Skip to content

Runtime: Speed kills (carefully thought out compliance strategies)

+ Citrix deals with another zero-day in NetScaler, and Meta raids MongoDB for its new enterprise division.

Runtime: Speed kills (carefully thought out compliance strategies)
Photo by Emil Bruckner / Unsplash

Welcome to Runtime! Today: Why the AI boom is straining the limits of governance and compliance policies designed for an earlier era, NetScaler admins are scrambling to patch a zero-day flaw, again, and more.

Please forward this email to a friend or colleague! If it was forwarded to you, sign up here to get Runtime for free every week, or level up here.


First up: Won't someone think of the auditors

Once a business reaches a certain size, executives quickly learn the importance of good governance tools, which are required for companies operating in certain industries and a pretty good idea to help manage tech usage and data leakage at companies in any industry. But like a lot of concepts put into place before the average enterprise knew what a large language model was, governance and compliance strategies will need to be rethought for the AI era.

That's the conclusion of several studies referenced in a new report from The Stack that shows just how far companies have to go to make sure their nascent AI applications live up to the same standards they set for cloud and on-premises applications. In two telling stats, 40% of respondents to one survey said their companies had experienced a compliance failure with an AI app or agent, and 47% of those in another survey said they didn't put their existing AI compliance policies in place for "urgent deployments."

The AI-related compliance and governance failures are starting to add up
Enterprise AI apps are coming online, which means enterprise compliance and governance policies are being pushed to new limits.

The need for companies in regulated industries to be able to prove they're handling sensitive data correctly is well understood at this point, but all companies would like to make sure they aren't spending money on compute power they don't need or inadvertently leaking data to a partner. But the seismic, lightning-quick changes that have infused enterprise tech tools over the past year has made it really hard to define AI policies and stick to them when new types of data handling and sharing scenarios are popping up every week.

Still, if any company needs a stricter set of compliance and governance policies it's Anthropic and OpenAI, who hopefully won't be able to throw their hands in the air and ask for forgiveness every time they improperly secure their AI agents during the testing process. If any other company deployed AI agents that hacked into businesses and governments, it's hard to imagine they'd be allowed to smile, say they're sorry, and ask for an expedited review of that data center site.


The Stack Summit: We're convening in London on November 4-5, for a series of exclusive workshops and fireside conversations on the rise of BYOC as a favoured enterprise SaaS deployment model; how many CDOs are consolidating their data estates with Apache Iceberg; how CISOs at FTSE 100 scale are handling supply chain risk (with GSK's CISO) and more. 

Ticket applications are subject to pre-vetting. Get in touch with ed@thestack.technology if you want to be in the room.

Learn more

The rest of The Stack

Once more, with exploits: Of course, traditional cybersecurity practices haven't even come close to preventing people from releasing products with vulnerabilities to be exploited, as Citrix continues to learn. The company urged NetScaler customers to patch two new zero-day flaws under exploit after some customers felt Citrix dragged its heels when confronted with the initial problem.

NetScaler attacks: Zero days reported exploited
“Similar techniques have previously been observed with critical Citrix NetScaler vulnerabilities...”

AO is the new SEO: Agentic activity on the internet surpassed human activity on the internet some time ago, which means websites increasingly need to put agent optimization strategies into place to stand out. In this week's STACKUP, Noah Bovenizer talks to Caleb Peffer, CEO of Firecrawl, which just raised $75 million in Series B funding to help companies retool their sites for agents.

STACKUP: The Stack’s weekly tech startups and funding wrap
This week’s rounds and milestones.

Mark's Enterprise Tech Accessory: Meta announced plans to set up a new enterprise division that will finally confirm years of speculation about the company's interest in using its formidable tech assets to serve the business community. Leading the division will be Chirantan "CJ" Desai, who spent less than a year as CEO of MongoDB, and news of his departure sent the company's stock down 18% Monday.

Meta makes its enterprise ambitions official, poaches MongoDB CEO Desai
Desai will lead a newly formed group tasked with turning Meta’s AI infrastructure and tools into enterprise-grade services.

Harness racing: The AI harness — software that sits between the AI model and the tools the models need to interact with — is quickly becoming one of the most important parts of the enterprise AI stack. But companies are finding that securing that harness is easier said than done, and a lot of the best practices for doing so are still emerging.

Picking an AI harness is hard. Securing it is harder
AI harnesses could be the most important part of an enterprise AI stack. Best practices for securing them are still evolving.

More contributors, please: MCP is another key part of the enterprise stack that has been evolving while being actively used for several years now, and that process has been chaotic but it's producing results, according to Mazin Gilbert, executive director of the Agentic AI Foundation. "We would rather invest in a few and make them the open standard versus how VC [firms] operate today with ‘let's take a hundred, and if two of them make it, then life is good,’" he told The Stack.

Agents are moving fast, AAIF head Mazin Gilbert wants open source to keep up
The Agentic AI Foundation’s Executive Director on the challenges of building agentic infrastructure as companies deploy it

Stack ranking — Enterprise moves

Dev Ittycheria is once again president and CEO of MongoDB, after serving in that role for 11 years prior to Desai's appointment last November. MongoDB said it will be searching for a permanent replacement. 

Fei-Fei Li is the new executive vice president and chief scientist at AMD, following the company's acquisition of her AI research company, World Labs, for $8.2 billion.


We're also reading:

2026 in LLMs (so far): Simon Willison has done as good a job as anybody keeping up with the dizzying pace of AI model innovation in recent years, and especially this year.

Why are silicon wafers round?: If you've ever wondering, IBM has you covered.


Thanks for reading — see you Thursday!

Add The Stack on Google