<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Aisvs on Sakura Sky: Cloud, Data, Security</title><link>https://www.sakurasky.com/tags/aisvs/</link><description>Recent content in Aisvs on Sakura Sky: Cloud, Data, Security</description><generator>Hugo</generator><language>en-US</language><copyright>Sakura Sky</copyright><lastBuildDate>Tue, 26 May 2026 11:23:18 +0200</lastBuildDate><atom:link href="https://www.sakurasky.com/tags/aisvs/index.xml" rel="self" type="application/rss+xml"/><item><title>The Regulatory Stack, Part 2: Why the Boardroom Should Be Funding the Verification Layer in 2026</title><link>https://www.sakurasky.com/blog/regulatory-stack-part-2/</link><pubDate>Thu, 21 May 2026 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/regulatory-stack-part-2/</guid><description>&lt;style>
 
.series-pull-quote {
 float: right;
 clear: both;
 width: 340px;
 margin-left: 2rem;
 margin-bottom: 1.5rem;
 border: 1px solid #e9ecef;
 border-radius: 6px;
 overflow: hidden;
 background-color: #ffffff;
 
 position: relative;
 z-index: 20;
}

 
@media (max-width: 768px) {
 .series-pull-quote {
 float: none;
 clear: both;
 width: 100%;
 margin-left: 0;
 }
}

.series-header {
 background-color: #f8f9fa;
 color: #6c757d;
 font-size: 0.65rem;
 font-weight: 700;
 letter-spacing: 0.05em;
 padding: 0.8rem 1.25rem;
 border-bottom: 1px solid #e9ecef;
}

.part-label {
 display: block;
 font-size: 0.6rem;
 color: #adb5bd;
 margin-bottom: 0.15rem;
 text-transform: uppercase;
}

.nav-link-text {
 font-size: 0.85rem;
 line-height: 1.4;
 color: #495057;
 text-decoration: none;
 
 position: relative;
 z-index: 21;
}

 
.active-part {
 border-left: 4px solid #000 !important;
 background-color: #ffffff !important;
}

.active-part .nav-link-text {
 font-size: 0.9rem;
 font-weight: 700;
 color: #212529;
 text-decoration: underline;
 text-underline-offset: 3px;
}

.locked-part .nav-link-text {
 color: #ced4da;
}

.list-group-item {
 border-bottom: 1px solid #f8f9fa;
 padding: 1rem 1.25rem !important;
}
&lt;/style>

&lt;aside class="series-pull-quote shadow-sm">
 &lt;div class="series-header">
 READ MORE IN THIS SERIES
 &lt;/div>
 &lt;div class="list-group list-group-flush">
 
 
 

 &lt;div class="list-group-item ">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;a href="https://www.sakurasky.com/blog/regulatory-stack-part-1/" class="nav-link-text">Part 1 - AISVS Has 14 Categories. GATE Has 16 Controls. Here Is the Map.&lt;/a>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item active-part ">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;a href="https://www.sakurasky.com/blog/regulatory-stack-part-2/" class="nav-link-text">Part 2 - Why the Boardroom Should Be Funding the Verification Layer in 2026&lt;/a>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 3 - How the EU AI Act Made Verification a Legal Question, Not a Best-Practice One&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 4 - Engineering Under the AI Act: Article 15 Cybersecurity in Practice&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 5 - The Cyber Resilience Act Closes the Last Loophole&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 6 - Building Under the CRA: A Reference Architecture&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 &lt;/div>
&lt;/aside>


&lt;p>The capital deployment decisions boards make this year will determine whether their autonomous AI systems are governable assets or existential liabilities by 2027. Here is the strategic case.&lt;/p></description></item><item><title>The Regulatory Stack, Part 1: AISVS Has 14 Categories. GATE Has 16 Controls. Here Is the Map.</title><link>https://www.sakurasky.com/blog/regulatory-stack-part-1/</link><pubDate>Tue, 19 May 2026 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/regulatory-stack-part-1/</guid><description>&lt;style>
 
.series-pull-quote {
 float: right;
 clear: both;
 width: 340px;
 margin-left: 2rem;
 margin-bottom: 1.5rem;
 border: 1px solid #e9ecef;
 border-radius: 6px;
 overflow: hidden;
 background-color: #ffffff;
 
 position: relative;
 z-index: 20;
}

 
@media (max-width: 768px) {
 .series-pull-quote {
 float: none;
 clear: both;
 width: 100%;
 margin-left: 0;
 }
}

.series-header {
 background-color: #f8f9fa;
 color: #6c757d;
 font-size: 0.65rem;
 font-weight: 700;
 letter-spacing: 0.05em;
 padding: 0.8rem 1.25rem;
 border-bottom: 1px solid #e9ecef;
}

.part-label {
 display: block;
 font-size: 0.6rem;
 color: #adb5bd;
 margin-bottom: 0.15rem;
 text-transform: uppercase;
}

.nav-link-text {
 font-size: 0.85rem;
 line-height: 1.4;
 color: #495057;
 text-decoration: none;
 
 position: relative;
 z-index: 21;
}

 
.active-part {
 border-left: 4px solid #000 !important;
 background-color: #ffffff !important;
}

.active-part .nav-link-text {
 font-size: 0.9rem;
 font-weight: 700;
 color: #212529;
 text-decoration: underline;
 text-underline-offset: 3px;
}

.locked-part .nav-link-text {
 color: #ced4da;
}

.list-group-item {
 border-bottom: 1px solid #f8f9fa;
 padding: 1rem 1.25rem !important;
}
&lt;/style>

&lt;aside class="series-pull-quote shadow-sm">
 &lt;div class="series-header">
 READ MORE IN THIS SERIES
 &lt;/div>
 &lt;div class="list-group list-group-flush">
 
 
 

 &lt;div class="list-group-item active-part ">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;a href="https://www.sakurasky.com/blog/regulatory-stack-part-1/" class="nav-link-text">Part 1 - AISVS Has 14 Categories. GATE Has 16 Controls. Here Is the Map.&lt;/a>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item ">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;a href="https://www.sakurasky.com/blog/regulatory-stack-part-2/" class="nav-link-text">Part 2 - Why the Boardroom Should Be Funding the Verification Layer in 2026&lt;/a>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 3 - How the EU AI Act Made Verification a Legal Question, Not a Best-Practice One&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 4 - Engineering Under the AI Act: Article 15 Cybersecurity in Practice&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 5 - The Cyber Resilience Act Closes the Last Loophole&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 6 - Building Under the CRA: A Reference Architecture&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 &lt;/div>
&lt;/aside>


&lt;p>AISVS tells you what to verify. The AI Act tells you that you must. Neither tells you how to enforce. This is the engineering map.&lt;/p></description></item><item><title>OWASP Just Drew a New Map, Read It Before Your Auditors Do</title><link>https://www.sakurasky.com/blog/owasp-strategic-plan-2026/</link><pubDate>Thu, 07 May 2026 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/owasp-strategic-plan-2026/</guid><description>&lt;p>&lt;em>The Foundation&amp;rsquo;s new strategic plan is not a community update. It commits OWASP to setting the technical floor for AI security, secure-development competence, and EU compliance. Three things on it should already be on your roadmap.&lt;/em>&lt;/p></description></item><item><title>Your Most Powerful User Is Your Growing Security Blind Spot</title><link>https://www.sakurasky.com/blog/your-most-powerful-user-is-your-growing-security-blind-spot/</link><pubDate>Wed, 20 Aug 2025 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/your-most-powerful-user-is-your-growing-security-blind-spot/</guid><description>&lt;p>I’ve spent countless hours in boardrooms and design sessions recently, and the conversation is always the same: AI. Many have been captivated by the immense potential of Large Language Models, autonomous agents, and AI-powered copilots. We’re integrating them into our workflows, connecting them to our APIs, and pointing them at our most valuable data.&lt;/p></description></item><item><title>Understanding &amp; Addressing the Critical Concerns of API Security</title><link>https://www.sakurasky.com/blog/api-security-concerns/</link><pubDate>Wed, 17 May 2023 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/api-security-concerns/</guid><description>&lt;p>An API, or Application Programming Interface, is a set of protocols or rules that allow different software applications to communicate with each other. APIs define the methods and data formats that applications can use to request and exchange information.&lt;/p></description></item><item><title>Security, Penetration, &amp; Compliance Testing</title><link>https://www.sakurasky.com/blog/security-penetration-compliance-testing/</link><pubDate>Tue, 31 Mar 2015 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/security-penetration-compliance-testing/</guid><description>&lt;p>Sakura Sky has introduced a new range of security, penetration, and compliance testing services including vulnerability, configuration, and compliance scanning. Featuring high-speed discovery, configuration auditing, asset profiling, malware detection, sensitive data discovery, and vulnerability analysis.&lt;/p></description></item></channel></rss>