From the practice

Latest Thinking

Analysis, frameworks, and advisory perspectives for organisations navigating AI regulation, enterprise AI architecture, and the governance of consequential systems.

Insights

Structural analysis

Structural arguments about how AI governance works — and fails. Longer, analytical pieces grounded in our advisory framework.

Insight
Data governance · Cyber resilience · RBI

Why data governance can no longer be isolated from cyber resilience

Integrity controls were built to catch accidents, not adversaries. When data can be manipulated to pass every internal check, the boundary between data governance and cyber resilience becomes the gap an intrusion is designed to exploit.

July 2026 · 6 min read
Primer · Part 1 of 3
AI Architecture · Enterprise AI · Governance

What you are actually using when you use ChatGPT

ChatGPT is an application. Behind every conversation, different specialised systems handle different tasks. The distinction that controls everything that comes next.

July 2026 · 12 min read
Primer · Part 2 of 3
AI Architecture · Enterprise AI · Governance

How AI finds information

A language model can only reason over what it is given. Structured retrieval, vector search, and why governing meaning at ingestion changes what happens at query time.

July 2026 · 13 min read
Primer · Part 3 of 3
AI Architecture · Enterprise AI · Governance

How do you govern a system that is inherently probabilistic?

Three frontier models, one photograph, three completely different failure signatures. What that reveals about escalation, variance, and the assumption your existing governance framework does not account for.

July 2026 · 14 min read
Insight
AI Operations · Scale

The bottleneck is not your AI. It is your review process.

You deployed the AI. Throughput increased. The expected returns did not. The constraint is almost always the review process.

June 2026 · 9 min read
Insight
AI Governance · Source verification

Hallucination is the failure you can catch. Omission is the one you can't.

A withdrawn KPMG report shows the failure mode everyone is now watching for. The one that matters more in production systems is harder to see.

June 2026 · 7 min read
Insight
Enterprise AI · ROI · Deployment

Where does the AI value gap lie?

Five independent studies converge on the same order of magnitude. The pattern in what does work is narrower than most programmes admit.

June 2026 · 8 min read
Insight
Data privacy · AI architecture

Why AI breaks traditional privacy controls

Access control was designed for humans querying databases. AI workloads consume datasets. The distinction changes everything.

May 2026 · 4 min read
Insight
Data privacy · Compliance

Why privacy costs scale with identity sprawl

Every system that holds raw identity is a separate point of trust. Privacy cost scales with identity sprawl — and AI accelerates it.

May 2026 · 4 min read
Insight
DPDP · Legal operations

DPDP compliance does not scale if every AI initiative requires a fresh legal review

AI generates data-use requests faster than legal teams can review them individually. The Act makes that mismatch impossible to ignore.

May 2026 · 10 min read
Insight
Capability · Training

You cannot hire your way to AI governance

The reflex is to hire for the gap. Four decades of building analytics practices suggests the constraint is rarely talent supply — it is the absence of a training framework.

June 2026 · 7 min read

Technical

Implementation detail

How the governance actually gets built — architecture-level pieces on the mechanisms, registries, and controls that make AI systems auditable.

Technical
Enterprise AI · Semantic architecture

Your AI is rediscovering your enterprise on every query

Most retrieval systems resolve the meaning of your data at runtime, on every query, with a model you do not control. A governed semantic registry fixes that.

May 2026 · 7 min read
Technical
AI Governance · Architecture · Controls

What controls actually look like in enterprise AI

Policy documents are not controls. Four technical mechanisms that constrain what an AI system can do and verify what it actually did.

May 2026 · 11 min read
More technical writing
in progress