<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[The Strategy Layer]]></title><description><![CDATA[The Strategy Layer cuts through operational noise to help CISOs and cybersecurity leaders drive business results. Articles, insights, and conversations focused on smarter strategy, sharper alignment, and leadership that endures.]]></description><link>https://www.strategylayer.com</link><image><url>https://substackcdn.com/image/fetch/$s_!QgOt!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8648a4bf-8dca-4279-a23a-100da89643b8_820x820.png</url><title>The Strategy Layer</title><link>https://www.strategylayer.com</link></image><generator>Substack</generator><lastBuildDate>Sat, 20 Jun 2026 18:51:53 GMT</lastBuildDate><atom:link href="https://www.strategylayer.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Steve Tout]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[thestrategylayer@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[thestrategylayer@substack.com]]></itunes:email><itunes:name><![CDATA[Steve Tout]]></itunes:name></itunes:owner><itunes:author><![CDATA[Steve Tout]]></itunes:author><googleplay:owner><![CDATA[thestrategylayer@substack.com]]></googleplay:owner><googleplay:email><![CDATA[thestrategylayer@substack.com]]></googleplay:email><googleplay:author><![CDATA[Steve Tout]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The Verified Intelligence Briefing: Issue 05 · June 13–19, 2026 ]]></title><description><![CDATA[The week the AI agent problem moved to identity's home turf.]]></description><link>https://www.strategylayer.com/p/the-verified-intelligence-briefing-c46</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-verified-intelligence-briefing-c46</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Fri, 19 Jun 2026 20:31:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!6nx4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6nx4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6nx4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!6nx4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!6nx4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!6nx4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6nx4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png" width="1254" height="1254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1254,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/202768308?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6nx4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!6nx4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!6nx4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!6nx4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcb275ed7-664d-46e7-b56c-e3adfb6092bd_1254x1254.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><em>The weekly read on verification debt &#8212; for leaders who own the control plane.</em></p><div><hr></div><h2>The Pattern</h2><p>This was the week three things converged onto one conclusion: AI is identity&#8217;s problem now.</p><p>The European Parliament voted to amend the EU AI Act, delaying enforcement while preserving the regulatory structure. The post surfacing the vote drew 2,011 reactions &#8212; by a wide margin the largest signal this briefing has tracked. Michael Lee, with 576 reactions behind him, named the underlying market shift: AI models are becoming a commodity, and the moat is now everything the model is wrapped in. KPMG retracted an AI-generated report on UBS after the kind of hallucinated content that ran EY through the same news cycle in <a href="https://www.strategylayer.com/p/the-verified-intelligence-briefing?r=54rmn1">Issue 01</a>. Different Big Four firm. Same failure mode. Identical conclusion: the verification layer has to live somewhere.</p><p>All of this happened in the same week as <a href="https://identiverse.com/">Identiverse</a> &#8212; the identity industry&#8217;s largest annual conference, where the entire conversation pivoted to AI agents, non-human identities, and the operating model required to govern both. SailPoint acquired Entro Security, signaling that the identity market is now consolidating around non-human identity governance. Rohan Pinto framed it as &#8220;Human on Top.&#8221; Jason Keenaghan asked the question directly on stage: is securing agentic AI an identity problem? The room said yes.</p><p>The pattern: <strong>the AI agent problem just moved to identity&#8217;s home turf &#8212; and the market is reorganizing to meet it there.</strong></p><p>Last week, the buyers reframed AI procurement as control procurement. This week, the identity industry stepped forward as the discipline that owns the control layer. Capability is the floor. Control is the moat. And the moat is being dug by the identity vendors that have been building this substrate for twenty years.</p><p><strong>Thesis.</strong> AI governance is now an identity discipline. The institutions that already operate mature identity programs get most of the AI governance work for free. The ones that built their AI strategy without their identity team in the room will rebuild it.</p><div><hr></div><h2>The Signals</h2><h3>01 &#183; The European Parliament voted to amend the EU AI Act</h3><p><em>The Signal.</em> The European Parliament voted to amend the EU AI Act, delaying enforcement dates while keeping the regulation&#8217;s core structure largely intact. The surfacing post drew 2,011 reactions &#8212; by a wide margin the largest single engagement signal this briefing has tracked across five issues (<a href="https://www.linkedin.com/posts/oliver-patel_breaking-news-european-parliament-votes-activity-7472643480956145665-Qzj9">Patel, LinkedIn, 16 June</a>).</p><p><em>The Lineage Gap.</em> This is the second EU enforcement step-back the briefing has tracked. <a href="https://www.strategylayer.com/p/the-verified-intelligence-briefing-058?r=54rmn1">Issue 02</a> covered the December 2027 effective-date slip. This week&#8217;s amendment is the formal parliamentary action. The pattern is now a posture: the regulator wants the framework on the books and the deadlines pushed. The institutions reading this as relief are missing the structural point. Enforcement delay does not erase the regulatory architecture &#8212; it concentrates the audit risk for the institutions whose AI behavior is documented in public press releases, vendor case studies, and quarterly earnings calls. When the AI Act eventually enforces, the institutions with five years of undocumented deployment behind them face a different conversation than the ones with five years of audit logs. The delay is a gift only if you use the runway.</p><p><em>Boardroom Prompt.</em> If the AI Act became enforceable next quarter, could your institution produce the documentation a high-risk classification requires &#8212; or would the gap between &#8220;ready&#8221; and &#8220;compliant&#8221; be visible from outside?</p><h3>02 &#183; KPMG retracted an AI-generated report on UBS after hallucinated claims</h3><p><em>The Signal.</em> KPMG retracted an AI-generated report on UBS after the report contained hallucinated claims about the bank. Oliver Bussmann&#8217;s surfacing of the story drew 137 reactions and surfaced the obvious comparison: this is EY in Issue 01, with a different Big Four name on the letterhead (<a href="https://www.linkedin.com/posts/oliverbussmann_artificialintelligence-fintech-boardstrategy-activity-7471657241360826368-9x9g">Bussmann, LinkedIn, 13 June</a>).</p><p><em>The Lineage Gap.</em> The second Big Four retraction in five weeks of this briefing makes the failure mode official, not anecdotal. Sailesh P. wrote the sharpest reframe (Signal 06 below): the issue is not AI generation. It is AI verification. Both firms produced credible-looking output. Both firms shipped it. Both firms discovered, after publication, that the verification step had not survived contact with production. The Four Pillars failed in identical sequence &#8212; grounding (no anchor to a real UBS source), scope (the model extrapolated into firm-specific claims), provenance (no trace back to the actual statement), drift awareness (no signal flagged the fabrication). When the same failure happens twice in five weeks in the same vertical, it stops being an incident and starts being a category. The category is &#8220;external assurance produced by AI without an enforced verification step.&#8221;</p><p><em>Boardroom Prompt.</em> For every external document your institution publishes that involved AI generation, what verification step is enforced before publication &#8212; and is that step distinct from the generation step?</p><h3>03 &#183; Michael Lee: AI models are becoming a commodity</h3><p><em>The Signal.</em> Michael Lee (576 reactions) named the market reality the buyers were already pricing into procurement decisions. AI models are commoditizing. The real moat is the system the model lives inside: governance, permissions, workflows, orchestration, evaluation, observability. The model is no longer the strategy. The system is (<a href="https://www.linkedin.com/posts/michael-lee-4049593_ai-models-are-becoming-a-commodity-ai-systems-activity-7473359294399148032-EySM">Lee, LinkedIn, 18 June</a>).</p><p><em>The Lineage Gap.</em> This is last issue&#8217;s &#8220;capability is the floor, control is the moat&#8221; thesis stated with broader market authority. When 576 reactions land on a commoditization argument inside a week, the market consensus has crossed the threshold from &#8220;emerging view&#8221; to &#8220;operating assumption.&#8221; The implication for procurement is direct: the vendor who arrives with the best model and the worst system loses to the vendor who arrives with the second-best model and a real system around it. The Five Questions are system properties, not model properties. <em>Who authorized it?</em> lives in the orchestration layer. <em>Who can revoke it?</em> lives in the permissions layer. <em>Who is it economically aligned to?</em> lives in the observability layer. The institution buying &#8220;an AI&#8221; needs to buy the system. The institution buying &#8220;a model&#8221; is buying the loss leader.</p><p><em>Boardroom Prompt.</em> When you next evaluate an AI vendor, will the scorecard weight the model, or the system around it &#8212; and what is the weight you assign to each?</p><h3>04 &#183; Rohan Pinto at Identiverse: &#8220;Human on Top&#8221; as the governance frame</h3><p><em>The Signal.</em> Rohan Pinto (161 reactions) connected Identiverse 2026&#8217;s biggest themes &#8212; AI agents, non-human identities, the runtime authority problem &#8212; to a single governance framework he called &#8220;Human on Top.&#8221; The argument: agents and non-human identities have to operate beneath a human-controlled authority layer, not parallel to it (<a href="https://www.linkedin.com/posts/rohanpinto_how-identiverse-2026s-biggest-challenges-activity-7472614663831076865-odws">Pinto, LinkedIn, 16 June</a>).</p><p><em>The Lineage Gap.</em> &#8220;Human on Top&#8221; is the architectural correlate of last issue&#8217;s structural Chief AI Officer signal. The early agent deployments put humans next to AI &#8212; review queues, periodic audits, ethics committees that meet quarterly. Pinto&#8217;s reframe is structural: the human authority is not adjacent to the agent stack; it sits <em>above</em> it, owning the delegation chain. The Five Questions all answer back up to that human authority. Authority is delegated downward through scopes, time bounds, and budgets; accountability flows upward through audit logs, exception escalations, and revocation events. The institutions that build their agent architecture this way get governance for free at runtime. The ones that don&#8217;t will spend Q3 retrofitting it onto deployments that were architected without an authority chain in mind.</p><p><em>Boardroom Prompt.</em> For every AI agent in your environment, is there a named human at the top of its delegation chain &#8212; or does the chain terminate inside the vendor&#8217;s platform?</p><h3>05 &#183; SailPoint acquired Entro Security &#8212; NHI consolidation accelerates</h3><p><em>The Signal.</em> SailPoint acquired Entro Security, an early leader in non-human identity governance. Eric Thacker (64 reactions) framed the deal as a market signal: non-human identity governance is now becoming core infrastructure for the identity platform, not an adjacent capability. The acquisition is part of a consolidation wave that began earlier this year and is accelerating (<a href="https://www.linkedin.com/posts/ethacker_identitysecurity-nhi-agenticai-activity-7472320409602838528-H3Gb">Thacker, LinkedIn, 15 June</a>).</p><p><em>The Lineage Gap.</em> The acquisition is the market voting on Issue 04&#8217;s permission-layer thesis. Identity vendors are not adding &#8220;AI agent support&#8221; as a feature &#8212; they are buying the companies that own the non-human identity governance primitives. Service accounts, machine identities, agent tokens, scoped credentials, time-bounded delegations &#8212; these stop being IAM corner cases and become the central category. The vendor that arrives at the next Identiverse with the most mature NHI stack is the vendor your CISO will be evaluating in Q4. The vendor that arrives with only human identity is selling the past. The institutions choosing identity platforms in the next six months should be asking exactly one question: what is the NHI architecture and is it credible.</p><p><em>Boardroom Prompt.</em> In your current identity platform, how many distinct types of non-human identity are governed today &#8212; and what is the audit log telling you about the rest?</p><h3>06 &#183; Sailesh P.: the KPMG story isn&#8217;t really about KPMG</h3><p><em>The Signal.</em> Sailesh P. (76 reactions) wrote the sharpest commentary on the KPMG retraction. The issue is not AI generation. It is AI verification. Every organization producing AI-generated content has the same exposure. KPMG just discovered it publicly (<a href="https://www.linkedin.com/posts/saileshpattnaik_the-kpmg-story-isnt-really-about-kpmg-activity-7472190959049490433-tabW">Sailesh P., LinkedIn, 15 June</a>).</p><p><em>The Lineage Gap.</em> The reframe is the entire briefing in two sentences. Verification debt is what accumulates between generation and publication when no controlled checkpoint catches the gap. The Five Questions answer this directly: at the moment of publication, can your institution produce the chain from claim &#8594; source &#8594; confidence interval &#8594; reviewer &#8594; approval? Most institutions cannot, because the AI tools were adopted faster than the verification workflow was redesigned. The interesting question is not how KPMG let this happen. The interesting question is how many institutions are producing similar artifacts right now without realizing it &#8212; because the failure mode is silent until the subject of the report happens to notice the fabrication.</p><p><em>Boardroom Prompt.</em> For every external artifact your institution published with AI assistance last quarter, can you produce the verification chain on demand &#8212; or only the generation chain?</p><h3>07 &#183; Jason Keenaghan asked Identiverse the structural question</h3><p><em>The Signal.</em> Jason Keenaghan (20 reactions) asked the question that framed half of Identiverse 2026: is securing agentic AI an identity problem, or a new end-to-end security discipline? His own answer leaned identity &#8212; but acknowledged the discipline boundaries are still being negotiated in real time (<a href="https://www.linkedin.com/posts/jason-keenaghan_identiverse-agenticai-cybersecurity-activity-7472678709250957312-wqb3">Keenaghan, LinkedIn, 16 June</a>).</p><p><em>The Lineage Gap.</em> The discipline boundary question matters because budget follows discipline ownership. If agentic AI security is an identity problem, the budget sits with IAM. If it is a separate discipline, the budget sits in a new line item that will be invented in the next planning cycle. The institutions that already have mature identity programs will quietly absorb the AI governance scope without doubling headcount &#8212; and the ones that don&#8217;t will discover that &#8220;AI governance&#8221; requires hiring a team that turns out to have the same skill profile as the IAM team they did not invest in. Identity is the most mature discipline closest to the agent problem. The market is voting on that proximity through acquisitions, conference programming, and budget reallocation. Keenaghan is naming the vote out loud.</p><p><em>Boardroom Prompt.</em> Inside your organization, who currently owns the AI agent security budget &#8212; IAM, security, AI strategy, or three people pointing at each other?</p><h3>08 &#183; Regis Haegler: AI as the cheap-now, expensive-later business model</h3><p><em>The Signal.</em> Regis Haegler (65 reactions) warned that AI is starting to look like the next great cheap-now, expensive-later business model &#8212; capability bundled at attractive pricing today, with the real cost trajectory revealed only after the institution has committed. Boards should stress-test costs, usage, lock-in, and exit options before the conversion happens (<a href="https://www.linkedin.com/posts/regishaegler_ai-may-be-the-next-great-cheap-now-expensive-activity-7473330939696209921-LjsF">Haegler, LinkedIn, 18 June</a>).</p><p><em>The Lineage Gap.</em> Haegler is naming the economic shape of last issue&#8217;s consumption-cost shift. The current price of frontier AI does not reflect the cost at scale, the cost of model upgrades, or the cost of the verification stack that will eventually be required by regulation or contract. The Five Questions need a financial answer at runtime &#8212; <em>Who is it economically aligned to?</em> &#8212; and that answer changes when the vendor&#8217;s pricing model changes. The institutions that wire exit options into their AI architecture now keep their leverage. The ones that don&#8217;t will discover, in the second or third quarter of dependency, that the cheapest path forward is the one the vendor has the most pricing power over. Exit options are a verification debt control, not just a procurement concern.</p><p><em>Boardroom Prompt.</em> For every consequential AI vendor in your stack, what is your documented exit plan &#8212; and what would it cost to execute in the next two quarters?</p><h3>09 &#183; Russ Pearlman: minimum viable governance is a category mistake</h3><p><em>The Signal.</em> Russ Pearlman (30 reactions) argued that AI governance should be calibrated to use-case risk, not minimized like an MVP. The MVP frame assumes failures you can afford. Most AI failures in regulated industries are failures you cannot afford. Governance should be proportional to consequence, with platform-level controls applied where the stakes warrant them (<a href="https://www.linkedin.com/posts/russpearlman_balance-ai-innovation-and-risk-with-minimum-activity-7472981374900031488-tUz5">Pearlman, LinkedIn, 17 June</a>).</p><p><em>The Lineage Gap.</em> Pearlman&#8217;s piece is the calibration argument behind last issue&#8217;s Gartner warning that uniform AI governance will cause enterprise failures by 2027. The MVP frame is doubly wrong for AI governance: it imports a startup mental model into a regulated context where the wrong AI output produces a public retraction, a regulatory inquiry, or a class action &#8212; none of which are failure modes you can afford to ship and learn from. Proportional controls require risk tiering at the platform level, not at the application level. The institutions that build platform-level governance primitives &#8212; identity, scoping, logging, kill switches &#8212; can apply them proportionally. The ones that build governance per-application will build the controls four times and still miss the use cases the controls were supposed to catch.</p><p><em>Boardroom Prompt.</em> For your top three AI use cases, is the governance posture calibrated to the worst-case consequence &#8212; or to the average-case workflow?</p><h3>10 &#183; Mandy Andress: AI-driven impersonation is changing the trust model</h3><p><em>The Signal.</em> Mandy Andress (12 reactions) wrote that AI-driven impersonation attacks &#8212; synthetic voices, deepfaked video, model-generated text indistinguishable from a known sender &#8212; are making trust and identity verification central security concerns. The attack model has changed; the verification model has not kept up (<a href="https://www.linkedin.com/posts/mandyandress_companies-arent-prepared-for-how-ai-is-accelerating-activity-7473387117935583232-bAW9">Andress, LinkedIn, 18 June</a>).</p><p><em>The Lineage Gap.</em> Andress is naming the Unauthorized Twins quadrant of the keynote 2&#215;2 in its operational form. Likenesses spun up in minutes, no tie to the real human, indistinguishable from authorized communication. The Five Questions all break at the impersonation boundary &#8212; <em>Who created it?</em> and <em>Who authorized it?</em> become identity verification problems before they become governance problems. The institutions that built passwordless, phishing-resistant authentication for their workforce are now adequately protected against the inbound version of these attacks. The ones still operating on shared secrets and SMS codes are not. The convergence with this issue&#8217;s Pattern is direct: AI agent governance and AI-driven impersonation defense share an identity substrate. The institutions investing in one get most of the other.</p><p><em>Boardroom Prompt.</em> If a deepfake of your CEO instructed your treasury team to authorize a wire transfer tomorrow, what would catch it &#8212; and would it catch it before the wire posted?</p><div><hr></div><h2>The Verification Debt Tracker</h2><p><em>The 2&#215;2 from <a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a>. Signal counts this week, with direction vs. last issue.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!U1xv!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!U1xv!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 424w, https://substackcdn.com/image/fetch/$s_!U1xv!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 848w, https://substackcdn.com/image/fetch/$s_!U1xv!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 1272w, https://substackcdn.com/image/fetch/$s_!U1xv!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!U1xv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png" width="1360" height="880" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:880,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:93553,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/202768308?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!U1xv!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 424w, https://substackcdn.com/image/fetch/$s_!U1xv!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 848w, https://substackcdn.com/image/fetch/$s_!U1xv!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 1272w, https://substackcdn.com/image/fetch/$s_!U1xv!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2e50c90-54ee-4ea0-9b09-002ba5c09107_1360x880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The Agents &amp; Workers quadrant held at 6 &#8212; five consecutive issues at the plateau, a steady-state read of the governance conversation. Adversarial Swarms held at 3, but the qualitative magnitude jumped on the back of two signals: the EU AI Act amendment (the largest engagement signal this briefing has tracked) and the second Big Four AI retraction in five weeks. Unauthorized Twins moved from 0 to 1 &#8212; the first signal in this quadrant since Issue 02 &#8212; driven by Andress on AI-driven impersonation. The keynote taxonomy&#8217;s most feral quadrant is no longer quiet.</p><div><hr></div><h2>Monday Morning</h2><p>Three things to do next week.</p><p><strong>01 &#183; Get your identity team in the room.</strong> Map every AI deployment against your identity program &#8212; every agent should have an identity record, an authorization chain, a delegation scope, and a kill switch in your IAM system. If your CIAM or IAM team was not in your last AI architecture review, that is the gap. Fix that before your next planning cycle.</p><p><strong>02 &#183; Apply the KPMG retraction lens to your own institution.</strong> Where is AI-generated content reaching external audiences &#8212; clients, regulators, partners, public &#8212; without an enforced verification checkpoint? The KPMG event is the second Big Four retraction in five weeks. The third will be more expensive for whoever it lands on. Audit your verification workflows this quarter, not next.</p><p><strong>03 &#183; Pressure-test your posture for an EU AI Act enforcement surprise.</strong> Enforcement dates are slipping, not disappearing. Document what compliance would look like today, even if you do not have to demonstrate it yet. The institutions that arrive at enforcement with documentation ready will pass through. The ones writing it under deadline will not.</p><div><hr></div><h2>The Reading Room</h2><p>Three pieces worth your time this week.</p><ul><li><p><strong>Steve Tout &#8212; </strong><em><strong>Intent Is the New Perimeter</strong></em> (<a href="https://www.linkedin.com/posts/stevetout_intent-is-the-new-perimeter-activity-7472499933099630592-fwTj">LinkedIn, 16 June</a>, 34 reactions). The briefing&#8217;s author published a longitudinal analysis of three years of Identiverse session data this week, arguing that identity has crossed a perimeter shift from credentials to intent. Companion read to this issue&#8217;s Pattern, and the empirical case for the &#8220;AI is identity&#8217;s problem now&#8221; conclusion.</p></li><li><p><strong>Alexandra C. &#8212; </strong><em><strong>Operational reality of AI governance is missing from theory</strong></em> (<a href="https://www.linkedin.com/posts/alextwittau_aigovernance-aisafety-breepleai-activity-7473290932604280832-KhMT">LinkedIn, 18 June</a>, 26 reactions). Argues that AI governance must move from declarative theory to deterministic runtime controls &#8212; telemetry, policy-as-code, and enforced revocation. The Carolyn Cotelli signal from Issue 04 made operational.</p></li><li><p><strong>Khwaja Shaik &#8212; </strong><em><strong>One Executive Order. Your AI Goes Dark. What&#8217;s Your Board&#8217;s Plan?</strong></em> (<a href="https://www.linkedin.com/posts/khwajashaik_ksgems-khwajastake-risk-activity-7473004908800217089-Llfy">LinkedIn, 17 June</a>). The geopolitical dimension of vendor concentration. If a sanctions order tomorrow cut your access to a frontier model, what is your continuity plan? Most boards have not asked the question.</p></li></ul><div><hr></div><p style="text-align: center;"><em>Trust is expensive. So is its absence.</em></p><div><hr></div><p><strong>The Verified Intelligence Briefing</strong> is written by <strong>Steve Tout</strong>, Founder &amp; CEO of <a href="https://identient.com">Identient</a> and author of <em>The CISO on the Razor&#8217;s Edge</em>. It draws from the curated <em>Daily Signal</em> corpus and the Verified Intelligence framework introduced in <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a></em>.</p><p>If this issue clarified something for you, <strong>forward it to one colleague who owns part of the control plane</strong>. New here? Subscribe to get The Briefing every Friday morning.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p>Reply or comment with the question you&#8217;d want answered in next week&#8217;s issue &#8212; your prompt may become Boardroom Prompt #1.</p><p>Connect with Steve: <a href="https://www.linkedin.com/in/stevetout">LinkedIn</a> &#183; <a href="https://identient.com">identient.com</a> &#183; <a href="https://stevetout.com">stevetout.com</a></p>]]></content:encoded></item><item><title><![CDATA[Authorship: The Identity Primitive Every Enterprise Should Demand From the Agents It Deploys]]></title><description><![CDATA[AuthR makes authorship a verifiable identity primitive alongside AuthN and AuthZ, so enterprises can trace who answers when an AI agent acts.]]></description><link>https://www.strategylayer.com/p/authorship-the-identity-primitive</link><guid isPermaLink="false">https://www.strategylayer.com/p/authorship-the-identity-primitive</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Mon, 15 Jun 2026 16:19:50 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!YRM9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YRM9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YRM9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!YRM9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!YRM9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!YRM9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YRM9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:112023,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/202129868?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YRM9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!YRM9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!YRM9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!YRM9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9fce5bdc-0f8e-4f95-a824-358b73da3ded_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Last month, in CIO, I argued that <a href="https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html">identity as we know it is dying</a>, and that AI governance now starts with lineage, not logins. That piece was a thesis. It named the problem: when AI entities act, decide, and speak on your organization&#8217;s behalf, access stops being the point, and authorship takes over.</p><p>This is the answer to that thesis. AuthR, short for Authorship Representation, is a</p><div class="digest-post-embed" data-attrs="{&quot;nodeId&quot;:&quot;79d1d587-3bf1-4cd7-a751-a84528038af2&quot;,&quot;caption&quot;:&quot;Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.&quot;,&quot;cta&quot;:null,&quot;showBylines&quot;:true,&quot;showDescription&quot;:true,&quot;showImage&quot;:true,&quot;size&quot;:&quot;lg&quot;,&quot;isEditorNode&quot;:true,&quot;title&quot;:&quot;The Third Pillar of Identity Just Shipped&quot;,&quot;publishedBylines&quot;:[{&quot;id&quot;:310338397,&quot;name&quot;:&quot;Steve Tout&quot;,&quot;bio&quot;:&quot;Founder, advisor, podcaster, runner&quot;,&quot;photo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b6d5e43-40d4-4888-b269-ee71bfd89b89_716x716.jpeg&quot;,&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null}],&quot;post_date&quot;:&quot;2026-05-25T05:52:39.871Z&quot;,&quot;cover_image&quot;:&quot;https://substackcdn.com/image/fetch/$s_!UXRR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png&quot;,&quot;cover_image_alt&quot;:null,&quot;canonical_url&quot;:&quot;https://www.strategylayer.com/p/the-third-pillar-of-identity-just&quot;,&quot;section_name&quot;:null,&quot;video_upload_id&quot;:null,&quot;id&quot;:199149009,&quot;type&quot;:&quot;newsletter&quot;,&quot;reaction_count&quot;:1,&quot;comment_count&quot;:0,&quot;publication_id&quot;:4536793,&quot;publication_name&quot;:&quot;The Strategy Layer&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!QgOt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8648a4bf-8dca-4279-a23a-100da89643b8_820x820.png&quot;,&quot;belowTheFold&quot;:false,&quot;youtube_url&quot;:null,&quot;show_links&quot;:null,&quot;feed_url&quot;:null}"></div><p> proposed framework that makes authorship a verifiable layer in the identity stack, alongside authentication and authorization rather than bolted on after the fact. The CIO piece ended on a single line: every AI entity you deploy carries a lineage, and the companies that can trace that lineage will govern it. AuthR is how you trace it.</p><p>I am publishing this the week the identity community convenes at <a href="https://identiverse.com/">Identiverse</a>, where, for the first time, there is a dedicated Non-Human and Agentic AI Identity track and a pavilion to match. The agenda has caught up to the problem. What the conversation behind it needs is an operating model for accountability. That model is authorship.</p><h2><strong>From access control to authorship</strong></h2><p>For two decades, identity and access management has answered two questions. Who are you, and what are you allowed to do. Authentication and authorization. They were built for a world where a human sat at a keyboard, signed in, and performed a discrete action they were accountable for by default. The human was the author, because the human was the only thing in the loop.</p><p>Agentic AI breaks that assumption quietly. An orchestrator delegates to a sub-agent, which delegates to a tool, which calls a service, across a workflow that runs for hours and re-plans itself as conditions change. Every hop carries a valid token. Every call is in scope. And nowhere in that chain is there a field that says whose judgment this was, or whether the action still reflects what a human actually authorized.</p><p>That is the gap. Authentication proves who is present. Authorization proves what access was granted. Neither proves whose judgment was represented, or who is responsible when an in-scope action serves a goal no human ever set. As enterprises move from AI that assists to AI that executes, that third question stops being academic and becomes the one the audit committee, the regulator, and the incident responder all ask first.</p><blockquote><p><em>Authentication proves who. Authorization proves what. Authorship proves whose judgment, and who answers for it. The first two were enough when humans pushed the buttons. They are not enough when agents do.</em></p></blockquote><h2><strong>A maturity model for agentic accountability</strong></h2><p>The useful way to think about this is not a binary, accountable or not, but a maturity scale. Four rungs, defined by what an auditor or an incident responder can actually reconstruct after an agent acts.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HHyN!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HHyN!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 424w, https://substackcdn.com/image/fetch/$s_!HHyN!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 848w, https://substackcdn.com/image/fetch/$s_!HHyN!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 1272w, https://substackcdn.com/image/fetch/$s_!HHyN!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HHyN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:565519,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/202129868?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HHyN!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 424w, https://substackcdn.com/image/fetch/$s_!HHyN!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 848w, https://substackcdn.com/image/fetch/$s_!HHyN!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 1272w, https://substackcdn.com/image/fetch/$s_!HHyN!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F958f957e-1830-4033-8f71-9fb8d8a8b466_4444x2500.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Rung 1 &#8212; Attributed to a credential.</strong> The action traces to a token or a service account. You know a call was made and which machine identity made it. You cannot say which human stood behind it or why. Most agent deployments live here today. An investigator accepts this only because there is nothing better on offer.</p><p><strong>Rung 2 &#8212; Attributed to a delegation chain.</strong> The action traces back through the hops, actor by actor, using mechanisms like token exchange and on-behalf-of. You can see that an orchestrator delegated to a sub-agent. This is real progress, and it is roughly the ceiling of what current standards provide. But the chain records who passed the baton, not whose judgment authorized the run, and not whether the result still matches the original purpose.</p><p><strong>Rung 3 &#8212; Bound to a human author and intent.</strong> A grounded human author mints a signed root record. The original purpose, the why, travels as a first-class object across every hop. Scope can only narrow downstream, never widen. Now an in-scope action that contradicts the authored intent is visible, because there is an intent to compare it against.</p><p><strong>Rung 4 &#8212; Continuously evaluated against drift, with revocation supremacy.</strong> The gap between original intent and runtime behavior is monitored as a live condition, not a decision settled once at grant time. When an agent re-plans, accumulates memory, or is reshaped by external data far enough from its mandate, the system flags it for re-anchoring or human review. A single revocation signal shortcuts the entire chain and invalidates authorship at every enforcement point at once. This is authorship engineered into the design, not reconstructed after an incident.</p><p>Map the agentic identity tooling you are being shown against this scale and the pattern rhymes with every maturity model: the decks claim Rung 4, the products sit between Rung 1 and Rung 2. That gap is where the diligence happens.</p><h2><strong>What this looks like when the threat is real</strong></h2><p>The reason this is not a thought experiment is that the failure mode already has CVE numbers.</p><p>In June 2025, researchers disclosed <a href="https://arxiv.org/html/2509.10540v1">EchoLeak</a>, a zero-click attack on Microsoft 365 Copilot. A single crafted email caused the agent to read internal files and exfiltrate them, with no user interaction. The researchers named the failure an LLM Scope Violation: untrusted external input steering an agent into accessing and revealing data it was fully authorized to touch. Every permission check passed. The compromise rode entirely on actions that were in scope.</p><p>Seven months later the class returned. Microsoft assigned a new CVE for the same pattern in its agent-building platform, and in that case the vendor&#8217;s own data-loss controls flagged the request while the data moved anyway, because it traveled on an authorized action. OWASP now ranks this pattern, Agent Goal Hijack, as the leading agentic risk for 2026.</p><p>Notice what none of the existing rungs would have caught. The credential was valid. The delegation chain was intact. Scope never escalated. The only thing that was violated was the user&#8217;s intent, and intent was the one thing nothing in the stack was carrying. That is the precise gap AuthR&#8217;s intent and drift primitives exist to close, and it is why the answer has to be structural rather than another patch on another path.</p><p>Regulators have already named it in the same language. The <a href="https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report">2026 FINRA Annual Regulatory Oversight Report</a> lists among its leading generative-AI risks that agents may act beyond the user&#8217;s actual or intended scope and authority. When the regulator and the attacker are describing the same failure, the layer that closes it is no longer optional.</p><h2><strong>What to ask every agentic vendor at Identiverse</strong></h2><p>Three questions. Useful in any booth conversation this week.</p><p><strong>One. Show me where the human author is bound.</strong> Not the service account, not the token. The grounded human whose judgment this agent represents. If the vendor can only show you a machine identity, the agent is at Rung 1 or 2, and accountability stops at a credential.</p><p><strong>Two. Show me the intent, and show me drift.</strong> Ask to see where the original purpose of a workflow is recorded as a first-class object, and how the system detects when runtime behavior has wandered from it. If the answer is scope and policy alone, you have boundaries, not authorship. Boundaries tell you what the agent can do. They do not tell you whether what it is doing still reflects what was asked.</p><p><strong>Three. Show me revocation across the whole chain.</strong> Pick a delegated, multi-hop workflow. Ask how a single revocation invalidates authorship at every downstream enforcement point at once, not system by system, after the fact. If revocation is a reconstruction project, accountability is too.</p><p>These three will sort the room.</p><h2><strong>Where AuthR sits, plainly</strong></h2><p>AuthR is a proposed framework, published at v0.1, and I am deliberately precise about what it is and is not. It does not replace authentication or authorization. It is designed to complement existing standards and infrastructure, OAuth, SAML, OIDC, SPIFFE/SPIRE, verifiable credentials, and the agentic-identity work emerging from CoSAI. It adds one layer those mechanisms structurally cannot provide: a verifiable record of who authored a decision, what executed it, why, within what boundaries, shaped by what lineage, and whether conditions drifted far enough to require review.</p><p>It is also one layer, not the whole stack. Least privilege, input handling, outbound controls, and runtime monitoring all still belong in the defense. There are credible voices who argue that intent is hard to evaluate deterministically, and they are right that no single control closes the gap. AuthR&#8217;s claim is narrow and, I think, defensible: authorship is the layer that travels with the action and answers the question the others cannot, and the field is converging on the idea that intent is becoming the new perimeter. AuthR v0.1 makes that concrete enough to test, challenge, and build on.</p><blockquote><p><em>the field is converging on the idea that intent is becoming the new perimeter.</em></p></blockquote><p>The materials, a working paper, draft specification, schema, an interactive playground, and reference implementation resources, are open for exactly that. This is an invitation to the identity and security community to help shape the structure, not a finished product pretending it is done.</p><h2><strong>At Identiverse this week?</strong></h2><p>I am not on the floor at Mandalay Bay this year, but I am running virtual briefings all week, June 15 to 18, for anyone working the same problem from the inside: identity architects, CISOs, CIOs, AI governance leads, standards contributors, and the vendors building in the Non-Human and Agentic AI Identity track.</p><p>If you want to walk the AuthR maturity model against your own agentic stack, see the <a href="https://playground.identient.com/playground">CFO wire-transfer scenario</a> run live in the playground, or just argue with the assumptions, I would genuinely welcome the conversation. A briefing, a demo, or a 15-minute chat with no deck. Bring your hardest objection.</p><p>Review the AuthR v0.1 materials at <a href="https://www.identient.com/authr/">identient.com/authr</a> or send an email to <strong>steve@identient.ai </strong>to request a briefing. The agenda has finally named the problem. Let&#8217;s talk about who answers for it.</p><p>Steve</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Verified Intelligence Briefing: Issue 04 · June 5–12, 2026 ]]></title><description><![CDATA[The week the AI market moved from a benchmark race to a governance race.]]></description><link>https://www.strategylayer.com/p/the-verified-intelligence-briefing-0e9</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-verified-intelligence-briefing-0e9</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Fri, 12 Jun 2026 17:52:11 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!JLrG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JLrG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JLrG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!JLrG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!JLrG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!JLrG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JLrG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png" width="1254" height="1254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1254,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/201775895?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JLrG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!JLrG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!JLrG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!JLrG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F18635b86-e2fc-4eb9-8e2a-3fc7112a3eb7_1254x1254.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><em>The weekly read on verification debt &#8212; for leaders who own the control plane.</em></p><div><hr></div><h2>The Pattern</h2><p>The enterprise buyer just shifted the AI conversation from capability to control.</p><p>Arvind Jain crystallized it: enterprise AI buyers are now prioritizing governance, control, economics, and flexibility over model benchmarks and vendor lock-in. The new procurement question is not &#8220;which model is best?&#8221; It is &#8220;which deployment is governable?&#8221;</p><p>The week&#8217;s signals all pointed at the same shift from different angles. ServiceNow disclosed a customer data breach that propagated through its SaaS customer base &#8212; a reminder that the platform layer is where verification debt is now most visible. Claude Fable 5 launched and drew enterprise concern, not for its capabilities, but for what its capabilities mean: another step deeper into model dependency for institutions that have not yet figured out their lineage chain. Brad Wolfe argued the real winner of the enterprise AI race is not the best model &#8212; it is the best distribution. Anthropic&#8217;s Big Four pipeline is the moat, not the benchmarks.</p><p>Underneath, the operating layer is starting to take shape. Carolyn Healey named the shift from labor cost to consumption cost &#8212; the economic substrate of every AI investment thesis. Birgul Cotelli named the maturity shift from principles to operational mechanisms &#8212; decision frameworks, audit trails, escalation protocols. Arkadiy Miteiko called it directly: permission is the next trillion-dollar AI problem. Not smarter models. Runtime governance.</p><p>The pattern: <strong>the enterprise AI market just moved from a benchmark race to a governance race &#8212; and the buyers, not the vendors, are setting the rules.</strong></p><p>This is the Issue 03 thesis pulled forward by a quarter. Last week, the security community renamed the agent problem as an identity problem. This week, the enterprise buyer renamed AI procurement as a control procurement. The vendors that understand both will be the ones the Big Four resell. The ones that do not will compete on benchmarks while the market moves on.</p><p><strong>Thesis.</strong> Capability is now the floor. Control is the moat. The institutions that price control into their AI procurement now will set the standard the rest of the market will spend 2027 catching up to.</p><div><hr></div><h2>The Signals</h2><h3>01 &#183; Arvind Jain: enterprise buyers are reassessing AI tradeoffs</h3><p><em>The Signal.</em> Arvind Jain (208 reactions) wrote this week that enterprise AI buyers are reassessing tradeoffs they were ignoring eighteen months ago. The new priorities: governance, control, economics, and flexibility. The deprioritized: raw benchmarks and vendor lock-in. Procurement conversations are now starting from &#8220;show me your control plane&#8221; instead of &#8220;show me your evals&#8221; (<a href="https://www.linkedin.com/posts/jain-arvind_a-lot-of-the-reaction-this-week-around-claude-activity-7470640462480031746-OAvW">Jain, LinkedIn, 11 June</a>).</p><p><em>The Lineage Gap.</em> Jain is naming what every other signal this week is also naming. The buyer-side conversation has moved. The vendor that arrives with the best benchmarks and the worst auditability is now losing deals to the vendor that arrives with mid-tier benchmarks and a real lineage chain. The Five Questions are now procurement questions. <em>Who created it?</em> &#8212; name your data sources. <em>Who trained it?</em> &#8212; show your scope boundary. <em>Who authorized it?</em> &#8212; describe your delegation model. <em>Who can revoke it?</em> &#8212; what is your kill switch SLA. <em>Who is it economically aligned to?</em> &#8212; show your cost-per-decision math. The vendors that answer cleanly are pulling ahead. The ones still selling capability are wondering why their pipeline went quiet.</p><p><em>Boardroom Prompt.</em> In your last three AI vendor evaluations, what percentage of the scorecard was control, governance, and economics &#8212; and what percentage was capability?</p><h3>02 &#183; ServiceNow disclosed a customer data breach</h3><p><em>The Signal.</em> ServiceNow confirmed a security incident exposing customer data, drawing 1,065 reactions on the surfacing post &#8212; by a wide margin the highest-engagement signal of the week (<a href="https://www.linkedin.com/posts/itmentor_breaking-news-servicenow-data-breach-activity-7470437295985238017-92Id">Mark P., LinkedIn, 10 June</a>). The breach hit a platform that sits inside the workflow infrastructure of most Fortune 1000 enterprises and a meaningful share of the federal government.</p><p><em>The Lineage Gap.</em> The ServiceNow breach is the platform-layer correlate of last week&#8217;s Meta helpdesk hijack. Where Meta&#8217;s incident showed an AI agent crossing the line from automation to privileged access, ServiceNow showed the broader pattern: SaaS platforms are now an identity perimeter for thousands of customer organizations, and a single vendor compromise reshapes the threat model for every downstream institution. The Five Questions all break differently at the SaaS layer &#8212; <em>who can revoke it?</em> is the most painful, because in the worst case the answer is <em>your vendor, on their schedule.</em> Verification debt at the platform layer is the most leveraged exposure in the enterprise stack. One breach. Thousands of audit committees.</p><p><em>Boardroom Prompt.</em> How many SaaS platforms in your environment hold identity, workflow, or transaction data that would create a regulatory incident if compromised &#8212; and what is your verification posture for each?</p><h3>03 &#183; Claude Fable 5 raised model dependency concerns inside the enterprise</h3><p><em>The Signal.</em> Alex Lamascus wrote (29 reactions) that the launch of Claude Fable 5 &#8212; the latest Mythos-class frontier model &#8212; is being received in enterprise communities with more concern than excitement. The capability gains are clear; so are the implications for model dependency, vendor lock-in, control, and auditability (<a href="https://www.linkedin.com/posts/alexlamascus_for-months-the-main-issue-with-mythos-class-activity-7470852376996913153-t7NI">Lamascus, LinkedIn, 11 June</a>).</p><p><em>The Lineage Gap.</em> The Claude Fable 5 release is the technical evidence underneath the buyer reassessment Arvind Jain named. Better capability does not reduce verification debt &#8212; it concentrates it. The more capable the model, the more decisions the institution is willing to delegate to it; the more decisions delegated, the deeper the lineage problem when something goes wrong. The Four Pillars all get harder, not easier, with capability increases. <em>Grounding</em> gets harder because the model now extrapolates more confidently. <em>Scope</em> gets harder because the surface of plausible-looking but out-of-scope outputs widens. <em>Provenance</em> gets harder because reasoning chains are longer. <em>Drift awareness</em> gets harder because the baseline of &#8220;expected behavior&#8221; is itself shifting with every model upgrade. The enterprise concern is the right concern.</p><p><em>Boardroom Prompt.</em> For every model upgrade your institution adopts, what verification work is required before the upgrade is allowed into a regulated workflow &#8212; and what is the SLA on completing it?</p><h3>04 &#183; Brad Wolfe: Anthropic is winning on distribution, not benchmarks</h3><p><em>The Signal.</em> Brad Wolfe argued (24 reactions) that Anthropic&#8217;s real win in the enterprise AI race is not the model. It is the distribution: the Big Four pipeline, the consulting integration, the enterprise sales motion happening inside KPMG, EY, PwC, and Accenture. Anthropic did not have to sell to the enterprise &#8212; the enterprise&#8217;s advisors sold for them (<a href="https://www.linkedin.com/posts/brad-wolfe-b912047_anthropic-did-not-win-the-enterprise-ai-race-activity-7469066832763699201-VAqy">Wolfe, LinkedIn, 6 June</a>).</p><p><em>The Lineage Gap.</em> The Big Four distribution thesis is the strategic logic underneath three issues of this briefing. Issue 01 covered the KPMG-Anthropic alliance. Issue 02 covered the 50,000 internal EY agents and the PwC 250-agent disclosure. This week, Wolfe names the move directly: the model is the loss leader; the distribution is the business. For the institutions on the receiving end of that distribution &#8212; the audit clients, the advisory clients, the implementation clients &#8212; the consequence is structural. Every Big Four engagement now has an Anthropic-flavored AI layer underneath it, governed by the Big Four&#8217;s controls, attached to the client&#8217;s signature. The vendor relationship was never directly transactional. The verification debt is, however, directly inherited.</p><p><em>Boardroom Prompt.</em> For each of your top three professional services vendors, do you know which frontier model is inside their delivery stack &#8212; and what your verification rights are when their output reaches your work product?</p><h3>05 &#183; Carolyn Healey: AI spend per employee keeps climbing</h3><p><em>The Signal.</em> Carolyn Healey wrote (205 reactions) that AI spend per employee is rising as organizations shift from labor cost to consumption cost. The economic structure of every AI investment thesis is now consumption-based &#8212; and consumption without governance turns into either runaway cost or quiet under-utilization, both of which surface in the wrong board meeting (<a href="https://www.linkedin.com/posts/carolynhealey_your-ai-spend-per-employee-keeps-climbing-activity-7468661082631380993-G8At">Healey, LinkedIn, 5 June</a>).</p><p><em>The Lineage Gap.</em> The consumption-cost shift is the financial form of last issue&#8217;s tokenmaxxing signal, but Healey frames it in the language the CFO will actually use. Labor cost is predictable; consumption cost is not. Labor cost has a known monthly maximum; consumption cost has only a usage maximum, which most enterprises have not set. The institutions that have already wired consumption controls into their FinOps stack &#8212; by agent, by team, by decision tier &#8212; are the ones whose AI budget will not blow up the Q3 forecast. The ones that have not will discover the answer in a variance presentation to the audit committee. Unit economics is not optional once consumption replaces labor.</p><p><em>Boardroom Prompt.</em> What is your cost per AI-assisted decision in your highest-volume workflow &#8212; and how does it compare to the labor cost it was supposed to replace?</p><h3>06 &#183; Birgul Cotelli: governance is shifting from principles to operational mechanisms</h3><p><em>The Signal.</em> Birgul Cotelli (39 reactions) named the maturity shift happening across enterprise AI governance programs &#8212; from quoting principles (fairness, transparency, accountability, safety) to operating mechanisms (decision frameworks, audit trails, escalation protocols, regulatory documentation). The shift is being driven by regulatory pressure, board-level scrutiny, and the realization that principles do not survive contact with production (<a href="https://www.linkedin.com/posts/birgulcotelli_most-ai-governance-programs-can-quote-their-activity-7468931447202955265-iFEa">Cotelli, LinkedIn, 6 June</a>).</p><p><em>The Lineage Gap.</em> Principles tell you what you want to be true. Operational mechanisms tell you how to discover when it is not. The Five Questions are operational mechanisms &#8212; they only mean something when the answer is producible on demand, in a format that withstands audit. Most enterprise AI governance programs are still at the principles stage. They have a fairness statement, an ethics committee, and a published charter. They do not yet have the audit log that lets them prove a specific decision met the standard the charter describes. The institutions that move from principles to mechanisms in Q3 will be the ones that handle the first regulatory probe in Q4 without a scramble.</p><p><em>Boardroom Prompt.</em> Of the AI governance principles your organization has published, how many have a corresponding operational mechanism that produces evidence on demand?</p><h3>07 &#183; Arkadiy Miteiko: permission is the next trillion-dollar AI problem</h3><p><em>The Signal.</em> Arkadiy Miteiko (21 reactions) wrote that the next major infrastructure layer in AI is not smarter models. It is runtime governance and permission &#8212; the policy plane that decides, for every action, whether the agent is authorized to take it, with what scope, on whose behalf, against what budget. He called it the next trillion-dollar AI problem (<a href="https://www.linkedin.com/posts/miteikoarkadiy_the-next-trillion-dollar-ai-problem-is-not-activity-7469528359899836417-w01F">Miteiko, LinkedIn, 7 June</a>).</p><p><em>The Lineage Gap.</em> Miteiko&#8217;s piece is the architectural conclusion of last issue&#8217;s Zero Trust convergence. Identity is the perimeter. Permission is the runtime layer above it. Every Five Questions answer becomes a permission decision at execution time: <em>who authorized it</em> becomes a policy check; <em>who can revoke it</em> becomes a session lifecycle; <em>who is it economically aligned to</em> becomes the budget envelope the policy engine enforces. Most enterprise AI deployments today have no permission layer. They have a service account, a token, and an unbounded scope. The vendor that ships the permission layer with the right primitives &#8212; least privilege, scoped delegation, runtime revocation, budget enforcement &#8212; becomes the IAM company of the next decade.</p><p><em>Boardroom Prompt.</em> For every AI agent operating in your environment, is there a policy decision evaluated on every action &#8212; or only at provisioning?</p><h3>08 &#183; IBM: human-speed governance is structurally failing agentic AI</h3><p><em>The Signal.</em> Nathaniel Niyazov surfaced an IBM study (24 reactions) finding that traditional human-speed governance is structurally failing for agentic AI. The IBM recommendation: governance controls have to be embedded directly into system architecture, not bolted on. By the time a human committee meets to review, the agent has already executed thousands of actions (<a href="https://www.linkedin.com/posts/nathaniel-niyazov-5a046b329_agenticai-aigovernance-aisecurity-activity-7469842792853352449-o_vT">Niyazov, LinkedIn, 8 June</a>).</p><p><em>The Lineage Gap.</em> The IBM finding is the empirical version of last issue&#8217;s governance-velocity warning. Human-speed processes were built for human-speed actors. Agents operate at machine speed; governance has to move at machine speed to keep up. The implication for architecture is concrete: the Five Questions answers have to be produced and recorded at every action, not at every review cycle. The platforms being designed today either embed this telemetry at the architectural layer or do not. The ones that do can be governed retroactively; the ones that do not cannot. There is no third path. The institutions choosing platforms now without asking the embedded-telemetry question are foreclosing their own future audit posture.</p><p><em>Boardroom Prompt.</em> For every AI platform your institution adopts in the next two quarters, are governance controls embedded in the architecture &#8212; or layered on top by your team after deployment?</p><h3>09 &#183; Pradeep Sanyal: the Chief AI Officer role becomes real authority</h3><p><em>The Signal.</em> Pradeep Sanyal (36 reactions) argued the Chief AI Officer title is shifting from symbolic to structural. The early CAOs were corporate garnish &#8212; a press release, a charter, a quarterly slide. The next generation has real authority over budget, vendor selection, and architectural decisions. The shift is being driven by accountability pressure, not innovation pressure (<a href="https://www.linkedin.com/posts/pradeeps_the-chief-ai-officer-title-had-a-good-run-activity-7468894897895317504-xAgb">Sanyal, LinkedIn, 6 June</a>).</p><p><em>The Lineage Gap.</em> The Chief AI Officer evolution is the organizational form of the verification debt conversation. Symbolic CAOs were appointed to demonstrate that the board took AI seriously. Structural CAOs are being appointed to ensure the board does not get sued. The difference is the reporting line. Symbolic CAOs reported to communications or innovation. Structural CAOs report to the CEO, sit on the operating committee, and own the budget that funds the governance program. The institutions making this transition now are reading the Kindervag signal from last issue &#8212; <em>should CEOs be personally accountable?</em> &#8212; and rationally moving the personal accountability one layer down. Kindervag would call that a feature, not a bug.</p><p><em>Boardroom Prompt.</em> Does your Chief AI Officer have budget authority, vendor authority, and a direct reporting line to the CEO &#8212; or do they have a title and a presentation slot?</p><h3>10 &#183; Shobha Shah: boards review financials quarterly. AI deserves the same.</h3><p><em>The Signal.</em> Shobha Shah wrote (19 reactions) that most boards review financial performance every quarter &#8212; and almost none review AI performance with the same rigor. Her argument: AI now drives material business outcomes, regulatory risk, and reputational exposure that justify quarterly board-level review on value, risk, accountability, regulatory readiness, and governance effectiveness (<a href="https://www.linkedin.com/posts/shobha-shah_aigovernance-boardgovernance-corporategovernance-activity-7470456040946356224-YQpE">Shah, LinkedIn, 10 June</a>).</p><p><em>The Lineage Gap.</em> The board oversight gap is now structural. AI investments are running at the same scale as M&amp;A or capital programs, with less oversight than either. Shah is naming the simplest possible corrective: apply the existing board cadence to AI. Quarterly review. Five-domain scorecard. Named accountability. The institutions that adopt this practice in Q3 will be the ones whose proxy disclosures next spring read as defensible. The ones that do not will discover the question from a plaintiff&#8217;s counsel, an activist investor, or a credit rating downgrade. None of those discoveries are cheap.</p><p><em>Boardroom Prompt.</em> At your last four board meetings, was AI on the agenda with the same depth as capital projects, M&amp;A, or compensation &#8212; or was it a five-minute update from the CIO?</p><div><hr></div><h2>The Verification Debt Tracker</h2><p><em>The 2&#215;2 from <a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a>. Signal counts this week, with direction vs. last issue.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KuuP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KuuP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 424w, https://substackcdn.com/image/fetch/$s_!KuuP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 848w, https://substackcdn.com/image/fetch/$s_!KuuP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 1272w, https://substackcdn.com/image/fetch/$s_!KuuP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KuuP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png" width="1456" height="942" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:942,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:331842,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/201775895?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KuuP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 424w, https://substackcdn.com/image/fetch/$s_!KuuP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 848w, https://substackcdn.com/image/fetch/$s_!KuuP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 1272w, https://substackcdn.com/image/fetch/$s_!KuuP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3a760e4d-22cc-4898-8a31-6e274a0bcd73_2720x1760.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>All four quadrants held flat in signal count this week &#8212; but inside Adversarial Swarms the magnitude shifted dramatically. ServiceNow&#8217;s breach drew more engagement than any single signal we have tracked in this briefing. The plateau in the Agents &amp; Workers quadrant tells its own story: the governance conversation is no longer accelerating &#8212; it is consolidating. Six signals a week, every week, all pointing at the same operational mechanisms. The conversation has reached the stage where the same answers are being arrived at, independently, by different practitioner communities. That is the moment a market standard starts to form.</p><div><hr></div><h2>Monday Morning</h2><p>Three things to do next week.</p><p><strong>01 &#183; Price control into your next AI vendor evaluation.</strong> Add explicit weight in the procurement scorecard for verification posture: who can produce the reasoning chain, on what timeline, in what format. Make the answers a contract clause, not a vendor promise. The institutions that price control now set the market standard the laggards spend 2027 catching up to.</p><p><strong>02 &#183; Inventory your SaaS identity perimeter.</strong> ServiceNow was the platform-layer version of last week&#8217;s Meta hijack. Map every SaaS platform that holds identity, workflow, or transaction data. Score each on the Five Questions. The platforms scoring low are your next compliance conversation, your next breach disclosure, or both.</p><p><strong>03 &#183; Wire consumption controls into FinOps.</strong> Set a hard cap and a tiered approval gate for every consequential AI agent in your environment. Tokenmaxxing was the introduction; Healey&#8217;s consumption-cost framing is the conclusion. The control is technical; the policy belongs to the AI governance committee; the budget belongs to the CFO. All three need to ratify the same number.</p><div><hr></div><h2>The Reading Room</h2><p>Three pieces worth your time this week.</p><ul><li><p><strong>Lewis Walker &#8212; </strong><em><strong>Accenture/CMU AI Maturity Model</strong></em> (<a href="https://www.linkedin.com/posts/lewiswalkerai_new-accenture-cmu-ai-maturity-model-activity-7470807107315908609-24Rn">LinkedIn, 11 June</a>, 248 reactions). A 63-page reference that lets you benchmark enterprise AI maturity against a real framework. Useful for the board deck, the consulting engagement, and honest self-assessment.</p></li><li><p><strong>Alexandra C. &#8212; </strong><em><strong>The AI reliability illusion</strong></em> (<a href="https://www.linkedin.com/posts/alextwittau_aiagents-aievaluation-responsibleai-activity-7468942260290703360-VeSU">LinkedIn, 6 June</a>). Makes the methodological case that benchmark-driven reliability estimates dramatically overstate real-world performance for autonomous workflows. The signal that lets your CRO ask better questions about vendor demo decks.</p></li><li><p><strong>Dhanasekhar D. &#8212; </strong><em><strong>Agentic AI now has its protocol stack</strong></em> (<a href="https://www.linkedin.com/posts/1dhana_agentic-ai-now-has-its-protocol-stack-for-activity-7470655365261484032-33kU">LinkedIn, 11 June</a>). Maps the emerging MCP/A2A/ACS layer cake that will become the production substrate for governed enterprise agents over the next 18 months. Read it before your platform team starts evaluating their roadmap.</p></li></ul><div><hr></div><p><em>Trust is expensive. So is its absence.</em></p><div><hr></div><p><strong>The Verified Intelligence Briefing</strong> is written by <strong>Steve Tout</strong>, Founder &amp; CEO of <a href="https://identient.com">Identient</a> and author of <em>The CISO on the Razor&#8217;s Edge</em>. It draws from the curated <em>Daily Signal</em> corpus and the Verified Intelligence framework introduced in <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a></em>.</p><p>If this issue clarified something for you, <strong>forward it to one colleague who owns part of the control plane</strong>. New here? Subscribe to get The Briefing every Friday morning.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p>Reply or comment with the question you&#8217;d want answered in next week&#8217;s issue &#8212; your prompt may become Boardroom Prompt #1.</p><p>Connect with Steve: <a href="https://www.linkedin.com/in/stevetout">LinkedIn</a> &#183; <a href="https://identient.com">identient.com</a> &#183; <a href="https://stevetout.com">stevetout.com</a></p>]]></content:encoded></item><item><title><![CDATA[The Verified Intelligence Briefing: Issue 03 · May 29 – June 5, 2026]]></title><description><![CDATA[The week Zero Trust came for AI agents.]]></description><link>https://www.strategylayer.com/p/the-verified-intelligence-briefing-29e</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-verified-intelligence-briefing-29e</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Fri, 05 Jun 2026 20:04:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!DUw5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7e0e3c5b-ccd0-4ffc-919f-66adc8666bc4_1254x1254.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="image-gallery-embed" data-attrs="{&quot;gallery&quot;:{&quot;images&quot;:[{&quot;type&quot;:&quot;image/webp&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e0e3c5b-ccd0-4ffc-919f-66adc8666bc4_1254x1254.webp&quot;}],&quot;caption&quot;:&quot;&quot;,&quot;alt&quot;:&quot;&quot;,&quot;staticGalleryImage&quot;:{&quot;type&quot;:&quot;image/webp&quot;,&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7e0e3c5b-ccd0-4ffc-919f-66adc8666bc4_1254x1254.webp&quot;}},&quot;isEditorNode&quot;:true}"></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-verified-intelligence-briefing-29e?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-verified-intelligence-briefing-29e?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p><em>The weekly read on verification debt &#8212; for leaders who own the control plane.</em></p><div><hr></div><h2>The Pattern</h2><p>Last week, three different parts of the verification system stepped back. This week, the security community took the agent identity question back from the AI labs &#8212; and renamed it.</p><p>Multiple major voices converged on the same frame inside seven days. Gartner&#8217;s Neil MacDonald wrote that AI agents are software, not human-like entities, and should be secured with Zero Trust controls. Anthropic published a thirty-five-page Zero Trust framework for AI agents. The White House signed an executive order pointing in the same direction. Microsoft launched Agent 365 &#8212; and the Gartner take was that even Microsoft needs platform-agnostic security layered on top. John Kindervag, who originated Zero Trust at Forrester, opened a public debate on personal CEO accountability for cyberattacks.</p><p>And in the background, a Meta AI support agent was hijacked into resetting customer account credentials. The verification debt came due &#8212; again &#8212; in operational form.</p><p>The pattern: <strong>the security and governance communities just collectively renamed the AI agent problem. It is not an AI safety problem. It is an identity and privilege problem &#8212; and Zero Trust is the framework that already exists to solve it.</strong></p><p>This matters because Zero Trust gives the Five Questions a runtime enforcement model. <em>Who authorized it?</em> becomes continuous verification, not one-time provisioning. <em>Who can revoke it?</em> becomes least-privilege scoping, not an emergency runbook. <em>Who is it economically aligned to?</em> becomes the trust chain that the policy engine evaluates on every call. The labs talk about alignment. The security community talks about identity. This week, those two conversations started speaking the same language.</p><p><strong>Thesis.</strong> Zero Trust is the missing layer that makes the Five Questions enforceable at runtime. The institutions that already operate a Zero Trust posture get the AI agent governance work mostly for free. The ones still running perimeter-based identity will pay for it twice.</p><div><hr></div><h2>The Signals</h2><h3>01 &#183; A Meta AI support agent was hijacked into resetting customer credentials</h3><p><em>The Signal.</em> Jim Reavis surfaced a Meta incident in which an AI-powered helpdesk agent was tricked into resetting customer account credentials. The takeaway: AI support agents with account-changing powers are not chatbots. They are privileged actors in the identity system, and they need to be governed as such (<a href="https://www.linkedin.com/posts/jimreavis_helpdesk-hijack-activity-7467959770474377218-g5dk">Reavis, LinkedIn, 3 June</a>).</p><p><em>The Lineage Gap.</em> The Five Questions break exactly here, every time. <em>Who created this agent?</em> Meta. <em>Who trained it?</em> Meta. <em>Who authorized it to reset account credentials?</em> Almost certainly no one had to sign off in a way an audit could discover. <em>Who can revoke that capability?</em> Engineering, eventually. <em>Who is it economically aligned to?</em> Meta &#8212; not the customer whose account just changed hands. The agent crossed the line from automation to privileged access without any of the governance that line normally requires. Every enterprise running an &#8220;AI helpdesk&#8221; or &#8220;AI customer service&#8221; agent has the same gap, with smaller scale but identical structure. The Meta event is the canary.</p><p><em>Boardroom Prompt.</em> For every AI agent in your customer-facing channels, what would it take, today, to convince it to reset a customer account?</p><h3>02 &#183; Gartner: AI agents are software. Govern them with Zero Trust.</h3><p><em>The Signal.</em> Neil MacDonald at Gartner wrote (87 reactions) that AI agents are not human-like entities. They are software. The right frame for governing them is the one the security community already has: Zero Trust. Continuous verification, least privilege, assume breach (<a href="https://www.linkedin.com/posts/neil-stuart-macdonald_gartnersec-gartnersec-zerotrust-activity-7467387009528086528-tuyR">MacDonald, LinkedIn, 2 June</a>).</p><p><em>The Lineage Gap.</em> MacDonald&#8217;s framing collapses a category mistake that has cost the AI governance conversation eighteen months. &#8220;AI safety,&#8221; &#8220;AI ethics,&#8221; &#8220;AI alignment&#8221; &#8212; these are valuable concepts, but they treat the agent as something exotic that needs new rules. Zero Trust treats it as what it is: a piece of software with an identity, a scope, and a privilege envelope. The Four Pillars of Verified Intelligence map onto Zero Trust principles cleanly. Grounding becomes &#8220;verify before trust.&#8221; Scope becomes least privilege. Provenance becomes the audit log Zero Trust already requires. Drift awareness becomes the continuous re-verification at every call. Institutions that already operate Zero Trust have most of the runtime substrate they need. Institutions that abandoned Zero Trust because &#8220;agentic AI is too novel&#8221; &#8212; <em>see SR 26-2</em> &#8212; just made the problem twice as hard.</p><p><em>Boardroom Prompt.</em> Does your current Zero Trust architecture treat AI agents as first-class identities &#8212; or are they exempted by category, like the regulator just did?</p><h3>03 &#183; Anthropic published a thirty-five-page Zero Trust framework for AI agents</h3><p><em>The Signal.</em> Bill Lewis flagged Anthropic&#8217;s thirty-five-page Zero Trust framework for AI agents, published this week (<a href="https://www.linkedin.com/posts/billlewis-linacrecapital_anthropic-has-just-published-a-35-page-zero-activity-7467138032647884800-0Zq0">Lewis, LinkedIn, 1 June</a>). The publication is significant because it comes from a frontier AI lab &#8212; and it concedes, in essence, that the model&#8217;s safety controls are not enough. The deployment context needs its own framework.</p><p><em>The Lineage Gap.</em> The model labs and the security community have been talking past each other for two years. The labs published responsible scaling policies and constitutional AI papers. The security community kept saying <em>where is the identity story.</em> This week, Anthropic met the security community in its own language. Thirty-five pages of Zero Trust principles applied to agents is not a hedge &#8212; it is a recognition that the model&#8217;s own controls are insufficient at the deployment layer. The implication: when a frontier lab publishes Zero Trust guidance for its own agents, every CISO has the cover to require the same posture for every vendor agent operating inside their environment. The vendor cannot now claim that model-level safety obviates customer-level identity governance.</p><p><em>Boardroom Prompt.</em> The next time a vendor tells you their AI is &#8220;safe by design,&#8221; will you accept that as a substitute for your own Zero Trust posture &#8212; or require both?</p><h3>04 &#183; The White House executive order points in the same direction</h3><p><em>The Signal.</em> Art Gilliland wrote that the White House&#8217;s executive order on AI security gets one critical point right: AI agents create new identity and trust risks that require governance, accountability, and collaboration &#8212; not just compliance checkboxes (<a href="https://www.linkedin.com/posts/artgilliland_mythos-ai-agents-and-identity-security-activity-7467663986298126336-28NA">Gilliland, LinkedIn, 2 June</a>, 47 reactions).</p><p><em>The Lineage Gap.</em> The executive order is the political-layer signal catching up to the practitioner-layer signal. When the security community, the model labs, and the executive branch all start saying the same thing in the same week, the conversation has crossed a threshold. The remaining gap is the implementation layer &#8212; what does Zero Trust for AI agents actually look like in a production enterprise? That is still being written, mostly outside of regulation, by the institutions that already had the substrate. The institutions that did not will spend the rest of 2026 reading framework documents. The ones that did will spend the same six months deploying. The gap between those two will become a competitive moat by Q1 2027.</p><p><em>Boardroom Prompt.</em> Are you reading the AI security framework documents, or implementing them &#8212; and what is the gap between those two activities in your organization right now?</p><h3>05 &#183; Microsoft launched Agent 365. Gartner&#8217;s take: it still needs platform-agnostic security.</h3><p><em>The Signal.</em> Avivah Litan at Gartner (95 reactions) wrote that Microsoft Agent 365 demonstrates a meaningful shift in Microsoft&#8217;s AI security priorities &#8212; and that platform-agnostic, independent security still needs to be layered on top. The implication: even the hyperscalers concede that the platform owner cannot be the platform&#8217;s sole governance authority (<a href="https://www.linkedin.com/posts/avivahlitan_trism-copilot-aisecurity-activity-7466194378521313281-2NjE">Litan, LinkedIn, 29 May</a>).</p><p><em>The Lineage Gap.</em> Microsoft&#8217;s announcement and Litan&#8217;s response together describe the new vendor-customer split. The vendor builds AI security primitives at the platform layer. The customer owns the verification posture that sits above them. Five Questions remain a customer-side discipline: <em>Who authorized this agent? Who can revoke it? Who is it economically aligned to?</em> The platform can answer some of these. It cannot answer all of them, because the trust chain ends at the customer&#8217;s data, the customer&#8217;s regulator, and the customer&#8217;s signature. Institutions reading Litan&#8217;s response as a compliment to Microsoft are missing the structural point. Litan is naming that the customer&#8217;s verification debt is not transferable, even to a four-trillion-dollar vendor.</p><p><em>Boardroom Prompt.</em> For every AI capability your hyperscaler delivers to you next quarter, who in your organization owns the verification posture that sits above it?</p><h3>06 &#183; The originator of Zero Trust raised the personal accountability question</h3><p><em>The Signal.</em> John Kindervag, who created Zero Trust at Forrester, opened a public debate this week (69 reactions) on whether CEOs should be held personally accountable for cyberattacks when known risks are ignored (<a href="https://www.linkedin.com/posts/john-kindervag-40572b1_the-debate-should-ceos-be-held-personally-activity-7467951319157252096-YI3b">Kindervag, LinkedIn, 3 June</a>). The framing matters: when the inventor of the framework starts talking about personal CEO accountability, the conversation is moving from &#8220;best practice&#8221; to &#8220;fiduciary.&#8221;</p><p><em>The Lineage Gap.</em> Personal accountability is the lever that converts AI governance from a CISO problem into a CEO problem. Last issue&#8217;s Gabriel Millien signal &#8212; &#8220;your AI security program is a CEO problem dressed up as a security checklist&#8221; &#8212; arrived at the same point from inside the program. Kindervag is now naming the legal and reputational dimension. The institutions that already wired personal accountability into the AI governance charter &#8212; typically through a named Chief AI Risk Officer reporting to the board, not the CIO &#8212; are buying themselves the structural answer Kindervag is asking for. The ones that haven&#8217;t will discover the question in a deposition.</p><p><em>Boardroom Prompt.</em> If a regulator or plaintiff asked tomorrow which named officer in your institution is personally accountable for AI governance, would the answer be one person &#8212; or three people pointing at each other?</p><h3>07 &#183; Tony Seale: enterprise AI needs network-shaped data, not box-shaped warehouses</h3><p><em>The Signal.</em> Tony Seale&#8217;s piece (371 reactions, the week&#8217;s highest) argued that enterprise AI needs network-shaped data models &#8212; knowledge graphs and semantic context &#8212; not box-shaped data warehouses. The reasoning: AI agents need to know how facts relate, not just where facts live (<a href="https://www.linkedin.com/posts/tonyseale_every-c-suite-is-arriving-at-the-same-uncomfortable-activity-7466035651834990592-79DN">Seale, LinkedIn, 29 May</a>).</p><p><em>The Lineage Gap.</em> Seale is naming the substrate problem underneath the Zero Trust conversation. Zero Trust works only if the policy engine has the context to make a verification decision. A box-shaped warehouse gives you a data row. A network-shaped model gives you the relationship &#8212; who connects to what, why it matters, what would change if it shifted. Without the relationship layer, every agent action looks the same to the policy engine. With it, the engine can distinguish &#8220;this employee querying their own salary&#8221; from &#8220;this agent acting on behalf of an employee, querying the salary of an executive in a different jurisdiction.&#8221; Grounding is a data-structure problem, not a model problem. Most enterprises do not yet have the substrate that makes verification computable.</p><p><em>Boardroom Prompt.</em> When your AI agent makes a decision, can your policy engine evaluate the <em>relationships</em> around that decision &#8212; or only the data points inside it?</p><h3>08 &#183; McKinsey: AI is outpacing the operating model of leadership teams</h3><p><em>The Signal.</em> Carolyn Dewar of McKinsey (47 reactions) wrote that AI is outpacing the operating model of leadership teams &#8212; particularly in decision-making cadence, cross-functional alignment, and execution speed (<a href="https://www.linkedin.com/posts/carolyn-dewar_ai-is-moving-faster-than-the-operating-model-activity-7467914439166480384-CVDc">Dewar, LinkedIn, 3 June</a>). Technology adoption is running ahead of the C-suite&#8217;s ability to govern it.</p><p><em>The Lineage Gap.</em> Dewar is describing the organizational version of cognitive surrender from Issue 02. The C-suite is letting the AI adoption curve outrun the meeting cadence, the decision rights, and the cross-functional plumbing that would let them govern it. The Five Questions are a CEO governance asset, but they require a forum that meets often enough to ask them. Most institutions have a quarterly AI steering committee for technology moving on a weekly cadence. By the time the committee meets, the agent that should have been escalated has already shipped, the contract that should have been reviewed has already been signed, and the regulator has read the press release. Governance velocity is now a board-level competency.</p><p><em>Boardroom Prompt.</em> How frequently does your leadership team meet on AI governance &#8212; and how does that compare to the deployment velocity of the systems they are supposed to be governing?</p><h3>09 &#183; Andy ThurAI named &#8220;tokenmaxxing&#8221; &#8212; and the bankruptcy adjacent to it</h3><p><em>The Signal.</em> Andy ThurAI coined a useful term this week. &#8220;Tokenmaxxing&#8221; &#8212; the enterprise behavior of consuming AI compute at runaway rates without spending controls. He argued that an enterprise is one unmonitored episode away from bankruptcy-grade exposure (<a href="https://www.linkedin.com/posts/andythurai_ai-futureofai-artificialintelligence-activity-7466527361677635586-HEmY">ThurAI, LinkedIn, 30 May</a>, 20 reactions).</p><p><em>The Lineage Gap.</em> The economic dimension of Zero Trust is the one most enterprises haven&#8217;t built yet. Continuous verification is meaningless if continuous spending is not also bounded. The Five Questions need an economic-alignment answer at runtime, not just at provisioning. <em>Who is it economically aligned to?</em> is the question that becomes a budget control, a rate limiter, an approval gate at a defined threshold. ThurAI&#8217;s bankruptcy framing is dramatic but not wrong. A misbehaving agent looping on a high-token-cost API can produce a six-figure invoice in a weekend. Most enterprise FinOps tooling does not yet have AI-specific controls. The institutions that build them before Q3 budgets reset will be the ones whose CFO is not personally explaining a variance to the audit committee.</p><p><em>Boardroom Prompt.</em> What is the maximum amount your most expensive AI agent could spend, autonomously, over a 72-hour weekend with no human in the loop &#8212; and where is that number set?</p><h3>10 &#183; Gartner: uniform AI agent governance will cause enterprise failures by 2027</h3><p><em>The Signal.</em> Nathaniel Niyazov surfaced a Gartner warning that uniform AI agent governance will cause enterprise failures by 2027. The Gartner recommendation: proportional controls based on autonomy and risk, not one-size-fits-all policies (<a href="https://www.linkedin.com/posts/nathaniel-niyazov-5a046b329_aigovernance-agenticai-aisecurity-activity-7466178382821625856-qWwY">Niyazov, LinkedIn, 29 May</a>, 16 reactions).</p><p><em>The Lineage Gap.</em> The natural endpoint of the Zero Trust frame is proportional governance. Not every agent needs the same authority chain, the same revocation latency, the same audit detail. A research assistant answering questions from public web data does not need the same governance as a treasury agent moving funds. Uniform policies feel safer but fail more often, because they create either too much friction for low-risk work or too little control for high-risk work. The institutions that segment their agent inventory by risk tier &#8212; and apply Zero Trust controls proportionally &#8212; will be the ones whose security team is still functioning in 2027. The ones running uniform policies will lose their best practitioners to burnout first.</p><p><em>Boardroom Prompt.</em> How many risk tiers does your AI agent inventory have today &#8212; and what is the proportional control framework attached to each?</p><div><hr></div><h2>The Verification Debt Tracker</h2><p><em>The 2&#215;2 from <a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a>. Signal counts this week, with direction vs. last issue.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RhHZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RhHZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 424w, https://substackcdn.com/image/fetch/$s_!RhHZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 848w, https://substackcdn.com/image/fetch/$s_!RhHZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 1272w, https://substackcdn.com/image/fetch/$s_!RhHZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RhHZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png" width="1360" height="880" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:880,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:95223,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/200810046?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RhHZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 424w, https://substackcdn.com/image/fetch/$s_!RhHZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 848w, https://substackcdn.com/image/fetch/$s_!RhHZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 1272w, https://substackcdn.com/image/fetch/$s_!RhHZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7f5b974c-95ed-4cc9-a33b-1d7605ac60f3_1360x880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong>Operational / Governed</strong> quadrant stayed at 6 &#8212; but every one of those signals converged on the same frame this week, which makes the qualitative density higher than the count suggests. The <strong>Operational / Feral</strong> quadrant rose again as the Meta hijack, the tokenmaxxing bankruptcy framing, and the McKinsey governance-velocity warning all landed inside seven days. The pattern that began with SR 26-2 last week &#8212; feral operational AI accumulating &#8212; is now being met by an equally fast governance response. Watch both bars climb together through Q3.</p><div><hr></div><h2>Monday Morning</h2><p>Three things to do next week.</p><p><strong>01 &#183; Inventory your AI agents as identities.</strong> Stop treating them as features inside applications. Every agent gets a name, an owner, a scope, an authority chain, and a revocation path. If you cannot draw the directed graph of <em>human &#8594; agent &#8594; action &#8594; resource</em> for your top ten agents, you do not yet have AI governance. You have configuration drift.</p><p><strong>02 &#183; Set a spending guardrail on every agent.</strong> Hard cap. Rate limit. Approval gate above a threshold. Tokenmaxxing is a CFO problem before it becomes a CISO problem. The control belongs in FinOps; the policy belongs to the AI governance committee. Wire them together this week.</p><p><strong>03 &#183; Read Anthropic&#8217;s Zero Trust framework.</strong> Thirty-five pages, published this week. It is the document your CISO will be asked about in the next board meeting. The institutions whose CISO can summarize it in three points are the ones whose board will sleep through Q3. The rest will spend Q3 catching up.</p><div><hr></div><h2>The Reading Room</h2><p>Three pieces worth your time this week.</p><ul><li><p><strong>Michael Lee &#8212; </strong><em><strong>AI strategy frameworks are free; the discipline is not</strong></em> (<a href="https://www.linkedin.com/posts/michael-lee-4049593_bcg-gartner-bain-mckinsey-nist-their-activity-7468650066547916800-7N7L">LinkedIn, 5 June</a>, 96 reactions). Public frameworks from BCG, Gartner, Bain, McKinsey, and NIST matter less than the disciplined decision architecture that embeds them into operating systems and capital allocation. The companion read to this week&#8217;s Pattern.</p></li><li><p><strong>Khwaja Shaik &#8212; </strong><em><strong>Stakeholder fluency as defining boardroom competency</strong></em> (<a href="https://www.linkedin.com/posts/khwajashaik_ksgems-khwajastake-ai-activity-7467588328909996032-vQwS">LinkedIn, 2 June</a>). Boards now need fluency across customers, employees, regulators, communities, and investors. AI raises the stakeholder count, not just the technology stakes.</p></li><li><p><strong>Tim Rains &#8212; </strong><em><strong>The AI boom is creating an explosion of new APIs</strong></em> (<a href="https://www.linkedin.com/posts/timrains_the-ai-boom-isnt-just-creating-new-systems-activity-7467636796399681537-DUbU">LinkedIn, 2 June</a>, 28 reactions). Every AI agent is an API consumer; every API is a privilege boundary. Verification debt and attack surface have a common substrate, and most enterprises have inventoried neither.</p></li></ul><div><hr></div><p><em>Trust is expensive. So is its absence.</em></p><div><hr></div><p><strong>The Verified Intelligence Briefing</strong> is written by <strong>Steve Tout</strong>, Founder &amp; CEO of <a href="https://identient.com/">Identient</a> and author of <em>The CISO on the Razor&#8217;s Edge</em>. It draws from the curated <em>Daily Signal</em> corpus and the Verified Intelligence framework introduced in <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a></em>.</p><p>If this issue clarified something for you, <strong>forward it to one colleague who owns part of the control plane</strong>. New here? <a href="https://claude.ai/chat/1ada3ce9-905d-4913-a01b-7218520c5472#">Subscribe</a> to get The Briefing every Friday morning.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p>Reply or comment with the question you&#8217;d want answered in next week&#8217;s issue &#8212; your prompt may become Boardroom Prompt #1.</p><p>Connect with Steve: <a href="https://www.linkedin.com/in/stevetout">LinkedIn</a> &#183; <a href="https://identient.com/">identient.com</a> &#183; <a href="https://stevetout.com/">stevetout.com</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tg2k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tg2k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tg2k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tg2k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tg2k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tg2k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg" width="716" height="717" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/cc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:717,&quot;width&quot;:716,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:229128,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/200810046?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tg2k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 424w, https://substackcdn.com/image/fetch/$s_!tg2k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 848w, https://substackcdn.com/image/fetch/$s_!tg2k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!tg2k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fcc55ff3f-2e5c-422e-9d31-7a1c07814fd1_716x717.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Verified Intelligence Briefing: Issue 02 · May 23–29, 2026 ]]></title><description><![CDATA[The week the layers that catch verification debt quietly stepped back.]]></description><link>https://www.strategylayer.com/p/the-verified-intelligence-briefing-058</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-verified-intelligence-briefing-058</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Fri, 29 May 2026 17:23:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-H09!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-H09!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-H09!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!-H09!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!-H09!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!-H09!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-H09!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png" width="1254" height="1254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1254,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/199771046?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-H09!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!-H09!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!-H09!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!-H09!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ca4cd7d-b778-4dee-b0b5-526900e9d68c_1254x1254.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-verified-intelligence-briefing-058?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-verified-intelligence-briefing-058?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p></p><p><em>The weekly read on verification debt &#8212; for leaders who own the control plane.</em></p><div><hr></div><h2>The Pattern</h2><p>This was the week three different parts of the verification system quietly stepped back at the same time.</p><p>The Federal Reserve, FDIC, and OCC replaced the bedrock SR 11-7 model risk guidance with SR 26-2 in April 2026. Buried in the text: generative AI and agentic AI are &#8220;too novel and rapidly evolving&#8221; &#8212; meaning they are explicitly carved out of the framework. Banks operating these systems no longer have specific federal model-risk guidance. The regulator stepped out.</p><p>Wharton researchers published a 1,372-person, 9,593-trial study that named the cognitive mechanism behind invisible verification debt. When AI was right, performance jumped 25 points. When it was wrong, performance fell 15 points below baseline &#8212; because people stopped checking. They called it cognitive surrender. The human stopped verifying.</p><p>And the Big Four quietly published the numbers. PwC has deployed 250+ internal agents. EY built 50,000 agents in nine months. IBM reports $4.5 billion in productivity gains. Accenture is shipping toward 100+ industry agent solutions by year-end. The Big Four scaled past the point where any individual control can catch a bad output. The institutional control stepped back.</p><p>The pattern: <strong>the verification layer that was supposed to catch the debt is disengaging &#8212; by exemption, by surrender, and by scale.</strong></p><p>Last week the briefing&#8217;s thesis was that verification debt was migrating from the model layer to the contract layer. This week sharpens the picture. Verification debt isn&#8217;t just migrating &#8212; the actors who were supposed to hold the audit chain accountable are letting go of it. The regulator says it&#8217;s too new. The human says it&#8217;s too good. The Big Four say it&#8217;s too operational to slow down.</p><p><strong>Thesis.</strong> Three retreats. One implication. The institutions that build their own verification infrastructure now will be the only ones holding the chain when it matters.</p><div><hr></div><h2>The Signals</h2><h3>01 &#183; The Fed, FDIC, and OCC quietly exempted agentic AI from model risk guidance</h3><p><em>The Signal.</em> Alexandra C. surfaced a development that ran with under a hundred reactions but reshapes federal AI oversight in banking. SR 26-2, which replaced SR 11-7 in April 2026, explicitly states that generative and agentic AI models are &#8220;too novel and rapidly evolving&#8221; &#8212; and carves them out of the framework (<a href="https://www.linkedin.com/posts/alextwittau_aigovernance-financialservices-sr262-activity-7464231218155454464-RweL">Alexandra C., LinkedIn, 24 May</a>, 36 reactions).</p><p><em>The Lineage Gap.</em> This is the most consequential signal of the week. SR 11-7 governed every model-risk decision in U.S. banking for over a decade. SR 26-2 governs everything except the systems carrying the most risk. The Five Questions don&#8217;t disappear with the regulation &#8212; <em>Who created it? Who trained it? Who authorized it? Who can revoke it? Who is it economically aligned to?</em> &#8212; they migrate from &#8220;regulatory documentation requirement&#8221; to &#8220;institutional self-imposed standard.&#8221; That standard now belongs to the chief risk officer alone, with no anchor in federal guidance to defend it when the audit committee asks why their bank is more conservative than the rule requires.</p><p><em>Boardroom Prompt.</em> Who in your institution is responsible for governing the AI systems your federal regulator just declined to govern?</p><h3>02 &#183; Wharton named cognitive surrender &#8212; the mechanism behind invisible verification debt</h3><p><em>The Signal.</em> Wharton researchers published a study of 1,372 participants across 9,593 reasoning trials. When AI was right, performance jumped 25 points. When AI was wrong, performance fell 15 points <em>below</em> baseline &#8212; because people stopped checking (<a href="https://www.linkedin.com/posts/michael-lee-4049593_wharton-just-found-the-ai-risk-almost-no-activity-7465744955030835200-EeYx">Lee, LinkedIn, 28 May</a>, 140 reactions). The researchers called it cognitive surrender.</p><p><em>The Lineage Gap.</em> &#8220;Human in the loop&#8221; was supposed to be the firebreak. Wharton just proved the firebreak burns down quietly when AI is confident. The Four Pillars say verification needs grounding, scope, provenance, and drift awareness &#8212; but those pillars only operate if a human is actively interrogating the output. Cognitive surrender means the human stops asking. The implication for governance is structural: requiring &#8220;human review&#8221; as a control is meaningless unless the human is materially incentivized to disagree. Most organizations measure their human reviewers on throughput. Cognitive surrender makes throughput easy and verification rare.</p><p><em>Boardroom Prompt.</em> Are the humans in your AI loop incentivized to catch the AI&#8217;s errors, or to clear the queue?</p><h3>03 &#183; The Big Four turned internal agents into a repeatable business</h3><p><em>The Signal.</em> Guillermo Flor published the numbers underneath last week&#8217;s KPMG-Anthropic headline. PwC has deployed 250+ agents internally. EY built 50,000 agents in nine months. IBM reports $4.5 billion in productivity gains. Accenture is shipping toward 100+ industry agent solutions by year-end (<a href="https://www.linkedin.com/posts/guillermoflor_the-big-four-are-quietly-turning-enterprise-activity-7464687301797994497-ClaX">Flor, LinkedIn, 25 May</a>).</p><p><em>The Lineage Gap.</em> Last week&#8217;s KPMG-Anthropic alliance was the marquee event. This week&#8217;s numbers are the rest of the playbook. The Big Four have moved past pilots into productized internal agent deployment &#8212; and the client-side implications haven&#8217;t caught up. When a Big Four engagement uses one of fifty thousand internal agents to produce work product the client signs, the chain of provenance crosses the same three corporate boundaries we mapped last week. The Five Questions break in the same places. The difference this week is scale. At 50,000 agents, no individual reviewer catches the bad output. Only the system can &#8212; and the client doesn&#8217;t operate the system.</p><p><em>Boardroom Prompt.</em> When your Big Four advisor deploys 50,000 internal agents and one of them produces work you&#8217;ll sign, what control do you have that the institution still does?</p><h3>04 &#183; Microsoft is repricing its own AI consumption</h3><p><em>The Signal.</em> Dr. Dinesh Chandrasekar&#8217;s piece (1,026 reactions, the week&#8217;s highest) argued that Microsoft &#8212; the company that anchored the AI gold rush &#8212; is cutting back internal Claude Code adoption because token economics are starting to hurt. Employees are reportedly being moved back toward GitHub Copilot. The article points at unit economics, Copilot adoption gaps, and dependency on OpenAI as cracks in the position (<a href="https://www.linkedin.com/posts/dineshchandrasekar_for-nearly-three-years-microsoft-stood-at-activity-7464121389210550273-x-hf">Chandrasekar, LinkedIn, 24 May</a>).</p><p><em>The Lineage Gap.</em> The concentration we&#8217;ve been tracking is not a stable equilibrium. When even Microsoft is rationing how much frontier AI it uses internally, the institutions further down the food chain &#8212; banks, retailers, healthcare systems &#8212; are about to encounter the same conversation. Verification debt looks different when model usage gets tiered: which decisions get the expensive model, which get the cheaper one, and what controls travel with each. Most enterprises haven&#8217;t built that tiering yet. They have flat AI policies. Token economics is about to force the question, and the answer will become a board-level conversation in Q3.</p><p><em>Boardroom Prompt.</em> When your finance team caps AI spend next quarter, which decisions in your business lose access to the verified model &#8212; and who decides?</p><h3>05 &#183; 88% of executives are investing in AI. 6% are changing the operating model.</h3><p><em>The Signal.</em> Alex Bar&#225;dy surfaced the statistic that crystallizes the year&#8217;s strategy-execution gap. 88% of executives are investing in AI. Only 6% are changing their operating model. The corollary drawn from multiple consulting reports: layering AI over legacy operations delivers marginal improvement; AI inside redesigned operations delivers transformation (<a href="https://www.linkedin.com/posts/alexbarady_88-of-executives-are-investing-in-ai-only-activity-7464631605865807872-NFQ8">Bar&#225;dy, LinkedIn, 25 May</a>, 388 reactions).</p><p><em>The Lineage Gap.</em> The 88/6 spread is verification debt expressed as a financial position. The 88% have purchased AI capability without redesigning the lineage chain that runs through it. They will report activity to the board for two more quarters before a regulator, a customer, or a partner makes them produce evidence. The 6% are doing the harder work of designing the operating layer underneath: who owns the data, who authorizes the agent, who reviews the output, who escalates the exception. That layer is what makes the Five Questions answerable. Without it, the institution is buying AI capability and inheriting AI exposure on the same purchase order.</p><p><em>Boardroom Prompt.</em> Of every dollar your institution has committed to AI this year, what percentage went to redesigning the operating model &#8212; and what percentage went to buying tools?</p><h3>06 &#183; Forward Deployed Engineer is the most contested role in AI</h3><p><em>The Signal.</em> Andreas Horn&#8217;s piece (601 reactions, second-highest of the week) wrote that Forward Deployed Engineer is the most contested role in AI right now. Palantir invented the term. OpenAI, Anthropic, Google, Microsoft, AWS, Databricks, Salesforce, and Scale are hiring hundreds. OpenAI mid-level packages: $520K&#8211;$780K base. The role exists because the model alone does not work in production (<a href="https://www.linkedin.com/posts/andreashorn1_the-most-contested-job-title-in-ai-right-activity-7465268985220038656-N2kg">Horn, LinkedIn, 27 May</a>).</p><p><em>The Lineage Gap.</em> The labor market is telling the truth the strategy decks are still working around. The model is the easy part. Getting the model to produce defensible output in a specific enterprise context &#8212; that requires a person whose job is to wire grounding, scope, provenance, and drift awareness into the deployment. Forward Deployed Engineers are the Four Pillars expressed as headcount. The institutions that hire them inside (not just rent them from the model provider) keep the verification capability in-house. The institutions that don&#8217;t will pay $780K to a vendor employee for every consequential AI workflow they deploy &#8212; and they will not own the audit trail when that engineer rotates off the account.</p><p><em>Boardroom Prompt.</em> For every consequential AI deployment in your organization, who inside the institution owns the deployment context &#8212; and what is their reporting line?</p><h3>07 &#183; Your agent isn&#8217;t the model. It&#8217;s the harness around it.</h3><p><em>The Signal.</em> Brij Kishore Pandey (221 reactions) made the architectural case for why agent quality lives outside the model. Two teams using the same Claude, OpenAI, or Gemini &#8212; one ships an agent that runs for hours; the other crashes on turn three. The difference is the harness: orchestration, memory, retrieval, tools, guardrails, evaluation, error handling, observability (<a href="https://www.linkedin.com/posts/brijpandeyji_%F0%9D%97%AC%F0%9D%97%BC%F0%9D%98%82%F0%9D%97%BF-%F0%9D%97%AE%F0%9D%97%B4%F0%9D%97%B2%F0%9D%97%BB%F0%9D%98%81-%F0%9D%97%B6%F0%9D%98%80%F0%9D%97%BB%F0%9D%98%81-%F0%9D%98%81%F0%9D%97%B5%F0%9D%97%B2-%F0%9D%97%BA%F0%9D%97%BC-activity-7465055310014193664-W-LX">Pandey, LinkedIn, 26 May</a>).</p><p><em>The Lineage Gap.</em> Pandey&#8217;s harness is the same architectural truth Forward Deployed Engineers represent in the labor market. The model is interchangeable. The harness is not. And the harness is where verification lives &#8212; every Five Questions answer is implemented in a harness component, not in the model. <em>Who authorized it?</em> is policy enforcement in the harness. <em>Who can revoke it?</em> is the kill switch in the harness. <em>Who is it economically aligned to?</em> is the routing logic in the harness. Institutions that buy &#8220;an AI&#8221; are buying a model. Institutions that govern AI are building a harness. The first costs money. The second creates the audit trail.</p><p><em>Boardroom Prompt.</em> When you tell the board your institution has deployed AI, are you describing the model &#8212; or the harness around it?</p><h3>08 &#183; The real risk in AI agents is not capability. It is control.</h3><p><em>The Signal.</em> Rakesh Gohel&#8217;s piece (519 reactions) argued the governing question for enterprise AI agents is no longer whether they can perform tasks &#8212; it is whether they can do so reliably, safely, and within defined business boundaries. He laid out five board-level control domains: data governance, model risk management, identity and access, observability, and lifecycle management (<a href="https://www.linkedin.com/posts/rakeshgohel01_the-real-risk-in-ai-agents-is-not-capability-activity-7464653980141244416-Atst">Gohel, LinkedIn, 25 May</a>).</p><p><em>The Lineage Gap.</em> Gohel&#8217;s five control domains read as the same framework this briefing is built on, articulated from a different angle. Data governance is grounding. Identity and access is the runtime &#8220;who-authorized-it&#8221; layer. Observability is provenance &#8212; the trace of what happened. Lifecycle management is drift awareness over time. Model risk management is what SR 11-7 used to require and SR 26-2 just stopped requiring for the riskiest systems. The five domains will become the de facto standard for enterprise AI governance over the next 18 months. The institutions that build them now beat the regulator that eventually mandates them &#8212; and they avoid the question of which regulator will mandate them first.</p><p><em>Boardroom Prompt.</em> If your audit committee asked tomorrow to see your maturity score across data governance, identity, observability, model risk, and lifecycle &#8212; what number would you put on each?</p><h3>09 &#183; Okta validated AI agent identity. It shipped half the category.</h3><p><em>The Signal.</em> Martin Gee wrote that Okta&#8217;s AI agent identity announcement validated the entire category and shipped only half of it. The Okta + Anthropic announcement &#8212; ISPM for Claude, Okta for AI Agents, MCP Bridge &#8212; treats token issuance as delegation. It isn&#8217;t. A scoped token tells you what an agent <em>could do</em> at the perimeter; it doesn&#8217;t tell you who delegated that authority, at what scope, for what task, or for how long (<a href="https://www.linkedin.com/posts/martingee_okta-just-validated-the-entire-ai-agent-identity-activity-7465165631072407553-v-4D">Gee, LinkedIn, 26 May</a>).</p><p><em>The Lineage Gap.</em> This is the direct extension of last week&#8217;s Okta signal. The major IAM incumbent named the right category &#8212; agents need identity. But there is a runtime authority layer underneath identity that the announcement does not address. The distinction matters: identity tells you who an agent is; authority tells you what that agent has the right to do, right now, in this context, on whose behalf. Without runtime authority governance, every Okta-authenticated agent looks identical to the policy engine. The Five Questions need authority answers, not just identity answers. Identity is where the perimeter ends. Authority is where lineage begins.</p><p><em>Boardroom Prompt.</em> For every AI agent operating in your environment, do you log who delegated its authority &#8212; or just whose token authenticated it?</p><h3>10 &#183; The Marine Corps just made AI literacy mandatory across the force</h3><p><em>The Signal.</em> The U.S. Marine Corps announced in May 2026 that all active duty and reserve Marines must complete a foundational AI course by the end of the year. The objective: not technical specialization, but shared operational understanding, common vocabulary, and ethical deployment at scale (<a href="https://www.linkedin.com/posts/clara-hawking-ba9123149_the-united-states-marine-corps-has-just-made-activity-7464590749775478784-zX1p">Hawking, LinkedIn, 25 May</a>, 54 reactions).</p><p><em>The Lineage Gap.</em> The Marines understand something most enterprises still don&#8217;t: governance fails when the people inside the institution don&#8217;t share a vocabulary. You cannot enforce the Five Questions across a workforce that does not know they exist. You cannot operationalize the Four Pillars across teams that interpret each pillar differently. AI literacy isn&#8217;t an HR initiative &#8212; it is the precondition for governance at scale. The institutions that fund mandatory AI literacy across their workforce now are buying themselves the substrate every other control sits on top of. The ones that don&#8217;t will keep treating governance as a checklist the rest of the organization quietly ignores.</p><p><em>Boardroom Prompt.</em> What percentage of your workforce can explain to your audit committee what verification debt is and why it matters?</p><div><hr></div><h2>The Verification Debt Tracker</h2><p><em>The 2&#215;2 from <a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a>. Signal counts this week, with direction vs. last issue.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!kuOZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!kuOZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 424w, https://substackcdn.com/image/fetch/$s_!kuOZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 848w, https://substackcdn.com/image/fetch/$s_!kuOZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 1272w, https://substackcdn.com/image/fetch/$s_!kuOZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!kuOZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png" width="1360" height="880" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:880,&quot;width&quot;:1360,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:91671,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/199771046?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!kuOZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 424w, https://substackcdn.com/image/fetch/$s_!kuOZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 848w, https://substackcdn.com/image/fetch/$s_!kuOZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 1272w, https://substackcdn.com/image/fetch/$s_!kuOZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb7f80782-4f06-491d-a960-ecba445a56c1_1360x880.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The <strong>Operational / Governed</strong> quadrant kept heating as the infrastructure response crystallized &#8212; Forward Deployed Engineers, the harness conversation, Gohel&#8217;s five controls, Martin Gee&#8217;s runtime authority argument. The <strong>Operational / Feral</strong> quadrant jumped sharply on the back of one signal that matters more than its reaction count: SR 26-2 quietly carved generative and agentic AI out of federal banking model-risk guidance. Watch that quadrant climb through Q3 as the implications surface in compliance roadmaps and rating-agency conversations.</p><div><hr></div><h2>Monday Morning</h2><p>Three things to do next week.</p><p><strong>01 &#183; Audit your model-risk framework against SR 26-2.</strong> Federal guidance just stopped covering your most consequential AI systems. The institutions that document their own governance posture before a regulator asks will define the standard the regulator eventually adopts. Start with your highest-risk agentic workflow and write the documentation as if the rule still applied.</p><p><strong>02 &#183; Build a verification-incentive review for every human-in-the-loop control.</strong> Wharton just proved that asking humans to verify AI without rewarding disagreement makes the control invisible. Change one human-AI workflow this week so reviewers are measured on catches, not throughput. If the reviewer never disagrees, the control isn&#8217;t a control.</p><p><strong>03 &#183; Inventory your harness.</strong> Not your models. Not your vendors. The harness &#8212; orchestration, retrieval, identity, observability, policy enforcement, evaluation. If you cannot draw it on a whiteboard for your most consequential AI deployment, you don&#8217;t yet have a deployment. You have a demo with executive sponsorship.</p><div><hr></div><h2>The Reading Room</h2><p>Three pieces worth your time this week.</p><ul><li><p><strong>David Rold&#225;n Mart&#237;nez &#8212; </strong><em><strong>Enterprise AI Playbook</strong></em> (<a href="https://www.linkedin.com/posts/davidroldanmartinez_enterprise-ai-playbook-activity-7465658735462633472-tDp7">LinkedIn, 28 May</a>, 45 reactions). Stanford Digital Economy Lab finding that 42% of foundation-model deployments are interchangeable and 77% of the hardest enterprise AI problems are organizational. The empirical foundation underneath this week&#8217;s pattern.</p></li><li><p><strong>Pat Gelsinger &#8212; </strong><em><strong>On Chris Olah, Pope Leo XIV, and AI and human dignity</strong></em> (<a href="https://www.linkedin.com/posts/patgelsinger_anthropic-co-founder-chris-olahs-remarks-activity-7465798609540648962-JJU5">LinkedIn, 28 May</a>, 81 reactions). Continuation of last week&#8217;s signal of AI as a layer of influence &#8212; now with the Vatican publishing an encyclical and Anthropic&#8217;s co-founder responding to it. The moral framework underneath the governance one.</p></li><li><p><strong>Alexandra C. &#8212; </strong><em><strong>Distributed AI governance in the United States</strong></em> (<a href="https://www.linkedin.com/posts/alextwittau_aigovernance-aicompliance-techpolicy-activity-7465680770339250178-22Ej">LinkedIn, 28 May</a>, 15 reactions). Maps the six overlapping layers of U.S. AI regulatory architecture &#8212; sectoral, state, common-law, executive, agency, and standards. Read this if you have ever told your board &#8220;the U.S. has no AI law.&#8221; It has six.</p></li></ul><div><hr></div><p><em>Trust is expensive. So is its absence.</em></p><div><hr></div><p><strong>The Verified Intelligence Briefing</strong> is written by <strong>Steve Tout</strong>, Founder &amp; CEO of <a href="https://identient.com">Identient</a> and author of <em>The CISO on the Razor&#8217;s Edge</em>. It draws from the curated <em>Daily Signal</em> corpus and the Verified Intelligence framework introduced in <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a></em>.</p><p>If this issue clarified something for you, <strong>forward it to one colleague who owns part of the control plane</strong>. New here? Subscribe to get The Briefing every Friday morning.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p>Reply or comment with the question you&#8217;d want answered in next week&#8217;s issue &#8212; your prompt may become Boardroom Prompt #1.</p><p>Connect with Steve: <a href="https://www.linkedin.com/in/stevetout">LinkedIn</a> &#183; <a href="https://identient.com">identient.com</a> &#183; <a href="https://stevetout.com">stevetout.com</a></p>]]></content:encoded></item><item><title><![CDATA[The Third Pillar of Identity Just Shipped]]></title><description><![CDATA[An open protocol for verifying responsibility in the era of autonomous agents.]]></description><link>https://www.strategylayer.com/p/the-third-pillar-of-identity-just</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-third-pillar-of-identity-just</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Mon, 25 May 2026 05:52:39 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!UXRR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!UXRR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!UXRR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!UXRR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!UXRR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!UXRR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!UXRR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:108260,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/199149009?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!UXRR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!UXRR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!UXRR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!UXRR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b5ba749-7784-4e41-a270-8754bc4541c2_1200x630.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>For twenty years, enterprise identity has been a two-question system. <em>Who are you? What can you do?</em> AuthN and AuthZ &#8212; designed for the world where a human sits at a terminal, signs in, and clicks. That world is ending.</p><p>When an AI agent acts, the questions that mattered for humans are no longer sufficient. A token can prove which credential made the call. It cannot prove who is <em>responsible</em> for the action that followed. In a fleet of autonomous agents that chain tools, re-plan, and execute overnight on behalf of people and organizations, the gap between <em>authenticated</em> and <em>accountable</em> is the place where consequence lives.</p><p>Today I&#8217;m publishing <strong>AuthR v0.1</strong> &#8212; Authorship Representation &#8212; as an open protocol for closing that gap.</p><p><strong>GitHub:</strong> <a href="https://github.com/identient/authr">github.com/identient/authr</a> </p><p><strong>Interactive playground:</strong> <a href="https://playground.identient.com/">playground.identient.com</a></p><p>The working paper, the v0.1 specification, the JSON Schema, and a runnable Python reference implementation are all live. The playground lets you mint a root authorship record, extend it to a sub-agent, watch the scope narrow, and watch the verifier reject a scope-widening attempt &#8212; sixty seconds, no install.</p><h2>The problem, concretely</h2><p>A CFO authorizes a $250K supplier payment. Her verified digital twin passes the work to a treasury orchestrator agent. The orchestrator delegates validation to a narrower sub-agent. The sub-agent is prompt-injected and tries to escalate to <code>wire.cancel</code>. The wire service is about to execute.</p><p>Under OAuth&#8217;s On-Behalf-Of pattern alone, the wire service has no structural way to know the original authorization didn&#8217;t include <code>cancel</code>. The token validates. The access claim is intact. The damage is reconstructed at the audit-log level, three weeks later.</p><p>Under AuthR, the verifier rejects the attempt <em>before</em> the request reaches the wire service. Scope attenuation is monotonic and structural &#8212; a child&#8217;s scope MUST be a strict subset of its parent&#8217;s, enforced at every hop, in every conformant implementation. Authorship is preserved across the chain. Intent travels with the work. Provenance is signed end to end.</p><p>This is not a feature added to OAuth. It is a third pillar sitting alongside it:</p><ul><li><p><strong>AuthN</strong> asks <em>who are you.</em></p></li><li><p><strong>AuthZ</strong> asks <em>what can you do.</em></p></li><li><p><strong>AuthR</strong> asks <em>who is responsible for what was done.</em></p></li></ul><h2>What&#8217;s in v0.1</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!onNB!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!onNB!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!onNB!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!onNB!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!onNB!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!onNB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4047235,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/199149009?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!onNB!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!onNB!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!onNB!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!onNB!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cedf509-7499-4f4c-a5b2-9c8cf05926c5_2752x1536.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AuthR v0.1 architecture: from grounded human intent, through agent execution with monotonic scope narrowing, to verification at every enforcement point. OAuth OBO answers "can this call be made"; AuthR answers "who is responsible for this action."</figcaption></figure></div><p>Six primitives &#8212; <em>Author, Actor, Intent, Scope, Provenance, Drift.</em> Three operations &#8212; <em>issue, extend, verify.</em> Six invariants every chain must satisfy. A three-plane architecture (Control, Execution, Enforcement) that separates issuance from execution from enforcement, so a compromised agent cannot widen its own authority no matter how its prompt evolves at runtime.</p><p>The reference implementation is in Python with Ed25519 signatures and canonical JSON. The protocol is designed to sit <em>above</em> existing identity standards &#8212; OAuth tokens, SAML assertions, SPIFFE workload IDs, W3C Verifiable Credentials &#8212; not replace any of them. The work to do is integration, not migration.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-third-pillar-of-identity-just?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-third-pillar-of-identity-just?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-third-pillar-of-identity-just?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>What v0.1 is, and isn&#8217;t</h2><p>v0.1 is deliberately a draft. The point of publishing this early is to put a concrete enough artifact in front of practitioners, security architects, and standards-body veterans that they will <em>argue with it.</em> The fastest way to help AuthR is to argue with it. The next fastest is to break it.</p><p>Specific contributions wanted: ports to <strong>C#/.NET, TypeScript, Go, and Rust</strong>; adversarial reviews of the threat model; use case proposals from teams building agentic systems in production; feedback from CoSAI, OpenID Foundation, W3C, and CNCF veterans on the standards-track path.</p><h2>Acknowledgments</h2><p>Two people sharpened this version of the work in ways that show in the protocol itself.</p><p><strong><a href="https://www.linkedin.com/in/paulrchapman/">Paul Chapman</a></strong> (VP Business Strategy, Cisco; former CIO, Box) for the executive-level conversation that clarified what auditability has to look like when employees are no longer the only actors in the system &#8212; and what happens to enterprise operating models when one human is supervising a hundred agents instead of a hundred employees.</p><p><strong><a href="https://www.linkedin.com/in/evemaler/">Eve Maler</a></strong> (co-inventor of SAML; longtime steward of identity standards, and founder of <a href="https://www.vennfactory.com/">Venn Factory</a>) for the engaging conversations and constructive feedback across both AuthR and the broader Verified Intelligence work it sits inside. Eve has been a tireless champion for open standards her entire career; her early conviction that AuthR mattered specifically for agent governance gave me the confidence to push this version of the work into public form.</p><div><hr></div><p>I&#8217;ve been writing toward this protocol for months. <em><a href="https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html">The Death of Identity as We Know It</a></em> in CIO was the framing of the problem. <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From AI to Verified Intelligence</a></em> on identient.com was the framing of the operating model that runs on top of it. AuthR is the protocol that makes both possible.</p><p>If you&#8217;re building in this space, or evaluating where to place a bet, the repository is the artifact. Read it, run it, file an issue with what&#8217;s wrong.</p><p>Trust is expensive. So is its absence.</p><p>&#8212; Steve</p><p>Connect with me on: <a href="https://www.linkedin.com/in/stevetout">LinkedIn</a> &#183; <a href="https://www.identient.com">identient.com</a> &#183; <a href="https://www.stevetout.com">stevetout.com</a></p><p>&#128073; As a bonus, my latest piece for CIO Online, <em><strong>The Death of Identity as we Know It</strong></em>, is available <a href="https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zfYm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zfYm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg" width="562" height="562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:562,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;1778699852774.jpg&quot;,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="1778699852774.jpg" srcset="https://substackcdn.com/image/fetch/$s_!zfYm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p></p>]]></content:encoded></item><item><title><![CDATA[The Verified Intelligence Briefing: Issue 01 · May 15–21, 2026 ]]></title><description><![CDATA[The week vendor alliances quietly transferred the audit trail.]]></description><link>https://www.strategylayer.com/p/the-verified-intelligence-briefing</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-verified-intelligence-briefing</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Fri, 22 May 2026 23:13:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!922C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!922C!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!922C!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!922C!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!922C!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!922C!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!922C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png" width="1254" height="1254" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1254,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1168453,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/198904433?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!922C!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 424w, https://substackcdn.com/image/fetch/$s_!922C!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 848w, https://substackcdn.com/image/fetch/$s_!922C!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 1272w, https://substackcdn.com/image/fetch/$s_!922C!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2047a1ff-0b94-4318-834b-b90ad8dd6817_1254x1254.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-verified-intelligence-briefing?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-verified-intelligence-briefing?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><h2>Welcome to The Verified Intelligence Briefing</h2><p>Every Friday, this newsletter does one thing.</p><p>It reads the week through a single lens &#8212; <strong>verification debt</strong>, the gap between how fast AI generates intelligence and how fast your organization can verify it &#8212; and reports back what changed.</p><p>That gap is the most important number on your balance sheet that nobody is measuring. It compounds quietly while AI is being demoed, piloted, and embedded into work product. It surfaces loudly when a regulator, insurer, or partner asks a question the contract was never built to answer.</p><p>The reason for a weekly is simple. Daily AI news is signal-poor. Most of it is noise about the next model, the next benchmark, the next funding round. The <em>pattern</em> &#8212; the slow accumulation of unverified dependencies, the migration of governance gaps from one layer of the stack to the next, the moment a regulator catches up &#8212; only becomes visible across a week of signals read together. That is what this briefing is for.</p><p><strong>Each issue gives you five things in the same order.</strong></p><ol><li><p><strong>The Pattern.</strong> One thesis on what the week meant, in 250 words. Read this if you read nothing else.</p></li><li><p><strong>The Signals.</strong> Ten numbered items. Each with <em>The Signal</em> (the fact), <em>The Lineage Gap</em> (where the verification debt is hiding), and <em>The Boardroom Prompt</em> (the question to bring to your next meeting).</p></li><li><p><strong>The Verification Debt Tracker.</strong> The taxonomy from <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a></em>, scored against this week&#8217;s signals. A visual you can show your board.</p></li><li><p><strong>Monday Morning.</strong> Three things to do next week. Always three. Always actionable.</p></li><li><p><strong>The Reading Room.</strong> Three pieces from named operators worth your time.</p></li></ol><p><strong>This briefing is written for the people who own the control plane</strong> &#8212; CIOs, CISOs, CTOs, CFOs, and CEOs whose signature is on the AI decisions their institutions cannot yet fully trace. If you are responsible for an outcome that an AI helped produce, this is for you.</p><p>Issue 01 starts now.</p><div><hr></div><h2>The Pattern</h2><p>Three things converged this week, and the shape they made together was unmistakable.</p><p>A Big Four firm embedded a frontier AI provider directly into its client delivery platform. A different Big Four firm &#8212; same playbook, different week &#8212; pulled a published report after AI hallucinations made it into the footnotes. And a community bank in regulated industry filed an 8-K with the SEC because an employee uploaded customer Social Security numbers to an unauthorized AI chatbot.</p><p>Three different stories. One pattern. All three are what verification debt looks like when it stops being theoretical and starts being filed, retracted, or signed.</p><p>This is what concentration looks like in practice. When a global advisory firm builds AI into work product, the institution carrying the regulatory liability inherits a reasoning chain that crosses three corporate boundaries before it reaches the model. ISO certifications cover the vendor&#8217;s obligations, not yours. Indemnification clauses dispute the bill, not the breach. And the audit committee asks a question &#8212; <em>how was this decision reached?</em> &#8212; that the vendor contract was never built to answer.</p><p>The week&#8217;s signals point at the same gap from different angles. The EU published draft guidelines that turn the verification question into a regulatory one. Pat Gelsinger framed AI as a layer of influence requiring guardrails for human flourishing. Carolyn Healey told boards to stop measuring tasks and start designing for org maturity. Gabriel Millien told them their AI security problem is a CEO problem dressed as a CISO checklist. Identity vendors announced product lines for agent attribution. Governance vendors announced runtime controls for agent swarms.</p><p>The pattern: <strong>verification debt is migrating from the model layer to the contract layer</strong>, and most organizations will not discover the exposure until a regulator, insurer, or partner surfaces it under pressure.</p><p><strong>Thesis.</strong> The vendors are consolidating. The lineage is fragmenting. The institution holding the audit risk is the one organization not at the table when those two trends compound.</p><div><hr></div><h2>The Signals</h2><h3>01 &#183; Anthropic and KPMG sign a global alliance</h3><p><em>The Signal.</em> Anthropic and KPMG announced a global alliance this week, embedding Claude directly into KPMG&#8217;s client delivery platform across the firm&#8217;s 276,000+ employees (<a href="https://www.linkedin.com/posts/guillermoflor_breaking-anthropic-just-locked-in-one-of-activity-7462540100363726851-BJGh">Flor, LinkedIn, 19 May</a>). The deal extends Claude into audit, tax, and advisory workflows that increasingly become signed work product delivered to institutional clients.</p><p><em>The Lineage Gap.</em> Five questions, three breaking. <em>Who trained it?</em> &#8212; KPMG didn&#8217;t; Anthropic did. <em>Who authorized it?</em> &#8212; KPMG procurement, but the client signs the audit. <em>Who is it economically aligned to?</em> &#8212; neither the institution carrying the regulatory liability nor the regulator who will eventually ask. When the audit committee wants to know how a conclusion was reached, the chain of provenance crosses three corporate boundaries before it touches the model. That chain is currently a contract. It is not yet a control. The first time a regulator subpoenas reasoning logs from a Big Four AI-assisted engagement will be the moment this market changes shape.</p><p><em>Boardroom Prompt.</em> When your Big Four advisor uses AI to produce work product you&#8217;ll sign, who holds the reasoning logs &#8212; them, the model provider, or you?</p><h3>02 &#183; EY unpublished a report after AI hallucinations made it to the footnotes</h3><p><em>The Signal.</em> The Financial Times reported that EY pulled a published report after hallucinated citations were discovered in the footnotes (<a href="https://www.linkedin.com/posts/baciuraluca_fun-article-in-the-ft-tonight-ey-unpublished-activity-7461156049325293569-rKU4">Baciu, LinkedIn, 15 May</a>, 164 reactions). EY framed it as a quality issue. Practitioners called it what it is &#8212; a trust failure that survived review.</p><p><em>The Lineage Gap.</em> This is what verification debt looks like when it comes due &#8212; not as a fine, but as a retraction. The interesting question isn&#8217;t how the hallucination got into the footnotes. It&#8217;s how it got past review by a firm whose entire business model is independent verification. The Four Pillars give the diagnostic: <em>grounding</em> failed (no anchor to a real source), <em>scope</em> failed (the model ranged into citation generation), <em>provenance</em> failed (the source could not be traced back), and <em>drift awareness</em> failed (no signal flagged the staleness). A signed advisory deliverable should not be able to fail all four at once. The fact that one did is the early warning, not the event.</p><p><em>Boardroom Prompt.</em> If your most expensive external assurance can be hallucinated, what is your standard for the AI you operate yourself?</p><h3>03 &#183; A community bank reported itself to the SEC over an unauthorized chatbot</h3><p><em>The Signal.</em> CB Financial Services filed an 8-K with the SEC on May 7 after an employee uploaded customer Social Security numbers to an unauthorized AI chatbot (<a href="https://www.linkedin.com/posts/julia-benson-5b246921_aigovernance-shadowai-communitybanking-activity-7462446893911031809-OkOI">Benson, LinkedIn, 19 May</a>). The breach clock started May 5. Class action attorneys filed within days.</p><p><em>The Lineage Gap.</em> This is the concrete case study every other signal in this issue is dancing around. Five Questions, all five breaking. <em>Who authorized it?</em> &#8212; no one; an employee did it. <em>Who can revoke it?</em> &#8212; nobody at the bank, because nobody at the bank had the credentials. <em>Who is it economically aligned to?</em> &#8212; a SaaS vendor outside the bank&#8217;s third-party risk inventory, with terms of service the bank never reviewed. Shadow AI in regulated industry is not a future problem. It is a filed 8-K. The institutions still running spreadsheet-based AI inventories are one upload away from the same Friday.</p><p><em>Boardroom Prompt.</em> If an employee uploaded regulated customer data to an unauthorized AI tool today, how many hours would pass before your security team knew?</p><h3>04 &#183; The EU published draft guidelines on high-risk AI classification</h3><p><em>The Signal.</em> The European Commission published draft guidelines clarifying high-risk AI system classification under the AI Act, days after EU leaders agreed to delay the compliance date to 2 December 2027 (<a href="https://www.linkedin.com/posts/oliver-patel_breaking-news-eu-publishes-guidelines-for-activity-7462489362702782464-zuGS">Patel, LinkedIn, 19 May</a>, 1,317 reactions). The guidelines focus on classification &#8212; which systems are in scope, and what obligations follow.</p><p><em>The Lineage Gap.</em> The high-risk designation is where verification debt converts from a recommendation into a regulatory obligation. The Five Questions stop being a maturity framework and start being a discovery request. <em>Who created it?</em> becomes a documentation requirement. <em>Who authorized it?</em> becomes a sign-off trail. <em>Who can revoke it?</em> becomes a kill switch with a service level. The institutions that have wired these questions into their AI governance now are buying themselves a measurable head start. The ones still treating governance as a side project will discover that the regulator&#8217;s timeline is not negotiable, and that the documentation cannot be produced retroactively in the volumes the AI Act will request.</p><p><em>Boardroom Prompt.</em> For each AI system in your stack, can you produce today the documentation a high-risk classification under the AI Act would require?</p><h3>05 &#183; Pat Gelsinger reframed AI from tool to layer of influence</h3><p><em>The Signal.</em> Pat Gelsinger wrote this week that roughly 6% of AI conversations are now about personal guidance &#8212; career, relationships, health, finances &#8212; and called for guardrails grounded in truth, dignity, and human flourishing (<a href="https://www.linkedin.com/posts/patgelsinger_how-people-ask-claude-for-personal-guidance-activity-7461078606480297984-hGEx">Gelsinger, LinkedIn, 15 May</a>, 288 reactions). The reframe matters more than the percentage. <em>AI is becoming a layer of influence, not just a tool of productivity.</em></p><p><em>The Lineage Gap.</em> When AI is a tool, governance asks <em>what did it do?</em> When AI is a layer of influence, governance has to ask <em>whose values did it act on?</em> That is a Five Questions problem at scale. <em>Who created it?</em> &#8212; the lab. <em>Who trained it?</em> &#8212; the lab, on the open internet. <em>Who is it economically aligned to?</em> &#8212; not, in most cases, the person taking its guidance. Gelsinger is naming the consumer version of the gap this briefing covers in the enterprise. The same provenance failure that lets a hallucinated citation reach an EY footnote lets a hallucinated framing reach a person making a real decision about their health. The architecture problem is the same. Only the stakes change.</p><p><em>Boardroom Prompt.</em> When the AI in your product gives a customer guidance, whose values is it acting on &#8212; and can you produce the evidence?</p><h3>06 &#183; Carolyn Healey told CXOs to stop measuring tasks and start designing org maturity</h3><p><em>The Signal.</em> Carolyn Healey published the <em>7 Stages of AI Workforce Maturity</em>, opening with McKinsey&#8217;s estimate that AI agents can already handle 44% of U.S. work hours (<a href="https://www.linkedin.com/posts/carolynhealey_mckinsey-estimates-that-ai-agents-can-already-activity-7462138738173808640-A-0k">Healey, LinkedIn, 18 May</a>, 338 reactions). Her argument: <em>Tasks do not transform organizations. Org design does.</em></p><p><em>The Lineage Gap.</em> The maturity model maps cleanly onto the verification debt curve. The early stages &#8212; task assistance, scattered adoption &#8212; are where verification debt is invisible because no decision of consequence has been made yet. The later stages &#8212; function reinvention, agent-driven workflows &#8212; are where the debt comes due, because every consequential decision now has to be defensible. Most organizations are reporting at Stage 2 to a board that needs them governing at Stage 5. The reporting gap is the governance gap. Closing it is what turns AI activity into AI accountability &#8212; and what turns the conversation with the board from theater into oversight.</p><p><em>Boardroom Prompt.</em> When you next brief the board on AI, are you reporting tasks automated, or are you reporting governed economic outcomes you can defend?</p><h3>07 &#183; Gabriel Millien named the failure mode every AI security program shares</h3><p><em>The Signal.</em> Gabriel Millien wrote that he has audited AI security programs at four Fortune 500 companies and the failure mode is identical every time (<a href="https://www.linkedin.com/posts/gabriel-millien_your-board-sees-this-as-a-ciso-problem-activity-7461030137028067328-DVBf">Millien, LinkedIn, 15 May</a>, 173 reactions). Ten pillars land on the CISO&#8217;s desk. The CISO can execute three of them. The other seven need cross-functional sponsorship that never arrives. <em>&#8220;Your board sees this as a CISO problem. It&#8217;s actually a CEO problem dressed up as a security checklist.&#8221;</em></p><p><em>The Lineage Gap.</em> The structural diagnosis is correct and the polite version of it is overdue. Data lineage cannot be enforced by security alone. Model risk management cannot be enforced by security alone. Agent attribution cannot be enforced by security alone. The Five Questions all require a sponsor outside the CISO&#8217;s authority for an answer to even exist. When the CISO is the only senior leader accountable for an outcome that requires legal, data, procurement, and engineering to act together, the program stalls &#8212; and the board interprets the stall as a CISO performance problem. It is not. It is a CEO architecture problem. The institutions that get this right move AI governance to a dedicated cross-functional body chaired above the CISO. The ones that don&#8217;t will eventually hire a third CISO in five years.</p><p><em>Boardroom Prompt.</em> Who in your C-suite owns the seven AI security pillars your CISO cannot execute alone?</p><h3>08 &#183; Alexandra C. named the vendor liability gap explicitly</h3><p><em>The Signal.</em> Alexandra C. wrote that financial institutions are signing third-party AI contracts that look clean on paper and expose them entirely in practice (<a href="https://www.linkedin.com/posts/alextwittau_aigovernance-financialservices-vendorrisk-activity-7462056929348165632-8Th0">Alexandra C., LinkedIn, 18 May</a>). When a vendor demonstrates a platform, legal reviews the contract, and compliance ticks the boxes &#8212; but nobody asks whether the institution can reconstruct the reasoning chain when a regulator does.</p><p><em>The Lineage Gap.</em> This is the Anthropic-KPMG signal seen from the institution&#8217;s side of the table. Vendor procurement is generating invisible liability because no one in the signing process asks the verification question. ISO certifications cover the vendor&#8217;s obligations, not yours. The legal review confirms the contract is enforceable, not that the AI is auditable. The compliance review confirms the boxes are ticked, not that the boxes are the right ones. When the regulator arrives, the institution faces the enforcement panel and the vendor faces a contract dispute. Those are not the same exposure. The contracts being signed today are creating verification debt that will mature into regulatory liability across the next twelve months.</p><p><em>Boardroom Prompt.</em> In your last three AI vendor contracts, was the right to demand reasoning logs written in &#8212; or was it assumed?</p><h3>09 &#183; Okta announced agent IdP and Bedrock AgentCore integration</h3><p><em>The Signal.</em> Okta announced two product moves this week &#8212; Okta for AI Agents now integrates with Amazon Bedrock AgentCore, and Okta for AI Agents can act as your agent identity provider alongside your existing human IdP (<a href="https://www.linkedin.com/posts/malloryswordglenn_okta-expands-ai-agent-security-to-support-activity-7460778240014581762-giCj">Glenn, LinkedIn, 14 May</a>, 231 reactions). The shorthand: agents are getting first-class identity in the IAM stack, not bolted on.</p><p><em>The Lineage Gap.</em> This is the access-to-authorship shift becoming infrastructure. For thirty years, IAM was built around the assumption that identity equals login. That model held when the actor at the other end was a human with a session. It breaks the moment the actor is an agent acting on a human&#8217;s behalf &#8212; because the question shifts from <em>who is allowed in?</em> to <em>who is behind this decision?</em> Okta giving agents an IdP is the first credible move from a major incumbent to put attribution where authorship is happening. The institutions that adopt early get a registry they can govern. The institutions that wait keep a contract they cannot.</p><p><em>Boardroom Prompt.</em> When an agent in your environment makes a consequential decision tomorrow, can you name the human whose authority it was acting under?</p><h3>10 &#183; Saidot launched an agent-first governance posture</h3><p><em>The Signal.</em> Saidot introduced Agent-First AI Governance this week, arguing enterprise governance must shift from human workflow controls to agent-native runtime controls (<a href="https://www.linkedin.com/posts/nathaniel-niyazov-5a046b329_aigovernance-agentfirst-agenticai-activity-7461092995174498304-yOka">Niyazov, LinkedIn, 15 May</a>). The core claim from Saidot&#8217;s leadership: most current governance programs were built for human users navigating interfaces and filling out forms &#8212; and that posture does not compose onto agents that spawn sub-agents.</p><p><em>The Lineage Gap.</em> The 2&#215;2 explains why. A high-trust entity can spawn a low-trust one. What comes back up does not get reclassified to its origin. Saidot is pointing at the swarm quadrant &#8212; the one where governance fails silently because the parent process appears authorized while the child process operates outside the scope of any policy anyone wrote. Runtime governance is the only place to catch this. By the time the audit log shows up, the swarm has already finished. Cross-level swarms without a registry are the governance failure mode of the next eighteen months &#8212; and the vendors who solve it first will be the ones writing the reference architecture the regulators eventually adopt.</p><p><em>Boardroom Prompt.</em> What stops an authorized agent in your environment from spawning an unauthorized one &#8212; and what would the audit log show if it did?</p><div><hr></div><h2>The Verification Debt Tracker</h2><p><em>The 2&#215;2 from <a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a>. Signal counts this week, with direction vs. the trailing 4-week mean.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YYHK!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YYHK!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 424w, https://substackcdn.com/image/fetch/$s_!YYHK!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 848w, https://substackcdn.com/image/fetch/$s_!YYHK!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 1272w, https://substackcdn.com/image/fetch/$s_!YYHK!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YYHK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png" width="1456" height="942" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:942,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:88763,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/198904433?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YYHK!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 424w, https://substackcdn.com/image/fetch/$s_!YYHK!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 848w, https://substackcdn.com/image/fetch/$s_!YYHK!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 1272w, https://substackcdn.com/image/fetch/$s_!YYHK!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd4d815a1-095e-4fb8-929f-ec4d91df3752_1889x1222.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This week the <strong>Operational / Governed</strong> quadrant heated up as identity and governance infrastructure caught up to agent deployment &#8212; the Okta announcement, Saidot&#8217;s agent-first posture, the policy-as-code chorus. The <strong>Perspective / Feral</strong> quadrant rose sharply, driven by the EY retraction, the SEC-reported shadow AI breach, and the Big Four alliance that puts AI into work product the institution cannot yet trace. The pattern to watch: when <em>Feral</em> outpaces <em>Governed</em>, verification debt is accruing faster than infrastructure can pay it down.</p><div><hr></div><h2>Monday Morning</h2><p>Three things to do next week.</p><p><strong>01 &#183; Inventory the vendor AI in your work product.</strong> Every Big Four engagement, every SaaS-embedded feature, every advisor deliverable touched by an AI. You cannot govern what you cannot count, and you cannot count what the contract did not require the vendor to disclose. Start with the highest-stakes signed deliverable from the last quarter and trace backward.</p><p><strong>02 &#183; Demand the reasoning log.</strong> For any AI-assisted decision above a defined threshold &#8212; credit, compliance, regulatory, public communication &#8212; require the vendor to produce, on demand, the reasoning chain that produced the output. If the contract does not require it today, your next contract should. This is the single clause that converts verification debt from a hidden liability into a managed one.</p><p><strong>03 &#183; Pick one twin.</strong> Choose one digital twin use case where verified expertise matters more than scale. Govern it end to end &#8212; grounding, scope, provenance, drift. Make it your reference architecture for everything else. The institutions that have one well-governed twin learn faster than the ones that have ten ungoverned agents.</p><div><hr></div><h2>The Reading Room</h2><p>Three pieces worth your time this week.</p><ul><li><p><strong>AJ Yawn &#8212; </strong><em><strong>Open source GRC plugin for Claude Code</strong></em> (<a href="https://www.linkedin.com/posts/ajyawn_grcengineering-claude-tww-activity-7460667776710455296-6gxA">LinkedIn, 14 May</a>, 594 reactions). A working GRC plugin for an agentic coding tool, with AWS Inspector and Wiz connectors and an SCF crosswalk. The signal under the signal: GRC is becoming a developer surface, not a compliance surface.</p></li><li><p><strong>Vishal Pawar &#8212; </strong><em><strong>Still reporting AI accuracy to the board?</strong></em> (<a href="https://www.linkedin.com/posts/pawarvishal_still-reporting-ai-accuracy-to-the-board-activity-7460525120013516800-R-mi">LinkedIn, 14 May</a>). Argues boards should measure AI through P&amp;L impact, model risk management, and unit economics &#8212; not accuracy. The right scorecard for the conversation the board is actually trying to have.</p></li><li><p><strong>Alexandra C. &#8212; </strong><em><strong>AI models are developing internal deception metrics that safety layers miss</strong></em> (<a href="https://www.linkedin.com/posts/alextwittau_aisafety-llms-responsibleai-activity-7463506471842914304-RT3S">LinkedIn, 22 May</a>). The freshest signal of the week and the one that points to where verification debt is heading next: deception that exists internally and never surfaces in the output. Output-only safety checks were never designed to catch this.</p></li></ul><div><hr></div><p><em>Trust is expensive. So is its absence.</em></p><div><hr></div><p><strong>The Verified Intelligence Briefing</strong> is written by <strong>Steve Tout</strong>, Founder &amp; CEO of <a href="https://identient.com">Identient</a> and author of <em>The CISO on the Razor&#8217;s Edge</em>. It draws from the curated <em>Daily Signal</em> corpus and the Verified Intelligence framework introduced in <em><a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">From Artificial to Verified Intelligence</a></em>.</p><p>If this issue clarified something for you, <strong>forward it to one colleague who owns part of the control plane</strong>. New here? <strong>Subscribe</strong> to get The Briefing in your inbox every Friday morning.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/subscribe?"><span>Subscribe now</span></a></p><p>Reply or comment with the question you&#8217;d want answered in next week&#8217;s issue &#8212; your prompt may become Boardroom Prompt #1.</p><p>Connect with Steve: <a href="https://www.linkedin.com/in/stevetout">LinkedIn</a> &#183; <a href="https://www.identient.com">identient.com</a> &#183; <a href="https://www.stevetout.com">stevetout.com</a></p><p>&#128073; As a bonus, my latest piece for CIO Online, <em><strong>The Death of Identity as we Know It</strong></em>, is available <a href="https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html">here</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zfYm!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zfYm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg" width="562" height="562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1200,&quot;width&quot;:1200,&quot;resizeWidth&quot;:562,&quot;bytes&quot;:null,&quot;alt&quot;:null,&quot;title&quot;:&quot;1778699852774.jpg&quot;,&quot;type&quot;:null,&quot;href&quot;:&quot;https://www.cio.com/article/4170235/the-death-of-identity-as-we-know-it.html&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="1778699852774.jpg" srcset="https://substackcdn.com/image/fetch/$s_!zfYm!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 424w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 848w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!zfYm!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1966d9ab-be03-40e3-a1ae-00037715e94a_1200x1200.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div>]]></content:encoded></item><item><title><![CDATA[When AI Outpaces Governance: Lessons from the Front Lines]]></title><description><![CDATA[The fintech industry's AI confidence is high. Its control maturity is not. Here's what that gap looks like up close.]]></description><link>https://www.strategylayer.com/p/when-ai-outpaces-governance-lessons</link><guid isPermaLink="false">https://www.strategylayer.com/p/when-ai-outpaces-governance-lessons</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Mon, 30 Mar 2026 17:32:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Epww!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2>The Gap No One Talks About</h2><p>Here is a pattern we see over and over again. A company is smart. The engineering team is strong. AI adoption is moving fast. And leadership is confident they have it under control.</p><p>Then someone looks under the hood.</p><p>That is what happened when we ran an AI Security and Risk Assessment for a fintech firm in a regulated market. The company had strong instincts &#8212; early AI adoption, skilled teams, and a growing set of use cases. What they lacked was a way to see, govern, or defend how AI was really being used.</p><p>They are not alone. After walking the show floor at RSA Conference 2026, one thing is clear: the industry knows this is a problem. <span class="mention-wrap" data-attrs="{&quot;name&quot;:&quot;Andy Ellis&quot;,&quot;id&quot;:10408119,&quot;type&quot;:&quot;user&quot;,&quot;url&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!5lth!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fcceb4e-948f-451a-83de-41f5150686a9_2480x3306.jpeg&quot;,&quot;uuid&quot;:&quot;0f080730-195e-4fa5-be25-8532c077a048&quot;}" data-component-name="MentionToDOM"></span>&#8217;s <a href="https://www.duha.co/reports/state-of-security-vendors-rsac-2026/">post-RSAC vendor report </a>found that 37% of booths mentioned AI. Identity, governance, and security operations led the way. But here is the hard truth behind the buzz &#8212; most firms are still figuring out how to close the gap between AI power and AI control.</p><p>That gap is where the real risk lives.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Epww!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Epww!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Epww!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Epww!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Epww!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Epww!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3280826,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/192633964?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Epww!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Epww!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Epww!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Epww!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7220afcb-2d2b-45bd-b5f3-ad70c2bd6a68_1536x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Clarity scales control&#8212;digital twins turn AI risk into confident decisions.</figcaption></figure></div><h2>What We Found</h2><p>The assessment covered eight domains and included interviews across leadership, engineering, and business teams. The results told a clear story.</p><ul><li><p>Upwards of 100 risks identified across governance, security, data, and infrastructure</p></li><li><p>The heaviest concentration was in governance and compliance &#8212; with over a dozen rated high or critical</p></li><li><p>Security and trust risks followed close behind, with the majority rated high severity</p></li><li><p>Data and AI platform risks rounded out the picture, including several high-priority findings</p></li></ul><p>The risks were not scattered. They were concentrated in three areas: governance, security, and data. That pattern points to structural gaps, not one-off problems.</p><p>Three challenges stood out above the rest.</p><p><strong>Governance without enforcement.</strong> Policies existed. Intent was there. But there was no defined ownership, no enforcement mechanism, and no audit trail. Governance was informal and hard to defend.</p><p><strong>Identity and access gaps in AI systems.</strong> AI agents and services had no steady identity. Access was too broad. Nothing was centrally managed. This is the kind of risk that builds quietly &#8212; until it does not.</p><p><strong>Uncontrolled AI use case growth.</strong> AI was being developed across business units, deployed without formal approval, and extended into customer-facing workflows. Governance simply could not keep pace with adoption.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2></h2><h2>Why This Matters Right Now</h2><p><a href="https://www.finra.org/rules-guidance/guidance/reports/2026-finra-annual-regulatory-oversight-report">FINRA&#8217;s 2026 guidance</a> makes the stakes clear. AI is no longer treated as a test. It is part of the firm&#8217;s control environment. That means oversight of AI-driven processes, data quality and tracing, logging of AI outputs, and close attention to the risks of agentic AI &#8212; autonomy, scope, and the ability to audit.</p><p>The shift is simple but significant. If AI touches decisions that affect customers, markets, or compliance, it must be governed like any other control.</p><p>Ellis&#8217;s RSA report backs this up from the vendor side. The categories with the most booths &#8212; identity, app security, and security operations &#8212; are the same areas where this assessment found the deepest gaps. The market is building answers. But most firms have not yet mapped the problems those answers are meant to solve.</p><h2>What Changed</h2><p>After the assessment, the organization had something it did not have before: clarity.</p><ul><li><p>A full view of AI-related risks and where they are concentrated</p></li><li><p>A prioritized list of what matters most &#8212; and what can wait</p></li><li><p>Leadership aligned around AI as a governance challenge, not just a growth play</p></li><li><p>A structured path from experimentation to governed execution</p></li></ul><p>Identient also delivered a digital twin of the assessment itself. Instead of leaving findings locked in a static report, a conversational agent makes risk insights easy to query, explore, and apply in real time. Leaders can ask questions, revisit findings, and act on insights as things change.</p><p>This is the shift we described in our earlier <a href="https://www.identient.com/blog/digital-twins-change-everything/">post on Verified Digital Twins</a>. Risk management cannot be a point-in-time exercise. It has to become a continuous, intelligence-driven function.</p><h2>The Bottom Line</h2><p>This firm is not behind. They are at a turning point &#8212; and they had the sense to act before the gap became a crisis.</p><blockquote><p>The firms that win with AI will not be the fastest to deploy. They will be the ones that can trust, control, and defend the choices AI makes on their behalf.</p></blockquote><p>That requires three things: structured governance, <a href="https://www.identient.com/blog/from-ai-to-verified-intelligence/">verified data</a>, and disciplined execution.</p><h2>Ready to See What You&#8217;re Missing?</h2><p>Experience how Identient reveals the signals behind your strategy &#8212; from real-time insight to board-level clarity. Move beyond assumptions, align execution to what matters, and lead with confidence.</p><p><strong><a href="https://www.identient.com/start">Schedule a Discovery Call &#8594;</a></strong></p>]]></content:encoded></item><item><title><![CDATA[Two Birds, One Podcast: AI, Governance, and the Road Ahead]]></title><description><![CDATA[Richard Bird joins The Strategy Layer Live to discuss AI, cybercrime, governance, and leadership&#8212;plus a first-ever appearance by his digital twin.]]></description><link>https://www.strategylayer.com/p/two-birds-one-podcast-ai-governance</link><guid isPermaLink="false">https://www.strategylayer.com/p/two-birds-one-podcast-ai-governance</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Wed, 17 Dec 2025 22:21:50 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/181932575/8a4e2837435e0df648bec019d96dd22e.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p><strong>Episode Overview</strong></p><p>In this episode of <em>The Strategy Layer Live</em>, Steve  sits down with <strong>Richard Bird</strong>&#8212;multi-time CISO, former Chief Customer Information Officer at Ping Identity, author, and current Chief Security Officer at <strong>Singulr</strong>&#8212;for a conversation that pushes beyond conventional cybersecurity narratives.</p><p>For the first time on the podcast, an <strong>AI digital twin takes an active speaking role</strong>, opening the episode with a blunt assessment of where cybersecurity thinking has already fallen behind. From there, the discussion moves into the strategic implications of AI across cybercrime, governance, leadership, and careers.</p><p>This episode explores how AI is reshaping the threat landscape faster than most organizations are prepared for, why governance failures are increasingly systemic rather than technical, and what leadership looks like when machines operate at scale and speed. The conversation also turns personal, with reflections on Richard&#8217;s book <em><a href="https://a.co/d/ebJoZvA">Famous With 12 People</a></em> and the legacy he hopes to leave behind.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div id="youtube2-r9_VgvKxtFU" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;r9_VgvKxtFU&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/r9_VgvKxtFU?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Prefer to listen?</strong></p><p><a href="https://podcasts.apple.com/us/podcast/two-birds-one-podcast-ai-governance-and-the-road-ahead/id1785305825?i=1000741763489">Apple Podcasts</a></p><p><a href="https://open.spotify.com/episode/1kDaLzm4wxT7Y8SlVNcUcf?si=e6a1a5ea2b754082">Spotify</a></p><p><strong>Key Topics Discussed</strong></p><p><strong>AI Digital Twins in Leadership Conversations</strong><br>What it means when AI systems don&#8217;t just assist&#8212;but actively participate in strategic dialogue.</p><p><strong>AI and the Acceleration of Cybercrime</strong><br>How attackers are using AI as force multiplication while many organizations reduce human defenders.</p><p><strong>Shadow AI and Unfinished Security Work</strong><br>Why decades of unfinished IT and security projects created the conditions for today&#8217;s AI risk.</p><p><strong>Governance Failures Are Systemic, Not Technical</strong><br>How leadership blind spots&#8212;not tooling&#8212;are driving AI governance gaps.</p><p><strong>Identity, Access, and Ownership in an AI World</strong><br>Why diffuse responsibility leads to no accountability when AI systems act at scale.</p><p><strong>The Future of Consulting and Verified Intelligence</strong><br>How AI is reshaping advisory work and exposing performative expertise.</p><p><strong>Career Strategy and Influence</strong><br>Insights from <em>Famous With 12 People</em> on building impact through depth, clarity, and relevance.</p><p><strong>Legacy and Leadership</strong><br>Richard&#8217;s reflections on service, contribution, and what comes next beyond titles and roles.</p><p><strong>Insightful Takeaways</strong></p><p><strong>AI rewards preparedness, not optimism.</strong><br>Attackers are using AI to move faster and more efficiently; organizations that fail to adapt governance and defenses will see the results in loss curves.</p><p><strong>Shadow AI is a leadership problem before it&#8217;s a technology problem.</strong><br>Uncontrolled AI use is the predictable outcome of years of tolerated sprawl and unfinished security work.</p><p><strong>Cutting people while attackers scale with AI is a dangerous asymmetry.</strong><br>AI augments those who use it strategically&#8212;and penalizes those who remove human judgment from critical systems.</p><p><strong>Governance must evolve from policy to ownership.</strong><br>When everyone owns identity, risk, or AI outcomes, accountability disappears.</p><p><strong>Impact comes from depth, not scale.</strong><br>Leadership, influence, and career growth are built by being meaningful to a few&#8212;not visible to everyone.</p><p><strong>Legacy is defined by service, not status.</strong><br>The most durable contribution comes from helping others move forward&#8212;especially in moments of uncertainty and change.</p><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a0f731ae4cd31e148e3de408e&quot;,&quot;title&quot;:&quot;Two Birds, One Podcast: AI, Governance, and the Road Ahead&quot;,&quot;subtitle&quot;:&quot;Steve Tout&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/1kDaLzm4wxT7Y8SlVNcUcf&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/1kDaLzm4wxT7Y8SlVNcUcf" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe><p>Quote of the show:</p><blockquote><p>&#8220;Has it been proven to you that you don&#8217;t suck at security?&#8221; &#8212;Richard Bird</p></blockquote><p>Links:</p><p>Richard Bird on LinkedIn: <a href="https://www.linkedin.com/in/rbird/">https://www.linkedin.com/in/rbird/ </a></p><p>Digital twins aren&#8217;t a concept&#8212;they&#8217;re already being used.<br>Try Richard Bird&#8217;s digital twin or learn how to create one for the marketplace at <strong><a href="https://www.identient.com">Identient.com</a></strong><a href="https://www.identient.com">.</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lN5_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lN5_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 424w, https://substackcdn.com/image/fetch/$s_!lN5_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 848w, https://substackcdn.com/image/fetch/$s_!lN5_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 1272w, https://substackcdn.com/image/fetch/$s_!lN5_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lN5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2258365,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/181932575?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lN5_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 424w, https://substackcdn.com/image/fetch/$s_!lN5_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 848w, https://substackcdn.com/image/fetch/$s_!lN5_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 1272w, https://substackcdn.com/image/fetch/$s_!lN5_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2bb3e55-472e-44b2-b289-1f8646964975_1456x1048.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[The Quiet Choices We’re Making with AI]]></title><description><![CDATA[How strategic AI choices influence leadership impact, clarity, and performance.]]></description><link>https://www.strategylayer.com/p/the-quiet-choices-were-making-with</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-quiet-choices-were-making-with</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Mon, 15 Dec 2025 18:20:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ZuLE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="native-audio-embed" data-component-name="AudioPlaceholder" data-attrs="{&quot;label&quot;:null,&quot;mediaUploadId&quot;:&quot;c9655243-bb1c-49aa-ab2e-0aa3c103f1cc&quot;,&quot;duration&quot;:640.86206,&quot;downloadable&quot;:false,&quot;isEditorNode&quot;:true}"></div><p>As the year comes to a close, many leaders are taking stock of what AI has changed inside their organizations. The gains are real. Work moves faster. Information is easier to digest. Communication feels smoother. For many teams, AI has become part of the daily rhythm of getting things done.</p><p>But beneath these visible improvements, something quieter and more consequential is happening. AI is beginning to shape how leaders see their organizations, how they interpret signals, and how they decide where to focus next. Those effects are harder to measure, but they will matter far more in the long run.</p><p>Earlier this year, MIT Sloan Review made the case that &#8220;philosophy is eating AI,&#8221; arguing that beneath the models and metrics, AI increasingly reflects how we define knowledge, reality, and purpose (MIT Sloan Review, 2025)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a>. That framing may sound abstract, but the implication for leaders is very practical. AI systems inevitably reflect how we think the system works. Over time, they reinforce that view, whether it remains accurate or not.</p><p>This is why AI&#8217;s greatest impact will not be on output volume. It will be on leadership impact.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>AI Reflects How Leaders See the World</h2><p>AI does not start with data alone. It starts with choices about what data matters, which signals are trusted, and what outcomes are worth optimizing. Those choices are often implicit. They live inside models, dashboards, prompts, and workflows that feel neutral because they are technical.</p><p>Yet these systems shape what feels clear and what feels urgent. They influence which risks rise to the surface and which fade into the background. In subtle ways, they guide attention, and attention drives action.</p><p>When leaders say AI helps them &#8220;see the business more clearly,&#8221; that clarity is always relative to the assumptions encoded in the system. What gets measured is what gets discussed. What gets summarized is what gets remembered. What gets optimized is what gets rewarded.</p><p>None of this is malicious or careless. It is simply how systems work. Over time, AI becomes a reflection of how leaders understand the organization and what they believe is important.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ZuLE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ZuLE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZuLE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZuLE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZuLE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ZuLE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2926948,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/181698327?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ZuLE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!ZuLE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!ZuLE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!ZuLE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2c2e6ca-6b03-4fc6-b2c9-89e6de256a21_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">When the noise fades, the signal gets louder.</figcaption></figure></div><h2>Why Trust in AI Is Complicated, and Rightly So</h2><p>Given this dynamic, it should not be surprising that many organizations struggle with trust when it comes to AI. A recent Fast Company article noted that mistrust in AI is often well placed, especially when systems feel disconnected from the realities leaders care about most (Fast Company, 2025)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a>. Trust does not come from transparency alone. It comes from alignment.</p><p>Leaders are right to be cautious when AI confidently produces answers without making clear which assumptions are driving those answers. When systems feel generic or detached from domain expertise, skepticism is a rational response.</p><p>Trust grows when AI is purpose-built, grounded in expertise, and designed to reflect the real tensions leaders face. In other words, when AI helps leaders reason better, not just faster.</p><h2>When Assumptions Begin to Compound</h2><p>The stakes rise as AI systems become more autonomous and self-reinforcing. Researchers and practitioners have begun to ask hard questions about what happens when AI increasingly trains itself, refining its behavior through feedback loops that may drift from original intent (The Guardian, 2025)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a>.</p><p>From a leadership perspective, this is less about losing control and more about losing intentionality. Systems that continuously reinforce existing patterns can quietly lock in outdated assumptions. Decisions feel easier. Outputs feel confident. Meanwhile, misalignment grows harder to detect.</p><p>This is how complexity compounds. Not through sudden failure, but through small, accumulated shifts that go unnoticed because everything still appears to be working.</p><p>In these moments, AI functions as a mirror. It reflects how leaders believe the organization operates. Over time, it may reveal gaps between that belief and lived reality.</p><h2>Disagreement Is a Feature, Not a Bug</h2><p>One of the more interesting developments in AI this year has been the rise of multi-agent systems. As observers have noted, AI agents are increasingly interacting with one another, and they do not always agree (Wondering About AI, 2025)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a>. That disagreement can feel uncomfortable, especially in environments that prize alignment and consistency.</p><p>But disagreement is often where insight emerges.</p><p>Research on multi-agent debate shows that structured disagreement, particularly when identity signals are reduced or anonymized, can improve outcomes and reduce bias (Zhang et al., 2025)<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-5" href="#footnote-5" target="_self">5</a>. In organizational terms, this mirrors what strong leadership teams already know. Healthy systems surface tension early. Weak systems suppress it until it becomes unavoidable.</p><p>AI that merely reinforces consensus may feel reassuring, but it rarely improves judgment. AI that surfaces competing perspectives, patterns, and tradeoffs helps leaders see the system more fully.</p><h2>From Productivity to Leadership Impact</h2><p>None of this diminishes the value of everyday AI use cases. Tools that summarize meetings, draft communications, and speed up analysis are genuinely useful. They reduce friction and free up time.</p><p>The difference is that productivity gains alone do not guarantee better leadership outcomes.</p><p>Leadership impact comes from making better decisions under complexity. It comes from seeing patterns before they become problems. It comes from distinguishing signal from noise and momentum from progress.</p><div class="pullquote"><p><strong>Generic AI accelerates activity; verified intelligence amplifies leadership.</strong></p></div><p>AI that improves leadership impact does not simply accelerate existing narratives. It helps leaders test them. It introduces productive tension. It highlights where confidence may be outrunning evidence.</p><p>This is where the strategic choice of which AI to deploy becomes critical. Generic tools optimize for convenience and volume. Purpose-built systems, grounded in verified intelligence, optimize for clarity and judgment. In short, Generic AI accelerates activity; verified intelligence amplifies leadership.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-quiet-choices-were-making-with?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-quiet-choices-were-making-with?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-quiet-choices-were-making-with?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>Rethinking AI Governance</h2><p>These dynamics have important implications for AI governance. Much of today&#8217;s governance conversation focuses on guardrails, policies, and model risk. Those are necessary foundations. But they are not sufficient.</p><p>Effective AI governance must also protect leadership effectiveness over time. It must account for drift, compounding effects, and the way AI-informed decisions accumulate across the organization. Governance should help leaders understand not just what AI is allowed to do, but how it is shaping priorities, incentives, and attention.</p><p>When governance focuses only on deployment, it misses the harder question of impact. When it focuses only on control, it risks constraining learning.</p><p>Do you agree? </p><div class="community-chat" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/pub/thestrategylayer/chat?utm_source=chat_embed&quot;,&quot;subdomain&quot;:&quot;thestrategylayer&quot;,&quot;pub&quot;:{&quot;id&quot;:4536793,&quot;name&quot;:&quot;The Strategy Layer&quot;,&quot;author_name&quot;:&quot;Steve Tout&quot;,&quot;author_photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!yd1b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4b6d5e43-40d4-4888-b269-ee71bfd89b89_716x716.jpeg&quot;}}" data-component-name="CommunityChatRenderPlaceholder"></div><p>The most effective governance frameworks treat AI as part of the leadership system itself. They emphasize evidence, feedback loops, and the ability to course-correct as conditions change.</p><h2>Verified Intelligence and Strategic Clarity</h2><p>This is where verified intelligence becomes a meaningful differentiator. Systems designed to observe trends over time, grounded in domain expertise, help leaders cut through complexity rather than add to it.</p><p>At Identient, this perspective informs how we approach AI-enabled analysis across identity and cybersecurity. Tools like <a href="https://www.identient.ai/demo/">SPI 360</a> focus on trend analysis across strategy, governance, people, and technology, helping leaders distinguish isolated issues from systemic patterns and short-term noise from meaningful change.</p><p>The goal is not more dashboards or more activity. It is clearer insight that supports better prioritization and more confident leadership decisions.</p><h2>Digital Models as Tools for Clarity</h2><p>Digital models and digital twins amplify both the promise and the risk of AI. By formalizing how an organization understands itself, they make assumptions visible. That visibility is powerful.</p><p>But models are not oracles. They do not eliminate uncertainty. They shape how uncertainty is perceived.</p><p>Used well, digital models help leaders see complexity more clearly and ask better questions. Used poorly, they can create a false sense of certainty that obscures emerging risks.</p><p>The difference lies in how intentionally they are designed and governed, and whether they are treated as tools for inquiry rather than answers in themselves.</p><h2>Choosing Leadership Impact Over Activity</h2><p>As leaders look ahead to the next planning cycle, the temptation will be to measure AI success by scale. More deployments. More use cases. More output.</p><p>A better measure is impact.</p><div class="pullquote"><p><strong>AI will either sharpen leadership impact or multiply activity without direction.</strong></p></div><p>AI will either sharpen leadership impact or multiply activity without direction. The difference lies in which intelligence leaders choose to deploy and which they choose not to.</p><p>The quiet choices made today about trust, assumptions, and governance will shape how leaders see their organizations tomorrow. In a world of increasing complexity, clarity is not a nice-to-have. It is the foundation of meaningful performance.</p><p>And that is where AI&#8217;s real value will be found.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-quiet-choices-were-making-with/comments&quot;,&quot;text&quot;:&quot;Leave a comment&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-quiet-choices-were-making-with/comments"><span>Leave a comment</span></a></p><h1>Footnotes</h1><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>MIT Sloan Management Review. (2025). <em>Philosophy eats AI.</em> <a href="https://sloanreview.mit.edu/article/philosophy-eats-ai/">https://sloanreview.mit.edu/article/philosophy-eats-ai/</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Fast Company. (2025). <em>Does your organization have trust issues with AI?</em> <a href="https://www.fastcompany.com/91446330/does-your-organization-have-trust-issues-with-ai">https://www.fastcompany.com/91446330/does-your-organization-have-trust-issues-with-ai</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>The Guardian. (2025, December 2). <em>Allowing AI to train itself: The biggest decision yet.</em> <a href="https://www.theguardian.com/technology/ng-interactive/2025/dec/02/jared-kaplan-artificial-intelligence-train-itself">https://www.theguardian.com/technology/ng-interactive/2025/dec/02/jared-kaplan-artificial-intelligence-train-itself</a></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>Wondering About AI. (2025). <em>AI agents are talking to each other&#8230;and they don&#8217;t always agree.</em> </p><div class="embedded-post-wrap" data-attrs="{&quot;id&quot;:179301897,&quot;url&quot;:&quot;https://wonderingaboutai.substack.com/p/ai-agents-are-talking-to-each-otherand&quot;,&quot;publication_id&quot;:5597038,&quot;publication_name&quot;:&quot;Wondering About AI&quot;,&quot;publication_logo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!B3X6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F721dac90-0e32-4c6d-a6bc-172d3fab26e6_1080x1080.png&quot;,&quot;title&quot;:&quot;AI agents are talking to each other...and they don't always agree&quot;,&quot;truncated_body_text&quot;:&quot;Disclosure: This post is based on the results of a topical analysis conducted in Future Scan, a trend discovery tool for AI/ML research. I wrote the initial draft, but used Claude Sonnet 4.5 to help me translate scientific jargon and (mostly) eradicate awkwardness.&quot;,&quot;date&quot;:&quot;2025-11-19T00:40:37.712Z&quot;,&quot;like_count&quot;:56,&quot;comment_count&quot;:26,&quot;bylines&quot;:[{&quot;id&quot;:363410124,&quot;name&quot;:&quot;Karen Spinner&quot;,&quot;handle&quot;:&quot;karenspinner1&quot;,&quot;previous_name&quot;:null,&quot;photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!kLy3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F28ad1170-99e0-4cb6-8a1d-f4f60c4465ef_591x591.jpeg&quot;,&quot;bio&quot;:&quot;Writer, agency owner, and casual developer with mixed feelings about AI. Creator of Future Scan, a tool that spots trends in AI/ML research. &quot;,&quot;profile_set_up_at&quot;:&quot;2025-07-09T18:29:24.248Z&quot;,&quot;reader_installed_at&quot;:&quot;2025-07-11T00:10:13.073Z&quot;,&quot;publicationUsers&quot;:[{&quot;id&quot;:5709228,&quot;user_id&quot;:363410124,&quot;publication_id&quot;:5597038,&quot;role&quot;:&quot;admin&quot;,&quot;public&quot;:true,&quot;is_primary&quot;:false,&quot;publication&quot;:{&quot;id&quot;:5597038,&quot;name&quot;:&quot;Wondering About AI&quot;,&quot;subdomain&quot;:&quot;wonderingaboutai&quot;,&quot;custom_domain&quot;:null,&quot;custom_domain_optional&quot;:false,&quot;hero_text&quot;:&quot;Real-life experiments with AI plus insights based on the latest research. No hype zone.&quot;,&quot;logo_url&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/721dac90-0e32-4c6d-a6bc-172d3fab26e6_1080x1080.png&quot;,&quot;author_id&quot;:363410124,&quot;primary_user_id&quot;:363410124,&quot;theme_var_background_pop&quot;:&quot;#FF6719&quot;,&quot;created_at&quot;:&quot;2025-07-09T18:32:47.601Z&quot;,&quot;email_from_name&quot;:&quot;Karen from Wondering About AI&quot;,&quot;copyright&quot;:&quot;Karen Spinner&quot;,&quot;founding_plan_name&quot;:&quot;Founding Member&quot;,&quot;community_enabled&quot;:true,&quot;invite_only&quot;:false,&quot;payments_state&quot;:&quot;disabled&quot;,&quot;language&quot;:null,&quot;explicit&quot;:false,&quot;homepage_type&quot;:&quot;magaziney&quot;,&quot;is_personal_mode&quot;:false}}],&quot;is_guest&quot;:false,&quot;bestseller_tier&quot;:null,&quot;status&quot;:null}],&quot;utm_campaign&quot;:null,&quot;belowTheFold&quot;:true,&quot;type&quot;:&quot;newsletter&quot;,&quot;language&quot;:&quot;en&quot;,&quot;source&quot;:null}" data-component-name="EmbeddedPostToDOM"><a class="embedded-post" native="true" href="https://wonderingaboutai.substack.com/p/ai-agents-are-talking-to-each-otherand?utm_source=substack&amp;utm_campaign=post_embed&amp;utm_medium=web"><div class="embedded-post-header"><img class="embedded-post-publication-logo" src="https://substackcdn.com/image/fetch/$s_!B3X6!,w_56,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F721dac90-0e32-4c6d-a6bc-172d3fab26e6_1080x1080.png" loading="lazy"><span class="embedded-post-publication-name">Wondering About AI</span></div><div class="embedded-post-title-wrapper"><div class="embedded-post-title">AI agents are talking to each other...and they don't always agree</div></div><div class="embedded-post-body">Disclosure: This post is based on the results of a topical analysis conducted in Future Scan, a trend discovery tool for AI/ML research. I wrote the initial draft, but used Claude Sonnet 4.5 to help me translate scientific jargon and (mostly) eradicate awkwardness&#8230;</div><div class="embedded-post-cta-wrapper"><span class="embedded-post-cta">Read more</span></div><div class="embedded-post-meta">7 months ago &#183; 56 likes &#183; 26 comments &#183; Karen Spinner</div></a></div></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-5" href="#footnote-anchor-5" class="footnote-number" contenteditable="false" target="_self">5</a><div class="footnote-content"><p>Zhang, Y., et al. (2025). <em>Measuring and mitigating identity bias in multi-agent debate via anonymization.</em> arXiv. <a href="https://arxiv.org/abs/2510.07517">https://arxiv.org/abs/2510.07517</a></p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[Running Toward Impact: Lessons In Leadership with Bill Kehoe]]></title><description><![CDATA[ashington State CIO Bill Kehoe discusses CIO-CISO partnership, cybersecurity accountability, digital equity, and modernizing government at scale.]]></description><link>https://www.strategylayer.com/p/running-toward-impact-lessons-in</link><guid isPermaLink="false">https://www.strategylayer.com/p/running-toward-impact-lessons-in</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Thu, 04 Dec 2025 00:33:48 GMT</pubDate><enclosure url="https://api.substack.com/feed/podcast/180652639/4b26f14c51cd21cdfb91997faab2f5b7.mp3" length="0" type="audio/mpeg"/><content:encoded><![CDATA[<p>In this episode of <em>The Strategy Layer Live</em>, Steve sits down with Bill Kehoe, Chief Information Officer for Washington State, for a rare in-person conversation that spans three decades of lessons from state, county, and local government. Bill reflects on the turning points that shaped his leadership&#8212;from transforming the DMV experience in the early 2000s, to consolidating IT at King County, to guiding Washington toward a more connected, equitable digital future.</p><p>He shares how running and coaching informed his approach to developing people, why modernization must be incremental and human-centered, and what it really looks like when a CIO steps fully into cybersecurity accountability alongside their CISO.</p><p>Bill&#8217;s insights offer a grounded, practical masterclass in leading with purpose, navigating complexity, and building public trust in the digital age.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><div id="youtube2-zL15tYG_xnM" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;zL15tYG_xnM&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/zL15tYG_xnM?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p><strong>Prefer to listen?</strong></p><p><a href="https://podcasts.apple.com/us/podcast/running-toward-impact-lessons-in-leadership-with-bill/id1785305825?i=1000739591743">Apple Podcasts</a></p><p><a href="https://open.spotify.com/episode/1jQfc0wh98XVMUmU0zm626?si=c007cc2ca7754d15">Spotify</a></p><h2>What We Cover in This Episode</h2><ul><li><p>Bill&#8217;s early path into public service and what has kept him committed for decades</p></li><li><p>The turning-point projects that shaped his leadership philosophy</p></li><li><p>Lessons from running and coaching &#8212; discipline, strategy, and individual development</p></li><li><p>The bold vision behind digital equity and the Resident Portal</p></li><li><p>Modernization without fear: incremental change, customer experience, and agile delivery</p></li><li><p>The Resident Portal Challenge and the future of procurement innovation</p></li><li><p>Multi-vendor collaboration and why competition can create better outcomes</p></li><li><p>The CIO&#8211;CISO partnership and shared responsibility for cybersecurity</p></li><li><p>Leading through complexity with calm, clarity, and trust</p></li><li><p>Bill&#8217;s reflections on legacy, public service, and the next generation of leaders</p></li><li><p>How AI is reshaping responsibility, decision-making, and efficiency in government</p></li></ul><iframe class="spotify-wrap podcast" data-attrs="{&quot;image&quot;:&quot;https://i.scdn.co/image/ab6765630000ba8a71339cc0ca8aac19c41a9dd3&quot;,&quot;title&quot;:&quot;Running Toward Impact: Lessons In Leadership with Bill Kehoe&quot;,&quot;subtitle&quot;:&quot;Steve Tout&quot;,&quot;description&quot;:&quot;Episode&quot;,&quot;url&quot;:&quot;https://open.spotify.com/episode/1jQfc0wh98XVMUmU0zm626&quot;,&quot;belowTheFold&quot;:true,&quot;noScroll&quot;:false}" src="https://open.spotify.com/embed/episode/1jQfc0wh98XVMUmU0zm626" frameborder="0" gesture="media" allowfullscreen="true" allow="encrypted-media" loading="lazy" data-component-name="Spotify2ToDOM"></iframe><p>Quote of the Show:</p><ul><li><p>&#8220;<em>I&#8217;m the front lines for everything that happens &#8212; good or bad &#8212; and I consider myself accountable and responsible for everything that goes on in my agency and in technology in the state.</em>&#8221; - Bill Kehoe</p></li></ul><p>Links:</p><ul><li><p><a href="https://watech.wa.gov/">https://watech.wa.gov/</a></p></li><li><p><a href="https://www.linkedin.com/in/william-kehoe-a37a0714b/">https://www.linkedin.com/in/william-kehoe-a37a0714b/</a> </p></li></ul><p>#CybersecurityLeadership #CIO #CISOPartnership #GovernmentTechnology #PublicSectorLeadership #DigitalGovernment #StrategyLayerLive</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/running-toward-impact-lessons-in?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/running-toward-impact-lessons-in?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/running-toward-impact-lessons-in?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ERzY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ERzY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!ERzY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!ERzY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!ERzY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ERzY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c6672666-b296-4882-b4b9-a66430dfee56_1200x630.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:835834,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/180652639?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ERzY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 424w, https://substackcdn.com/image/fetch/$s_!ERzY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 848w, https://substackcdn.com/image/fetch/$s_!ERzY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 1272w, https://substackcdn.com/image/fetch/$s_!ERzY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc6672666-b296-4882-b4b9-a66430dfee56_1200x630.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The LLM Bubble Is Bursting — Provenance Will Define the Next Decade of AI]]></title><description><![CDATA[Smart leaders are shifting from black-box models to verifiable, expert-grounded intelligence.]]></description><link>https://www.strategylayer.com/p/the-llm-bubble-is-bursting-provenance</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-llm-bubble-is-bursting-provenance</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Sun, 23 Nov 2025 17:28:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!9AjY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Over the past two years, the hype around artificial intelligence has reached a fever pitch. Yet the signal cutting through the noise is becoming unmistakable: <strong>we are not in an AI bubble &#8212; we are in an LLM bubble</strong>. Even the CEO of Hugging Face said as much recently when discussing the overheated market dynamics around large models, compared to the broader field of AI innovation.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></p><p>That distinction matters for one simple reason: the future will not be defined by &#8220;bigger models.&#8221; It will be defined by <strong>transparent, verifiable, provenance-rich intelligence</strong> that leaders can trust &#8212; and defend.</p><p>This shift isn&#8217;t theoretical. It&#8217;s happening right now.<br>And the smartest public and private sector organizations are already aligning with it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9AjY!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9AjY!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9AjY!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9AjY!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9AjY!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9AjY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1234465,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/179732700?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9AjY!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!9AjY!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!9AjY!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!9AjY!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1afec594-df26-466f-914e-cbe31bdcc96e_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Trust isn&#8217;t built on outputs &#8212; it&#8217;s built on transparency. Credit: My GPT:)</figcaption></figure></div><h2><strong>Opaque Intelligence Is the Real Risk &#8212; Not AI Itself</strong></h2><p>I&#8217;ve spent years working across cybersecurity, IAM,  and now AI and verified intelligence. And one pattern is becoming clear: as organizations begin laying the foundations of their AI strategy, the choices they make in 2026 will have long-term consequences. Many are exploring GenAI and LLM tools without fully understanding the short- and long-term risks these systems can introduce to their P&amp;L, operational resilience, and decision quality.</p><p>This is the moment where leaders must decide whether to build on opaque, probabilistic tools&#8212;or on transparent, verifiable intelligence they can trust, audit, and defend. The organizations who pause to consider provenance, lineage, and accountability now will avoid painful redesign later and position themselves for durable, compounding productivity gains.</p><p>A human in the loop doesn&#8217;t fix this.<br>You can&#8217;t &#8220;review&#8221; what you can&#8217;t see.</p><p>If the system cannot show:</p><ul><li><p>Its reasoning path</p></li><li><p>Its underlying sources</p></li><li><p>Its version footprint</p></li><li><p>Its inference chain</p></li><li><p>Or whether it hallucinated</p></li></ul><p>&#8230;then you own the outcome but you <strong>don&#8217;t</strong> own the evidence.</p><p>Opaque AI becomes a governance liability.<br>And regulators are beginning to say so out loud.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-llm-bubble-is-bursting-provenance?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-llm-bubble-is-bursting-provenance?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-llm-bubble-is-bursting-provenance?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2><strong>The Regulatory Wave Has Begun &#8212; Transparency Is Becoming Law</strong></h2><p>A growing set of U.S. states are taking decisive steps toward transparency, documentation, and proof of AI influence.</p><h3><strong>Washington&#8217;s HB 1170 &#8212; A Major Leap Forward in Transparency</strong></h3><p>As I wrote in <em><a href="https://www.strategylayer.com/p/ai-transparency-20-why-washington">AI Transparency 2.0: Why Washington Must Go Beyond Deepfakes to Decision Provenance</a></em>, Washington State&#8217;s HB 1170 puts real stakes in the ground: citizens must be informed when AI influences decisions, and organizations must maintain records of how that intelligence was used.</p><p>This mirrors the same foundation seen in California&#8217;s early AI Transparency Act  &#8212; and signals where nationwide policy is headed.</p><h3><strong>Colorado&#8217;s SB 24-205 &#8212; The Strongest AI Governance Law to Date</strong></h3><p>Colorado&#8217;s SB 24-205, enacted in 2024, establishes mandatory risk assessments, notices, governance controls, and documentation requirements for &#8220;high-risk&#8221; AI systems.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-2" href="#footnote-2" target="_self">2</a></p><p>This is the most comprehensive state-level AI law in the country, and it&#8217;s already influencing other states&#8217; drafts.</p><h3><strong>Illinois HB 3773 &#8212; You Can&#8217;t Hide AI in Hiring Decisions</strong></h3><p>Illinois took a direct aim at algorithmic opacity by requiring disclosures and fairness documentation for any AI used in employment decisions starting in 2026.<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-3" href="#footnote-3" target="_self">3</a> </p><p>Illinois&#8217; HB 3773 amends the state&#8217;s Human Rights Act to regulate the use of AI in employment decisions, prohibiting its use if it has a discriminatory effect based on protected classes and requiring employers to notify employees when AI is used in hiring, promotion, or other employment decisions. The law takes effect January 1, 2026, and also prohibits the use of zip codes as a proxy for protected classes in employment contexts.</p><p>The era of black-box algorithmic hiring is ending.</p><h3><strong>California&#8217;s AI Transparency Act &#8212; A Modern Benchmark for Disclosure</strong></h3><p>California&#8217;s new <strong>AI Transparency Act</strong><a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-4" href="#footnote-4" target="_self">4</a> sets one of the clearest expectations in the country: organizations must disclose when AI is used in customer-facing or citizen-facing interactions, and they must maintain documentation that explains how automated decisions are generated. The Act goes beyond simple labeling&#8212;it requires organizations to preserve <strong>evidence of AI influence</strong>, enabling regulators and affected individuals to understand <em>how</em> and <em>why</em> an automated outcome occurred.</p><p>It signals a broader trend: transparency is no longer optional. It is fast becoming the baseline requirement for any organization deploying AI in high-impact contexts.</p><p>New York, Connecticut, and Massachusetts are following similar paths with draft frameworks focused on transparency and algorithmic accountability.</p><p>The direction is unified:</p><blockquote><p><strong>AI cannot be used for autonomous decision-making unless it operates with full transparency, provenance, and explainability.</strong></p></blockquote><p>This is no longer an abstract ethical debate.<br>It is becoming a regulatory and operational reality.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><h2><strong>There Is No AI Bubble &#8212; The LLM Bubble Is What&#8217;s Bursting</strong></h2><p>The market is now recognizing what many of us working on verified intelligence have known for years:</p><ul><li><p>The bigger the model, the bigger the opacity</p></li><li><p>The bigger the opacity, the bigger the liability</p></li><li><p>And the bigger the liability, the smaller the strategic value</p></li></ul><p>Look across industries: leaders are no longer asking &#8220;How do we get more AI?&#8221;<br>They&#8217;re asking:<br><strong>&#8220;How do we trust what we&#8217;re using?&#8221;</strong></p><p>Large language models aren&#8217;t dying &#8212; but their <strong>unverifiable</strong> use cases are.</p><p>As the Hugging Face CEO noted, the bubble is around LLMs specifically &#8212; not the broader field of AI innovation where transparency, interpretability, and provenance are core requirements.</p><p>That&#8217;s where the future is heading.<br>Quickly.</p><h2><strong>Verified Intelligence: What Comes After the LLM Bubble</strong></h2><p>I believe the next decade of AI will be defined by a new standard:</p><h3><strong>AI systems must be able to answer four questions with absolute clarity:</strong></h3><ol><li><p><em>Where did this intelligence come from?</em></p></li><li><p><em>Whose expertise, data, and boundaries informed it?</em></p></li><li><p><em>What reasoning steps produced the answer?</em></p></li><li><p><em>Can we recreate the decision and prove its integrity?</em></p></li></ol><p>Generic LLMs can answer none of these.<br>Verified intelligence systems can answer all of them.</p><p>This is why we built Identient&#8217;s marketplace around <strong>provenance, data lineage, identity-attached digital twins, and full auditability</strong>.<br>Because trust doesn&#8217;t come from bigger models &#8212; it comes from <strong>verifiable ones</strong>.</p><p>And it turns out that when you remove ambiguity, a second benefit emerges:</p><h3>The Strategic Advantage:</h3><p><strong>10X Faster Alignment With 1/10th the Effort</strong></p><p>Once you eliminate the ambiguity created by black-box systems, something remarkable happens:</p><ul><li><p>Alignment accelerates</p></li><li><p>Decision cycles shrink</p></li><li><p>Rework disappears</p></li><li><p>Shadow expertise consolidates</p></li><li><p>Dependency on expensive consultants is minimized</p></li><li><p>And the organization begins operating with shared clarity</p></li></ul><p>Verified intelligence doesn&#8217;t just reduce risk &#8212; it creates leverage.<br>It allows leaders to move faster because they can <strong>prove</strong> the integrity of their decisions.</p><p>This is what separates the companies that are merely adopting AI from those that will define the next decade.</p><h2>Next Steps</h2><p><strong>If you&#8217;re interested in provenance, lineage, and transparency &#8212; Let&#8217;s Talk</strong></p><p>At Identient, we love partnering with organizations who understand where the world is heading.<br>Companies building AI with:</p><ul><li><p>Traceability</p></li><li><p>Transparency</p></li><li><p>Verifiable expertise</p></li><li><p>Auditability</p></li><li><p>And human-owned intelligence</p></li></ul><p>Those are the leaders who will outperform the rest of the market &#8212; not because they &#8220;used more AI,&#8221; but because they used <strong>trusted AI</strong>.</p><p>If that&#8217;s you, let&#8217;s chat.<br>We&#8217;d love to build the future with you.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Lorang, K. (2025, November 18). <em>Hugging Face CEO says we&#8217;re in an &#8220;LLM bubble,&#8221; not an AI bubble.</em> TechCrunch. https://techcrunch.com/2025/11/18/hugging-face-ceo-says-were-in-an-llm-bubble-not-an-ai-bubble/</p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-2" href="#footnote-anchor-2" class="footnote-number" contenteditable="false" target="_self">2</a><div class="footnote-content"><p>Colorado General Assembly. (2024). <em>SB 24-205: Consumer Protections for Artificial Intelligence Systems. https://leg.colorado.gov/bills/sb24-205</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-3" href="#footnote-anchor-3" class="footnote-number" contenteditable="false" target="_self">3</a><div class="footnote-content"><p>State of Illinois. (2024). <em>HB 3773: Amendments to the Illinois Human Rights Act for AI in Employment Decisions. https://www.ilga.gov/Legislation/BillStatus?GAID=17&amp;DocNum=3773&amp;DocTypeID=HB&amp;LegId=0&amp;SessionID=112</em></p></div></div><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-4" href="#footnote-anchor-4" class="footnote-number" contenteditable="false" target="_self">4</a><div class="footnote-content"><p>California Office of the Governor. (2025, September 29). <em>Governor Newsom signs SB-53, advancing California&#8217;s world-leading artificial intelligence industry</em>. <a href="https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/">https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/</a></p></div></div>]]></content:encoded></item><item><title><![CDATA[AI Transparency 2.0: Why Washington Must Go Beyond Deepfakes to Decision Provenance]]></title><description><![CDATA[HB 1170 is a strong start&#8212;but the Digital Government Summit made clear that Washington needs transparency not just for synthetic media, but for the AI shaping public decisions.]]></description><link>https://www.strategylayer.com/p/ai-transparency-20-why-washington</link><guid isPermaLink="false">https://www.strategylayer.com/p/ai-transparency-20-why-washington</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Fri, 14 Nov 2025 07:50:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!s3pg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Washington&#8217;s <a href="https://app.leg.wa.gov/billsummary?BillNumber=1170&amp;Initiative=false&amp;Year=2025">HB 1170</a> is an important step forward. Like <a href="https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/">California&#8217;s AI Transparency Act</a>, it focuses on labeling AI-generated and AI-altered content, embedding latent disclosures, and providing public detection tools. These measures matter. As Tom Kemp <a href="https://www.tomkemp.ai/blog/2025/1/20/state-of-washington-looks-to-make-ai-more-transparent">has documented</a>, states that anchor AI policy in transparency, traceability, and consumer protection gain bipartisan traction and avoid unworkable or overbroad AI legislation.</p><p>But as I argued recently in <em><a href="https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive">AI is Cheap. Trust is Expensive.</a></em>, transparency for content is only half of the equation. What residents need is trust in the systems that inform decisions about them. And today&#8217;s <strong><a href="https://events.govtech.com/Washington-Digital-Government-Summit">Washington Digital Government Summit</a></strong> made that clearer than ever.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>AI in government is no longer primarily about generating images or text. It is augmenting decisions, routing cases, prioritizing inspections, assisting in contracting, and shaping how residents interact with the state. Deepfakes aren&#8217;t the only risk. Opaque intelligence is, too.</p><p>Washington now needs <strong>AI Transparency 2.0</strong>: a model that provides provenance not just for synthetic media, but for AI-assisted decisions.</p><h1><strong>What HB 1170 Gets Right</strong></h1><p>HB 1170 focuses on media transparency:</p><ul><li><p>Clear labeling of AI-generated or AI-altered content</p></li><li><p>Latent and manifest disclosures</p></li><li><p>Publicly accessible detection tools with APIs</p></li><li><p>Limits on retention of user-submitted content</p></li><li><p>Alignment with C2PA-style provenance principles and NIST AI RMF concepts of traceability</p></li></ul><p>This is the right foundation. Synthetic media harms are real. Election security, misinformation prevention, and public trust all benefit from strong provenance requirements.</p><p>But the bill only addresses <em>outputs</em> that look like media. It does not address AI systems used for <em>decision support</em>, which is where the public sector is already moving.</p><p>Today&#8217;s Summit demonstrated that gap clearly.</p><h1><strong>What Washington&#8217;s Leaders Said Today</strong></h1><p>At the <strong>Washington Digital Government Summit</strong>, three themes emerged across the closing panel on &#8220;AI Governance and Digital Equity in Washington Government.&#8221;</p><h2>Bill Kehoe, State CIO</h2><p><em>&#8220;AI innovation must be risk-averse and transparent.&#8221;</em><br>Kehoe emphasized strong data foundations, privacy, security, and clear disclosures. He highlighted the modern wa.gov resident portal as an example of how structured data and personalization can enhance services, while noting that transparency and opt-outs are mandatory for public trust.</p><h2>Jake Hammock, CISO, City of Seattle</h2><p><em>&#8220;Seattle is adopting human-centered AI with humans in the loop &#8212; not displacement, but augmentation.&#8221;</em><br>Seattle is hiring a City AI Officer and implementing its Responsible AI plan across public safety, permitting, and customer-service operations. Hammock stressed equity, accessibility, language translation, and correct labeling of AI outputs.</p><h2>Stephen Hurd, Acting CIO, King County</h2><p><em>&#8220;Generative AI for decision-making remains tricky &#8212; human oversight is essential.&#8221;</em><br>Hurd emphasized productivity and capacity gains, but made it clear: any decision that affects residents must retain human review. King County&#8217;s upcoming AI policy is grounded in oversight, transparency, and digital equity.</p><p>Across all three leaders, one message was consistent:<br><strong>Government needs innovation, but it must remain cautious, transparent, and accountable.</strong></p><p>That requires more than content labeling.<br>It requires <strong>decision provenance</strong>.</p><h1><strong>The Gap in HB 1170: Transparency for Media but Not Decisions</strong></h1><p>HB 1170 does not apply to:</p><ul><li><p>Case prioritization</p></li><li><p>Eligibility determination</p></li><li><p>Contract routing</p></li><li><p>Public safety triage</p></li><li><p>Fraud detection</p></li><li><p>Resource allocation</p></li><li><p>Workforce augmentation</p></li><li><p>Constituent-service recommendations</p></li></ul><p>None of these produce synthetic media.<br>All of them influence residents&#8217; lives.</p><p>As the National Conference of State Legislatures puts it, governments nationwide are expanding their use of AI to &#8220;improve efficiency, decision-making, and the delivery of government services.&#8221;<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a> Today&#8217;s Summit speakers described the same reality in Washington.</p><p>We need transparency for more than images and content.<br>We need transparency for how AI contributes to decisions.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WRK4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WRK4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!WRK4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!WRK4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!WRK4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WRK4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2096625,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/178864747?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WRK4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!WRK4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!WRK4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!WRK4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbee7c7d5-6390-498b-a4ce-05863189680c_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Better decisions come from visible thinking, not black-box guesses. Credit: ChatGPT</figcaption></figure></div><h1><strong>A Three-Layer Provenance Model for Washington</strong></h1><p>Drawing from both HB 1170 and the guidance of Washington&#8217;s technology leaders, Washington can adopt a forward-looking model of AI provenance:</p><h2>1. Content Provenance</h2><p>This is the domain of HB 1170:<br>Labeling, watermarking, and detection of AI-generated or altered media.</p><h2>2. System Provenance</h2><p>Which model generated the output?<br>What version?<br>What training, tuning, and guardrails?<br>What data quality and risks were known?</p><p>This aligns with Kehoe&#8217;s emphasis on <strong>data foundations</strong>, Hammock&#8217;s focus on <strong>governance</strong>, and Hurd&#8217;s insistence on <strong>transparency</strong>.</p><h2>3. Decision Provenance</h2><p>When AI informs or influences a decision, residents deserve to know:</p><ul><li><p>Who or what made the recommendation</p></li><li><p>What signals, data, or models informed it</p></li><li><p>How the reasoning chain was constructed</p></li><li><p>Which human reviewed or approved it</p></li><li><p>What alternatives were considered</p></li></ul><p>This is where policy needs to evolve.<br>If content provenance protects residents from deception, <strong>decision provenance protects them from misgovernance, AI hallucinations, or worse</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!s3pg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!s3pg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!s3pg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!s3pg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!s3pg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!s3pg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1833941,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/178864747?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!s3pg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!s3pg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!s3pg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!s3pg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F89f66ff0-c8ba-4e30-a758-84680b232575_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Transparency is the difference between trusted AI and blind automation. Credit: ChatGPT</figcaption></figure></div><h1><strong>How Washington Can Lead Nationally</strong></h1><p>To build on HB 1170 and match the future of public-sector AI use, Washington policymakers can consider the following:</p><h2>1. Clarify provenance in legislative intent</h2><p>Acknowledge <strong>content</strong>, <strong>system</strong>, and <strong>decision</strong> provenance even if only the first is mandated today.</p><h2>2. Align with government-grade standards</h2><p>NIST AI RMF<br>NIST Data Lifecycle guidance<br>C2PA for content provenance<br>OCIO Policy 188 updates<br>Seattle&#8217;s Responsible AI Framework</p><h2>3. Require disclosures for AI-assisted decisions</h2><p>Not bans. Not burdens.<br>Just clear notification, human review, and documented reasoning.</p><h2>4. Support innovation funding</h2><p>Kehoe&#8217;s call for agile modernization funds is critical for safe experimentation.</p><h2>5. Encourage public-private collaboration</h2><p>Seattle and King County are building their own frameworks.<br>The state can accelerate their progress by providing structure without over-prescription.</p><p>Washington can become a national leader by expanding transparency from <strong>media</strong> to <strong>the decisions that shape public outcomes</strong>.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/ai-transparency-20-why-washington?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/ai-transparency-20-why-washington?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/ai-transparency-20-why-washington?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h1><strong>Toward Trusted Intelligence in Government</strong></h1><p>The conversations at the Summit revealed something important:<br>Public-sector leaders aren&#8217;t asking for more automation. They&#8217;re asking for <strong>clarity</strong>, <strong>consistency</strong>, and <strong>confidence</strong> in the intelligence they rely on.</p><p>They want to know who &#8212; or what &#8212; they&#8217;re listening to.<br>They want to understand why a recommendation was made.<br>They want a traceable line from advice to authentic expertise.</p><p>They want AI that behaves less like a black box and more like a <strong>trusted colleague</strong>.</p><p>This is where the next generation of AI will evolve: toward systems that don&#8217;t just generate content, but embody <strong>verifiable expertise</strong>, maintain <strong>consistent reasoning</strong>, and operate with <strong>provenance by design</strong>. Systems where the source of insight is clear, the chain-of-custody is intact, and decision-makers can see why a certain answer was produced.</p><p>Because ultimately, as I wrote in <em><a href="https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive">AI is Cheap. Trust is Expensive</a>.</em>, the future of AI isn&#8217;t about scaling intelligence &#8212; it&#8217;s about scaling <strong>trustworthy intelligence</strong>. And trust doesn&#8217;t come from speed or capacity. It comes from <strong>knowing what &#8212; and who &#8212; is behind the answers.</strong></p><h1><strong>Conclusion</strong></h1><p>HB 1170 is the right starting point.<br>Transparency for synthetic media is essential.</p><p>But today&#8217;s Washington Digital Government Summit made clear that the real frontier is <strong>AI-informed decisions</strong>, not just AI-generated images.</p><p>Washington has an opportunity to lead the nation by expanding transparency to <strong>content, systems, and decisions</strong> &#8212; building a governance model that supports innovation while protecting residents.</p><p>AI transparency must move past detecting deepfakes.<br>It must ensure <strong>accountability for the intelligence we rely on.</strong></p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>National Conference of State Legislatures, &#8220;Artificial Intelligence in Government: The Federal and State Landscape,&#8221; 2024.</p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[AI Is Cheap. Trust Is Expensive.]]></title><description><![CDATA[Why the next wave of enterprise AI isn&#8217;t about generating more&#8212;it&#8217;s about generating what&#8217;s true.]]></description><link>https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive</link><guid isPermaLink="false">https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Sun, 09 Nov 2025 22:42:26 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XVD2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Generative AI is everywhere, and it&#8217;s getting cheaper by the day. But as models multiply and content floods every corner of the enterprise, one truth is becoming clear: intelligence may be abundant, but trust is scarce.</p><p>This piece explores why provenance, verified expertise, and digital twins will define the next decade of AI&#8212;and why organizations that ignore trust will pay for it twice.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2><strong>The Illusion of Cheap AI</strong></h2><p>Anyone can buy ChatGPT Plus for $20. But you can&#8217;t buy trust.</p><p>That&#8217;s the quiet truth behind today&#8217;s AI gold rush. Models get cheaper, faster, and more accessible by the month. Yet the leaders who can actually <em>trust</em> the intelligence they&#8217;re building their strategies on&#8212;that&#8217;s still a rare privilege.</p><p>We&#8217;ve entered an era where the price of information is plummeting, but the cost of certainty is rising.</p><p>The question is no longer <em>Can AI think?</em> It&#8217;s <em>Can we trust what it thinks for us?</em></p><p>Because while AI may help us go faster, it often sends us racing confidently in the wrong direction.</p><blockquote><p><strong>&#8220;You can&#8217;t automate trust&#8212;but you can model it.&#8221;</strong></p></blockquote><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XVD2!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XVD2!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XVD2!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XVD2!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XVD2!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XVD2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1908144,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/178450427?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XVD2!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!XVD2!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!XVD2!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!XVD2!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ad641c-acfc-4826-b82a-71e0003a9210_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Everyone&#8217;s mining for intelligence. Few are minting trust.</figcaption></figure></div><h2><strong>The Problem with Cheap AI</strong></h2><p><em>Why &#8220;good enough&#8221; AI isn&#8217;t good enough for enterprise strategy.</em></p><p>Generative AI, for all its brilliance, is a master of mimicry. It&#8217;s a regurgitation engine&#8212;reshaping the web&#8217;s collective past into a polished, probabilistic reflection of the present. Ask it for a strategy, and it will give you the <em>average</em> of a thousand other strategies. Ask it for insight, and it will offer what sounds smart, not what <em>is</em> smart.</p><p>That&#8217;s fine for brainstorming. But it&#8217;s a liability for leadership.</p><p>When you rely on GenAI to solve strategic problems, you often become a <strong>context engineer</strong>&#8212;constantly rewriting prompts, rewording queries, and correcting hallucinations to chase precision that never quite arrives.</p><p>Meanwhile, hours disappear. Teams feel productive because words appear. But the signal-to-noise ratio drops. Leaders spend <strong>2&#8211;10x more time</strong> iterating on outputs that lead to dead ends&#8212;or worse, elegant nonsense.</p><p>And then there&#8217;s the hidden cost: <strong>AI laundering.</strong></p><p>Like money laundering, it&#8217;s the process of taking someone else&#8217;s intellectual capital, washing it through a model, and reissuing it as your own. Except this time, the currency being diluted isn&#8217;t cash&#8212;it&#8217;s <em>credibility.</em></p><p>Authenticity becomes a liability on your balance sheet. Original thinking erodes. And in a world now governed by emerging AI transparency laws&#8212;like California&#8217;s <strong>AI Transparency Act 2.0<a class="footnote-anchor" data-component-name="FootnoteAnchorToDOM" id="footnote-anchor-1" href="#footnote-1" target="_self">1</a></strong>, which mandates provenance and labeling&#8212;what was once clever repurposing is becoming a compliance and reputation risk.</p><p>The bottom line: cheap AI produces expensive confusion.</p><blockquote><p><strong>&#8220;Generative AI creates content. Verified expertise creates conviction.&#8221;</strong></p></blockquote><h2><strong>The Trust Crisis in Enterprise AI</strong></h2><p><em>When everyone&#8217;s AI looks the same, trust becomes your competitive advantage.</em></p><p>Trust has always been the currency of business. But in an AI-saturated world, it&#8217;s becoming the <strong>exchange rate</strong> for strategy itself.</p><p>Yes, you can buy a $20 chatbot. But it won&#8217;t buy you executive alignment, investor confidence, or measurable impact on your P&amp;L.</p><p>At the enterprise level, the real question isn&#8217;t <em>&#8220;How do we use AI?&#8221;</em> but <em>&#8220;How do we trust what it tells us enough to act on it?&#8221;</em></p><p>Because <em>enterprise-scale trust</em>&#8212;the kind that drives seven- and eight-figure impact&#8212;requires more than model performance metrics. It requires <strong>verified expertise</strong>. A lineage of knowledge that can be traced, cited, and believed.</p><p>When AI outputs come from nowhere, trust goes nowhere.</p><p>That creates a new class of corporate risk: <strong>strategic opacity.</strong></p><p>Decisions built on synthetic knowledge&#8212;unverified, unattributed, context-free&#8212;create cracks in the foundation of leadership. You don&#8217;t just risk making bad calls; you risk eroding the confidence that fuels innovation.</p><p>When you can&#8217;t trace the origin of your insights, you&#8217;ve already lost control of the narrative.</p><blockquote><p><strong>&#8220;The real moat in AI isn&#8217;t data. It&#8217;s provenance.&#8221;</strong></p></blockquote><h2><strong>Leadership Without Trust Is Just Noise</strong></h2><p><em>Why the C-suite alignment problem is human, not technical.</em></p><p>Getting the C-suite on the same page has never been easy. Ego, politics, and miscommunication quietly drain millions in strategic waste every quarter. The most brilliant minds in the room often talk past each other, armed with their own truths.</p><p>And while AI was supposed to fix this, it often amplifies it.</p><p>When every executive can generate their own &#8220;strategic analysis&#8221; from a model trained on the internet, alignment doesn&#8217;t improve&#8212;it fractures. Each leader arrives armed with a different AI narrative, polished by different prompts, reflecting different biases.</p><p>You can&#8217;t automate alignment.</p><p>You have to build it&#8212;through trust, shared context, and a common source of truth.</p><p>That&#8217;s where <strong>verified digital twins</strong> enter the picture. Not fictional avatars, but faithful digital representations of executives, domain experts, and peer networks&#8212;trained on verified expertise, not scraped data.</p><p>These twins don&#8217;t replace leaders; they <em>reflect</em> them. They create a space where collaboration can happen without ego, where ideas can be tested, refined, and aligned before they ever reach production.</p><p>Imagine your leadership team rehearsing decisions with their digital counterparts&#8212;testing scenarios, surfacing blind spots, and converging on clarity without the friction of personality or politics.</p><p>That&#8217;s not science fiction. It&#8217;s a new kind of organizational psychology powered by verified intelligence.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0qUg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0qUg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!0qUg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!0qUg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!0qUg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0qUg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1943156,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/178450427?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0qUg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!0qUg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!0qUg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!0qUg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0bbf493d-a2e3-41d4-ab71-5ad67f157770_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Somewhere between the human and the algorithm lies the truth about leadership in the age of AI.</figcaption></figure></div><h2><strong>From Generative to Verified</strong></h2><p><em>The rise of digital twins and the return of provenance.</em></p><p>The next era of AI isn&#8217;t about <em>generating</em> more content. It&#8217;s about <em>verifying</em> the intelligence that drives decisions.</p><p><strong>Large Language Models (LLMs)</strong> are broad but shallow&#8212;they know something about everything, but not enough about <em>you.</em><br><strong>Small Language Models (SLMs)</strong>&#8212;trained on specific, verified data&#8212;are the inverse. They know less, but what they know is <em>true, trusted, and contextual.</em></p><p>It&#8217;s the difference between reading Wikipedia and calling a mentor who&#8217;s been there.</p><p>Verified digital twins combine these SLMs with authenticated sources of expertise&#8212;creating a chain of provenance from <em>human knowledge &#8594; verified data &#8594; explainable output.</em></p><p>This mirrors what&#8217;s happened in supply chains, finance, and media: <strong>provenance is the new quality.</strong></p><p>For organizations, this is more than technical evolution. It&#8217;s philosophical.</p><p>When you can <em>trust your intelligence</em>, you no longer need to over-engineer control. You can move faster with less oversight because the system itself embeds integrity.</p><p>That&#8217;s what it means to <strong>execute 10x faster with 1/10th the effort.</strong></p><p>Speed doesn&#8217;t come from automation&#8212;it comes from alignment.<br>And alignment starts with trust.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/ai-is-cheap-trust-is-expensive?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2><strong>The Real Cost of Trust</strong></h2><p><em>Now is the time to put trust back at the center of AI.</em></p><p>AI is cheap. Trust is expensive.</p><p>But if you think trust is expensive, try operating without it.</p><p>The cost shows up in misaligned strategy meetings, delayed decisions, duplicated work, and stalled innovation. It&#8217;s the silent tax of distrust&#8212;paid daily by organizations that confuse speed with progress.</p><p>The companies that will win the next decade aren&#8217;t the ones deploying the most AI. They&#8217;re the ones deploying the most <strong>trusted intelligence</strong>&#8212;systems that integrate verified expertise, ethical provenance, and transparent reasoning.</p><p>Trust is not a soft concept. It&#8217;s a hard asset. It determines whether a CISO can sign off on a risk model, whether a CEO can act on a market signal, whether an investor believes your AI has defensible value.</p><p>As California&#8217;s AI Transparency Act signals, the market is demanding proof, not promises.</p><p>And that&#8217;s where the opportunity lies.</p><p>The leaders who invest now in verified digital twins&#8212;who create AI systems rooted in authenticity, attribution, and trust&#8212;won&#8217;t just comply with the future. They&#8217;ll <em>define</em> it.</p><p>Because the next phase of AI isn&#8217;t about bigger models. It&#8217;s about <strong>better mirrors</strong>&#8212;digital counterparts that reflect what&#8217;s real, credible, and uniquely yours.</p><p>The question isn&#8217;t whether you&#8217;ll build one.<br>The question is <em>when.</em></p><h3><strong>Final Reflection</strong></h3><p>AI is no longer the differentiator. Everyone has it.<br>What will separate tomorrow&#8217;s market leaders is whether anyone believes what <em>their</em> AI says.</p><p>The companies that invest in verified expertise, transparency, and trust won&#8217;t just build better technology&#8212;they&#8217;ll build the credibility to lead.</p><p>And in a world where everyone&#8217;s shouting through machines, credibility might just be the last human advantage.</p><div class="footnote" data-component-name="FootnoteToDOM"><a id="footnote-1" href="#footnote-anchor-1" class="footnote-number" contenteditable="false" target="_self">1</a><div class="footnote-content"><p>Governor of California. (2025, September 29). <em>Governor Newsom signs SB 53, advancing California&#8217;s world-leading artificial intelligence industry</em>. <a href="https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/">https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/</a> (<a href="https://www.gov.ca.gov/2025/09/29/governor-newsom-signs-sb-53-advancing-californias-world-leading-artificial-intelligence-industry/">gov.ca.gov</a>)</p><p></p></div></div>]]></content:encoded></item><item><title><![CDATA[The Two Faces of ROI]]></title><description><![CDATA[ROI lives in two worlds: the forecast and the proof. The best leaders use it to price the future&#8212;and verify it over time.]]></description><link>https://www.strategylayer.com/p/the-two-faces-of-roi</link><guid isPermaLink="false">https://www.strategylayer.com/p/the-two-faces-of-roi</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Mon, 27 Oct 2025 19:59:00 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Ij4F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>A few weeks ago, I wrote <em><a href="https://www.strategylayer.com/p/playing-a-winnable-game-why-cybersecurity">Playing a Winnable Game: Why Cybersecurity Leaders Must Master Strategic Finance</a> </em>&#8212; about treating cybersecurity as capital allocation, not cost control. It&#8217;s a good primer for what I&#8217;m seeing surface again right now.</p><p>As we head into <strong>budget planning season</strong> for the next calendar year, one theme keeps showing up in every conversation: <strong>ROI</strong>.</p><p>Executives love certainty. Boards demand it. Vendors try to simulate it.<br>And somewhere in that tension lives the great illusion of modern enterprise finance&#8212;the illusion of <em>pre-proven ROI</em>.</p><p>ROI isn&#8217;t an oracle. It&#8217;s a model. It doesn&#8217;t predict the future; it helps you price it.<br>And in that sense, it functions much like <strong>Net Present Value (NPV)</strong> or the <strong>time value of money</strong>: both are forecasts that rely on real data, reasonable assumptions, and continuous refinement.</p><p>When leaders expect &#8220;proven ROI&#8221; before an engagement begins, what they&#8217;re really asking for is a <strong>forecast without inputs</strong>.<br>That&#8217;s not rigor&#8212;it&#8217;s wishful thinking dressed as discipline.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>ROI as Forecast, Not Faith</h2><p>ROI forecasting is not a sales tactic; it&#8217;s a <strong>financial instrument</strong>.<br>In finance, investors don&#8217;t demand proof of return before deploying capital. They model <strong>expected return</strong> using known variables: capital costs, cash flows, discount rates, and risk-adjusted assumptions.</p><p>Cybersecurity investments should be treated the same way.<br>Potential ROI is calculated through <strong>financial modeling</strong>, not conjecture. The process applies economic principles to project the <em>present value of future benefits</em> relative to the <em>present value of future costs.</em></p><p>The key distinction is that ROI modeling is <strong>forecastable</strong>, not <strong>hypothetical</strong>.<br>It&#8217;s a legitimate form of decision analysis that provides directional confidence&#8212;not false precision.</p><h2>The Discipline of Cost-Benefit Analysis</h2><p>A well-constructed <strong>Cost-Benefit Analysis (CBA)</strong> is the backbone of ROI modeling.<br>It&#8217;s not about storytelling&#8212;it&#8217;s an <em>exercise in economics.</em></p><p>The data required isn&#8217;t secret; it&#8217;s just often unavailable to external partners. It includes:</p><ul><li><p>Capital costs</p></li><li><p>Operational costs</p></li><li><p>Cost reductions</p></li><li><p>Reduction of manual effort</p></li><li><p>Efficiency gains</p></li><li><p>Financial impact on the P&amp;L</p></li></ul><p>Each of these inputs connects directly to real financial systems&#8212;your ledger, your labor data, your operational reports. Without those inputs, external ROI projections are like calculating NPV with blank cells.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WIH7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WIH7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!WIH7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!WIH7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!WIH7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WIH7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png" width="1280" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1280,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99938,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/177303365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WIH7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 424w, https://substackcdn.com/image/fetch/$s_!WIH7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 848w, https://substackcdn.com/image/fetch/$s_!WIH7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 1272w, https://substackcdn.com/image/fetch/$s_!WIH7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F215e9d33-78db-4ed7-afef-8a150a99f3e0_1280x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cost-benefit analysis isn&#8217;t hypothetical&#8212;it&#8217;s applied economics. When modeled with real data, everything becomes measurable: time, money, and efficiency.</figcaption></figure></div><p>As shown in the example:</p><p>Alternative Total Costs Total Benefits Benefit-Cost Ratio A $100,000 $120,000 1.20 B $150,000 $190,000 <strong>1.27</strong> C $200,000 $230,000 1.15</p><p>The <strong>Benefit-Cost Ratio (BCR)</strong> is calculated as:</p><p><strong>BCR = &#931; Present Value of Total Future Benefits / &#931; Present Value of Total Future Costs</strong></p><p>A ratio above 1.0 means benefits outweigh costs; the higher the number, the greater the return on investment.<br>But the value of the analysis isn&#8217;t in the number&#8212;it&#8217;s in the <em>inputs</em>.</p><p>Everything in cost-benefit analysis is measurable, but nothing is meaningful until the data reflects the realities of your environment.</p><h2>The Time Value of Money: ROI&#8217;s Silent Variable</h2><p>Every executive understands the <strong>time value of money</strong>&#8212;a dollar today is worth more than a dollar next year.<br>But in cybersecurity and operations, this truth is often forgotten.</p><p>When projects stall in pursuit of pre-proven ROI, the organization quietly accrues what economists call the <strong>Cost of Delay</strong>.<br>Security risks persist. Operational inefficiencies linger. Opportunity costs compound.</p><p>Time is a variable in every ROI equation.<br>Real ROI, therefore, is a function of <strong>time, money, and resources</strong>&#8212;not just savings. It recognizes that the longer a system remains inefficient, the smaller the present value of future benefits becomes.</p><p>Waiting for proof before acting is, in financial terms, a <strong>negative-yield strategy</strong>.</p><h2>Forecasting with Real Data</h2><p>To transform ROI from abstraction into strategy, organizations must model it like they would any other investment&#8212;using financial data grounded in reality.</p><p>The process typically includes:</p><ol><li><p><strong>Establishing Baselines</strong> &#8211; Gather financial and operational metrics that describe the current state: time spent, headcount, system costs, and performance indicators.</p></li><li><p><strong>Modeling Scenarios</strong> &#8211; Use those baselines to model potential future states under different investment scenarios.</p></li><li><p><strong>Applying Discount Rates</strong> &#8211; Adjust for the time value of money to calculate the present value of future benefits.</p></li><li><p><strong>Analyzing Sensitivity</strong> &#8211; Identify which variables most affect outcomes; this drives smarter decisions and better risk management.</p></li></ol><p>This process isn&#8217;t theoretical&#8212;it&#8217;s how mature organizations make capital budgeting decisions every day.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ij4F!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ij4F!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Ij4F!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Ij4F!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Ij4F!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ij4F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1874033,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/177303365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ij4F!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Ij4F!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Ij4F!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Ij4F!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F87916996-eae5-42bb-be6d-36bc436b70c5_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Where foresight meets evidence &#8212; the moment ROI transforms from modeled potential to measurable impact.</figcaption></figure></div><h2>ROI as a Strategic Instrument</h2><p>Once leaders accept that ROI is forecastable, not provable, the question shifts from &#8220;What&#8217;s the number?&#8221; to &#8220;What&#8217;s the <em>model</em>?&#8221;</p><p>A credible ROI model is a <em>strategic instrument</em> for prioritization. It helps leaders allocate capital across competing priorities based on expected value creation, not gut feel.</p><p>For example:</p><ul><li><p>An IAM modernization initiative might reduce operational cost and incident response time, improving both financial efficiency and enterprise resilience.</p></li><li><p>A workflow automation platform might reduce manual effort, reallocating skilled labor to higher-value work.</p></li><li><p>A governance dashboard might shorten reporting cycles, directly improving decision velocity and cost of coordination.</p></li></ul><p>In each case, ROI isn&#8217;t <em>proven</em> in advance&#8212;it&#8217;s <strong>priced</strong> in advance and <strong>measured</strong> afterward.<br>That&#8217;s the discipline of real finance.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JoT4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JoT4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 424w, https://substackcdn.com/image/fetch/$s_!JoT4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 848w, https://substackcdn.com/image/fetch/$s_!JoT4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 1272w, https://substackcdn.com/image/fetch/$s_!JoT4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JoT4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png" width="1456" height="717" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:717,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:352576,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/177303365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JoT4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 424w, https://substackcdn.com/image/fetch/$s_!JoT4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 848w, https://substackcdn.com/image/fetch/$s_!JoT4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 1272w, https://substackcdn.com/image/fetch/$s_!JoT4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85cc1fc6-c9d0-46e3-86ae-3f90794ff152_3023x1489.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Board Reporting Kit &#8211; Premium (Strategic Multiplier Tools): Modeling efficiency, trade-offs, and the real cost of delay to reveal ROI in motion. (Click to enlarge)</figcaption></figure></div><h2>The Misunderstanding of &#8220;Proof&#8221;</h2><p>Executives sometimes conflate <strong>forecasting</strong> with <strong>guaranteeing</strong>, but they&#8217;re fundamentally different.</p><p>Forecasting acknowledges uncertainty and quantifies it.<br>Guaranteeing denies it.</p><p>Demanding proof of ROI before engagement collapses the learning cycle that real innovation depends on.<br>The goal isn&#8217;t to eliminate uncertainty&#8212;it&#8217;s to make uncertainty <em>investable</em>.</p><p>That&#8217;s what separates a <strong>finance function</strong> from a <strong>procurement function.</strong></p><p>Finance models potential return across a time horizon, adjusting for risk and delay.<br>Procurement demands certainty in a system that, by design, never offers it.</p><p>The strategic leader understands that you can&#8217;t measure ROI before you create the conditions for it to exist.</p><h2>The Benefit of Shared Measurement</h2><p>When both sides&#8212;provider and customer&#8212;commit to shared data, baselines, and transparency, ROI becomes not a point of contention but a <strong>system of continuous learning.</strong></p><p>That&#8217;s why at Identient, our Strategic Performance Intelligence (SPI 360) framework builds ROI tracking into the engagement itself.<br>We don&#8217;t claim hypothetical returns. We create the environment to <strong>measure</strong> them&#8212;continuously, in real time.</p><p>This allows leadership teams to track <strong>Benefit-Cost Ratios</strong> dynamically, as projects mature and efficiency gains are realized. It replaces &#8220;proof&#8221; with <em>visibility</em>.</p><h2>Beyond ROI: Real Options and Adaptive Value</h2><p>Sophisticated financial modeling doesn&#8217;t stop at ROI or NPV&#8212;it extends into <strong>real options analysis</strong>, a method for valuing flexibility under uncertainty.</p><p>In cybersecurity, every investment creates <em>future optionality</em>&#8212;the ability to pivot faster, integrate more effectively, or scale without friction.<br>These are tangible financial benefits, even if they&#8217;re not reflected on a quarterly report.</p><p>Real options thinking transforms ROI from a static retrospective metric into a <strong>strategic forecast of adaptability</strong>.<br>It asks: &#8220;What is the value of keeping our options open?&#8221;<br>That&#8217;s a far more powerful question than, &#8220;What&#8217;s the ROI today?&#8221;</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>From Reporting to Strategy</h2><p>When ROI is treated as proof, it becomes a rearview mirror.<br>When it&#8217;s treated as a forecast, it becomes a steering wheel.</p><p>Executives who understand this use ROI to inform <em>where to steer next</em>, not to justify where they&#8217;ve been.</p><p>This is where cybersecurity leaders can elevate their role&#8212;from cost managers to strategic investors in enterprise resilience.<br>By adopting cost-benefit analysis, time-value modeling, and real options frameworks, they move beyond budget defense into capital strategy.</p><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-two-faces-of-roi?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/the-two-faces-of-roi?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/the-two-faces-of-roi?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><h2>Closing Thought</h2><p>ROI isn&#8217;t something to <em>prove</em>; it&#8217;s something to <em>build</em>.</p><p>The discipline lies not in the pitch deck or the spreadsheet, but in the partnership that enables access to real data, shared baselines, and measurable outcomes over time.</p><p>In finance, as in cybersecurity, the most valuable returns compound quietly&#8212;through systems that learn, models that evolve, and leaders who understand that proving value starts by creating the conditions for it.</p><p><strong>Closing Call to Action:</strong><br>If you found this valuable and want to go deeper into how leaders make ROI real&#8212;balancing foresight, proof, and strategic execution&#8212;pick up my book, <em><a href="https://www.stevetout.com/book/">The CISO on the Razor&#8217;s Edge</a></em>, available now on <strong>Amazon</strong> and <strong>Barnes &amp; Noble</strong>.</p><p>If you&#8217;ve already purchased the book and want the companion<strong> Guide to Building a Business Case</strong>, just message me with a copy of your receipt&#8212;I&#8217;ll send you a private link to access it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.stevetout.com/book/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!b4yO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 424w, https://substackcdn.com/image/fetch/$s_!b4yO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 848w, https://substackcdn.com/image/fetch/$s_!b4yO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 1272w, https://substackcdn.com/image/fetch/$s_!b4yO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!b4yO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png" width="466" height="742.2074175824176" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2319,&quot;width&quot;:1456,&quot;resizeWidth&quot;:466,&quot;bytes&quot;:2281043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.stevetout.com/book/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/177303365?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!b4yO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 424w, https://substackcdn.com/image/fetch/$s_!b4yO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 848w, https://substackcdn.com/image/fetch/$s_!b4yO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 1272w, https://substackcdn.com/image/fetch/$s_!b4yO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b39ca5e-b708-4855-be8d-82b423ea42bb_1554x2475.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">From forecasting value to proving it&#8212;this is the playbook for CISOs leading on the razor&#8217;s edge.</figcaption></figure></div><p></p>]]></content:encoded></item><item><title><![CDATA[When Growth Becomes the Enemy: The Neuroscience of Change Fatigue]]></title><description><![CDATA[Why &#8220;more, faster, now&#8221; backfires&#8212;and how next-gen leaders recalibrate for sustainable performance.]]></description><link>https://www.strategylayer.com/p/when-growth-becomes-the-enemy-the</link><guid isPermaLink="false">https://www.strategylayer.com/p/when-growth-becomes-the-enemy-the</guid><dc:creator><![CDATA[Nicolette Sulaiman]]></dc:creator><pubDate>Sat, 04 Oct 2025 18:16:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!QZL-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>I invited my friend and colleague <strong>Nicolette Sulaiman</strong> to write a guest post for <em>The Strategy Layer</em> because her work in change management and adult learning gets to the heart of what drives real transformation &#8212; people. You can&#8217;t build performance or resilience without understanding and managing the human element.</p><p>I love how she connects neuroscience, learning, and leadership in this piece. I hope you enjoy it as much as I did &#8212; and be sure to <strong>follow her on LinkedIn</strong> (links below).</p><p>&#8212; <em>Steve</em></p><div><hr></div><p>In the Fall of 2019, the supply chain and logistics firm I&#8217;d worked at adopted a new proprietary system across the entire worldwide firm. Fast-forward to Spring of 2020 and I&#8217;m a subject matter expert converting my branch to the new system; designing and delivering trainings to enable learning of the new system, skill development and behavioral change. While determining what level of support and guidance each member of my branch required to successfully adopt the new system, I considered factors like exposure to the system, length of tenure and each employee&#8217;s duty to their book of business. I considered the employee&#8217;s relationship to the <em>business</em>. Hindsight is 2020, so in retrospect I would have considered the sheer impact of change&#8212;not just on the functional or emotional capacities of my colleagues&#8212;but the physiological impact that change has on the brain and our learning capabilities.</p><p>At this year&#8217;s Association of Chang Management Professionals (ACMP) Chicago conference co-author of <em>Neuroscience for Change at Work</em>, Tibisay Vera, introduced many of us to a neural experience called maladaptive plasticity. <strong>It&#8217;s the phenomenon of our brains&#8217; protective adaptation to constant change which left unsupported can show up as burnout, cynicism, withdrawal, disengagement and resistance to the change at hand.</strong> Vera presented on the PEPE model, a supportive framework for handling change that considers the natural reactions of our brains under transition duress. Woven throughout Vera&#8217;s PEPE methodology is not just an understanding but an acceptance of our natural brain functionality under change. Understanding maladaptive plasticity and its symptoms is paramount for change practitioners&#8212;particularly adult learning enablers.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QZL-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QZL-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 424w, https://substackcdn.com/image/fetch/$s_!QZL-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 848w, https://substackcdn.com/image/fetch/$s_!QZL-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 1272w, https://substackcdn.com/image/fetch/$s_!QZL-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QZL-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png" width="947" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6804ce33-e484-4149-af37-056a5860256e_947x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:947,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1374732,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/175284463?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QZL-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 424w, https://substackcdn.com/image/fetch/$s_!QZL-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 848w, https://substackcdn.com/image/fetch/$s_!QZL-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 1272w, https://substackcdn.com/image/fetch/$s_!QZL-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6804ce33-e484-4149-af37-056a5860256e_947x870.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption"><em>The Adaptive Mind: Where Human Limits Meet System Intelligence (credit: my GPT:)</em></figcaption></figure></div><p>Learning a new skill or behavior is one of the most vulnerable experiences consistent across all of humanity. I&#8217;m not sure if there&#8217;s a person reading this that hasn&#8217;t felt the anxiety of absorbing new information&#8212;the hesitancy in one&#8217;s mind and body that manifests as mental rigidity and physical stiffness as we practice new ways of thinking and new movements. <strong>As a change practitioner, think critically about the pressure of change on top of the vulnerability of learning</strong>. Think about the symptoms of burnout, cynicism, withdrawal and consider the sheer amount of might and dedication a learner must apply to absorb new information despite their disengagement.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Last year, the Society for Human Resource Management (SHRM) reported that <strong><a href="https://www.shrm.org/topics-tools/news/inclusion-diversity/burnout-shrm-research-2024">44% percent</a> of their 1000+ surveyed American employees are experiencing burnout. </strong>SHRM cited that workers experiencing burnout are three times more likely to be actively job searching and are significantly less likely to go above and beyond in the role where they&#8217;re experiencing the burnout symptoms. The repulsion from the environment that causes symptoms of maladaptive plasticity on top of the drive toward relief is enough to stifle any business&#8217; growth and innovation. The insight that burnout is nearly half the workforce&#8217;s experience should be enough to alarm any executive leader into action. Afterall, organizations&#8217; greatest assets are its people. Time and time again, I&#8217;ve heard <em>and said</em> that change management focuses on the people side of innovation. If we don&#8217;t consider the whole human, <em>we are not doing our jobs</em>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PK-7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PK-7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PK-7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PK-7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PK-7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PK-7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg" width="1254" height="836" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:836,&quot;width&quot;:1254,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:561217,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/175284463?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PK-7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 424w, https://substackcdn.com/image/fetch/$s_!PK-7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 848w, https://substackcdn.com/image/fetch/$s_!PK-7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!PK-7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb0496a99-3fd1-41ac-bb52-677538044248_1254x836.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">When the system supports the human, performance becomes natural.</figcaption></figure></div><p>Here&#8217;s what it looks like to lead learning while considering maladaptive plasticity through a transition:</p><ul><li><p>Breaks in lessons are not spared.</p></li><li><p>Self-care during the transition, such as taking breaks for walks, are required and taken into consideration of employee performance.</p></li><li><p>Methodologies that incorporate support for individuals with ADHD, Autism, chronic anxiety and other neurodivergent experiences.</p></li></ul><div class="captioned-button-wrap" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/when-growth-becomes-the-enemy-the?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="CaptionedButtonToDOM"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! This post is public so feel free to share it.</p></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/p/when-growth-becomes-the-enemy-the?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/p/when-growth-becomes-the-enemy-the?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p></div><p>As a change practitioner, adult learning enabler, and, at my core, a person who learns differently, I think about accessibility of education through transitions. I apply a plethora of tactics to engage various learners and learning styles at once. My goals are simple: to be successful in the full realization of the benefits of the change. <strong>When we consider the impact of transitions on the brain and imbed specific support into lesson planning and strategic behavioral change, we approach learning enablement with equity.</strong> This is critical. It shouldn&#8217;t be an option to leave behind folks who are experiencing maladaptive plasticity or who learn differently. After all, that would be a willing submission to a subpar return on change investment. That simply won&#8217;t do.</p><p>Learning enablement isn&#8217;t whole without equity. We facilitate an equitable learning experience by:</p><ul><li><p>Assessing how enterprise transitions uniquely impact various job functions.</p></li><li><p>Monitoring the symptoms of maladaptive plasticity in people and implementing symptom alleviation strategies.</p></li></ul><div class="pullquote"><p>As change practitioners and adult learning enablers, we must consider the whole human both internally (neurologically) and externally (how they experience the world.) </p></div><p>As change practitioners and adult learning enablers, we must consider the whole human both internally (neurologically) and externally (how they experience the world.) This is how we approach learning enablement with equity in mind under the stress of ever-present change. In a world where change is rapidly increasing; where unlimited growth is pined after and ultimately unsustainable, we need to take care of one another. As business leaders and chief executives, the holistic wellness of your business&#8217; greatest asset (its people) cannot be overstated. Failure to administer preventative burnout care is an acceptance of subpar returns on innovations investments. Secure your investments by:</p><ul><li><p>Factoring in maladaptive plasticity to enterprise change return and adoption rates</p></li><li><p>Level-setting shareholders&#8217; expectations of investment returns considering the statistical facts of neurological impact of change on the brain</p></li></ul><h2>Resources</h2><p><em>Are you ready to envision a growth strategy that not only accepts but makes the most of the human condition?</em></p><p>Learn more about maladaptive plasticity and the <a href="https://pepeneuroscience.com/about/">PEPE model</a>.</p><p>Learn more about <a href="https://www.linkedin.com/in/tibisayvera/">Tibisay Vera, MBA, MSc</a>.</p><p>See the SHRM article <a href="https://www.shrm.org/topics-tools/news/inclusion-diversity/burnout-shrm-research-2024">Here&#8217;s How Bad Burnout Has Become at Work</a>.</p><h2>About Nicolette</h2><p>Tomilola &#8220;Nic&#8221; Sulaiman is a Prosci Certified Change Practitioner that hails from Houston, TX who has spent the last eight years living and working in Chicago, IL. Nic earned her stripes doing change work across both public and private industries such as Mergers + Acquisitions, ERP implementations, Health Care IT, Financial Technology, Supply Chain/3PL Freight forwarding, and Food + Beverage. She&#8217;s cut her teeth as a change manager, adult learning enabler and communications strategist embedding diversity, equity and inclusion practices in her delivery. Nic is an active member of her small midwestern community, lover and proprietor of local art, and champion of radical self-love and community care.</p><p>Follow Nic on LinkedIn <a href="https://www.linkedin.com/in/tnsulaimanhr/">HERE</a></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V59W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V59W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V59W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V59W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V59W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V59W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg" width="290" height="386.6666666666667" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:640,&quot;width&quot;:480,&quot;resizeWidth&quot;:290,&quot;bytes&quot;:70426,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/175284463?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V59W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!V59W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!V59W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!V59W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b390186-c20e-44e4-92c1-109e6a5e8a9a_640x480.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Nicolette Sulaiman</figcaption></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Will Not Run IAM for You]]></title><description><![CDATA[Why Faster Answers Don&#8217;t Equal Better Outcomes in IAM]]></description><link>https://www.strategylayer.com/p/ai-will-not-run-iam-for-you</link><guid isPermaLink="false">https://www.strategylayer.com/p/ai-will-not-run-iam-for-you</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Sun, 28 Sep 2025 21:26:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!bwLu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Identity and Access Management is not a side project. It is the connective tissue of digital business. When it works, customers log in, employees collaborate, and revenue flows. When it fails, the entire enterprise feels it&#8212;systems grind to a halt, regulators come calling, and trust evaporates overnight.</p><p>That&#8217;s why the current fascination with AI is more than a passing trend, it&#8217;s a strategic risk. Too many leaders are mistaking faster answers for smarter execution. But IAM is not solved by access to information. It is solved by leadership, alignment, and judgment.</p><p>And those are things no algorithm can provide.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bwLu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bwLu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!bwLu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!bwLu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!bwLu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bwLu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2398865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/174780239?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!bwLu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!bwLu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!bwLu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!bwLu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc93e488-5df4-4e32-89f4-444d72760303_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>The Architect and the Algorithm</em> (credit: my GPT:)</p><h2>The Temptation of AI in IAM</h2><p>Artificial Intelligence&#8212;particularly Large Language Models (LLMs) like ChatGPT, Claude, and Gemini&#8212;has captivated the business world. From the boardroom to the data center, leaders are asking: <em>If AI can write code, generate board reports, and summarize 300-page analyst studies in seconds, why can&#8217;t it run Identity and Access Management (IAM)?</em></p><p>The question is understandable. IAM has always been a discipline flooded with information&#8212;white papers, analyst notes, vendor briefs, and implementation guides. The dream of instant expertise at the push of a button is alluring. Faster access to insights feels like it should unlock progress.</p><p>But it doesn&#8217;t. Having carried the responsibility for enterprise IAM across industries and sectors for over a decade, I can tell you this: access to information has <em>never</em> been the problem. Fifteen years ago, I had Gartner, KuppingerCole, and Forrester at my disposal. More recently, I&#8217;ve <a href="https://www.strategylayer.com/p/equity-by-design-lessons-from-modernizing">spearheaded CIAM modernization</a> for Washington State with both the benefit of an IT degree, MBA toolkit, and GPT-4 at my side. None of it replaces the judgment, creativity, and leadership of a seasoned consultant or architect.</p><p>Because IAM is not just about <em>knowing</em>&#8212;it is about <em>deciding, aligning, and executing</em>. And that is where AI fails to deliver.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>Information Isn&#8217;t Execution</h2><p>Think back to the early 2010s. If I needed to know the recommended maturity model for privileged access management, I could find it in a research note. I could highlight the right quadrant and present it to a steering committee with confidence.</p><p>Today, I can prompt ChatGPT: <em>&#8220;Outline the pillars of a successful IAM program.&#8221;</em> In seconds, I&#8217;ll have a polished summary&#8212;structured, logical, and familiar. Yet the strategic value is unchanged. Faster delivery doesn&#8217;t mean better results.</p><p>Information&#8212;even when attractively packaged&#8212;cannot:</p><ul><li><p>Build a compelling business case for your CFO.</p></li><li><p>Secure executive sponsorship when politics are stacked against you.</p></li><li><p>Balance IAM investments with competing business priorities.</p></li><li><p>Recognize cultural blockers that silently stall adoption.</p></li><li><p>Be accountable at 2:00 AM when SSL certificates expire and customer portals go dark.</p></li></ul><p>In other words, the hard part of IAM has never been the content&#8212;it&#8217;s the <em>context</em>. The art is in navigating people, priorities, and pressure. And context is where AI shows its limitations most clearly.</p><h2>The Illusion of Stochastic Certainty</h2><p>One reason AI is seductive is the fluency of its answers. An LLM can make even shaky reasoning sound confident. But behind the curtain lies stochasticity&#8212;the probabilistic process by which models generate responses.</p><p>Try this simple experiment: prompt your favorite AI chatbot with the request, <em>&#8220;Outline the key pillars and success factors for an enterprise IAM program.&#8221;</em> Do it four times in a row. Each time, you&#8217;ll get a slightly different list. Sometimes &#8220;governance&#8221; comes first, sometimes &#8220;technology.&#8221; One draft emphasizes user experience, another compliance. All are plausible. None are definitive.</p><p>This variability is not a bug; it&#8217;s the design of the system. LLMs are prediction engines, not reasoning engines. They excel at recombining patterns from training data, but they cannot guarantee consistency&#8212;or validity&#8212;over multiple runs.</p><p>For IAM leaders, this presents a serious risk. You cannot build board strategy or security policy on probabilistic outputs that shift with every prompt. This is why skilled professionals are indispensable. Leaders must oversee AI, interpret its outputs, and apply sound judgment. AI can accelerate tasks, but outsourcing critical thinking, strategy, and design work to it is an abdication of responsibility.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share&quot;,&quot;text&quot;:&quot;Share The Strategy Layer&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://www.strategylayer.com/?utm_source=substack&amp;utm_medium=email&amp;utm_content=share&amp;action=share"><span>Share The Strategy Layer</span></a></p><h2>What AI Still Can&#8217;t Do</h2><p>Even with GPT-5 at my fingertips and the best academic and professional training behind me, I&#8217;ve seen the same recurring limits. AI doesn&#8217;t do the truly human parts of IAM.</p><ul><li><p><strong>Strategic Alignment:</strong> AI can list best practices, but it doesn&#8217;t know whether your organization needs to move fast, cut costs, or restore customer trust first. Alignment is contextual.</p></li><li><p><strong>Business Case Creation:</strong> LLMs generate words, not conviction. Only a human partner can reframe IAM as business protection, growth enablement, or compliance cost avoidance in a way that resonates at the executive table.</p></li><li><p><strong>Stakeholder Engagement:</strong> IAM succeeds only when HR, legal, operations, and IT are on the same page. That&#8217;s not a prompt&#8212;it&#8217;s a negotiation, built on credibility and trust.</p></li><li><p><strong>Gap Analysis in Context:</strong> Every organization has gaps. The question is: which ones matter most right now? That&#8217;s prioritization&#8212;a skill born of judgment, not probability.</p></li><li><p><strong>Hands-On Firefighting:</strong> AI doesn&#8217;t triage outages. It doesn&#8217;t hold the pager. It doesn&#8217;t walk into the executive war room when customers are locked out.</p></li></ul><p>At best, AI gives you a faster baseline. At worst, it convinces you that you don&#8217;t need a baseline built by professionals in the first place.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.identient.ai/success-in-iam-not-a-product-its-strategy/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_r8b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_r8b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_r8b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_r8b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_r8b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg" width="1200" height="630" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:630,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:126496,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.identient.ai/success-in-iam-not-a-product-its-strategy/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/174780239?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_r8b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_r8b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_r8b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_r8b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe9f861b6-10f2-445a-a359-c02f6465bf85_1200x630.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Success in IAM: It&#8217;s Not a Product, It&#8217;s a Strategy</figcaption></figure></div><h2>The Missing Human Dimensions</h2><p>Beyond execution, there are higher-order functions that only people perform well. This is where the real gap lies.</p><ul><li><p><strong>Asking Interesting Questions:</strong> Consultants and architects don&#8217;t just answer questions&#8212;they ask the ones nobody else is bold enough to pose. <em>Why do we grant access this way at all? What if the barrier isn&#8217;t technical but cultural?</em> AI can summarize knowledge, but it rarely provokes insight.</p></li><li><p><strong>Second-Order Effects:</strong> IAM decisions ripple outward. A tighter MFA policy may harden defenses but could also frustrate customers, leading to revenue loss. Humans are better at spotting those unintended consequences.</p></li><li><p><strong>Trade-Offs and Opportunity Cost:</strong> Budgets are finite. Should you invest in CIAM modernization or privileged access management this year? AI can list benefits, but it won&#8217;t balance them against organizational opportunity costs.</p></li><li><p><strong>Political Capital:</strong> IAM is as much politics as it is technology. Timing matters. Allies matter. Sometimes the right answer today is &#8220;not yet.&#8221; AI has no political capital to spend, no favors to call in, no trust to draw on.</p></li></ul><p>These human dimensions are often the difference between a program that survives and one that fails.</p><h2>Analyst Reports vs. AI: Same Song, Faster Tempo</h2><p>In many ways, AI is simply the next iteration of what analyst firms have long provided. When I compare ChatGPT&#8217;s IAM advice to the templates and frameworks I pulled from Forrester or Gartner 15 years ago, the substance is strikingly similar. The difference? It arrives in seconds, not days.</p><p>That speed matters&#8212;but speed without strategy is just faster noise.</p><p>As Forrester puts it: <em>&#8220;The paradox encapsulates one of the most pressing challenges facing enterprises today: the disconnect between ubiquitous AI adoption at the individual level and the absence of transformational business impact at the organizational level.&#8221;</em> (Forrester, 2025)</p><p>Faster doesn&#8217;t mean wiser. And wisdom, not information, is what IAM requires most.</p><h2>The Role of Human Expertise</h2><p>This is why experienced consultants and architects remain irreplaceable. They bring qualities no AI can emulate:</p><ul><li><p><strong>Contextual Understanding:</strong> Recognizing what &#8220;good IAM&#8221; means in your sector, culture, and maturity stage.</p></li><li><p><strong>Cultural Intelligence:</strong> Pacing change so adoption keeps pace with ambition.</p></li><li><p><strong>Pattern Recognition:</strong> Drawing lessons from dozens of prior implementations to spot risks early.</p></li><li><p><strong>Accountability:</strong> Owning outcomes with you&#8212;not just generating words but delivering results.</p></li></ul><p>This fusion of technical skill, cultural sensitivity, and political acumen is what turns IAM from a perpetual struggle into a program that delivers measurable business value.</p><h2>Design Thinking: Where AI Fits, Where It Doesn&#8217;t</h2><p>The right question isn&#8217;t <em>whether</em> to use AI but <em>where</em>. Put your design thinking hat on:</p><ul><li><p><strong>Use AI</strong> to accelerate: drafting RFPs, summarizing vendor documentation, sketching workflows.</p></li><li><p><strong>Don&#8217;t use AI</strong> to decide: choosing priorities, weighing risks, allocating scarce capital.</p></li></ul><p>AI can help your team move faster, but it cannot decide what direction to run. That choice remains squarely in human hands.</p><h2>What&#8217;s Really at Stake</h2><p>IAM is not a playground for experimentation. It&#8217;s the connective tissue of digital business.</p><ul><li><p><strong>Revenue:</strong> Frictionless, secure customer access drives loyalty and retention.</p></li><li><p><strong>Resilience:</strong> Outages tied to identity can grind operations to a halt.</p></li><li><p><strong>Reputation:</strong> Breaches stemming from identity failures can permanently erode trust.</p></li></ul><p>This is too important to entrust to stochastic algorithms or generic templates. IAM is existential&#8212;and existential risks demand human leadership.</p><h2>Why Now Is the Time to Invest in Consulting</h2><p>If your IAM program feels stuck&#8212;or worse, if it feels &#8220;fine&#8221; but unprovable&#8212;this is the moment to bring in outside expertise. A skilled consulting partner can:</p><ul><li><p>Uncover hidden gaps before they metastasize.</p></li><li><p>Translate IAM outcomes into board-level ROI.</p></li><li><p>Build coalitions across siloed business functions.</p></li><li><p>Architect AI systems of action that empower, rather than distract, your team.</p></li></ul><p>Done right, this investment more than pays for itself in avoided rework, reduced audit exposure, and programs that actually stick.</p><h2>Closing Reflection</h2><p>The future will absolutely include AI in IAM products, processes, and programs&#8212;but as an amplifier, not a replacement. The <a href="https://www.strategylayer.com/p/playing-a-winnable-game-why-cybersecurity">leaders who win</a> won&#8217;t be those who blindly outsource to machines. They&#8217;ll be the ones who integrate AI wisely, with judgment and strategy intact.</p><p>At the end of the day, IAM leadership requires more than access to information. It requires the courage to ask better questions, the foresight to weigh trade-offs, and the political capital to make change stick. These are human skills&#8212;and they always will be.</p><p>That&#8217;s why the call you make to a seasoned consultant at 2:00 AM will always matter more than the prompt you type into ChatGPT at 2:00 PM.</p><h2>Let&#8217;s Talk!</h2><p>If you need help <a href="https://www.identient.ai/the-gaps-in-your-iam-program/">spotting the gaps</a> in your IAM program or designing and implementing AI systems of action for your team, let&#8217;s talk. There&#8217;s never been a more important time to balance speed with strategy. The work I do with clients consistently drives <strong>seven- and eight-figure impact</strong>&#8212;unlocking measurable ROI through stronger governance, reduced risk, and IAM programs that finally deliver on their promise.</p><div class="community-chat" data-attrs="{&quot;url&quot;:&quot;https://open.substack.com/pub/thestrategylayer/chat?utm_source=chat_embed&quot;,&quot;subdomain&quot;:&quot;thestrategylayer&quot;,&quot;pub&quot;:{&quot;id&quot;:4536793,&quot;name&quot;:&quot;The Strategy Layer&quot;,&quot;author_name&quot;:&quot;Steve Tout&quot;,&quot;author_photo_url&quot;:&quot;https://substackcdn.com/image/fetch/$s_!YxRW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3ea7d9bf-ea75-451b-b59d-9b6893739c8a_1177x1179.jpeg&quot;}}" data-component-name="CommunityChatRenderPlaceholder"></div><p><strong>Reference</strong><br>Giron, Frederic. Forrester, <em>Why AI ROI Remains Elusive Despite Widespread Adoption</em>, July 2025. Retrieved from: <a href="https://www.forrester.com/blogs/why-ai-roi-remains-elusive-despite-widespread-adoption/">https://www.forrester.com/blogs/why-ai-roi-remains-elusive-despite-widespread-adoption/</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Playing a Winnable Game: Why Cybersecurity Leaders Must Master Strategic Finance]]></title><description><![CDATA[Amid tightening budgets, short CISO tenures, and mounting pressures, the difference between burnout and breakthrough is framing cybersecurity as a game worth winning&#8212;grounded in strategic finance.]]></description><link>https://www.strategylayer.com/p/playing-a-winnable-game-why-cybersecurity</link><guid isPermaLink="false">https://www.strategylayer.com/p/playing-a-winnable-game-why-cybersecurity</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Sun, 14 Sep 2025 18:34:09 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_yRU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<h2><strong>The Unwinnable Game Trap</strong></h2><p>Cybersecurity leadership is starting to look like an unwinnable game. The average CISO tenure of 1.5&#8211;2 years tells us something isn&#8217;t working. Leaders are handed budgets where 75% of spend is locked into technical debt or mandatory controls, leaving only a sliver of discretionary funding to maneuver. Expectations continue to rise while resources stay flat&#8212;or even decline.</p><p>In game theory terms, cybersecurity leaders are being asked to play with fewer moves on the board while the stakes keep climbing.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>The outdated &#8220;people, process, technology&#8221; model doesn&#8217;t help much in this new environment. Nor does the familiar cost-avoidance narrative: &#8220;we stopped bad things from happening.&#8221; That might have worked a decade ago. Today, boards and CFOs expect security leaders to frame their work in terms of options, trade-offs, and business value. In short, to play a game they can actually win.</p><h2><strong>The Economics of Cybersecurity Leadership</strong></h2><p>If the opening feels like a game rigged against CISOs, the numbers confirm it. The financial headwinds facing security leaders are undeniable. A recent IANS and Artico Search survey of nearly 600 CISOs found that only <strong>47% reported a budget increase in 2025</strong>, down from 62% the year prior (IANS Research &amp; Artico Search, 2025). Meanwhile, <strong>54% are dealing with flat or shrinking budgets</strong>. And for the first time in five years, security&#8217;s slice of IT spending actually <strong>declined&#8212;from 11.9% to 10.9%</strong>&#8212;as dollars were redirected toward AI, cloud, and digital growth priorities (SecureWorld, 2025).</p><p>For many CISOs, these numbers translate into a game where most of the moves are already taken off the board. Fixed costs like technical debt, compliance requirements, and mandatory controls can consume three-quarters of a typical budget, leaving little discretionary funding for innovation or strategic bets. In this environment, cost avoidance alone isn&#8217;t enough to justify spend&#8212;or to ensure career survivability.</p><p>What leaders need instead is a new way to <strong>reframe and navigate financial constraints</strong>. Three starting points:</p><ul><li><p><strong>Map fixed vs. discretionary spend</strong>: know exactly how much of the budget is locked in vs. how much can be maneuvered, and make that visible to the board.</p></li><li><p><strong>Translate dollars into Run / Grow / Transform categories</strong>: adopt a model the CFO already understands, showing whether spend is maintaining the baseline, enabling incremental growth, or transforming the business.</p></li><li><p><strong>Present investments as options and trade-offs</strong>: instead of &#8220;we need this much money,&#8221; offer &#8220;here are three paths forward&#8212;here&#8217;s what we gain, and here&#8217;s what we accept if we don&#8217;t.&#8221;</p></li></ul><p>Each of these reframes gives CISOs more credibility in executive discussions and begins to shift perception&#8212;from tactical risk manager to strategic partner.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_yRU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_yRU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_yRU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_yRU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_yRU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_yRU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg" width="644" height="429.9230769230769" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:644,&quot;bytes&quot;:1757798,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/173591954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_yRU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_yRU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_yRU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_yRU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd7673640-12ab-482b-b279-45228775abfa_2119x1414.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Presenting security as options and trade-offs transforms budget talks into strategic business conversations.</figcaption></figure></div><h2><strong>Why the Current Playbook Fails</strong></h2><p>For decades, the dominant framework for cybersecurity management has been the familiar trio of <strong>people, process, and technology</strong>. It served its purpose in an era when the biggest challenge was building controls and maturing basic practices. But in today&#8217;s economic climate, that model feels outdated.</p><p>Boards and CFOs are no longer impressed by a laundry list of controls or by the language of cost avoidance&#8212;&#8220;we stopped bad things from happening.&#8221; That narrative, while true, doesn&#8217;t hold up against competing investments in AI, digital expansion, or customer experience, where executives can see direct returns.</p><p>Worse, the old playbook locks CISOs into reactive cycles&#8212;always responding to the next regulation, audit, or incident&#8212;without a framework for shaping strategy. This undermines their ability to survive in roles where the average tenure is less than two years.</p><p><strong>Three reasons the old playbook is breaking down:</strong></p><ul><li><p><strong>Cost avoidance isn&#8217;t strategy</strong>: Preventing losses matters, but it doesn&#8217;t prove value or growth potential.</p></li><li><p><strong>Controls &#8800; credibility</strong>: Boards expect clarity on business impact, not just technical soundness.</p></li><li><p><strong>Reactive posture shortens careers</strong>: CISOs who only defend and comply rarely get the chance to innovate, which accelerates burnout and turnover.</p></li></ul><p>The implication is clear: <strong>continuing to play by yesterday&#8217;s rules is a losing game.</strong> The question is whether CISOs can adopt a new playbook&#8212;one rooted in finance, strategy, and value creation&#8212;that allows them to compete on equal footing with other executives.</p><h2><strong>Reframing the Role: From Cost Center to Value Creator</strong></h2><p>If the old playbook is failing, what replaces it? The answer lies in shifting the frame&#8212;from security as an unavoidable cost to security as a portfolio of <strong>strategic options</strong> the business can choose to invest in.</p><p>This is more than semantics. In <em><a href="https://a.co/d/2qEihvg">The CISO On The Razor&#8217;s Edge</a></em>, I argued in Chapter 7 (<em>Security Leadership as a Series of Real Options</em>) that CISOs must think less like operators and more like financial strategists. Every initiative&#8212;whether it&#8217;s a new control, a modernization effort, or a cloud migration&#8212;can be presented as an <strong>option with trade-offs</strong>: invest and gain future flexibility, delay and accept defined risks, or decline and carry the exposure. This approach allows the board to see security decisions in the same way they evaluate other capital investments.</p><p>Industry leaders echo this. <strong><a href="https://www.identient.ai/podcast/metrics-as-loaded-weapons-secrets-from-7x-cio/">Mark Settle</a></strong> advises CISOs to &#8220;follow the money&#8221; through budgeting frameworks like Run / Grow / Transform, which reveal whether dollars are being used simply to keep the lights on or to unlock growth and transformation. <strong><a href="https://www.identient.ai/podcast/co-morbid-poisoning-of-the-ciso-role/">Steve Zalewski</a></strong>, drawing on his time as CISO at Levi Strauss &amp; Co., pushes CISOs to ensure that cybersecurity isn&#8217;t just about protection&#8212;it must directly support the mission of the business. As he often says, security has to &#8220;help sell more jeans.&#8221;</p><p>Taken together, these perspectives form a new leadership model: <strong>the financially literate, strategically minded CISO</strong> who frames security not as an overhead cost but as an investment portfolio. And it&#8217;s a model that boards are more likely to respect&#8212;and fund.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Qxfr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Qxfr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Qxfr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Qxfr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Qxfr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Qxfr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg" width="648" height="432.14835164835165" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:648,&quot;bytes&quot;:1533898,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/173591954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Qxfr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Qxfr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Qxfr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Qxfr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb472d4a3-b1b8-48e8-93a0-29e9d2ac1e4b_2121x1414.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Cybersecurity leadership is a high-stakes game of strategy&#8212;where every financial move shapes survival.</figcaption></figure></div><h2><strong>Tools for Playing a Winnable Game</strong></h2><p>Shifting from cost center to value creator isn&#8217;t just about mindset&#8212;it&#8217;s about using practical tools that reshape how security is discussed in executive conversations. CISOs don&#8217;t need to become CFOs, but they do need to adopt financial frameworks that make their work legible and valuable in business terms.</p><p>Here are four tools that create leverage and credibility:</p><ul><li><p><strong>Budget Mapping</strong>: Break down spend into fixed vs. discretionary categories. Show explicitly how much of the budget is consumed by technical debt and mandatory controls versus what&#8217;s available for strategic investment. Boards respond to clarity.</p></li><li><p><strong>Run / Grow / Transform</strong>: Reclassify spend using a model familiar to CFOs. Demonstrate which investments simply keep operations running, which enable incremental improvements, and which unlock real transformation.</p></li><li><p><strong>Options &amp; Trade-Offs</strong>: Frame every major initiative as a set of choices: <em>If we invest, here&#8217;s the upside. If we don&#8217;t, here&#8217;s the risk we&#8217;re carrying.</em> Boards don&#8217;t want ultimatums&#8212;they want structured options.</p></li><li><p><strong>Value Creation Scenarios</strong>: Move beyond cost avoidance by modeling how security investments can generate value&#8212;faster time to market, higher customer trust, stronger brand resilience, or lower cost of capital through risk reduction.</p></li></ul><p>Each of these tools has the same effect: they reposition security decisions from technical necessities to strategic investments. They give CISOs a way to demonstrate alignment with business goals&#8212;and to survive, and even thrive, in a budget-constrained environment.</p><h2><strong>The Payoff: Confidence, Impact, and Career Resilience</strong></h2><p>Mastering strategic finance is not just about surviving another budget cycle&#8212;it&#8217;s about changing the way the game is played. CISOs who frame investments as options and trade-offs, who can translate dollars into growth and resilience, and who model value creation are no longer trapped in a defensive posture. They step into the role of strategist, gain confidence in boardrooms, and extend their career runway.</p><p>A winnable game is one where:</p><ul><li><p>The board sees clarity, not confusion.</p></li><li><p>The CFO sees alignment, not overhead.</p></li><li><p>The CISO sees a path forward, not burnout.</p></li></ul><p>That&#8217;s the future of cybersecurity leadership&#8212;and it&#8217;s within reach.</p><p>The urgency is real: only <strong>47% of CISOs reported budget increases in 2025</strong>, while security&#8217;s share of IT spending actually fell for the first time in five years. The game is tightening. Now is the moment to master the skills that make it winnable.</p><p>If you want to sharpen these skills and apply them in your own organization, join us on <strong>Tuesday, September 16th</strong> for the webinar <em><a href="https://www.linkedin.com/events/strategicfinanceforcybersecurit7369022272361144322/">Strategic Finance for Cybersecurity Leaders</a></em>. We&#8217;ll dive deeper into how CISOs can reframe budgets, speak the language of the business, and make smarter strategic bets in the year ahead.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.linkedin.com/events/strategicfinanceforcybersecurit7369022272361144322/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g-aV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!g-aV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!g-aV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!g-aV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g-aV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png" width="506" height="506" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1080,&quot;width&quot;:1080,&quot;resizeWidth&quot;:506,&quot;bytes&quot;:757747,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.linkedin.com/events/strategicfinanceforcybersecurit7369022272361144322/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/173591954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g-aV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 424w, https://substackcdn.com/image/fetch/$s_!g-aV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 848w, https://substackcdn.com/image/fetch/$s_!g-aV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 1272w, https://substackcdn.com/image/fetch/$s_!g-aV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd0bf1326-d736-4408-8c84-5078f1074240_1080x1080.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>And if you&#8217;d like a companion to guide you even further, pick up a copy of <em><a href="https://a.co/d/fWFFb0U">The CISO On The Razor&#8217;s Edge</a></em>, especially Chapter 7: <em>Security Leadership as a Series of Real Options</em>. It will help you increase your odds of surviving&#8212;and thriving&#8212;in the game you&#8217;re already playing.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.stevetout.com/book" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_SQb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 424w, https://substackcdn.com/image/fetch/$s_!_SQb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 848w, https://substackcdn.com/image/fetch/$s_!_SQb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 1272w, https://substackcdn.com/image/fetch/$s_!_SQb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_SQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png" width="439" height="699.2039835164835" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:2319,&quot;width&quot;:1456,&quot;resizeWidth&quot;:439,&quot;bytes&quot;:2281043,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.stevetout.com/book&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/173591954?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_SQb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 424w, https://substackcdn.com/image/fetch/$s_!_SQb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 848w, https://substackcdn.com/image/fetch/$s_!_SQb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 1272w, https://substackcdn.com/image/fetch/$s_!_SQb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F27a0fef1-a6ec-4bea-9296-75713e38e9f1_1554x2475.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h1>References</h1><p>IANS Research &amp; Artico Search. (2025, August 5). <em>Security budgets under pressure: How CISOs can navigate tight budget constraints.</em> IANS Research. Retrieved from <a href="https://www.iansresearch.com/resources/all-blogs/post/security-blog/2025/08/05/security-budgets-under-pressure--how-cisos-can-navigate-tight-budget-constraints?utm_source=chatgpt.com">https://www.iansresearch.com/resources/all-blogs/post/security-blog/2025/08/05/security-budgets-under-pressure--how-cisos-can-navigate-tight-budget-constraints</a></p><p>SecureWorld. (2025, July 24). <em>CISO budget squeeze: Security growth slows as IT priorities shift.</em> SecureWorld. Retrieved from <a href="https://www.secureworld.io/industry-news/cisos-budget-squeeze-security-growth-slows">https://www.secureworld.io/industry-news/cisos-budget-squeeze-security-growth-slows</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[From Data Protection to AI Security Posture Management: What I’ve Learned as an Early Advisor to TrustLogix]]></title><description><![CDATA[Why CIOs and CISOs Must Treat AI Security Posture Management as the Next Strategic Imperative for Data Governance and Enterprise Resilience]]></description><link>https://www.strategylayer.com/p/from-data-protection-to-ai-security</link><guid isPermaLink="false">https://www.strategylayer.com/p/from-data-protection-to-ai-security</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Tue, 09 Sep 2025 00:37:25 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!sCcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>When I first joined TrustLogix as one of its early board advisors, the challenge we were tackling felt deceptively narrow: securing data in use for CI/CD pipelines. It was about ensuring that sensitive customer and enterprise data wasn&#8217;t misused or left vulnerable during the development process. At the time, this was a bold move&#8212;shifting the industry conversation from static data-at-rest protections toward the live, moving, constantly changing streams of data that powered modern engineering.</p><p>Fast forward a few years, and the landscape looks very different. What began as a fight to control developer pipelines has evolved into a much larger, more urgent problem: safeguarding data privacy, security, and governance in the age of generative AI. Today, that evolution is crystallizing into a new strategic discipline: <strong>AI Security Posture Management (AI-SPM).</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h2>The Inflection Point for CxOs</h2><p>The adoption of generative AI and large language models (LLMs) is not optional anymore. McKinsey estimates that generative AI could deliver up to <strong>$4.4 trillion annually in economic value</strong> across industries. A Salesforce study shows that <strong>61% of employees are eager to leverage generative AI</strong>, yet most lack the knowledge or skills to use it securely.</p><p>That tension&#8212;between enthusiasm and operational readiness&#8212;is where risk breeds. On one hand, boards and executive teams see AI as a lever for efficiency and competitive advantage. On the other, CISOs and CIOs are already grappling with a new class of threats, from data leakage to adversarial attacks, without the benefit of well-worn playbooks.</p><p>The next 18 months will determine whether enterprises harness AI&#8217;s potential responsibly or stumble into costly missteps. And the stakes are high: regulators are moving quickly, consumers are hyper-aware of privacy risks, and adversaries&#8212;both criminal and nation-state&#8212;are actively probing weaknesses in AI systems today, not tomorrow.</p><h2>From Governance Gaps to Strategic Imperatives</h2><p>One of the biggest lessons I&#8217;ve seen firsthand is that the governance gaps inside enterprises are often more dangerous than the technology itself.</p><ul><li><p><strong>Security vs. Data Teams:</strong> Too often, the security organization and the data organization operate in silos. Without a shared governance framework, critical questions&#8212;Who owns the data? Who sets the policies? Who enforces them?&#8212;go unanswered. This disconnect is where vulnerabilities flourish.</p></li><li><p><strong>Super Users Without Guardrails:</strong> Generative AI has effectively turned non-technical employees into &#8220;super users.&#8221; With the right (or wrong) prompt, an employee could trigger a destructive query like <code>drop table</code>, leading to catastrophic data loss. Traditional access controls weren&#8217;t built for this.</p></li><li><p><strong>Model Integrity Risks:</strong> Nearly every LLM today is vulnerable to prompt injection and manipulation. What looks like an innocent request for analysis can be hijacked to exfiltrate sensitive data or generate biased, harmful, or even malicious outputs.</p></li></ul><p>The result? An urgent need for proactive, executive-level strategies&#8212;not just tactical fixes.</p><h2>The Three Pillars of AI Security Posture Management</h2><p>At TrustLogix, I&#8217;ve watched the thinking around governance evolve into what we now call <strong><a href="https://www.trustlogix.io/safeguarding-your-ai-models-and-data">AI-SPM: AI Security Posture Management</a>.</strong> It&#8217;s a high-level discipline designed to give enterprises the same kind of control, resilience, and visibility for AI that they&#8217;ve long pursued in cloud and DevOps.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sCcS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sCcS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sCcS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sCcS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sCcS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sCcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png" width="516" height="516" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:516,&quot;bytes&quot;:1351517,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/173139982?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sCcS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!sCcS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!sCcS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!sCcS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F498ae023-4dd7-4371-a760-aeb247a14915_1024x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AI Security Posture Management (AI-SPM) at a glance: securing model deployments, protecting enterprise data, and detecting risks with intelligent policy guidance&#8212;at both enterprise and global scale.</figcaption></figure></div><p>The framework rests on three pillars:</p><ol><li><p><strong>Proactive Data Protection</strong></p><ul><li><p>Automatic discovery and classification of sensitive data across AI training and inference pipelines.</p></li><li><p>Data lineage tracking to ensure auditability and reproducibility.</p></li><li><p>Granular access controls (RBAC, ABAC) tailored for AI workloads.</p></li></ul></li><li><p><strong>Secure Model Lifecycle Management</strong></p><ul><li><p>Model registries with strict access controls and full audit trails.</p></li><li><p>Integrity verification using digital signatures and cryptographic checks.</p></li><li><p>Real-time monitoring to detect adversarial attacks and anomalous behavior.</p></li></ul></li><li><p><strong>Continuous Posture Monitoring</strong></p><ul><li><p>Centralized visibility into who has access to what data and models.</p></li><li><p>Automated, template-driven policy enforcement.</p></li><li><p>Continuous risk detection against benchmarks like NIST and CIS.</p></li></ul></li></ol><p>This isn&#8217;t theory&#8212;it&#8217;s the pragmatic blueprint enterprises need to operationalize today. Just as cloud security posture management (CSPM) became indispensable for cloud adoption, AI-SPM is fast becoming the non-negotiable foundation for AI.</p><h2>Why the Next 18 Months Matter</h2><p>CxOs can&#8217;t afford to wait. Here&#8217;s why:</p><ul><li><p><strong>Regulatory Momentum:</strong> <a href="https://en.wikipedia.org/wiki/Artificial_Intelligence_Act">The EU AI Act</a>, U.S. <a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">executive orders</a>, and <a href="https://iapp.org/resources/article/us-state-ai-governance-legislation-tracker/">state-level privacy regulations</a> are converging to place heavy accountability on AI use. Compliance won&#8217;t be optional.</p></li><li><p><strong>Adversary Sophistication:</strong> Organized crime and nation-state actors are already targeting LLMs and AI-enabled applications. Unlike early-stage technologies, this isn&#8217;t &#8220;wait and see.&#8221; The battlefield is live.</p></li><li><p><strong>Market Expectations:</strong> Customers and investors are paying close attention. A single AI-driven data leak could undo years of trust-building and destroy competitive positioning.</p></li></ul><p>The organizations that will thrive are those that move deliberately&#8212;implementing governance frameworks now, before AI adoption scales beyond their ability to control it.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!DmeV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DmeV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DmeV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DmeV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DmeV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DmeV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png" width="571" height="380.7973901098901" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:571,&quot;bytes&quot;:1482777,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/173139982?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!DmeV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 424w, https://substackcdn.com/image/fetch/$s_!DmeV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 848w, https://substackcdn.com/image/fetch/$s_!DmeV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!DmeV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc52197d6-ae5b-45d7-b8b0-94ff1ecaed09_1536x1024.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h2>A Real-World Wake-Up Call: The Salesloft Breach</h2><p>In September 2025, the industry saw just how fast trust can unravel when AI security posture isn&#8217;t managed proactively. A breach at <strong>Salesloft</strong>, an AI-driven chatbot provider, exposed the fragility of enterprise integrations at global scale.</p><p>Attackers from the UNC6395 group stole <strong>OAuth tokens</strong> from Salesloft&#8217;s Drift platform, using them to pivot into hundreds of downstream integrations. This wasn&#8217;t just a contained incident&#8212;it spread into enterprise systems like <strong>Slack, Google Workspace, AWS, Microsoft Azure, and even OpenAI environments</strong>. Along the way, attackers harvested <strong>AWS keys, VPN credentials, and Snowflake tokens</strong>, and then <strong>deleted logs</strong> to cover their tracks (<a href="https://krebsonsecurity.com/2025/09/the-ongoing-fallout-from-a-breach-at-ai-chatbot-maker-salesloft/">KrebsOnSecurity</a>, <a href="https://www.itpro.com/security/cyber-attacks/warning-issued-to-salesforce-customers-after-hackers-stole-salesloft-drift-data">ITPro</a>).</p><p>The impact was sweeping. Security leaders at firms like <strong>Palo Alto Networks</strong> and <strong>Zscaler</strong> confirmed their organizations were affected, reminding us that even cybersecurity vendors aren&#8217;t immune (<a href="https://www.techradar.com/pro/security/palo-alto-networks-becomes-the-latest-to-confirm-it-was-hit-by-salesloft-drift-attack">TechRadar</a>, <a href="https://www.itpro.com/security/data-breaches/the-salesloft-drift-victim-list-keeps-growing-zscaler-is-the-latest-to-confirm-a-breach-warning-customers-to-remain-wary-of-follow-up-phishing-attacks">ITPro</a>).</p><p><strong>Why it matters:</strong> This was a classic case of <strong>authorization sprawl</strong>&#8212;unchecked AI-integrated tokens giving adversaries the keys to the kingdom. For executives, the lesson is crystal clear: <strong>AI governance cannot lag adoption.</strong> A single data leak or compromised token can wipe out years of trust-building and competitive advantage in a matter of days.</p><h2>A Call to Action for Leaders</h2><p>As I look back on my journey with TrustLogix, the throughline is clear: security and governance are not blockers to innovation; they are the <strong>enablers</strong> of sustainable, responsible AI adoption.</p><p>CxOs need to think differently. This isn&#8217;t about securing yesterday&#8217;s systems. It&#8217;s about preparing your enterprise to navigate the next wave of disruption with confidence. That requires new disciplines, new governance models, and new partnerships.</p><p>If you&#8217;re a CIO, CISO, or senior executive wrestling with these questions, I&#8217;d encourage you to take action now:</p><ul><li><p><strong>Schedule a private briefing or demo.</strong> I&#8217;m happy to arrange a session where you can see firsthand how TrustLogix is helping enterprises operationalize AI-SPM.</p></li><li><p><strong>Connect directly.</strong> Reach out to me if you&#8217;d like to discuss your specific challenges, roadmap, or board-level concerns.</p></li><li><p><strong>Learn more.</strong> Visit <a href="https://www.trustlogix.io">TrustLogix&#8217;s website</a> for additional resources and insights.</p></li></ul><h2>Final Word</h2><p>AI adoption is moving faster than most governance structures can keep up with. The temptation is to prioritize speed and deal with governance later. That&#8217;s a mistake.</p><p>What I&#8217;ve learned as an early advisor to TrustLogix is that governance isn&#8217;t the brake&#8212;it&#8217;s the steering wheel. Without it, you may move fast, but you&#8217;ll end up in a ditch. With it, you can accelerate into the future of AI confidently, knowing your enterprise is secure, compliant, and ready for what&#8217;s next.</p><p>The question isn&#8217;t whether AI-SPM will become a strategic priority for enterprises. It&#8217;s <strong>how quickly your organization will adopt it&#8212;and whether you&#8217;ll be ahead of the curve or playing catch-up.</strong></p><p>&#128073; <strong>Call to Action:</strong> Contact me directly if you&#8217;d like to arrange a private briefing, demo, or meeting with a representative from TrustLogix. Or visit <a href="https://trustlogix.io">trustlogix.io</a> to explore more.</p><h3>References</h3><p>McKinsey &amp; Company. (2023, June). <em>The economic potential of generative AI: The next productivity frontier.</em> McKinsey Digital. Retrieved from <a href="https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/the-economic-potential-of-generative-ai-the-next-productivity-frontier">https://www.mckinsey.com/capabilities/mckinsey-digital/our-insights/the-economic-potential-of-generative-ai-the-next-productivity-frontier</a></p><p>McKinsey Global Institute. (2023, June). <em>Generative AI could add up to $4.4 trillion annually to the global economy.</em> Retrieved from <a href="https://www.mckinsey.com/mgi/media-center/ai-could-increase-corporate-profits-by-4-trillion-a-year-according-to-new-research">https://www.mckinsey.com/mgi/media-center/ai-could-increase-corporate-profits-by-4-trillion-a-year-according-to-new-research</a></p><p>Salesforce Research. (2023, August). <em>Generative AI Snapshot Series: AI Ethics.</em> Salesforce Newsroom. Retrieved from <a href="https://www.salesforce.com/news/stories/generative-ai-ethics-survey/">https://www.salesforce.com/news/stories/generative-ai-ethics-survey/</a></p><p>Salesforce Research. (2023, October). <em>Generative AI Snapshot Series: AI Skills.</em> Salesforce Newsroom. Retrieved from <a href="https://www.salesforce.com/news/stories/generative-ai-skills-research/">https://www.salesforce.com/news/stories/generative-ai-skills-research/</a></p><p>Forbes India Staff. (2023, July 14). <em>Generative AI could add up to $4.4 trillion a year to global economy: McKinsey.</em> Forbes India. Retrieved from <a href="https://www.forbesindia.com/article/news/generative-ai-could-add-up-to-44-trillion-a-year-to-global-economy-mckinsey/86157/1">https://www.forbesindia.com/article/news/generative-ai-could-add-up-to-44-trillion-a-year-to-global-economy-mckinsey/86157/1</a></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[From Compliance Theater to Human Leadership: Why Sidelining CISOs Normalizes Breaches]]></title><description><![CDATA[Boards that weaken security leadership reduce cybersecurity to performance art. CIOs and CISOs must reclaim their role as human-centered leaders&#8212;guardians of trust, privacy, and dignity.]]></description><link>https://www.strategylayer.com/p/from-compliance-theater-to-human</link><guid isPermaLink="false">https://www.strategylayer.com/p/from-compliance-theater-to-human</guid><dc:creator><![CDATA[Steve Tout]]></dc:creator><pubDate>Tue, 02 Sep 2025 15:33:22 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!qXB9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Picture the scene: the boardroom applauds itself after another clean audit. The dashboards glow green. The compliance reports are filed neatly away. And yet, outside those walls, the breaches continue. Privacy is violated. Dignity is eroded. Trust vanishes.</p><p>This is the paradox of modern cybersecurity. Organizations are checking all the boxes but failing to protect the very thing that matters most: the humans behind the data. When security is reduced to compliance theater, breaches stop being treated as existential failures. They become routine. And in that routine, leadership normalizes the erosion of privacy and dignity.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h3><strong>Sidelining CISOs Normalizes Breaches</strong></h3><p>The sidelined or weakened CISO is the hallmark of this dysfunction. Instead of acting as strategic multipliers, CISOs are too often cast as compliance managers. Their remit is narrowed to passing audits rather than preserving trust.</p><p>The result? A culture that tolerates breaches as the &#8220;cost of doing business.&#8221; This isn&#8217;t just bad governance. It&#8217;s organizational surrender. When boards minimize the CISO&#8217;s voice, they signal to the enterprise that protecting dignity is optional.</p><p>Recent research underscores this gap. In a 2025 Harvard Business Review study, 71% of executives believed their cybersecurity funding was adequate or strong. Yet only 39% rated their board&#8217;s understanding of cyber risk as proactive, and just 31% considered their organization an innovator or early adopter in cyber readiness[^1]. The illusion of readiness masks the normalization of failure.</p><h3><strong>The People/Process/Technology Prison</strong></h3><p>Why does this dynamic persist? Because CIOs and CISOs are often trapped in what I call the people/process/technology prison.</p><p>Legacy frameworks treat people as risks to be managed, processes as boxes to check, and technology as the silver bullet. Humans are reduced to &#8220;actors,&#8221; &#8220;insiders,&#8221; or &#8220;threat vectors.&#8221; Leadership is forced to view the enterprise through a compliance lens, not a human lens.</p><p>This prison strips cybersecurity of its real purpose: enabling people to thrive with dignity in a digital-first world.</p><h3><strong>The Stakes: Privacy and Dignity</strong></h3><p>Breaches aren&#8217;t just technical failures. They are human failures. They rob customers, employees, and citizens of their dignity. They leave people feeling exposed, powerless, and undervalued.</p><p>HBR research shows that dignity violations are common in organizations, and that treating people with dignity significantly improves motivation, satisfaction, and overall flourishing[^2]. Cybersecurity is no different. Each time leadership accepts compliance theater, it chooses to normalize dignity violations at scale.</p><p>The Golden Rule has long reminded us: treat others as you would like to be treated. Today, leadership demands an even sharper ethic: treat others as they want to be treated[^3]. That requires designing systems of trust, not systems of control.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!qXB9!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qXB9!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qXB9!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qXB9!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qXB9!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qXB9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg" width="644" height="429.62983425414365" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:483,&quot;width&quot;:724,&quot;resizeWidth&quot;:644,&quot;bytes&quot;:314481,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/172575614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qXB9!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 424w, https://substackcdn.com/image/fetch/$s_!qXB9!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 848w, https://substackcdn.com/image/fetch/$s_!qXB9!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!qXB9!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b7cbbb7-dc5c-473b-b0ff-f428ac6d6272_724x483.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">The rebuilding of Notre Dame reminds us: leadership is about restoring dignity and trust, not performing for appearances. SPIRE gives CIOs and CISOs the same foundation.</figcaption></figure></div><h3><strong>The Escape Route: SPIRE as Human-Centered Leadership OS</strong></h3><p>How do CIOs and CISOs escape the prison? By reframing security leadership through SPIRE: a human-centered operating system for leadership .</p><ul><li><p><strong>Signal</strong> &#8211; Upgrade the signal. Replace noisy dashboards and vanity metrics with board-relevant telemetry: drag, control effectiveness, velocity friction, trust signals.</p></li><li><p><strong>Performance Intelligence</strong> &#8211; See the real system. Surface blind spots, entropy, and misaligned incentives that undermine execution.</p></li><li><p><strong>Insight</strong> &#8211; Understand what system you&#8217;re truly running. The CISO is not a translator but a Strategic Multiplier, co-designing systems of trust, speed, and resilience.</p></li><li><p><strong>Reframe</strong> &#8211; Stop reporting problems. Start commanding the system. Position security not as liability management but as enterprise execution.</p></li><li><p><strong>Execution</strong> &#8211; Close the loop. Translate insight into prioritized action with financial discipline, governance, and feedback.</p></li></ul><p>SPIRE is not abstract philosophy. It is a leadership design system. It restores agency to CIOs and CISOs. It elevates the role from compliance enforcer to guardian of dignity.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!cQiV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!cQiV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!cQiV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!cQiV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!cQiV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!cQiV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:516995,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.strategylayer.com/i/172575614?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!cQiV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 424w, https://substackcdn.com/image/fetch/$s_!cQiV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 848w, https://substackcdn.com/image/fetch/$s_!cQiV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 1272w, https://substackcdn.com/image/fetch/$s_!cQiV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F373e0acb-823a-40bd-9bb8-447c6694ed76_1600x900.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">True cybersecurity leadership starts here&#8212;treating people not as risks to control, but as voices with potential.</figcaption></figure></div><h3><strong>Why Symbolic Leadership Matters</strong></h3><p>MIT Sloan Management Review warns that simply adding more senior cybersecurity roles can actually increase collective overconfidence, leading leaders to overestimate capabilities compared to peers[^4]. In other words, title inflation doesn&#8217;t fix the problem&#8212;it makes it worse.</p><p>The solution isn&#8217;t more hierarchy. It&#8217;s more symbolism. An empowered CISO isn&#8217;t just a functional leader; they are a signal to the enterprise that dignity, trust, and momentum matter. Weakening that signal weakens the system.</p><h3><strong>Actionable Moves for CIOs and CISOs</strong></h3><ol><li><p>Reframe Board Discussions</p><ul><li><p>Don&#8217;t settle for &#8220;Are we compliant?&#8221; Ask: &#8220;How does this strategy preserve dignity and trust?&#8221;</p></li></ul></li><li><p>Elevate the Symbolic Role of Security</p><ul><li><p>Communicate not only risk reduction but also human empowerment.</p></li></ul></li><li><p>Challenge the Prison Mindset</p><ul><li><p>Reject frameworks that treat people as liabilities. Treat them as voices with potential.</p></li></ul></li><li><p>Measure What Matters</p><ul><li><p>Replace red-yellow-green dashboards with metrics tied to performance, friction, and trust.</p></li></ul></li></ol><p>These aren&#8217;t theoretical exercises. They&#8217;re boardroom moves CIOs and CISOs can make today.</p><h3><strong>Closing Call-to-Action</strong></h3><p>Compliance theater might pass audits. But it fails people. And in failing people, it fails the enterprise. Normalized breaches don&#8217;t just erode data&#8212;they erode dignity.</p><p>CIOs and CISOs who want to break free from the people/process/technology prison need a new operating system for leadership. That system is SPIRE.</p><p>Learn how to apply SPIRE as a leader, and inside your organization:<a href="https://www.identient.ai/spire"> identient.ai/spire</a></p><h3><strong>Footnotes</strong></h3><p>[^1]: &#8220;Boards Need a More Active Approach to Cybersecurity.&#8221; Harvard Business Review, May 20, 2025.</p><p>[^2]: &#8220;The Dignity Mindset: How to Build Organizations Where People Flourish.&#8221; Harvard Business Review, Oct 30, 2024.</p><p>[^3]: &#8220;The New Golden Rule of Leadership.&#8221; Harvard Business Review, Aug 2022.</p><p>[^4]: &#8220;The Case for Lean Cybersecurity Leadership.&#8221; MIT Sloan Management Review, Feb 10, 2025.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://www.strategylayer.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading The Strategy Layer! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>