Intelligence
Vendor risk intelligence, regulatory analysis, and supply chain security research. Written by the VCRI team.
Nobody can track every setting in every AI tool. So here's the short list that actually protects you — across ChatGPT, Gemini, and Copilot — and a plain-language why for each. Vendor-neutral, tuned for risk-aware-but-not-paranoid individuals and small businesses.
A UK AI Security Institute incident report shows an AI agent’s accounts, credentials and repositories outliving the agent itself, and being found and trusted by other vendors’ agents. Permanence of damage has a third location, and it sits outside the system entirely.
Outsource your IT or security? A plain-language checklist for asking your MSP/MSSP how they use AI on your behalf — data, training, governance, access, accountability — with the green and red flags to listen for. No technical background needed.
By the time you hear about an exploit, you're already 11 days too late. Two independent 2026 findings — Seal Security (commit→advisory) and GreyNoise (exploit-surge→advisory) — measured opposite sides of the system and got the same 11-day gap. The advisory is the lagging indicator. Our inaugural quarterly report on abandonment, compromise, and the window between them.
Two independent 2026 findings — Seal Security on the commit side, GreyNoise on the exploit side — converge on the same number: 11 days. AI compresses one side of that gap to hours and minutes. The other side stays slow. The defender's window of safety has structurally collapsed. Companion piece to the Q2 State of Supply Chain report, dropping Tuesday 2026-05-26.
Independent regulatory bodies across the EU, US, and Japan have all arrived at roughly the same answer to the same question at roughly the same moment. That convergence is not coincidence. It's causation — a sequence of structural changes that matured at the same historical moment and forced the same policy response across jurisdictions simultaneously.
In January 2026, FedRAMP released six Requests for Comment that represent the most significant restructuring of federal cloud security authorization in the program's history. Two of them validate a thesis that VCRI has been built on from the beginning: point-in-time, self-reported vendor security data is structurally insufficient.
On February 13, 2026, the European Commission formally adopted the EU ICT Supply Chain Security Toolbox — tied directly to Article 22 of the NIS2 Directive. The EU just described, in regulatory language, the infrastructure problem that most organizations still treat as an aspiration.
Stay Informed
New research, regulatory analysis, and supply chain security briefings — direct to your inbox.
Subscribe →