DevSecOps

Kiro Crew Open Source: AWS Bets on Multi-Agent AI Dev Tools

Kiro Crew Open Source: AWS Bets on Multi-Agent AI Dev Tools

Amazon has open sourced Kiro Crew, a multi-agent AI orchestration platform built to coordinate autonomous agents across sessions, repos, and tools. With 39,000 internal users before launch and a security-first design, it’s a credible entry into a crowded but still-fragmented market. ECI Research breaks down what it means for ITDMs and developers evaluating agentic tooling in 2026.

Kiro Crew Open Source: AWS Bets on Multi-Agent AI Dev Tools Read More »

Payment Fraud Is Now Routine — And AI Is Both the Threat and the Fix

Payment Fraud Is Now Routine — And AI Is Both the Threat and the Fix

Yooz’s 2026 Payment Fraud Readiness Report finds that payment fraud attempts have become routine for finance teams, with manual AP processes losing money in 42% of known incidents. AI-powered tools detect fraud at more than twice the rate of non-users, but organizations must rethink trust-based controls to close the gap.

Payment Fraud Is Now Routine — And AI Is Both the Threat and the Fix Read More »

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms

PDQ has extended its vulnerability management workflow to macOS devices and added ticketing integrations with Zendesk, ServiceNow, and Halo. Three new APIs allow teams to push endpoint, vulnerability, and deployment data into external systems programmatically. The release positions PDQ as a unified endpoint management and security data platform for mixed Windows and macOS environments.

PDQ Expands Endpoint Vulnerability Management to macOS and Six Ticketing Platforms Read More »

AI Content Governance: Why the Output Layer Is the Real Risk

Why the Output Layer Is the Real Risk in AI Content Governance

Enterprise AI governance has advanced on access logging and provenance tracking, but most programs still lack enforcement at the content output layer. Markup AI calls this “compliance theater.” ECI Research data shows nearly two-thirds of practitioners already see elevated risk from AI-assisted development, making the case for output-layer controls more urgent.

Why the Output Layer Is the Real Risk in AI Content Governance Read More »

EU AI Act Transparency Rules: The Governance Debt Risk for Enterprises

EU AI Act Transparency Rules: The Governance Debt Risk for Enterprises

The EU AI Act’s transparency requirements are now enforceable, and most enterprises are not structurally ready. Kore.ai’s CSO warns of “governance debt” — AI initiatives that stall not because the technology fails, but because the oversight infrastructure was never built. ECI Research breaks down what this means for ITDMs and engineering teams.

EU AI Act Transparency Rules: The Governance Debt Risk for Enterprises Read More »

IREN Acquires Mirantis: Completing the AI Cloud Stack

IREN Acquires Mirantis: Completing the AI Cloud Stack

IREN has completed its acquisition of Mirantis, adding the k0rdent AI orchestration platform to its owned data centers and compute infrastructure. The deal represents a deliberate vertical integration play targeting enterprise AI Cloud buyers. ECI Research data shows AI-enabled development tools are the top investment priority for enterprises in 2026, validating the market IREN is now positioned to serve.

IREN Acquires Mirantis: Completing the AI Cloud Stack Read More »

ServiceNow Autonomous Security: AI-Native Cyber Defense Analyzed

ServiceNow Autonomous Security: AI-Native Cyber Defense Analyzed

ServiceNow announced Autonomous Security, a six-solution AI-native security portfolio integrating Armis and Veza capabilities into its AI Control Tower. The platform targets the 70-tool fragmentation problem with autonomous remediation, identity governance for AI agents, and continuous compliance monitoring. ECI Research examines what it means for ITDMs and security architects.

ServiceNow Autonomous Security: AI-Native Cyber Defense Analyzed Read More »

The Enterprise AI Governance Gap Is a Data Problem First

The Enterprise AI Governance Gap Is a Data Problem First

Most enterprises are running AI on ungoverned data foundations, and the gap between ambition and operational reality is widening. Quest Software’s Global Field CTO Sue Lane joins ECI Research’s Paul Nashawaty to explain why data quality, semantic layers, and portable governance frameworks determine whether AI investments deliver in production. The governance gap isn’t a maturity problem waiting to close — it’s an active risk posture demanding immediate structural attention.

The Enterprise AI Governance Gap Is a Data Problem First Read More »

Digital Media Provenance: Why C2PA Matters Beyond AI Fakes

Why C2PA Matters Beyond AI Fakes

A Utah judge’s rejection of unverified surveillance footage exposed a structural gap in digital media provenance that predates AI by decades. DigiCert is advancing C2PA, an open standard that cryptographically signs every edit in a media file’s history. ECI Research analysis explains why this matters for ITDMs and developers building media pipelines.

Why C2PA Matters Beyond AI Fakes Read More »

Cequence Brings Agentic AI Governance Across MCP, API, and LLM

Cequence Brings Agentic AI Governance Across MCP, API, and LLM

Cequence Security has released AI Discovery, API Registry, LLM Registry, and Skill Registry for AI Gateway, alongside upgraded Agent Personas that bind an AI agent’s tools, model, and APIs to a single policy-enforced job description. The approach, which Cequence calls Agentic Zero Trust, is the first to govern MCP, LLM, and API surfaces under a unified agent-bound identity. This research note examines the architectural logic, the competitive stakes, and what it means for enterprise security and development teams.

Cequence Brings Agentic AI Governance Across MCP, API, and LLM Read More »