article
Compliance can make systems less safe
When passing the audit becomes the objective, teams optimise evidence while operational risk moves elsewhere.
Emil Shirokikh · Published September 2, 2026 · Updated September 23, 2026 · 2 min read

Abstract
Controls written for general comparability may not match a specific threat model. Checkbox compliance can consume attention that should go to exposed paths and recovery.
Map controls to threats
Audit evidence can become the goal while unmodeled attack paths remain. A framework is a useful floor, not a complete threat model.
Control review
For each required control, name the threat and evidence. Record uncovered threats, compensating controls, control failures and operational tests outside the framework.
Acceptance evidence
Review whether evidence generation consumes attention without reducing exposure.
Challenge the conclusion
External standards create valuable discipline and common language. They remain a floor, not a complete security strategy.
Use this in a working session
Pick the most expensive control and ask which plausible attack it changes, how failure is detected and what residual risk remains.
BELTO editorial analysis. It does not describe a client engagement or claim a commercial result.
References
2 sourcesAuthor
Emil ShirokikhFounder
Founder of Belto Inc. Writes on engineering, venture building and applied intelligence.
Related
Read next
Most AI pilots should be killed sooner
The polite fiction around enterprise AI is that every pilot teaches something. Many teach only that nobody defined the decision, owner or failure cost.
AI agents need boundaries, not personalities
The market is decorating automation with human traits while neglecting permissions, reversibility and evidence.
A computer-vision demo is not a system
Benchmark accuracy says little about glare, drift, maintenance, latency or the operator who must act on an alert.