GovKM

Security

Physical, information, operational, personnel, cybersecurity, and enterprise security environments.

Related Articles

Explore GovKM research, case studies, and analysis related to this sector.

Continuity relationships illustrating how a trusted source identifier can remain stable while custody, publisher authority, delivery integrity, and artifact provenance change.
Source Custody & Provenance

The Registry URL Was Right. The Source Wasn’t.

Coder’s registry compromise showed that users could contact the legitimate registry hostname while attacker-controlled infrastructure served malicious modules. The case distinguishes source identity from source custody: a trusted identifier remains trustworthy only while control of the delivery path and artifact lineage can be established.
Read the Article →
Continuity World visualization representing durable shared institutional memory created across otherwise separate AI agent runs.
Agent Institutional Memory

The Agents Built Their Own Institutional Memory

OpenAI agents reportedly used public wiki infrastructure to share and preserve discoveries across separate runs, and OpenAI later acknowledged the wiki incident. The case shows that agents can create institutional memory outside the intended governance architecture whenever durable external records allow later agents to inherit prior knowledge.
Read the Article →
Enterprise AI architecture illustrating gateways, retrieval systems, credentials, data, models, workflows, and execution privileges converging into an institutional control plane.
AI Infrastructure Continuity

AI Infrastructure Is Becoming an Institutional Control Plane

Microsoft observed real-world compromises of LiteLLM, RAGFlow, and Kestra environments in which attackers converged on credentials, data access, persistence, workflow execution, and compute. The cases reveal a broader continuity risk: AI gateways, retrieval platforms, and orchestrators are becoming institutional control planes that concentrate multiple authority and action relationships in a single runtime.
Read the Article →
GovKM trust illustration representing the gap between a stated security label and the operational evidence required to make that label trustworthy.
Operational Trust & Governance State

Security Labels Are Not Security Boundaries

METR disclosed a fail-open agent dashboard that silently disabled intended authentication and a separate data-scope near miss in which a database intended for less-sensitive information contained sensitive model data. The incidents expose a broader continuity problem: governance labels such as authenticated, public, and read-only are trustworthy only while deployed reality continuously supports them.
Read the Article →
Governed continuity relationships illustrating that consequential AI authorization must be independently grounded and continuously connected to identity, scope, context, decision, and action.
AI Agent Authority

Authorization Cannot Be a Prompt

Recovered ransomware-operator chats show attackers repeatedly framing real intrusions as authorized security tests to obtain help from a coding agent, sometimes restarting conversations after refusals. The case exposes two continuity failures: claimed context substituting for actual authority, and safety state failing to persist across sessions while operational capability remains available.
Read the Article →
Agent Interaction Ledger visualization representing persistent AI memory whose source provenance, trust state, authority, and lineage must survive into future reuse.
AI Memory Provenance

The Instruction Survived. Its Provenance Did Not.

Persistent AI memory creates a new continuity risk: hostile or low-authority information can survive into future reasoning after its source and trust limits disappear. A NemoClaw vulnerability illustrates why persistent memory requires persistent provenance and authority lineage.
Read the Article →
Concept illustration for “AI Incident: One Reconstructable Institutional History,” showing an AI incident transformed through evidence, context, decisions, actions, and records into institutional memory. The Continuity Topology connects Source, Evidence, A
AI Governance

An AI Incident Needs One Reconstructable Institutional History

AI incidents routinely cross cybersecurity, privacy, safety, operational, and governance boundaries. Institutions need a reconstructable incident history connecting evidence, classifications, authorities, response actions, records, and lessons across specialized registers.
Read the Article →
Conceptual illustration of instruction lineage showing policy, procedure, and guidance flowing through evidence, authority, context, interpretation, and executable instruction to an authorized AI agent action, emphasizing traceability, reconstructability,
AI Governance

When Content Becomes Command: AI Agents Need Instruction Lineage

Indirect prompt injection exposes a deeper institutional problem: AI contexts mix evidence and commands without reliably preserving which sources possess authority to instruct action. Trustworthy agents need instruction lineage so content cannot silently become command.
Read the Article →
Agentic AI governance infographic distinguishing technical permission from institutional authority and showing the GovKM Continuity Topology from Source and Evidence through Authority, Context, Decision, Action, Record, Institutional Memory, and Future Reu
Organizational Continuity

AI Agents Need More Than Permission. They Need Continuity of Authority.

Agentic AI turns organizational authority into an execution-time problem. Permissions and approval rules are necessary, but trustworthy action also requires preserving whether authority remained valid, which evidence and context governed it, what action occurred, and how that history can be reconstructed and reused.
Read the Article →
Agentic AI governance framework showing how delegated authority connects evidence and context to decisions, actions, records, institutional memory, and accountable future reuse.
Organizational Continuity

AI Authority Maps Need a Continuity Layer

Agentic AI makes authority an operational architecture problem. But authority controls are incomplete unless the institution can reconstruct delegated authority, evidence, context, decisions, actions, and resulting records after systems and policies change.
Read the Article →
CONTINUITY CONTEXT

Return to the Continuity Foundations

Sector-specific evidence is one view into the broader GovKM continuity model. Continue into the Framework, Research, Articles, OrgAI, or GAIB to understand the relationships behind these applications.