AI Governance & Ethics Insights
Stay ahead of the curve with our expert analysis on AI governance, ethics, and compliance.
Regulation
Navigating the EU AI Act: A Guide for UK Businesses
Understand the implications of the EU AI Act for your UK-based operations and how to prepare for cross-border compliance.
Framework
Implementing the NIST AI Risk Management Framework
A practical walkthrough of the NIST AI RMF, from mapping and measuring to managing AI risks across the lifecycle.
Standard
The Ultimate Guide to ISO/IEC 42001 Certification
Everything you need to know about the new standard for AI management systems, and how to achieve certification.
Ethics
The Ethical Imperative of AI in HR and Recruitment
Bias in AI-powered hiring tools is a major risk. Learn how to implement fairness controls, oversight, and documentation to ensure equitable outcomes.
How-To Guide
How to Build a Model Card for Transparency
Model cards are essential for AI transparency. This guide provides a step-by-step template for documenting your models' performance, limitations, and ethical considerations.
Governance
Shadow AI in the Enterprise: Finding the Tools Nobody Approved
Unapproved AI tools rarely arrive through procurement. A practical method for discovering shadow AI, mapping it to UK GDPR and EU AI Act duties, and bringing it under control.
Governance
AI Agent Audit Trails: What to Log, and Why It Is No Longer Optional
AI agents act, not just answer. A practical guide to the records UK and EU organisations need to reconstruct, defend and explain what an autonomous agent actually did.
Governance
AI in Criminal Evidence Review: The Safeguards That Must Come First
How AI used to triage or interpret evidence changes the control set — EU AI Act classification, UK disclosure and expert-evidence duties, and the reproducibility record a court will expect.
Security
Securing AI Agents: Six Controls Drawn From NIST
A practical guide to securing autonomous AI agents using six control areas grounded in NIST's AI RMF and SP 800-53, mapped to UK GDPR and EU AI Act duties.
Regulation
AI Transparency Obligations: What Providers and Deployers Actually Have to Disclose
A practical guide to AI transparency duties for UK and EU organisations: who counts as a provider or deployer, what must be disclosed, how to mark synthetic content, and where to start.
Regulation
US AI Regulation: What UK and EU Compliance Teams Must Actually Do
The US has no single AI statute, but its patchwork of state laws and sector regulators still lands on UK and EU compliance teams through vendors, group operations and procurement. Here is what to do.
Framework
NIST AI RMF 1.0: A Practical Audit-Readiness Blueprint
How UK and EU compliance teams turn the NIST AI Risk Management Framework's four functions into evidence that survives a customer assessment or a regulator's questions.
Regulation
The EU AI Act in Practice: Scope, Risk Tiers and What UK Organisations Must Do
A practical guide to the EU AI Act for UK and EU compliance leads: what triggers extraterritorial scope, how the risk tiers work, provider versus deployer duties, and the first steps to take.
Regulation
US State AI Laws: What UK and EU Compliance Teams Must Do
American AI rules are arriving through state legislatures and federal enforcement, not one statute. A practical guide to when UK and EU organisations are caught, and what to build.
Governance
GPT-Red: Governing AI That Changes Itself
Self-improving models break the assumption behind every AI register entry and DPIA: that the system you assessed is the system running today. A practical change-control approach for compliance teams.
Security
The Security Risks of Large Language Models
The real exposure from large language models sits in the plumbing around them. Practical controls, evidence and first steps for UK and EU compliance and risk teams.
Governance
The Role of a Chief AI Officer
No law requires a Chief AI Officer, but the EU AI Act creates accountabilities that must land on someone. What the role actually owns, who should not hold it, and where to start.
Regulation
Claiming the Article 6(3) Exemption and Documenting the Case
Article 6(3) lets an Annex III system escape the high-risk regime, but only on a two-part test, only for the provider, and only with a written assessment and an EU database registration behind it. A practical guide to making the claim defensibly.
Regulation
Article 10 Data Governance and Proving a Training Set Fits
Article 10 of the EU AI Act requires the training, validation and testing data behind a high-risk AI system to be governed, documented and shown to fit the intended purpose. This guide sets out what the duty actually says, why it lands on the provider rather than the deployer, how a deployer can inherit it by fine-tuning or rebranding, what evidence an assessor expects to see, and where the standards are still unfinished.
Regulation
Declaring Accuracy and Robustness Metrics Under Article 15
Article 15 of the EU AI Act requires high-risk systems to reach an appropriate level of accuracy, robustness and cybersecurity and to declare their accuracy levels and metrics in the instructions for use. This guide sets out who owes that duty, what a defensible declaration contains, how a deployer can inherit it by rebadging or modifying a system, and what to check before you rely on a supplier's headline accuracy figure.
Regulation
Article 12 Logging and How Long You Must Keep the Records
What the EU AI Act's automatic logging requirement means in practice: the provider's duty to build logging capability, the six-month retention floor that binds both providers and deployers, the "under their control" trap in SaaS deployments, and how log retention collides with data protection law.
Regulation
The Article 4 AI Literacy Duty and the Evidence Behind It
Article 4 of the EU AI Act binds providers and deployers alike, applies to every AI system regardless of risk tier, and has been live since February 2025 — but it prescribes no record format. This guide sets out who the duty falls on, what "sufficient" literacy means by role, the evidence file that proves it, and how the duty is actually enforced.
Regulation
Emotion Recognition at Work and the Article 5 Prohibitions
Article 5(1)(f) bans inferring emotions in the workplace and in education, and it binds the employer that uses the system as directly as the vendor that supplies it. This guide explains what the prohibition covers, how narrow the medical and safety exception is, where the boundaries are genuinely uncertain, and what to inventory and document first.
Regulation
When Putting Your Brand on a Vendor Model Makes You the Provider
Article 25 of the EU AI Act converts a deployer into a provider through three ordinary commercial acts — white-labelling, substantial modification and repurposing. This guide sets out exactly when the transfer happens, which obligations move with it, and what to check before a rebrand goes live.
Regulation
Choosing and Briefing a Notified Body for AI Assessment
Most high-risk AI systems never touch a notified body — but knowing which ones do, and proving you decided correctly, is the provider's job. A practical route map through Article 43, the deployer-to-provider trap, and what to settle before you sign with an assessment body.
Regulation
Designing Human Oversight That Satisfies Article 14
Article 14 of the EU AI Act is a provider design duty with a separate deployer operating duty under Article 26 — this guide sets out the five capabilities an overseer must be enabled to exercise, when a deployer becomes the provider under Article 25, and the evidence that shows oversight is real rather than a sign-off box.
Regulation
Annex III Employment Systems: From CV Screening to Promotions
A practical guide to Annex III point 4 of the EU AI Act — which HR and workforce tools are caught, whether you are a provider or a deployer, and what evidence satisfies the duties.
Regulation
The Article 9 Risk Management System as a Continuous Process
Article 9 of the EU AI Act requires providers of high-risk AI systems to run a documented, continuously iterating risk management system across the whole lifecycle — not a one-off assessment signed off at launch. This guide sets out the four required steps, who actually owes the duty, when a deployer becomes a provider, the order in which risk measures must be considered, and the evidence that stands up to scrutiny.
Regulation
Article 26 Deployer Duties: Oversight, Input Data and Logs
Article 26 of the EU AI Act creates a set of duties that fall on the deployer of a high-risk AI system, not the provider: using the system per its instructions, staffing human oversight, controlling input data, retaining logs for at least six months, and informing workers and affected individuals. This guide sets out who each duty binds, when a deployer becomes a provider under Article 25, and the evidence that satisfies an auditor.
Governance
Checking Whether a Vendor Trains on Your Data by Default
A practical method for establishing whether an AI vendor uses your inputs for model training or product improvement by default: what the phrase actually covers, where the binding answer lives in the contract stack, who in your organisation owns the decision, and the carve-outs that quietly reverse a reassuring trust page.
Operations
Why the Vendor Demo Passes and Your Own Data Fails
A practical guide for compliance, risk and DPO teams on closing the gap between an AI vendor's demonstration and performance on your own records: what the demo was really showing, who holds which duty under the EU AI Act and data protection law, how to design an acceptance test that produces defensible evidence, and where pilots usually go wrong.
Governance
The Due Diligence Questions AI Vendors Struggle to Answer
A practitioner's guide to AI vendor due diligence: the questions that reliably expose gaps in a supplier's evidence pack, who actually holds each duty under the EU AI Act and data protection law, and what a usable answer has to contain before you sign.
Regulation
Registering an Annex III System You Judged Not High-Risk
Concluding that an Annex III system is not high-risk under Article 6(3) of the EU AI Act does not close the file — it creates a documented assessment duty and a registration in the EU database. A practical guide to who owes those duties, what the assessment must show, what goes into the database entry, and where the reasoning usually collapses.
Governance
Exit, Data Return and Deletion Terms in an AI Contract
A practitioner's guide to drafting and exercising exit, data return and deletion clauses in AI contracts — covering derived artefacts such as embeddings and fine-tuned weights, the controller/processor and provider/deployer split, and the evidence an ISO 42001 auditor will expect.
Regulation
Clinical Triage Chatbots and the NHS Duty of Candour
When an automated triage tool routes a patient wrongly, the statutory duty of candour sits on the registered care provider, not the software vendor — this guide sets out what triggers it, who holds which obligation across CQC, MHRA, DCB0160, UK GDPR and the EU AI Act, and what an honest account of an algorithmic decision has to include.
Standard
Management Review Inputs Your ISO 42001 Auditor Will Ask For
A practitioner's guide to ISO/IEC 42001 clause 9.3: what the management review must consider, why top management (not the governance lead or DPO) owns it, the evidence a certification body will sample, the AI-specific inputs generic templates omit, and where the record usually breaks.
Standard
Closing a Major Nonconformity Before the Surveillance Audit
A practitioner's guide to closing a major nonconformity raised against an ISO/IEC 42001 management system: who owns the fix, what the certification body decides, the five parts of an acceptable response, the evidence pack, and the mistakes that turn a process failure into an integrity problem.
Governance
Reading an AI Vendor's SOC 2 Report for What It Leaves Out
A practitioner's guide to reviewing an AI vendor's SOC 2 report: who actually sets the scope, the five passages that carry the information, and the AI governance questions the report was never designed to answer.
Governance
Audit Rights in an AI Contract That You Could Actually Use
Most AI contracts contain an audit clause that cannot be exercised when it matters. This guide separates the statutory rights you already hold — GDPR Article 28(3)(h), transfer clauses, DORA — from the ones you must negotiate, explains why the EU AI Act gives customers no audit right at all, and sets out what a usable clause, and the evidence behind it, looks like in practice.
Framework
The ICO Audit Framework Applied to a Live AI Deployment
How to run the ICO's data protection audit framework against an AI system that is already in production: who holds which duty, what evidence actually satisfies each control, and where these assessments usually fall apart.
Standard
Running an ISO 42001 Internal Audit Programme With a Small Team
A practitioner's guide to meeting ISO/IEC 42001 clause 9.2 when the AI governance function is one or two people: what the programme must contain, who may audit what, how to slice audits vertically across a certification cycle, and where small programmes fail.
Contact Us for AI Governance Support
Questions about AI compliance or ethics? Our expert team is ready to help you navigate the complexities of responsible AI.
Working Hours
Monday - Friday: 9:00am - 5:00pm GMT
Saturday - Sunday: Closed
Registered Office
128 City Road, London,
EC1V 2NX, UNITED KINGDOM