Start a conversation Contact
← Research

Research · page 04 of 06

Further back in the archive.

Articles

06 Aug 2026 The ICO code of practice arrives as a duty, not a suggestion A statutory code carries weight that guidance does not — a regulator must take it into account and a court may. The instrument requiring one on AI and automated decision-making is already in force, and the position it will encode is already published. Governance 05 Aug 2026 Reporting a serious AI incident starts long before the incident The AI Act's incident duty runs on a clock measured in days, and an organisation that begins assembling the facts when the clock starts will not meet it. What makes the deadline achievable is decided at design time. Governance 04 Aug 2026 Sovereign inference is a control question, not a map question European buyers have started asking where inference runs and receiving an answer about which region a service is deployed in. Those are different questions, and the gap between them is where most residency commitments quietly fail. Architecture 28 Jul 2026 Five decisions, not two: how an assessment should end An assessment whose only possible conclusions are "approved" and "not approved" is not an assessment. It is an approval process with a report attached, and everyone in the room knows which answer is expected. Governance 28 Jul 2026 NIST is writing the questionnaire. Read it before it arrives. The control overlays NIST is developing for AI systems will become the shape of enterprise security due diligence, because they map onto controls large buyers already run. Their drafts are public, and the categories they use are the useful part now. Governance 23 Jul 2026 The questions to ask an AI supplier before you sign Most AI supplier due diligence asks about security and certification and stops. The questions that decide whether a system can be operated, evidenced and left are commercial ones, and they are cheap to ask before a contract and impossible afterwards. Method 23 Jul 2026 Your data records a process, not the world Historical enterprise data is a record of what an organisation decided, who it decided about, and what it happened to write down. A model trained on it learns the process — including the parts nobody would defend if they were written as a rule. Data 21 Jul 2026 Agents need identities, not API keys The fastest way to get an agent working is to give it a service account with broad access. That decision is made in an afternoon, is almost never revisited, and turns every later security question into one that has no good answer. Architecture 21 Jul 2026 Retrieval is an access-control problem wearing a search interface The most common serious failure in enterprise retrieval systems is not a wrong answer. It is a correct answer, assembled from a document the person asking was never entitled to read, and no quality metric will ever detect it. Data 16 Jul 2026 Every tool description is executable text Connecting an agent to a tool server hands a third party a piece of writing that your model will read as instructions. That is not a configuration file. It is code with a supply chain, and almost nobody is reviewing it as one. Architecture 16 Jul 2026 Re-embedding is a migration, and nobody plans it Changing the embedding model invalidates every vector in the index, and the index is usually the only copy of how documents were chunked. It is treated as a configuration change, and it is closer to a database migration with no rollback. Data 14 Jul 2026 Energy has become an architectural constraint, not a sustainability line The limit on AI infrastructure has moved from capital to power delivery, and that changes where inference can be placed, what it costs and how quickly capacity can be added. It belongs in the design review, not the annual report. Architecture

Bring us the question

Something here already on your desk?

That is the conversation we are best at. Thirty minutes, a written summary, no obligation.