Episode

Priviso Live Episode 86: The Regulator shows her teeth

Podcast
Priviso Live
Published
May 10, 2026
Duration seconds
639
Processing state
not_requested
Canonical source
https://PrivisoLive.podbean.com/e/priviso-live-episode-86-the-regulator-shows-her-teeth/
Audio
https://mcdn.podbean.com/mf/web/9uop6nb0rzgyziqh/yt_video_3hoj6JAC1X4_ext5qc.mp3
JSON
/v1/public/podcasts/priviso-live-7043809/episodes/priviso-live-episode-86-the-regulator-shows-her-teeth
Markdown
/podcast/priviso-live-7043809/priviso-live-episode-86-the-regulator-shows-her-teeth.md

Actions

  • POST https://stenobird.com/v1/public/podcasts/priviso-live-7043809/episodes/priviso-live-episode-86-the-regulator-shows-her-teeth/transcription-requests
    Idempotently request low-priority transcript generation for this episode.
  • GET https://stenobird.com/podcast/priviso-live-7043809/priviso-live-episode-86-the-regulator-shows-her-teeth.md
    Read the agent-friendly Markdown representation of this episode resource.

Summary

Two themes. Both urgent. Both directly relevant to anyone working in information security or privacy in South Africa.๐Ÿค– Theme 1: Agentic AI and the Identity Crisis Nobody Planned ForAI is no longer just answering your questions. It is booking meetings, executing code, sending emails, and making API calls, autonomously, around the clock, with credentials your IAM tools were never designed to govern.These are called Non-Human Identities (NHIs), and the numbers should make you sit up:๐Ÿ“Š 78% of organisations have no formal policies for creating or removing AI agent identities.๐Ÿ“Š 92% are not confident their existing IAM tools can manage the associated risks.๐Ÿ“Š 88% of organisations running AI agents have already experienced a confirmed or suspected security incident.๐Ÿ“Š Only 6% of security budgets are currently dedicated to AI agent security.We also unpack Anthropic's Claude Mythos, Project Glasswing, and what Cisco's recent acquisition of Astrix Security signals about where the market is heading.๐Ÿ‡ฟ๐Ÿ‡ฆ Theme 2: The South African Information Regulator Means BusinessThe era of POPIA being treated as a suggestion is well and truly over.โš ๏ธ The Department of Justice: R5 million fine.โš ๏ธ The Department of Basic Education: R5 million fine.โš ๏ธ WhatsApp: enforcement notice, following a three-year investigation.Proposed amendments for 2026/2027 may also remove the grace period that currently gives organisations time to remediate non-compliance before sanctions are applied. The new POPIA Health Information Regulations, binding since 6 March 2026, add a further layer of obligation for eight categories of organisations. If your company processes health data in any form, the clock is already running.๐Ÿ’ก Governance frameworks, updated IAM policies, and POPIA compliance reviews are not optional. Not nexโ€ฆ