Defense Secretary Pete Hegseth took the unprecedented step of designating a U.S. firm-Anthropic-as a supply chain risk. Anthropic's crime? It refused to violate industry-wide protocols against using AI for mass surveillance or autonomous weapons. Hegseth's designation, which has until now been reserved for foreign firms, bars U.S. military contractors from doing business with the company.
Leading legal departments are shifting from reactive negotiation to proactive pricing design, setting guardrails before rates are proposed rather than responding after the fact. This approach enables departments to establish parameters and expectations upfront, fundamentally changing the negotiation dynamic and improving outcomes.
Rather than stolen data making headlines, it was business stoppage that triggered attention. Moving into 2026, the board's focus should be on ensuring business continuity and building resilience in the face of emerging risks generated by AI usage and attack vectors, quantum computing and geopolitics.
Companies are under attack publicly and privately for policies viewed as "too progressive" or "woke." The reality, however, is that most companies have strongly reaffirmed their sustainability commitments but less so their DEI commitments. Corporate social responsibility (CSR) works in the grey area between the two. Many affirming companies have opted for "greenhushing," staying quiet about their strategies and leadership.
Understanding the difference in purpose Unlike private businesses, which exist to make a profit, public institutions are designed to create impact - especially social and economic outcomes that benefit everyone, not just paying customers. A public agency doesn't measure its success in revenue or margins, but in how much it improves lives, builds equity and maintains public trust. This doesn't mean budgets and spending don't matter - they absolutely do - but money is not the goal. It's the tool.
If your partner in Munich mishandles customer data, or your reseller in Paris uses a "black box" AI tool to generate deceptive ads, it isn't just their reputation on the line. It's yours. With the EU AI Act now in full swing and GDPR entering its "mature enforcement" era, the distance between a partner's mistake and your company's $20 million fine has never been shorter.
Most company policies are written for a hypothetical, 'best-case' employee: rational, attentive, well-rested, and operating in a low-pressure environment. They assume employees will read the rules carefully, remember them, and apply them consistently at the point of purchase. As appealing as this assumption may be, it bears little resemblance to how real workplaces operate.
These changes reflect the lower structural cost base that we have signalled over recent years. Regrettably, this means a significant number of roles will no longer be required. We will support those impacted through this process. The measures are expected to generate annual cost savings of approximately £150 million.
As audit committees confront a rapidly expanding risk landscape, their role in corporate governance is being reshaped. Boards have often turned to current and former CFOs as independent directors, particularly for audit committees, because of their ability to translate complex operational and financial realities into effective oversight.For example, this month, J. Michael Hansen, former EVP and CFO of Cintas Corporation, was appointed to the audit committee at Paychex.
Running a small or medium-sized business is tough enough without getting buried in spreadsheets every month. A lot of us owners and managers end up wearing too many hats, sales, customer stuff, operations, and then accounting piles on top. Those routine financial tasks eat up hours, and honestly, one slip-up can cause big headaches like tax penalties or cash flow surprises.