Welcome to Runtime! Today: Why the AI boom is straining the limits of governance and compliance policies designed for an earlier era, NetScaler admins are scrambling to patch a zero-day flaw, again, and more.
Please forward this email to a friend or colleague! If it was forwarded to you, sign up here to get Runtime for free every week, or level up here.
First up: Won't someone think of the auditors
Once a business reaches a certain size, executives quickly learn the importance of good governance tools, which are required for companies operating in certain industries and a pretty good idea to help manage tech usage and data leakage at companies in any industry. But like a lot of concepts put into place before the average enterprise knew what a large language model was, governance and compliance strategies will need to be rethought for the AI era.
That's the conclusion of several studies referenced in a new report from The Stack that shows just how far companies have to go to make sure their nascent AI applications live up to the same standards they set for cloud and on-premises applications. In two telling stats, 40% of respondents to one survey said their companies had experienced a compliance failure with an AI app or agent, and 47% of those in another survey said they didn't put their existing AI compliance policies in place for "urgent deployments."

The need for companies in regulated industries to be able to prove they're handling sensitive data correctly is well understood at this point, but all companies would like to make sure they aren't spending money on compute power they don't need or inadvertently leaking data to a partner. But the seismic, lightning-quick changes that have infused enterprise tech tools over the past year has made it really hard to define AI policies and stick to them when new types of data handling and sharing scenarios are popping up every week.
Still, if any company needs a stricter set of compliance and governance policies it's Anthropic and OpenAI, who hopefully won't be able to throw their hands in the air and ask for forgiveness every time they improperly secure their AI agents during the testing process. If any other company deployed AI agents that hacked into businesses and governments, it's hard to imagine they'd be allowed to smile, say they're sorry, and ask for an expedited review of that data center site.
The Stack Summit: We're convening in London on November 4-5, for a series of exclusive workshops and fireside conversations on the rise of BYOC as a favoured enterprise SaaS deployment model; how many CDOs are consolidating their data estates with Apache Iceberg; how CISOs at FTSE 100 scale are handling supply chain risk (with GSK's CISO) and more.
Ticket applications are subject to pre-vetting. Get in touch with ed@thestack.technology if you want to be in the room.
The rest of The Stack
Once more, with exploits: Of course, traditional cybersecurity practices haven't even come close to preventing people from releasing products with vulnerabilities to be exploited, as Citrix continues to learn. The company urged NetScaler customers to patch two new zero-day flaws under exploit after some customers felt Citrix dragged its heels when confronted with the initial problem.

AO is the new SEO: Agentic activity on the internet surpassed human activity on the internet some time ago, which means websites increasingly need to put agent optimization strategies into place to stand out. In this week's STACKUP, Noah Bovenizer talks to Caleb Peffer, CEO of Firecrawl, which just raised $75 million in Series B funding to help companies retool their sites for agents.

Mark's Enterprise Tech Accessory: Meta announced plans to set up a new enterprise division that will finally confirm years of speculation about the company's interest in using its formidable tech assets to serve the business community. Leading the division will be Chirantan "CJ" Desai, who spent less than a year as CEO of MongoDB, and news of his departure sent the company's stock down 18% Monday.

Harness racing: The AI harness — software that sits between the AI model and the tools the models need to interact with — is quickly becoming one of the most important parts of the enterprise AI stack. But companies are finding that securing that harness is easier said than done, and a lot of the best practices for doing so are still emerging.

More contributors, please: MCP is another key part of the enterprise stack that has been evolving while being actively used for several years now, and that process has been chaotic but it's producing results, according to Mazin Gilbert, executive director of the Agentic AI Foundation. "We would rather invest in a few and make them the open standard versus how VC [firms] operate today with ‘let's take a hundred, and if two of them make it, then life is good,’" he told The Stack.

Stack ranking — Enterprise moves
Dev Ittycheria is once again president and CEO of MongoDB, after serving in that role for 11 years prior to Desai's appointment last November. MongoDB said it will be searching for a permanent replacement.
Fei-Fei Li is the new executive vice president and chief scientist at AMD, following the company's acquisition of her AI research company, World Labs, for $8.2 billion.
We're also reading:
2026 in LLMs (so far): Simon Willison has done as good a job as anybody keeping up with the dizzying pace of AI model innovation in recent years, and especially this year.
Why are silicon wafers round?: If you've ever wondering, IBM has you covered.
Thanks for reading — see you Thursday!





