Already in force

Regulators and underwriters don't have to prove negligence — an empty file does it for them. See what the law expects →

Resources · Open & free

Everything free. No login, no email gate.

SanctumShield publishes its learning resources in the open, refreshed monthly. Get up to speed on AI governance for free — before, alongside, or instead of a subscription.

Fill this in

Free Templates

Seven printable job aids, starting with a blank AI system register and the eight questions a board can ask about any AI system. No account, nothing to sign up for.

Open →
Test yourself

AI Governance Literacy Quiz

Ten questions on the distinctions that decide whether your controls protect anything — governance vs. observability, due care vs. due diligence, and who is accountable.

Open →
Test yourself

AI Misuse Quiz

Ten questions on Anthropic's September 2026 threat intelligence report, every answer carrying the report's own page reference. Free, no account.

Open →
How to

Playbook

The five-stage governance arc — Discover, Assess, Establish, Prove, Sustain — walked end to end.

Open →
Field guide

Explainer

A plain-English field guide to the core concepts: shadow AI, the four risk layers, agent governance, and the frameworks.

Open →
Reference

Glossary

185 primary-source-cited terms, defined in plain English, each linked to the regulation or standard it implements.

Open →
Methodology

Under the Hood

The methodology and the Authoritative References behind every artifact — every regulation, standard, and threat-research source, linked to its primary source.

Open →
Series

Blog

The CISO Learning Journey — a multi-week series on governing AI, from the regulatory cliff to board-ready evidence.

Open →
Changelog

What's New

The changelog: monthly registry refreshes, new framework mappings, and product updates.

Open →
Answers

FAQ

Straight answers to the questions buyers ask most — pricing, scope, data handling, and what SanctumShield does and doesn't do.

Open →
Security

Trust

Security, zero-retention posture, sub-processors, and full subscription terms.

Open →

Have a question you want answered right now? Ask the AI Governance Coach — it answers from this same corpus in seconds, cited to the source.

§ Primary sources we cite

The reports behind the analysis.

Published by their authors, credited to them, and linked rather than reproduced. Where we have written our own read of a source, that analysis is linked beside it so you can check our reasoning against the original.

Anthropic

Detecting and countering misuse of AI: September 2026

Published September 10, 2026 · 154 pages

Anthropic's fourth threat intelligence report, covering activity disrupted between December 2025 and August 2026 across seven harm areas. Documents adversaries running agent swarms with persistent memory, breaches completed in two to three hours, and a distillation chapter describing AI labs relaying their own users' prompts — with names, corporate data and live credentials — through model routers common in the US and Europe. Published by Anthropic and cited here with attribution; we link rather than reproduce.

Resources — Free AI-Governance Learning, No Email Gate