Writing

When there is something worth saying.

I write from the work, not on a schedule: what a readiness assessment actually finds, what a security questionnaire actually tests, where the frameworks agree and where they only appear to, and what the regulations coming into force actually require of a company your size.

If a claim cannot be verified, it does not go in. If a piece turns out wrong, a correction lands on the original, date-stamped.

First pieces, landing this fall

The security questionnaire is the real AI regulator

Most companies meet AI regulation first as a customer's procurement checklist, not as a law. What the AI sections actually ask, and what a credible answer looks like.

Forthcoming

ISO 42001 in plain terms

Thirty-eight controls, nine domains, and what each one means for a company that has never run a management system. Where certification is worth it and where alignment is enough.

Forthcoming

What December 2027 actually requires

The EU AI Act's high-risk obligations, separated from the panic around them: who is actually in scope, what evidence is actually due, and a sane timeline for getting there.

Forthcoming
Topics: AI governanceprivacyISO 42001EU AI Actoperating