Insights

Practical perspectives on AI governance, modern delivery, and building technology organizations that actually work.

LatestGenAI Governance

The AI Control That Makes Every Other Control Possible

Regulators spent fifteen years teaching banks to keep a model inventory — then carved generative AI out of it. Every oversight, access, and incident control assumes a complete list, and most enterprise lists are incomplete by design.

August 5, 2026 · 5 min read
Strategy5 min read

Governance Debt Comes Due in the Data Room

Speed is the right call before product-market fit. But the shortcuts that get a model shipped — undocumented training data, no model inventory, no approval trail — are borrowed against a buyer's diligence list, and the interest is priced into your valuation.

August 5, 2026Read
GenAI Governance5 min read

The Engagement Letter Is Where Third-Party AI Gets Settled

Bar regulators have written the consent expectation down, tax law got there decades ago, and most clients still have no idea what their firms are running. The engagement letter is where that ambiguity ends — one way or the other.

August 5, 2026Read
GenAI Governance5 min read

The Smallest AI Policy That Actually Works

Six in ten workplaces have no rule on generative AI, and employees have quietly filled the vacuum themselves — concealing usage, skipping verification, pasting client data into free tools. The answer is not a forty-page framework; it is one page and five decisions.

August 5, 2026Read
GenAI Governance5 min read

August 2 Still Matters: The EU AI Act Deadline That Didn't Move

Brussels bought companies seventeen extra months on the AI Act's hardest requirements. It did not touch the rule most businesses will feel first: Article 50's transparency duties still bind on August 2, with the same fines attached.

July 24, 2026Read
GenAI Governance2 min read

Why Most GenAI Governance Programs Stall

Generative-AI governance programs rarely stall for technical reasons. They stall because nobody owns approvals, controls arrive without enablement, and adoption is assumed rather than designed — three organizational failures that recur with remarkable consistency across enterprise deployments.

February 6, 2026Read
Security3 min read

The CISO's Guide to AI Risk

AI risk lives in four domains — model, data, supply chain, and operations — and no security team can address all of them at once. The discipline is in scoring each use case and letting resources follow the gradient.

February 5, 2026Read
Strategy2 min read

From Compliance Checkbox to Competitive Advantage

Most organizations treat compliance spending as a tax to be minimized. The ones that outperform ask a different first question — and turn the same audits, controls, and training into market access, enterprise deals, and better insurance terms.

February 4, 2026Read

Working through a governance question like this one?

Talk to the practice