Blog
Practical AI governance, written for the people who have to evidence it.
-
AI Governance Checklist: 12 Things Every Team Should Do Before Using AI at Work
A practical 12-point checklist for teams adopting AI — ownership, data boundaries, human oversight, testing, security and evidence, mapped to NIST, ISO 42001, the EU AI Act and OWASP.
-
EU AI Act High-Risk Deadline Moved to December 2027
The EU deferred high-risk AI Act obligations to 2 December 2027. What changed, what didn't, and a practical inventory-to-evidence plan for the runway.
-
Shadow AI: How to Find the AI Systems Nobody Put on a List
Shadow AI hides in vendor features, expired pilots, and backlog tickets. How to find ungoverned AI in the work-tracking data you already have.
-
The AI Governance Questions Boards Are Asking in 2026
Boards stopped asking for AI policies and now ask for evidence. The 8 AI governance questions directors ask in 2026 and how to answer each with data.
-
ISO 42001 vs EU AI Act vs NIST AI RMF: How They Fit Together
One is law, one is a certifiable standard, one is a voluntary framework. How ISO 42001, the EU AI Act and NIST AI RMF overlap — and where to start.
-
AI Agents Are Entering Production. Governance Isn't Keeping Up.
AI agents are shipping inside Jira and other enterprise tools. Audit logs aren't governance — how to inventory, risk-score, and assign owners to agents.