regulatory compliance

AI Is Breaking Open Source Trust — And Provenance Is the Fix

AI Is Breaking Open Source Trust — And Provenance Is the Fix

AI-accelerated development is flooding open source maintainers with unreviewed pull requests while cryptographic signing and SBOM adoption remain dangerously low. Timothy Lewis of tea.inc. argues that provenance and identity are the missing foundations of enterprise software supply chain security. ECI Research data shows that AI-generated package risk is now the top open-source security concern for 2026.

AI Is Breaking Open Source Trust — And Provenance Is the Fix Read More »

AI Content Governance: Why the Output Layer Is the Real Risk

Why the Output Layer Is the Real Risk in AI Content Governance

Enterprise AI governance has advanced on access logging and provenance tracking, but most programs still lack enforcement at the content output layer. Markup AI calls this “compliance theater.” ECI Research data shows nearly two-thirds of practitioners already see elevated risk from AI-assisted development, making the case for output-layer controls more urgent.

Why the Output Layer Is the Real Risk in AI Content Governance Read More »

AI Output Governance: The Blind Spot in Enterprise AI Strategy

AI Output Governance: The Blind Spot in Enterprise AI Strategy

Enterprise AI governance frameworks have focused on access control and data inputs, leaving output quality and compliance largely unmanaged. Markup AI is making the case for enforceable content standards that apply to what AI produces, not just what goes in. ECI Research data shows governance spending is rising, but organizations need to ensure it’s solving the right problem.

AI Output Governance: The Blind Spot in Enterprise AI Strategy Read More »

Eclipse Foundation & OWASP Unite for CRA Open Source Security

Eclipse Foundation & OWASP Unite for CRA Open Source Security

The Eclipse Foundation and OWASP have signed an MOU to strengthen open source security and support EU Cyber Resilience Act compliance. With mandatory reporting obligations taking effect September 11, 2026, the partnership targets SBOM adoption, supply chain security, and maintainer readiness. ECI Research data shows supply chain security is a top-12-month investment priority for nearly half of enterprise respondents.

Eclipse Foundation & OWASP Unite for CRA Open Source Security Read More »