// Topics / Governance

Governance

    Compliance Fails at the Vendor Handoff You answer for an AI system you can only partly witness. Build a compliance interface to each vendor, with owners, deadlines, and drills. compliance governance ai Content Marking Is a Pipeline, Not a Policy The EU AI Act marking deadline for existing generative systems is 2 December. Provenance survives only what your pipeline keeps, so test it in CI. compliance ai architecture Your Coding Agent Inherits the Engineer A coding agent inherits every credential the engineer holds and none of the judgment behind them. Close that gap with a runtime boundary, not a ban. security ai operations The Statistic Nobody Can Reconstruct I tried to reconstruct '95% of AI pilots fail.' It isn't in the report it cites. Card the numbers that steer your decisions: licensed, expired, or retired. metrics ai executive Autonomy Without a Demotion Path Is Permission Creep Teams can describe how agents earn autonomy. Few can take it back. Write the transition contract: trigger, authority, mechanics, re-entry. ai governance reliability The EU Gave You a Reprieve, Not a Pardon The Digital Omnibus deferred the AI Act's high-risk duties, not its live ones. Build a deferral ledger: one row per system and obligation. governance compliance ai The Eval Inversion Two frontier labs lost containment this summer, in eval environments. The more adversarial the workload, the weaker the walls around it. Invert that. ai security reliability Garbage Context, Confident Answer Most AI failures are context failures wearing a model's face. Score retrieval with groundedness and margin, check freshness against live state. ai reliability architecture Geopolitical Model Risk Is an Engineering Constraint Export controls, gated releases, and open-to-closed reversals make model availability an architecture-review line item. ai architecture strategy AI Insurance Will Ask for Evidence, Not Intent As insurers exclude AI, protection tracks evidence, not intent. Your operating cadence is your audit trail. governance ai executive The Board's AI Oversight Problem Is Operational Board AI oversight is operational: a named owner per system, a rehearsed halt path, an incident threshold, and a failure rate you can defend. governance ai executive Unsupervised Producing the work can be handed to a machine. Answering for it cannot. What an organization values when machines do most of the making, what people are for, and four things to try this week. opinion ai strategy Shadow AI Is an Operating Problem, Not a Ban Banning AI tools removes your visibility, not the tools. Make the governed path the fast path and pull usage into the control plane. governance ai security Regulatory Divergence Is a Routing Problem One global AI policy is wrong in every market. Tag requests by jurisdiction, data class, and user type, then route policy like cost and capability. governance ai privacy Reliability Is the Autonomy Ceiling How much autonomy to give an AI agent: bound its failure rate with the rule of three, shadow mode, and fault injection, then price it by failure cost. ai reliability operations Sovereignty-by-Design for AI: How to Win Regulated Enterprise Deals AI data sovereignty an auditor can test: BYOK, in-region decryption, and which copies key revocation kills versus which need signed delete receipts. ai privacy governance Agentic Systems at Scale: The New Reliability Contract An AI agent reliability contract is real only where the control plane enforces it: scoped credentials, a deny-by-default tool gateway, a sandbox. ai reliability operations The AI Strategy Stack: What Boards Mistake for Moats Models and prompt scaffolding are not AI moats. The defensible layer is a correction loop on your own work, tracked by escalation rate, and it depreciates. strategy ai executive Designing the AI Leadership Bench: Roles, Interfaces, and Failure Boundaries Canon post — Scaling AI needs a leadership bench: named owners for product, platform, applied AI, and governance, with failure handoffs rehearsed before incidents. leadership teams ai How to Run an AI Incident Review That Changes Architecture, Not Slides An AI incident review is done when it changes architecture, evals, alerting, or ownership. An eight-part template that ends in fixes, owners, and dates. reliability ai governance Build the System the Model Cannot Break Canon post — A manifesto for AI-native organizations: twelve tenets across strategy, architecture, economics, and people, and the one test that matters in year two. opinion ai strategy AI Governance Without Bureaucracy AI governance that works: tighter defaults, named owners, fast escalation, and a small control stack engineers can follow at 2 a.m. No new committees. governance ai security Measuring AI Progress Without Theater: A Board Scorecard Most AI progress reporting confuses activity with value. Executive measurement should collapse around adoption, reliability, margin, and delivery speed. metrics ai executive AI Evaluation and Production Governance: A Maturity Model A five-level maturity model for AI evaluation and production governance, from vibes-based deploys to CI eval gates, production sampling, and rollback. governance ai reliability Red-Teaming Distributed Databases Before the Black Swan Most catastrophic distributed database incidents are compound failures nobody practiced. How to red-team partitions, clock skew, and operator error. distributed-systems databases reliability AI Regulation Is Here: Treat Compliance as Engineering AI regulation already shows up in procurement and security reviews. How to build compliance evidence into the delivery pipeline instead of bolting it on. compliance ai governance AI Governance That Works: Risk Tiers and System Cards AI governance that blocks delivery is broken. How to make 'yes' safe and fast instead: risk tiers, one-page system cards, and living evidence. ai governance compliance AI Safety in Production Is Defense in Depth Production AI safety works like cyber defense: assume breach, layer input, output, and system controls, and watch every boundary with real monitoring. ai governance production Enterprise AI Compliance Without the Theater Enterprise AI compliance as architecture: a data inventory, model registry, audit logging, and risk tiers that let low-risk use cases ship in days. ai compliance business Responsible AI Is Operational Risk Management Responsible AI fails as a committee and works as risk management: know the blast radius, test the failures you fear, disclose AI use, name an owner. ai security governance AI Safety Is Just Security Engineering With Extra Steps For engineers shipping LLM features, AI safety is reliability, security, and accountability. A threat model and defenses from a security background. ai governance security Technical Due Diligence: What Investors Actually Check Technical due diligence from both sides of the table: what investors check, how to prepare when you are evaluated, and what to look for when evaluating. executive governance startups