News
Practical insights on AI governance, privacy, web and digital transformation - from a team that has led this work, not just written about it.
Third-party risk: the case for bringing together cyber, AI and data.
26-08-2026
Third-party risk is now the board's biggest concern, ahead of direct attacks. This piece makes the case for judging cyber, AI and data as one connected risk rather than three separate ones, with a practical starting point for boards, GCs and founders - Identify the ten vendor relationships that would hurt most, and why that isn't the same list as your ten highest-spend vendors.
Governance done badly: what most businesses build, and what it takes to be effective.
12-08-2026
Governance is either embedded in how a business runs its data, AI and cyber, or it is corporate decoration. Most businesses deploy weak, superficial versions of the five elements that make the difference, and without rigorous scoping and build, a poor version and what it produces, is often worse than admitting the gap. What each element actually requires, and why the roadmap is the one most businesses haven't built.
There is no AI without data.
03-08-2026
AI is its data - the quality of what comes out directly reflects the quality of what went in. Why 80-95% of enterprise AI investment is failing to deliver, where the data challenges extend further than most businesses realise, and five questions boards should hear answered before signing off the next AI spend.
"Compliance as growth" was never about compliance. Governance is business.
22-07-2026
"Compliance as growth" has become the industry line - and it means something narrower than what it was reaching for. Governance embedded in how the business decides what to do with its data, AI and cyber is not what most companies have built. A five-part test for whether governance is real or decoration, who has to own it, and what changes when the work is done.