risk rules landing 2 December 2027 (European Commission, AI Act Service Desk). Vendor contracts signed last year mostly don't account for it.

And the systems moved faster than the oversight. IBM's Institute for Business Value, with Oxford Economics, surveyed 2,000 CIOs and CTOs across 33 geographies and 19 industries in Q1 2026: 77% say AI adoption is outpacing their governance, enterprises averaged 54 AI agent incidents in twelve months, 37% of those caused data exposure or a breach, and 11% consider themselves prepared for the agent scale coming this year (IBM IBV 2026 Tech Leader Study). Breach math followed - nearly $5M average, up 12%, with AI-driven attacks up 56% and adding about $1M each (IBM, Cost of a Data Breach Report 2026).

The layer nobody's securing

Almost every AI security control on the market - MITRE ATLAS, OWASP Top 10 for LLMs - guards the model after it ships. The decision that created the risk happened months earlier, when someone picked the data, the vendor, and the use case with no gate in front of them. That is the layer the NIST AI Risk Management Framework governs: four functions - Govern, Map, Measure, Manage - applied to design, development, use, and evaluation, released January 26, 2023, now in revision under the White House AI Action Plan, with a Critical Infrastructure Profile concept note out April 7, 2026 (NIST).

The gap is widest where nobody's looking

Read the coverage and the RMF looks industrial. In practice the exposure is worst where AI arrived through a SaaS renewal instead of a capital project. The same three questions apply everywhere it shows up: which decision does the model influence, who owns that decision today, and what happens when it's wrong.

In healthcare, ambient scribing, triage assist, and prior-auth automation arrived without a gate; the RMF forces you to name whose PHI trains it, who overrides it, and what gets logged.

In logistics, routing, forecasting, and exception handling raise a blunter question: what happens when the model is confidently wrong at scale.

In financial and back-office functions, underwriting, claims, collections, and service now need explainability a regulator will accept.

In public sector and education, eligibility screening, admissions, and casework triage need someone accountable when an individual is affected.

In energy and manufacturing, predictive maintenance, quality, and process control need a defined loop the model can touch, under whose authority.

Buyers are asking too

ISO/IEC 42001, the AI management system standard, had roughly 350 certified organizations worldwide by spring 2026 (assembled from certification-body and company announcements; no official global register exists) - small enough that it still wins deals, growing fast enough that it won't for long.

What to do Monday

Inventory before policy. Every AI system in production, including what shipped inside tools you already bought. If it takes more than a week to list, that's your finding.

One named owner per system. Escalation is where governance breaks, and escalation requires a person who answers the page.

Map each system to a decision - who makes it today, what the override path is.

Audit non-human identities. Agent credentials and service accounts with production access are the surface most programs leave outside identity governance. Fewer than half of organizations secure them (IBM, 2026).

Pick your pairing and set a date. RMF for structure, 42001 if procurement is asking, EU AI Act if you have European exposure.

The AI RMF, End to End event
Live This Week
The AI RMF, End to End
Wednesday, Aug 26 · 6:00-8:00 pm ET
Miami Dade College, Wolfson Campus · with Rod Soto & Bianca Diosdado
Register Now

The decision that created the risk happened months earlier, when someone picked the data, the vendor, and the use case with no gate in front of them.

Signals · This Week in STEM
Technology
EU AI Act enforcement started 2 August 2026 for prohibited practices, Article 50 transparency, AI literacy, and general-purpose AI models. Providers who placed GPAI systems generating synthetic content on the market before that date have until 2 December 2026 to meet marking and detection obligations (European Commission, AI Act Service Desk). Vendor contracts signed in 2025 mostly don't account for this.
Talent
Demand for AI governance skills rose 81% year over year across Fortune 500 hiring (Draup, via HR Dive, Feb 2026), and the broader supply picture stays tight - BLS projects STEM occupations to grow 8.1% from 2024 to 2034 versus 2.7% for non-STEM, at a median wage of $103,580 against $48,000 (U.S. Bureau of Labor Statistics). The role that clears an AI risk gate is part lawyer, part architect, part operator, and it's rarely one hire.
Security
Fewer than half of organizations secure the non-human identities their AI workflows depend on, even as 50% of breached organizations report deploying agents in threat hunting, response, and containment - and only 18% in vulnerability scanning and management, precisely where frontier models are already finding high-severity bugs (IBM, Cost of a Data Breach Report 2026).
Wellness
IBM found 17% of AI agent incidents were high-severity, each taking more than four hours to contain (IBM IBV, 2026). Four hours is a night, and the people absorbing those nights are the same small group named on every escalation path. Governance that distributes ownership is also the thing that keeps your incident responders employed next year.
ONE STAT THAT MATTERS
87% vs 22%
Organizations with AI governance in place, versus those saying it works in practice (American Arbitration Association, May 2026).
Policy on a shared drive isn't governance until someone can act on it under pressure.
The ITRADE Lens
Your 60-Minute AI Governance Triage
1 Build the inventory (Minutes 1-15) - Every AI system in production, including embedded vendor features. One row per system: system, owner, data it touches, decision it influences.
2 Find the ungoverned entry points (Minutes 15-25) - Which systems arrived through procurement rather than architecture. Those are your highest-risk rows.
3 Name an owner per system (Minutes 25-35) - Write the escalation path in one sentence, ending in a person.
4 Audit non-human identities (Minutes 35-50) - List agent credentials and service accounts with production access, and check which are in your IdP.
5 Pick the framework pairing and set a date (Minutes 50-60) - RMF for structure, ISO 42001 if buyers are asking, EU AI Act if you have European exposure.

Total investment: one hour with the right people in the room. Cost of skipping it: the audit you can't pass.

Bianca Diosdado
Founder & CEO, ITRADE Innovations · Education Programs Chair, SIM South Florida

Bianca architects the systems most leaders buy in pieces - talent, technology, and security, designed to work as one.

ITRADE
The Dispatch · Weekly Intelligence for STEM Leaders
Fort Lauderdale's founding STEM security circle.