Category: AI Governance

  • August 2026 Is Not the Deadline

    August 2026 Is Not the Deadline

    The EU AI Act entered into force on 1st August 2024. Prohibited practices and the AI literacy duty applied from 2nd February 2025. The first rules for general-purpose AI models began applying from 2nd August 2025, with transitional arrangements for models already on the market. Most of the Act becomes applicable on 2nd August 2026,…

  • Things Made Too Dangerous to Release

    Things Made Too Dangerous to Release

    Every significant capability governance failure of the last fifty years follows the same shape. Someone drew a boundary around an approved use case. The capability moved outside it. Nobody had asked what happens when it does. That pattern predates AI by decades. It shows up in molecular biology, network infrastructure, industrial control systems, and weapons…

  • AI-Generated Evidence Is Only Caught By Accident

    AI-Generated Evidence Is Only Caught By Accident

    A Derbyshire Police case, and the reconstruction test most organisations have never run A Derbyshire Police officer is under criminal investigation for allegedly using AI to create evidential material in a number of cases. The Crown Prosecution Service is now working with the force to review which cases may be affected. No arrests. The officer…

  • Three AI Certifications, Three Governance Problems

    Three AI Certifications, Three Governance Problems

    Last year I spent a week talking to C-suite members individually as part of a wider governance assessment. The company was already using AI in several places. Some of it sanctioned. Some of it not. A couple of tools had been quietly adopted by teams who never thought to ask permission because they did not…

  • Classifying AI Risk Before You Deploy It

    Classifying AI Risk Before You Deploy It

    I was doing a review for a client in the entertainment sector recently. Not a cyber incident. A broader governance piece. During the review we found tools already embedded in their outreach operation. Approved software. Budget already signed off. Users already dependent on it. One of them was segmenting audiences. Deciding, in effect, who got…

  • The Quiet Risk Behind the AI Rush

    The Quiet Risk Behind the AI Rush

    We’ll Pick That Up in the Next Release Mid-career. An operational system going live. “We’ll pick that up in the next release.” The controls weren’t forgotten. They were scheduled. That’s a different problem. Forgotten means oversight. Scheduled means someone looked at the risk, decided the timeline mattered more, and moved on. The downside still felt…