Learn

Are We Using Automated Decision making Technology (ADMT)? A 10-Question Test for California Employers

California’s ADMT requirements bind on 1 January 2027, and they reach employees and applicants, not just customers. The organizations that miss it won’t miss it for lack of a policy — they’ll miss it because they started by asking which products contain AI. A scoping test, a readiness sequence, and the evidence an assessor will ask for.

Are We Using Automated Decision making Technology (ADMT)? A 10-Question Test for California Employers Read More »

ISO 42001 certification

The question arrives from sales, not compliance. A prospect’s vendor questionnaire has a line item — “Is your organization certified to ISO/IEC 42001?” — and the deal is large enough that someone forwards it upward with a note asking how quickly we can get that. That framing is the right one, and almost nobody uses

ISO 42001 certification Read More »

What AI Governance Actually Is?(And How It Differs From the Risk You Already Manage)

Education Series · 01 AI Governance Fundamentals EU AI Act · NIST AI RMF · ISO/IEC 42001 Updated 17 Sep 2026 Foundations · AI Governance What AI governance actually is — and what it isn’t. Most organizations adopting AI have nobody formally accountable for governing it. The gap is rarely unwillingness — it is that

What AI Governance Actually Is?(And How It Differs From the Risk You Already Manage) Read More »

How to Conduct an AI Security Risk Assessment: A Practical Guide for Organizations

AI security isn’t about replacing your existing cybersecurity program. It’s about extending governance, risk management, and security practices to address the unique risks introduced by artificial intelligence. Over the past few years, nearly every conversation I’ve had with organizations about AI adoption eventually lands on the same question: how do we actually know our AI

How to Conduct an AI Security Risk Assessment: A Practical Guide for Organizations Read More »

What Can We Learn from OpenAI, Anthropic, and Google’s Approach to AI Governance?

Over the last year, I’ve noticed something interesting. Whether I’m speaking with executives, board members, cybersecurity professionals, or risk teams, the conversation eventually comes back to the same question: How do we govern AI without slowing down innovation? Everyone wants to take advantage of AI. Organizations see the opportunities. They see the productivity gains, the

What Can We Learn from OpenAI, Anthropic, and Google’s Approach to AI Governance? Read More »