Where AI systems create governance and engineering exposure, and what controls are proportionate to the risk.
94 articles, most recent first within each group.
European Union
- Autonomy Tiers in Code: Enforcing an Agent Approval Matrix
- Building an Agent Kill-Switch: Circuit Breakers, Feature Flags and Drain Modes
- Post-Market Monitoring for High-Risk AI: The Plan, the Signals and the Feedback Loop
- Replaying an Agent Run: Event-Sourced Traces for Audit and Reproduction
- Data Governance Under AI Act Article 10: Training-Set Lineage, Bias Testing and Representativeness
- Accuracy, Robustness and Cybersecurity: The AI Act Article 15 Test Battery You Have to Evidence
- Colorado's AI Reset: What the ADMTA Replacement Means for Your 2027 Build
- Building an ISO 42001 AI Management System With Controls Expressed as Code
- CCPA ADMT Rules: What the January 2027 Automated-Decision Duties Require You to Build
- The AI System Inventory Schema That Maps to the AI Act Risk Tiers
- The AI Act's Obligations, Translated Into Actual Engineering Deliverables
- Agentic AI in Regulated Finance: Why Governance Keeps Most Firms on Deterministic Rails
- From Voluntary Code to Enforcement: How the GPAI Code of Practice Shapes Expectations
- Training-Data Transparency: What the GPAI Public Summary Template Requires
- AI Incident Disclosure: Building the Muscle Before the Regulation Demands It
- The 10^25 FLOP Threshold: How 'Systemic Risk' Gets Defined for AI Models
- The AI Controls Matrix: 243 Control Objectives Across 18 Domains
- AI System Inventories: The Foundation Most Governance Programmes Skip
- Model Lifecycle and 'Placed on the Market': When Fine-Tuning Makes You a Provider
- NIST's Agentic AI Profile Isn't Published Yet — What to Build Against in the Meantime
- The RAG Problem Nobody's Debugging: Retrieval Quality Starts With Classification
- Confidentiality Risk When LLMs Touch Privileged Material
- Autonomous Response: Governing the Kill Switch
- Agent Observability, Auditability and Reversibility
- From Copilots to Autonomous Agents: What Actually Changed
- Multi-Agent Systems and Agent-to-Agent Orchestration
- Deepfakes, Voice Cloning and Social Engineering at Scale
- AI Red-Teaming as a Standing Function
- OneTrust for AI Act + GDPR: One Platform, Two Regimes
- AI Incident Response and Serious-Incident Reporting Duties
- Prompt Injection and Jailbreaks as Board-Level Risk
- Security of the AI Supply Chain: Models, Weights, Training Data
- GDPR Enforcement Patterns and Cross-Border AI Data Flows
- Data Quality Is the Real AI ROI Blocker
- Bounded Autonomy: Defining What an Agent Can Decide
- Governing AI Agents: A Board and Tech-Function Reading
- Non-Human and Agent Identity: The 2026 IAM Gap
- ISO/IEC 42001: What Your Function Must Demonstrate
- AI Act × GDPR: The Dual-Obligation Trap
- Model Risk Management, Extended Beyond the Trading Desk
- Agentic Ransomware: What the First Autonomous Attacks Mean
- Shadow AI: A Governance Reading
- AI Due Diligence: The Diligence Workstream Nobody Ran Last Cycle
- The EU AI Act Digital Omnibus: What Changed, and What Your Technology Function Must Still Do Before 2 August 2026
- SDAIA AI Ethics Principles: A Technical Implementation Reading
- EU AI Act Article 9 Risk Management Systems: A Technology Function's Reading
- Your staff are already using AI. Now what?
- The AI policy every business should have before the regulator asks for it
- Who owns the output from your AI systems?
- AI tools, client data, and the GDPR question nobody is asking yet
- The EU AI Act deadlines just changed: what now applies, and when
AI Governance
- NIST AI RMF as Your US Anchor Framework: Turning the Four Functions Into Deliverables
- PRA SS1/23 Model Risk Management, Applied to AI and Machine-Learning Models
- AI Serious-Incident Reporting Pipeline: Engineering for the AI Act's 15-Day Clock
- Chargeback for AI: Token Budgets and Cost Allocation per Business Unit
- AI Model Risk Is Operational Risk: Extend Your ORM Framework, Don't Rebuild It
- Agent = Model + Harness: The Board's Mental Model for Agentic AI
- Delegation-Chain Accountability: Who Is Responsible When Agents Call Agents?
- AI Governance for Organisations With No AI Team
AI Agents
- Deterministic Automation vs Agentic Autonomy: Choosing the Right Level of Non-Determinism
- AI-Accelerated Shadow IT: When Non-Coders Build Ungoverned Agentic Workflows
- Agentic Systems: The Failure Modes Nobody Plans For
- Governing Permission-Hungry Agents: The Central Tension of Enterprise AI
- Small Language Models in the Enterprise: When Smaller Beats Frontier
- Technology Due Diligence in the Agent Era: New Questions for the Data Room
- Autonomy Tiers: A Classification Scheme for AI Agents Your Board Can Sign Off
- Evaluation Before Deployment: How to Know If the Model Is Working
- Hallucination as a Design Constraint, Not a Bug
- MCP Is the USB-C of AI: Why the N×M Integration Problem Just Collapsed
- The OWASP Top 10 for Agentic Applications: Why Autonomy Needs Its Own List
- The OWASP Top 10 for LLM Applications: A Board-Level Reading
- The Tasks LLMs Are Genuinely Good At (And the Ones They Aren't)
- Consolidating Point Security Tools Into a Platform Under Agent Load
- Agentic Commerce: What Happens When Agents Become Buyers
- Tool Poisoning and Prompt Injection in MCP: The New Attack Surface
Model Risk
- Constrained Decoding and Structured Outputs: Killing Malformed Tool Calls
- Board Reporting on AI: Turning Framework Alignment Into Evidence of Control
- Model Provenance: Third-Party AI Model Risk as a Board-Level Control
- Runtime Governance vs Framework Alignment: Why NIST AI RMF Isn't Enough Alone
- Context Engineering: Treating the Context Window as a Design Surface
Budgeting & Cost Control
- AI as Amplifier: Why It Makes Good Engineering Orgs Better and Bad Ones Worse
- Private and On-Prem Sovereign AI: Running Models Without Surrendering Jurisdiction
- The Fractional CTO's AI Adoption Playbook: Four Strategies
- Cognitive Debt: The New Technical Debt Boards Need to Track
- The AI Proof-of-Concept Graveyard: Why Pilots Never Reach Production
- Where AI Actually Fits in a Business Process (And Where It Doesn't)
- When to Fine-Tune and When You're Just Avoiding Better Retrieval
More in this area
- Data Classification Is a Prerequisite for AI Adoption, Not a Parallel Workstream
- Model-Agnostic Architecture: Abstracting the AI Provider
- One Control Environment, Many Frameworks: Crosswalking AI RMF, ISO 42001 and CSF
- The AI Productivity Paradox: Individuals Speed Up, the System Slows Down
- Legal Sector RAG: Role-Based Contextual Isolation for Privileged Data
- AI-Ready Data Management: Why Feature and Retrieval Systems Lean on Iceberg
- Why Coding Throughput Is a Dangerous Productivity Metric