✒️ Foreword
A seven-degree shadow was enough to measure the Earth.
Around 240 BC, Eratosthenes faced a rather inconvenient measurement problem: the object he wanted to measure was the planet beneath his feet. He could not walk its circumference, see its curvature from space, or place instruments around it. Instead, he compared what the Sun did in two Egyptian cities. At Syene, near modern Aswan, the midday Sun at the summer solstice was said to stand almost directly overhead. In Alexandria, a vertical rod cast a shadow. From that shadow, the Sun’s angle was estimated at about seven degrees, roughly one-fiftieth of a circle. If the two cities were separated by 5,000 stadia, then the circumference of the Earth should be about fifty times that distance.
The famous story is cleaner than the underlying measurement. The surviving account comes from Cleomedes, not Eratosthenes’ lost book, and it rests on simplifying assumptions: that Syene sat on the Tropic of Cancer, that it lay on the same meridian as Alexandria, and that the Earth could be treated as a sphere. The distance between the cities also had to come from surveying. Yet the method worked remarkably well because the pieces were connected. A local observation, a geometric model and a known baseline could reveal something far larger than any of them.
That is the interesting part. Eratosthenes did not solve the problem by observing everything. He solved it by choosing an observable whose relationship to the larger system could be reasoned about. More data would not necessarily have helped if he had been measuring the wrong thing. The power of the experiment came from its structure: each observation had a defined role in turning something visible and local into evidence about something vast and inaccessible.
AI governance increasingly has the opposite problem. Organizations can observe almost everything on paper: strategies, policies, risk registers, certifications, model documentation, committee structures. But those signals only matter if they reveal the behaviour we actually need to govern.
The comparison between AI risk and traditional ISMS risk makes this visible. ISO 27001 remains a useful foundation, but its usual security lens does not automatically capture explainability, algorithmic bias, model drift, AI supply-chain integrity or autonomous decision-making. The answer is not to discard existing controls. It is to extend the measurement system: inventory AI assets, place AI risks inside enterprise risk processes, map new controls onto established ones, and monitor model behaviour alongside existing security operations.
The corporate data tells a similar story from another direction. In the AICDI study, 43.7% of companies reported an AI strategy or guidelines, but only 13% reported alignment with a recognised governance framework. Seventy-two percent reported no AI impact assessment, while only 12.4% reported a policy ensuring human oversight. Those numbers should be read carefully—the dataset depends heavily on public disclosure, so silence is not proof of absence. But they still expose a measurement gap. It is much easier to observe governance language than operational evidence that governance is actually happening.
Agentic AI makes that gap harder to ignore because consequential behaviour moves into runtime. An agent may reason, call tools, use credentials, delegate tasks and trigger actions across other systems. At that point, a model-level assessment is only one observation point. The security guidance in this issue therefore shifts attention toward least privilege, just-in-time credentials, runtime monitoring, approval checkpoints, segmentation and containment. What matters is not only what the model is, but what the surrounding system allows it to do.
That suggests a more useful question for AI governance: not “How much evidence do we have?” but “Does our evidence have the right geometry?”
A credible governance system needs connected observations. An inventory tells you what exists. Impact assessments tell you what could go wrong before deployment. Runtime monitoring tells you what is changing after deployment. Identity and authorisation controls reveal what agents can actually reach. Incident logs show how actions propagate. Reassessment triggers tell you when yesterday’s assumptions have stopped describing today’s system. None of these is sufficient alone. Together, they can make the larger behaviour legible.
This also changes what counts as assurance. A policy is evidence that a rule exists; it is not evidence that the rule survives contact with a changing model, a new vendor, an unexpected tool call or an agent operating with inherited privileges. Governance becomes stronger when each claim can be connected to an observable control and, where necessary, to runtime evidence that the control still works.
Eratosthenes did not need to measure every metre of the Earth. He needed a shadow, a distance, and a model that connected them. AI governance faces the same design challenge in reverse: we already have plenty of shadows. The hard part is knowing which ones actually measure the system we think we are controlling.
— Kuba
Curator, AIGL 📚
☀️Spotlight Resources
AI Risk vs ISMS Risk – Comprehensive Comparison

What it is:
A practical guide for GRC and cybersecurity professionals explaining how AI risk differs from traditional information-security risk under ISO/IEC 27001, where the two overlap, and how they can be governed together. It contrasts the domains across scope, threat sources, ownership, controls and residual-risk treatment, then uses banking, healthcare and recruitment scenarios to show how AI-specific failures interact with conventional security weaknesses.
Why it’s worth reading:
The most useful section identifies five areas where a conventional ISMS leaves important gaps: explainability, algorithmic bias, AI supply-chain integrity, model drift and autonomous decision-making. Rather than proposing a separate governance programme, the guide recommends extending existing structures: build an AI inventory, add AI risks to the enterprise risk register, map ISO 42001 and NIST AI RMF controls against ISO 27001, assign cross-functional ownership, and integrate model monitoring into existing incident-response and security-monitoring processes.
Responsible AI in Practice: 2025 Global Insights from the AI Company Data Initiative

What it is:
A Thomson Reuters Foundation and UNESCO study examining responsible AI practices across 2,972 companies, drawing on the AI Company Data Initiative’s large dataset of corporate disclosures. It looks beyond AI adoption to governance frameworks, operational controls, workforce protections, human rights, environmental impacts, training data and third-party dependencies, while also providing guidance specifically for investors.
Why it’s worth reading:
Its central finding is a striking gap between governance language and governance practice. Although 43.7% of companies publicly communicate an AI strategy, only 13% report alignment with a formal AI governance framework; 72% report no AI-related impact assessment, and only 12.4% report a policy ensuring human oversight. The report is particularly useful because it connects these disclosure gaps to concrete investor risks—including model failures, labour disputes, regulatory exposure and weak vendor oversight—and finishes with an investor engagement checklist and principles for incorporating responsible AI into stewardship and proxy voting.
Careful Adoption of Agentic AI Services

What it is:
Joint cybersecurity guidance from agencies including Australia’s ACSC, CISA, the NSA, Canada’s Cyber Centre, New Zealand’s NCSC and the UK NCSC. It focuses on LLM-based agents that can reason, plan, use external tools and take actions without continuous human intervention, and examines what changes when those capabilities are introduced into operational IT environments.
Why it’s worth reading:
The guidance offers a strong security taxonomy covering privilege, design and configuration, behavioural, structural and accountability risks. Particularly useful are its examples of confused-deputy attacks, privilege creep, agent impersonation, specification gaming, rogue agents and cascading failures between interconnected agents and tools. Its recommendations follow the system lifecycle—from secure design and development through deployment and operation—with heavy emphasis on least privilege, runtime authorisation, human control points, segmentation, monitoring and just-in-time credentials. Its underlying message is deliberately conservative: start with low-risk, non-sensitive tasks and prioritise containment, reversibility and resilience over automation gains.