From the practice
Latest Thinking
Analysis, frameworks, and advisory perspectives for organisations navigating AI regulation, enterprise AI architecture, and the governance of consequential systems.
Trends
Market signalsWhat is shifting in the market and regulatory environment right now — timely, decision-prompting perspectives for organisations tracking where enterprise AI is heading.
The AI feature your PM wants to ship, and the conformity assessment standing in the way
High-risk classifications under the EU AI Act are beginning to create friction for Indian SaaS companies selling into Europe.
Your experts know more than your systems do
The bottleneck is no longer reasoning capability. It is institutional expertise that was never formally specified.
The deprecation notice your AI programme cannot afford
The model may perform well today. The question is whether the organisation controls when it changes.
Why AI is pushing privacy architectures toward centralised trust
Distributed identity creates a compliance surface that compounds with every deployment. Architectures are converging on centralised trust boundaries.
Agentic workflows are rediscovering software engineering
As agentic systems enter production, they acquire the familiar properties of distributed systems. The mechanisms are new; the disciplines are not.
Insights
Structural analysisStructural arguments about how AI governance works — and fails. Longer, analytical pieces grounded in our advisory framework.
Why data governance can no longer be isolated from cyber resilience
Integrity controls were built to catch accidents, not adversaries. When data can be manipulated to pass every internal check, the boundary between data governance and cyber resilience becomes the gap an intrusion is designed to exploit.
What you are actually using when you use ChatGPT
ChatGPT is an application. Behind every conversation, different specialised systems handle different tasks. The distinction that controls everything that comes next.
How AI finds information
A language model can only reason over what it is given. Structured retrieval, vector search, and why governing meaning at ingestion changes what happens at query time.
How do you govern a system that is inherently probabilistic?
Three frontier models, one photograph, three completely different failure signatures. What that reveals about escalation, variance, and the assumption your existing governance framework does not account for.
The bottleneck is not your AI. It is your review process.
You deployed the AI. Throughput increased. The expected returns did not. The constraint is almost always the review process.
Hallucination is the failure you can catch. Omission is the one you can't.
A withdrawn KPMG report shows the failure mode everyone is now watching for. The one that matters more in production systems is harder to see.
Where does the AI value gap lie?
Five independent studies converge on the same order of magnitude. The pattern in what does work is narrower than most programmes admit.
Why AI breaks traditional privacy controls
Access control was designed for humans querying databases. AI workloads consume datasets. The distinction changes everything.
Why privacy costs scale with identity sprawl
Every system that holds raw identity is a separate point of trust. Privacy cost scales with identity sprawl — and AI accelerates it.
DPDP compliance does not scale if every AI initiative requires a fresh legal review
AI generates data-use requests faster than legal teams can review them individually. The Act makes that mismatch impossible to ignore.
You cannot hire your way to AI governance
The reflex is to hire for the gap. Four decades of building analytics practices suggests the constraint is rarely talent supply — it is the absence of a training framework.
Technical
Implementation detailHow the governance actually gets built — architecture-level pieces on the mechanisms, registries, and controls that make AI systems auditable.
Your AI is rediscovering your enterprise on every query
Most retrieval systems resolve the meaning of your data at runtime, on every query, with a model you do not control. A governed semantic registry fixes that.
What controls actually look like in enterprise AI
Policy documents are not controls. Four technical mechanisms that constrain what an AI system can do and verify what it actually did.
in progress