Skip to content
Article

Your peers aren't blocked on budget

By DoGood Team · August 19, 2026

Member Signal

The Member Signal is DoGood’s weekly peer-intelligence briefing for the member network. This issue went to members on August 19, 2026, and appears here lightly edited for the web.

The Signal

Twenty-one member companies told us this month what is standing between them and a decision. Three of them said money.

Eighteen said a version of the same thing: the scope is not defined yet, or they are still working out which options are even in play. Four named internal alignment. That distribution holds across every category the network is working in right now, from AI governance to third-party risk to software licensing, which is what makes it worth your attention. It is not a security problem or a data problem. It is the same problem showing up inside all of them.

The members who reached an active evaluation this month were almost all the decision-maker on the project, and most had a budget band in hand. So the authority is there and the money is there. What is missing is the written requirement, and that is the one part of the process no vendor can produce for you. A first meeting is a bad place to discover your requirements. It is a very good place to test them.

From the Network

“Help us define scope and project for enterprise content management.”

Chief Information Officer, Manufacturing

“Data is key for AI to be successful. We have a lot of data but unsure if it is useful for AI.”

Vice President, Information Technology, Transportation

“We need to be able to proactively patch systems more regularly to meet our SoC2 requirements.”

Manager of Information Security, Legal Services

Three members, three categories. The first two are describing a situation. The third is describing a requirement with the reason it exists attached to it. Only the third can be answered in a first meeting, and the distance between them is a page of writing, not a year of maturity.

Top Open Priorities This Week

Ten member companies filed nineteen initiatives in August, across eight industries. Seventeen of the nineteen are marked high priority or critical, and sixteen are scheduled to start inside six months. Ten carry a budget band. The other nine say the number is still being worked out.

“I’m evaluating solutions to secure our GenAI roadmap with a focus on governance, prompt defense, and data privacy with adherence against NIST CSF 2.0. LLM usage and agentic AI are the primary areas of concern. I need one or more solutions that provide full visibility into how AI is being used across the enterprise.”

Chief Information Security Officer, Mining · critical path, next three months, budget still open

“We aim to establish a unified ML/AI Platform that enables secure, compliant, and scalable development of machine-learning solutions across the bank. This initiative will streamline model lifecycle management, centralize data access under strong governance, and accelerate deployment of AI capabilities for fraud detection, risk scoring, customer insights, and operational automation.”

Senior Director, IT & Analytics, Financial Services · high priority, three to six months, budget set

Both of these are AI projects sitting at opposite ends of the same gap. The first has the requirement written in detail and the number still open. The second has the number settled and the requirement still at the level of intent. Whichever half you have already finished, the peer who has not finished it will take your call.

Just Opened to the Network

Two partners are open to members and very few of you have met them yet, which cuts both ways: less peer intelligence available to you, and far more influence for you over what they build next.

Reclaim Security works on the gap between finding an exposure and actually fixing it, planning and executing remediations across tooling you already own. Their question to members: do you have an active or planned initiative in the next six months to reduce your backlog of unremediated security findings by automating fixes across your existing stack? Two of the initiatives filed with us this month are exactly that.

See their profile →

Sprocket Security runs penetration testing as a continuous and partly autonomous exercise rather than a periodic engagement. Their question is narrower and easier to answer: do you have a penetration testing project considering external vendors planned in the next six months? Two member companies filed one in August alone.

See their profile →

Both links open in your portal, so sign in first if you are not already.

Member Spotlight: Michael Dawisha, Genesee County, Michigan

This week’s Signal is about the requirement nobody has written down yet, and one member has a discipline for exactly that moment. Michael Dawisha is CIO of Genesee County, Michigan, where he is working to run fiber to every address in the county. The lesson he still runs on arrived when a boss told him to be humble, after he showed up with a list of everything that needed fixing, and he put it plainly in his DoGood spotlight, “Are you the first person you think thought of that? Really? And everybody thinks they are.”

His rule is to find out why things are the way they are, who already tried, and what it cost them, before prescribing the fix. That is most of what a written requirement actually contains.

Read his full story →

Deep Dive: AI Security & Governance

Fifty-one member submissions over the last ninety days touched AI security or AI governance, from thirty-eight companies across thirteen industries. That is the largest cluster of member activity in the network right now, and the pattern running through it is that members are trying to govern something they cannot yet see.

Where activity is concentrated

  • Agents and autonomous systems — 21 companies. The largest cluster by a wide margin, and the newest. These members are not asking whether to deploy agents. They already have, and they are asking who governs the access, the identity and the compute bill. A pharmaceuticals infrastructure leader wants agents reading across manufacturing and research data. A software engineering director is shopping AI platforms for agentic use cases in the customer experience layer. A business services CISO wants guardrails around agentic actions.
  • Governance that cannot be enforced — 11 companies. These members are working on AI policy and risk frameworks, and the complaint that keeps recurring inside the group is not that the rules are missing. It is that the rules exist and nothing makes them bind: no visibility, and usage spreading faster than the review process.
  • Knowing what is actually running — 10 companies. The literal question is how many AI tools, agents and MCP integrations are touching company data. An insurance security leader is evaluating tooling to inventory them. A manufacturing CIO has no insight into unapproved tools at all. A healthcare security leader whose next fiscal year opens in the autumn already has the budget earmarked and is shopping now.

What your peers are buying

  • Vertesia — eleven member companies in thirty days, the most-met vendor in the network over the period, mostly on getting unstructured content into a shape agents can actually use. One manufacturing CIO booked it with the words “help us define scope.”
  • Pluto Security — four member companies inside its first eight days open, on discovery and governance of AI tools, agents and MCP integrations. A healthcare IT director put the problem plainly: clinicians and analysts are already building agents, regulated data is moving through tools that never went through approval, and blocking does not solve it.
  • Conceal — eight member companies in thirty days, sixteen over ninety, on browser-level control, with shadow AI named alongside VPN replacement as the reason.
  • Nanonets — eleven member companies over ninety days, on automating high-volume document workflows against existing ERP and finance systems.

What is still open

An actual inventory of agents and MCP integrations. Ten companies raised it in ninety days and the first meetings are happening, but no shortlist has formed, which means references are thin and you will be evaluating without a crowd to check yourself against. The second gap is enforcement. Eleven companies are working on AI governance, and the vendors they are meeting can see and report; almost nothing they are meeting makes a policy bind at the moment of use.

What it means for your stack

Build your own AI inventory before you evaluate a governance platform, even a rough one assembled from expense reports and SSO logs. Every member in this data who could not say how many agents were running ended up evaluating against the vendor’s definition of the problem, which is reliably the definition that matches the product.

The Context

The EU AI Act’s obligations for high-risk AI systems were supposed to apply from August 2. They do not. Parliament endorsed the Digital Omnibus on June 16 and the Council approved it on June 29, moving standalone high-risk obligations to December 2, 2027 and AI embedded in regulated products to August 2, 2028. The Article 50 transparency rules did start on schedule. The reason given for the deferral was not a change of policy. It was that the harmonised standards and the national authorities were not ready.

The headlines are catching up to what the network already knew. Thirty-eight member companies have spent ninety days trying to write an AI governance requirement without a settled definition of what good looks like, and Europe has now conceded the same point in law.

Bottom Line: The deadline that was going to write your requirements for you has moved out by sixteen months, so a vendor selling you compliance readiness this year is selling readiness for a standard nobody has published. Ask each one what changes in the product on the day it is.

What to Do About It

Take the one project you would call critical this quarter and write its requirement on a single page: what you run today, what has to be true when it is finished, and who signs. Send it to the next vendor before the meeting rather than after. Eighteen of the twenty-one companies that told us what was in their way this month are stuck on exactly that page.

Build pipeline you can actually follow up on.