<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Spoiledlunch</title><link>https://511d98a7.spoiledlunch.pages.dev/</link><description>Nerdy Stuff. Tech Talk. Zero Freshness. Analysis and commentary on GRC, security, and AI.</description><generator>Hugo 0.160.1</generator><language>en-us</language><lastBuildDate>Thu, 28 May 2026 00:00:00 +0000</lastBuildDate><atom:link href="https://511d98a7.spoiledlunch.pages.dev/topics/grc/" rel="self" type="application/rss+xml"/><item><title>OpenAI's Frontier Governance Framework</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-28-openai-s-frontier-governance-framework/</link><pubDate>Thu, 28 May 2026 00:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-28-openai-s-frontier-governance-framework/</guid><description>News Brief • May 28, 2026 | Topics: GRC | Summary: Explore OpenAI’s Frontier Governance Framework and how our AI safety, security, and risk practices align with emerging EU and California …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>safety</category></item><item><title>Compliance Exceptions Tell You More Than Your Passed Controls</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-01-compliance-exceptions-tell-you-more-than-your-passed-controls/</link><pubDate>Tue, 26 May 2026 09:00:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-01-compliance-exceptions-tell-you-more-than-your-passed-controls/</guid><description>Article • May 26, 2026 • 4 min read | Topics: GRC | Organizations love to report passed controls because passed controls are flattering.
They suggest order. They suggest repeatability. They suggest that the environment behaves the way the framework …</description><author>Spoiledlunch</author><category>GRC</category><category>compliance</category><category>exceptions</category><category>controls</category><category>audit</category></item><item><title>GDPR Enforcement Anniversary: Eight Years of Real Privacy Law and Fake Compliance Theater</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-25-gdpr-enforcement-anniversary-eight-years-of-real-privacy-law-and-fake-compliance-theater/</link><pubDate>Mon, 25 May 2026 09:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-25-gdpr-enforcement-anniversary-eight-years-of-real-privacy-law-and-fake-compliance-theater/</guid><description>Article • May 25, 2026 • 6 min read | Topics: Privacy, GRC | Today marks eight years since GDPR enforcement began. Unlike most awareness campaigns we investigate, this anniversary commemorates something that actually works: the world’s first privacy law …</description><author>Spoiledlunch</author><category>Privacy</category><category>GRC</category></item><item><title>SEC and NFA Announce Memorandum of Understanding to Further Harmonize Regulatory Coordination</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-21-sec-and-nfa-announce-memorandum-of-understanding-to-further-harmonize-regulatory-coordination/</link><pubDate>Thu, 21 May 2026 12:51:10 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-21-sec-and-nfa-announce-memorandum-of-understanding-to-further-harmonize-regulatory-coordination/</guid><description>News Brief • May 21, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission and National Futures Association (NFA) today announced that they have entered into a Memorandum of …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>FTC Sends Warning Letters to Companies About Compliance with the TAKE IT DOWN Act</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-20-ftc-sends-warning-letters-to-companies-about-compliance-with-the-take-it-down-act/</link><pubDate>Wed, 20 May 2026 12:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-20-ftc-sends-warning-letters-to-companies-about-compliance-with-the-take-it-down-act/</guid><description>News Brief • May 20, 2026 | Topics: GRC | Summary: The Federal Trade Commission sent warning letters today to a dozen websites advising them of their obligation to comply with the TAKE IT DOWN …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-ftc-consumer-protection-press-releases</category></item><item><title>SOC 2 Became a Sales Requirement, Not a Trust Signal</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-25-soc-2-became-a-sales-requirement-not-a-trust-signal/</link><pubDate>Tue, 19 May 2026 09:00:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-25-soc-2-became-a-sales-requirement-not-a-trust-signal/</guid><description>Article • May 19, 2026 • 7 min read | Topics: GRC | SOC 2 still matters. That is exactly why the industry has let it become something more misleading than useless.
The report was supposed to be a narrow assurance artifact: a way to evaluate whether a …</description><author>Spoiledlunch</author><category>GRC</category><category>soc 2</category><category>audit</category><category>governance</category><category>assurance</category></item><item><title>FTC Begins Enforcing the TAKE IT DOWN Act</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-19-ftc-begins-enforcing-the-take-it-down-act/</link><pubDate>Tue, 19 May 2026 12:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-19-ftc-begins-enforcing-the-take-it-down-act/</guid><description>News Brief • May 19, 2026 | Topics: GRC | Summary: The Federal Trade Commission today began enforcing the TAKE IT DOWN Act (TIDA), a law requiring platforms, at the request of victims, to …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-ftc-consumer-protection-press-releases</category></item><item><title>SEC Rescinds Policy Regarding Denials of Settlements in Enforcement Actions</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-18-sec-rescinds-policy-regarding-denials-of-settlements-in-enforcement-actions/</link><pubDate>Mon, 18 May 2026 16:33:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-18-sec-rescinds-policy-regarding-denials-of-settlements-in-enforcement-actions/</guid><description>News Brief • May 18, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today rescinded a policy, codified in Rule 202.5(e) of its informal rules of procedures, stating that …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>executive-risk-sec-press-releases</category></item><item><title>International Anti-Ransomware Day: Who Really Profits from the Fear Campaign?</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-12-international-anti-ransomware-day-who-profits-from-fear/</link><pubDate>Tue, 12 May 2026 00:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-12-international-anti-ransomware-day-who-profits-from-fear/</guid><description>Article • May 12, 2026 • 6 min read | Topics: Security, GRC | It’s International Anti-Ransomware Day. Time to be very, very afraid of ransomware. And conveniently, very, very ready to buy solutions.
What started as a legitimate effort to raise awareness …</description><author>Spoiledlunch</author><category>Security</category><category>GRC</category></item><item><title>How enterprises are scaling AI</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-11-how-enterprises-are-scaling-ai/</link><pubDate>Mon, 11 May 2026 10:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-11-how-enterprises-are-scaling-ai/</guid><description>News Brief • May 11, 2026 | Topics: GRC | Summary: How enterprises scale AI: from early experiments to compounding impact through trust, governance, workflow design, and quality at scale.
Why …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>guides</category></item><item><title>World Password Day: Intel's Marketing Legacy Thirteen Years Later</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-07-world-password-day-intels-marketing-legacy-thirteen-years-later/</link><pubDate>Thu, 07 May 2026 17:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-05-07-world-password-day-intels-marketing-legacy-thirteen-years-later/</guid><description>Article • May 7, 2026 • 6 min read | Topics: Security, GRC | World Password Day just ended, and with it, another week of password managers explaining why your passwords aren’t complex enough, MFA vendors explaining why passwords are fundamentally broken, …</description><author>Spoiledlunch</author><category>Security</category><category>GRC</category></item><item><title>How ChatGPT learns about the world while protecting privacy</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-06-how-chatgpt-learns-about-the-world-while-protecting-privacy/</link><pubDate>Wed, 06 May 2026 08:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-06-how-chatgpt-learns-about-the-world-while-protecting-privacy/</guid><description>News Brief • May 6, 2026 | Topics: GRC | Summary: Learn how ChatGPT safeguards your privacy, reduces personal data in training, and gives you control over whether your conversations improve …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>global-affairs</category></item><item><title>New ways to buy ChatGPT ads</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-05-new-ways-to-buy-chatgpt-ads/</link><pubDate>Tue, 05 May 2026 00:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-05-05-new-ways-to-buy-chatgpt-ads/</guid><description>News Brief • May 5, 2026 | Topics: GRC | Summary: OpenAI expands ChatGPT ads with a beta self-serve Ads Manager, CPC bidding, and enhanced measurement tools—built to protect privacy and keep …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>product</category></item><item><title>Deputy Director of Enforcement Jason Burt to Conclude His Tenure at the SEC</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-30-deputy-director-of-enforcement-jason-burt-to-conclude-his-tenure-at-the-sec/</link><pubDate>Thu, 30 Apr 2026 20:30:36 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-30-deputy-director-of-enforcement-jason-burt-to-conclude-his-tenure-at-the-sec/</guid><description>News Brief • April 30, 2026 | Topics: GRC | Summary: The Securities and Exchange Commission today announced that Jason Burt, Deputy Director of the Division of Enforcement (Specialized Units), …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>press-releases</category></item><item><title>Our commitment to community safety</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-28-our-commitment-to-community-safety/</link><pubDate>Tue, 28 Apr 2026 00:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-28-our-commitment-to-community-safety/</guid><description>News Brief • April 28, 2026 | Topics: GRC | Summary: Learn how OpenAI protects community safety in ChatGPT through model safeguards, misuse detection, policy enforcement, and collaboration with …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>safety</category></item><item><title>Marking 10 years of the GDPR: the evolution of the European data protection landscape</title><link>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-27-marking-10-years-of-the-gdpr-the-evolution-of-the-european-data-protection-landscape/</link><pubDate>Mon, 27 Apr 2026 12:00:00 +0000</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/news/2026-04-27-marking-10-years-of-the-gdpr-the-evolution-of-the-european-data-protection-landscape/</guid><description>News Brief • April 27, 2026 | Topics: GRC | Summary: Brussels, 27 April – Today marks the 10th anniversary of the GDPR’s adoption, the first comprehensive data protection framework spanning an …</description><author>Spoiledlunch</author><category>GRC</category><category>grc</category><category>user-state-com-google-reading-list</category><category>user-label-spoiledlunch-news</category><category>user-state-org-freshrss-main</category><category>edpb-news</category></item><item><title>Compliance Gets Better When Regulators Ship Tools Instead of Slogans</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-24-compliance-gets-better-when-regulators-ship-tools-instead-of-slogans/</link><pubDate>Fri, 24 Apr 2026 08:20:00 -0400</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-24-compliance-gets-better-when-regulators-ship-tools-instead-of-slogans/</guid><description>Article • April 24, 2026 • 2 min read | Topics: GRC | A lot of compliance guidance dies as slideware because it explains principles without changing the operator’s daily work. The more interesting recent GRC signal is that standards bodies and …</description><author>Spoiledlunch</author><category>GRC</category><category>compliance</category><category>gdpr</category><category>csf 2.0</category><category>governance</category></item><item><title>Earth Day: How Environmental Activism Became Carbon Offset Subscription Theater</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-22-earth-day-how-environmental-activism-became-carbon-offset-subscription-theater/</link><pubDate>Wed, 22 Apr 2026 09:00:00 -0500</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-22-earth-day-how-environmental-activism-became-carbon-offset-subscription-theater/</guid><description>Article • April 22, 2026 • 6 min read | Topics: GRC, AI | Today is Earth Day, which means it’s time to feel guilty about your carbon footprint and grateful for the carbon offset subscriptions, green energy apps, and sustainability platforms that will …</description><author>Spoiledlunch</author><category>GRC</category><category>AI</category></item><item><title>Why AI Governance Frameworks Are Security Theater</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/</link><pubDate>Mon, 20 Apr 2026 09:00:00 -0700</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-20-ai-governance-security-theater/</guid><description>Article • April 20, 2026 • 4 min read | Topics: AI, GRC | Most enterprise AI governance frameworks are elaborate exercises in checkbox compliance that miss the actual risks. They’re designed to satisfy auditors and executives, not to manage the …</description><author>Spoiledlunch</author><category>AI</category><category>GRC</category><category>governance</category><category>risk management</category><category>enterprise AI</category><category>compliance</category></item><item><title>The SOC 2 Compliance Cargo Cult</title><link>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</link><pubDate>Sat, 18 Apr 2026 14:30:00 -0700</pubDate><guid>https://511d98a7.spoiledlunch.pages.dev/articles/2026-04-18-soc2-compliance-cargo-cult/</guid><description>Article • April 18, 2026 • 7 min read | Topics: GRC, Security | SOC 2 compliance has become a cargo cult ritual in enterprise security. Organizations implement the ceremonial controls, follow the prescribed procedures, and wait for security to magically appear. …</description><author>Spoiledlunch</author><category>GRC</category><category>Security</category><category>SOC 2</category><category>compliance</category><category>security controls</category><category>audit</category></item></channel></rss>