Insights
Writing
Practical governance guidance, mostly for organizations that are adopting AI considerably faster than they are governing it. Written for the person who has to make the decision, not for the conference stage.
-
Your vendor just shipped an AI feature. Is it still the same approved tool?
Software vendors are adding AI capability quickly, and it often arrives inside a platform you already approved. Thirteen questions to answer before you enable it — so you do not approve AI by accident.
-
An AI governance checklist for regulated small and mid-sized organizations
Generative AI is already inside most organizations, whether or not leadership formally approved it. Ten areas to get in order before broad adoption — without trying to stop every experiment.
Why I write about this
I established governance for enterprise AI platforms and agentic tooling at a $14B global manufacturer — acceptable-use standards, approval authority, and machine and agent identities inside access management. The problems are not exotic. They are the ordinary problems of data protection, vendor oversight, access control, incident response, and audit evidence, arriving faster than most governance functions are structured to absorb.
Smaller regulated organizations feel this most acutely, because they have the same obligations as large enterprises and a fraction of the governance capacity. That is who most of this writing is for.