The Axios Supply Chain Attack Hit OpenAI’s Signing Pipeline. What Every Organisation Should Learn About Dependency Governance

The Axios Supply Chain Attack Hit OpenAI’s Signing Pipeline. What Every Organisation Should Learn About Dependency Governance

When a North Korean state actor compromised the Axios npm package on March 31, 2026, the blast radius did not stop at developer laptops. It reached OpenAI’s macOS code-signing pipeline — the system that certifies ChatGPT Desktop, Codex, Codex CLI, and Atlas as...
Meta Muse Spark Promises “Personal Superintelligence.” Three Questions Every CIO Should Ask First

Meta Muse Spark Promises “Personal Superintelligence.” Three Questions Every CIO Should Ask First

On April 8, Meta Superintelligence Labs unveiled Muse Spark — their first model in a new Muse series — and framed it as the opening move toward “personal superintelligence.” The pitch is bold: an AI assistant that does not just answer questions, but...
What Claude Managed Agents Means for Enterprise AI Governance and Vendor Risk

What Claude Managed Agents Means for Enterprise AI Governance and Vendor Risk

Anthropic just revealed the architecture behind Claude Managed Agents. For any organisation deploying AI agents in production, the engineering decisions they made carry real implications for governance, security, and vendor risk. Here is what Australian IT leaders...
Anthropic, OpenAI, and Google Are All Locking In Enterprise Customers. How to Manage Vendor Risk

Anthropic, OpenAI, and Google Are All Locking In Enterprise Customers. How to Manage Vendor Risk

The three dominant AI vendors are no longer competing on model benchmarks alone. They are competing to become permanent infrastructure inside the enterprise. And most mid-market organisations are walking into these relationships without a vendor risk strategy. The...