Regulators and underwriters don't have to prove negligence — an empty file does it for them. See what the law expects →
Everything free. No login, no email gate.
SanctumShield publishes its learning resources in the open, refreshed monthly. Get up to speed on AI governance for free — before, alongside, or instead of a subscription.
Free Templates
Seven printable job aids, starting with a blank AI system register and the eight questions a board can ask about any AI system. No account, nothing to sign up for.
Open →AI Governance Literacy Quiz
Ten questions on the distinctions that decide whether your controls protect anything — governance vs. observability, due care vs. due diligence, and who is accountable.
Open →AI Misuse Quiz
Ten questions on Anthropic's September 2026 threat intelligence report, every answer carrying the report's own page reference. Free, no account.
Open →Playbook
The five-stage governance arc — Discover, Assess, Establish, Prove, Sustain — walked end to end.
Open →Explainer
A plain-English field guide to the core concepts: shadow AI, the four risk layers, agent governance, and the frameworks.
Open →Glossary
185 primary-source-cited terms, defined in plain English, each linked to the regulation or standard it implements.
Open →Under the Hood
The methodology and the Authoritative References behind every artifact — every regulation, standard, and threat-research source, linked to its primary source.
Open →Blog
The CISO Learning Journey — a multi-week series on governing AI, from the regulatory cliff to board-ready evidence.
Open →What's New
The changelog: monthly registry refreshes, new framework mappings, and product updates.
Open →FAQ
Straight answers to the questions buyers ask most — pricing, scope, data handling, and what SanctumShield does and doesn't do.
Open →Trust
Security, zero-retention posture, sub-processors, and full subscription terms.
Open →Have a question you want answered right now? Ask the AI Governance Coach — it answers from this same corpus in seconds, cited to the source.
The reports behind the analysis.
Published by their authors, credited to them, and linked rather than reproduced. Where we have written our own read of a source, that analysis is linked beside it so you can check our reasoning against the original.
Detecting and countering misuse of AI: September 2026
Anthropic's fourth threat intelligence report, covering activity disrupted between December 2025 and August 2026 across seven harm areas. Documents adversaries running agent swarms with persistent memory, breaches completed in two to three hours, and a distillation chapter describing AI labs relaying their own users' prompts — with names, corporate data and live credentials — through model routers common in the US and Europe. Published by Anthropic and cited here with attribution; we link rather than reproduce.