<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><description>CPA · CISSP · CISA | Federal technology compliance: FISMA/NIST RMF, FedRAMP, CMMC, Federal AI Governance, Zero Trust. Former KPMG, BDO, Stryker. Practitioner-depth guides at josefkamara.com. Newsletter: The Authority Brief.</description><link>https://bsky.app/profile/josefkamara.com</link><title>@josefkamara.com - Josef Kamara</title><item><link>https://bsky.app/profile/josefkamara.com/post/3mldq5o2tc32n</link><description>Traditional risk matrices miss five dimensions that define agentic AI failure modes.&#xA;&#xA;Most security teams are still using 2019 templates to assess 2026 systems.</description><pubDate>08 May 2026 12:28 +0000</pubDate><guid isPermaLink="false">at://did:plc:nhza4xaehdryso7ck3eghrni/app.bsky.feed.post/3mldq5o2tc32n</guid></item><item><link>https://bsky.app/profile/josefkamara.com/post/3ml6pkk6twz2n</link><description>NYC, Colorado, and Brussels are converging on the same bias audit requirement.&#xA;&#xA;Most companies are building three programs when one will satisfy all three jurisdictions.</description><pubDate>06 May 2026 12:34 +0000</pubDate><guid isPermaLink="false">at://did:plc:nhza4xaehdryso7ck3eghrni/app.bsky.feed.post/3ml6pkk6twz2n</guid></item><item><link>https://bsky.app/profile/josefkamara.com/post/3mkzogewh5i2j</link><description>Colorado&#39;s AI Act takes effect in 57 days.&#xA;&#xA;Most companies deploying agentic AI still treat governance like a 2024 problem.</description><pubDate>04 May 2026 12:30 +0000</pubDate><guid isPermaLink="false">at://did:plc:nhza4xaehdryso7ck3eghrni/app.bsky.feed.post/3mkzogewh5i2j</guid></item><item><link>https://bsky.app/profile/josefkamara.com/post/3mks4wydsk32v</link><description>More than 80% of workers use AI tools their employers haven&#39;t approved. (UpGuard, 2024)&#xA;&#xA;Gartner puts 69% of organizations with documented evidence of prohibited GenAI already in use.&#xA;&#xA;That&#39;s shadow AI.&#xA;&#xA;#AIGovernance #ShadowAI</description><pubDate>01 May 2026 12:29 +0000</pubDate><guid isPermaLink="false">at://did:plc:nhza4xaehdryso7ck3eghrni/app.bsky.feed.post/3mks4wydsk32v</guid></item><item><link>https://bsky.app/profile/josefkamara.com/post/3mkn3vku2mr2x</link><description>Your controls didn&#39;t fail on the day of the breach.&#xA;&#xA;They failed months before it.&#xA;&#xA;IBM&#39;s 2024 report puts the mean time to identify a breach at 194 days.&#xA;&#xA;That&#39;s compliance drift.&#xA;&#xA;#GRCEngineering #CyberSecurity</description><pubDate>29 Apr 2026 12:27 +0000</pubDate><guid isPermaLink="false">at://did:plc:nhza4xaehdryso7ck3eghrni/app.bsky.feed.post/3mkn3vku2mr2x</guid></item><item><link>https://bsky.app/profile/josefkamara.com/post/3mki4zxi7o42u</link><description>Colorado&#39;s AI Act goes into effect June 30, 2026.&#xA;&#xA;Most compliance teams don&#39;t know it includes a legal shield.&#xA;&#xA;It&#39;s called the affirmative defense. NIST AI RMF is one of the two conditions that activate it.</description><pubDate>27 Apr 2026 13:04 +0000</pubDate><guid isPermaLink="false">at://did:plc:nhza4xaehdryso7ck3eghrni/app.bsky.feed.post/3mki4zxi7o42u</guid></item></channel></rss>