Cybersecurity risk & governance advisory

Governance that
holds up under
scrutiny.

We work with boards and executive teams navigating complex threat environments, regulatory enforcement and the governance demands of AI at scale.

11 EU AI Office formal investigations now open
4.5h Median zero-day to active exploit, Aug 2026
14 EU frameworks requiring ISO 42001 certification
91% Orgs with uncontrolled AI agent permissions

Executive intelligence

Four critical stories

Written to inform. No agenda.

Incident category index — Q3 2026

Relative frequency composite from public threat intelligence

Memory poisoning Agentic compromise NHI abuse Side-channel Supply chain
Critical AI Security Aug 2026

LLM memory poisoning persists after session reset

Google DeepMind confirmed that injected false context survives session boundaries in long-context deployments. The model produces incorrect outputs indefinitely with no visible anomaly. Standard session management provides no protection.

Critical Regulation Aug 2026

EU AI Office opens 11 formal investigations

Enforcement is no longer a future risk. The AI Office has opened formal investigations into 11 organizations with high-risk AI deployments. Article 11 documentation gaps are the primary trigger. Fines up to €35M or 7% of global turnover apply.

High AI Security Aug 2026

Proprietary model weights extracted via timing side-channel

Multiple confirmed enterprise cases demonstrate model weight reconstruction through response timing analysis on shared cloud inference. An attacker with sustained API access needs no credentials and triggers no security alert. The attack operates below application controls entirely.

High Regulation Aug 2026

FTC files first enforcement action under AI deception rule

The FTC filed its first case in August 2026. The action targets false claims about AI accuracy and undisclosed AI involvement in consumer decisions. Marketing copy, product descriptions and service terms are all in scope. Inaccuracy — not intent — determines exposure.

Risk signals Composite intelligence — August 2026
Memory poisoning in LLM deployments
Critical
Agentic AI lateral movement
Critical
EU AI Act documentation exposure
Critical
NHI credential sprawl
Critical
Model side-channel exfiltration
High
FTC AI enforcement exposure
High

Practice

Three areas. No sprawl.

Partner-led work on the problems that matter most to boards and executive teams.

Governance and compliance

ISO 27001, ISO 42001, SOC 2, PCI DSS, HIPAA, EU AI Act, DORA and NIS2. Programs aligned to how the organization actually operates.

vCISO Board reporting M&A diligence ISO 42001

AI security and governance

Model security, agent controls, prompt injection defenses, EU AI Act Article 11 documentation and post-market monitoring.

AI red-teaming NHI controls Article 11 files NIST AI RMF

Threat detection and response

Curated detection engineering, incident response, red team exercises and executive-level tabletop scenarios.

Red teaming IR playbooks Tabletop exercises Cloud detection

Contact

Speak with TeraType

We keep it simple

No intake forms. No sales calls. Send us a direct email and a partner will respond within one business day.

info@teratype.com privacy@teratype.com

Who we work with. Boards and executive teams who need a trusted, experienced partner rather than a large firm with an account management layer. Engagements are scoped to the problem, not sold as retainers by default.

What to include. A sentence or two on your organization, what you are dealing with and a sense of timeline. We will take it from there.

We use your information only to respond. We do not sell or share personal data.


Legal

Privacy notice

TeraType Privacy Notice

Effective August 1, 2026

Who we are

TeraType is a cybersecurity, privacy and AI governance advisory firm. We help clients design, operate and evidence governance, risk and compliance programs.

What we collect

  • Contact details you submit — name, email address and message content.
  • Basic technical data — IP address, browser type and referring page.
  • Business context you share about your organization or timeline.

How we use it

  • To respond to your inquiry.
  • To operate and secure this website.
  • To comply with applicable legal obligations.

Sharing

We do not sell personal information. We share limited data with service providers under confidentiality obligations, or as required by law.

Your rights

  • EEA and UK residents may request access, correction, erasure, restriction or portability.
  • California residents may request access, deletion and correction.

Exercise rights by emailing privacy@teratype.com. DPAs and BAAs are available on request.

Cookies

We use essential session cookies only. No third-party analytics or advertising cookies are set.