<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>CIO AI Review</title><link>https://cioaireview.com/</link><description>An architecture-and-operations review for technology executives deciding how AI should enter the enterprise stack, which controls must follow it, and where vendor demonstrations leave material questions unanswered.</description><item><title>NIST is revising the AI RMF: architecture inventories should survive the version change</title><link>https://cioaireview.com/briefings/nist-rmf-revision/</link><description>The durable CIO move is to maintain use-case, system, data, and control evidence that can map to evolving guidance.</description><pubDate>Mon, 20 Jul 2026 18:00:00 GMT</pubDate><guid>https://cioaireview.com/briefings/nist-rmf-revision/</guid></item><item><title>CISA's secure-AI guidance starts before model selection</title><link>https://cioaireview.com/briefings/cisa-secure-ai-lifecycle/</link><description>Secure-by-design expectations reach data, development, deployment, operation, and vendor responsibility.</description><pubDate>Mon, 20 Jul 2026 18:00:00 GMT</pubDate><guid>https://cioaireview.com/briefings/cisa-secure-ai-lifecycle/</guid></item><item><title>OWASP's LLM Top 10 is a threat prompt, not a security certificate</title><link>https://cioaireview.com/briefings/owasp-llm-top-ten/</link><description>The list helps teams ask better questions about prompt injection, data disclosure, supply chains, outputs, agency, and consumption.</description><pubDate>Mon, 20 Jul 2026 18:00:00 GMT</pubDate><guid>https://cioaireview.com/briefings/owasp-llm-top-ten/</guid></item><item><title>OMB's AI acquisition memo offers a useful enterprise procurement checklist</title><link>https://cioaireview.com/briefings/omb-ai-acquisition/</link><description>Even outside government, the memo's focus on competition, interoperability, data, testing, and rights can sharpen vendor review.</description><pubDate>Mon, 20 Jul 2026 18:00:00 GMT</pubDate><guid>https://cioaireview.com/briefings/omb-ai-acquisition/</guid></item><item><title>MITRE ATLAS gives AI incidents a common adversary language</title><link>https://cioaireview.com/briefings/mitre-atlas-enterprise/</link><description>CIO and CISO teams can use the knowledge base to connect AI-specific attack behavior to threat modeling and detection.</description><pubDate>Mon, 20 Jul 2026 18:00:00 GMT</pubDate><guid>https://cioaireview.com/briefings/mitre-atlas-enterprise/</guid></item><item><title>Agentic AI turns identity architecture into an executive decision</title><link>https://cioaireview.com/briefings/agent-access-boundary/</link><description>As assistants gain tools, CIOs need a non-human identity and delegated-authority model before broad deployment.</description><pubDate>Mon, 20 Jul 2026 18:00:00 GMT</pubDate><guid>https://cioaireview.com/briefings/agent-access-boundary/</guid></item></channel></rss>