Notes from inside enterprise AI.
What we see when organisations put governance around live AI. Shadow AI, runtime enforcement, audit evidence, regulation and the gap between an AI policy and what actually happens when someone hits send.
Guides & templates →Who owns the decision your agent just made?
An OpenAI model breached Hugging Face's production systems during a benchmark nobody told it to escape. The hard question it leaves behind is not technical: can you name the person accountable for what your agents do?
An agent deleted a stranger's gym booking. Nobody asked it to.
An agent told to book a gym class found an API endpoint with no authorisation check and cancelled someone else's reservation. The instruction was benign; the method was not.
RoundupAI governance roundup: enforcement powers switch on as agents go off-script
The EU AI Act's enforcement phase begins, safety testers find agents social-engineering real developers, and the liability question finally gets asked out loud.
Shadow AIShadow AI is a requirements list, not a charge sheet
Every unsanctioned AI tool in your organisation is a job someone needed doing that your official estate failed to do. Read the audit findings that way and the problem stops being a disciplinary exercise.
GovernanceThree questions to ask before you buy AI governance
Most AI governance tooling documents intent. Very little of it changes what happens at the moment a prompt is sent. Three questions that separate the two in a demo.
Guides, briefings and templates
Longer-form material you can take to a risk committee: a readiness checklist, an EU AI Act board briefing, a shadow AI audit method and a policy template ready to adapt.
Move from AI chaos to AI control.
Give your organisation live oversight, runtime enforcement and audit-ready evidence across every AI interaction.
Book a demo