Articles
Trace the shared dependency behind every AI fallback
Put a decision gate on live AI testing
Shared responsibility starts at the AI service boundary
An AI log you cannot retrieve is not an audit trail
An AI-drafted control profile describes your documents, not your controls
Confirmation is not a mitigation. It is the classification.
The ICO's agentic AI timetable moved. The design work remains.
The first AI Act standard is published. Presumption of conformity is not.
What the EU AI Act actually asks of a retrieval system
Not every AI system needs the same governance
Someone else's capital cycle is your renewal risk
Who is the provider? The question that decides your obligations
Two governance blocs, one supplier list
The ICO code of practice arrives as a duty, not a suggestion
Reporting a serious AI incident starts long before the incident
Five decisions, not two: how an assessment should end
NIST is writing the questionnaire. Read it before it arrives.
ISO/IEC 42001 is a management system, not a badge
Shadow AI is a measurement problem before it is a policy problem
The deepfake did not defeat a control. It satisfied one.
Your assistant speaks for you, and a tribunal has already said so
Next step