top of page
BLOG


The AI Prediction Trap
When Prediction Becomes the Plan AI agents are being built to act on the predictions of AI models. That should give us pause. The belief behind this is simple. The model predicts the future, and the agent acts on that prediction as if it were reality. When an agent acts on a prediction, it helps make that prediction real. Its actions shape what happens next. The future arrives looking the way the model said it would. The model appears to have been right, and we trust it a lit


Digital Engineering as Strategy for AI in High-Risk Organizations
Digital Engineering as Strategy Organizations in high-risk industries are under pressure to adopt AI. They also carry commitments to regulators, workers, customers and the public. AI can help keep those commitments when it is engineered to do so. That requires being able to answer three questions at any time: - Are we on mission? - Are we operating between the lines? - Are we ahead of risk? Most organizations answer these after the fact, through audits, reports and reviews. A


It's Time for AI to Deliver the Goods
When we talk about AI adoption, most people mean efficiency. Making existing processes faster. Swapping one process stack for another. Here's the thing. With what has been borrowed against AI, efficiency does not come close to settling the account. Because that is what this is. A debt. We have directed much of the world's capital into a single technology and away from everything else it could have funded. That capital was not free. It was borrowed against a promise. And capit


Audit Will Not Make AI Safe
Audit Will Not Make AI Safe Ask almost anyone in compliance where the field ought to be heading and the answer comes back the same. Compliance should become proactive. It should anticipate risk rather than react to it. It should build the capability to meet obligations, not merely the paperwork to prove them. The obligations themselves have already moved. Regulation and standards have shifted toward risk-based and outcome-based designs, and they now ask organizations to conte


Investing in the Opportunity to Succeed
Investing in the Opportunity to Succeed Every business creates value under uncertainty. Some of that uncertainty can be reduced. It comes from what the organization does not yet know. About its processes. Its risks. Its obligations. The conditions it works in. Learning reduces it. So does capability. This is uncertainty you buy down. Some of it cannot be reduced. Variation is part of real conditions, and no amount of learning removes it. This is uncertainty you contend with b


Forward Assurance for AI Systems
Forward Assurance for AI Systems Audit looks backward. It verifies that something was done. Forward assurance is confidence that a system will keep its promises in operation — and that confidence cannot be inspected in after the fact. It is engineered in, by design. The gap AI is adopted when it can be trusted with the work that matters. We trust a mission critical system because we trust the people who design and build it, and the discipline they follow. That is what has to


Why AI is Used to Govern AI
Governance is a form of regulation. Cybernetics is the study of regulation in machines and living systems. It gives us two rules that matter here. First, the regulator must model the system it regulates. This is the Conant-Ashby theorem. Every good regulator of a system must be a model of that system. Second, the regulator must hold at least as much variety as the system it controls. This is Ashby's Law of Requisite Variety. Only variety can absorb variety. A set of finite co


THE FUTURE OF LEAN COMPLIANCE
Elevate Compliance Huddle · Session 100 THE FUTURE OF LEAN COMPLIANCE Elevate Compliance Huddle · Session 100 Monday, September 14 · Noon ET · Live on Zoom In our last webinar we explored what the future of compliance might look like in the age of intelligence. Obligations moving from rules to outcomes. AI arriving in the value chain, in the products organisations make, in their suppliers' processes, and in the compliance function itself. The message was this: compliance


What Stops Compliance From Improving
I have used the same Compliance Program Scorecard for ten years. No one has ever disagreed with their score. That tells me the scorecard is reliable at evaluating compliance. People see where their compliance stands and they recognize it. What the scorecard gives them is where and how to improve. The reason that matters more now is AI. It does not change what compliance is. It changes what it takes to produce it. Obligations do not disappear when work moves to machines. They


The Future of Compliance in the Age of Intelligence
Most conversations about AI and compliance go one of two ways. Either they are about technology, which tools to buy and what to monitor with them. Or they are about regulations, which rules now apply and how to map controls to them. Both are worth having. Neither is the one I think we are missing. Buying the right tools and knowing the right rules will not be enough, because underneath both is a culture and capability problem that AI is exposing rather than creating. AI adopt


We Built Fences and Called It Governance
Structural governance asks: are we inside the line? Directional governance asks: are we going to make it? Nearly every governance instrument we have answers the first question. The risk register. The control matrix. The attestation. The RAG dashboard. The assurance map. Not one of them answers the second. A ship inside its shipping lane is not thereby on course. Four years ago I wrote about bounded-set and centred-set compliance. A bounded set is defined by a boundary and you


ISO 9001:2026 – Time to Model Your Quality System
The revised standard is close. ISO/TC 176/SC 2 has completed the technical revision and submitted the Final Draft, with publication expected in September 2026. Organizations then have a three-year transition period, to September 2029. The revision is an evolution rather than a rewrite — the process approach, the harmonized structure, and the core requirements stay. What's new is context. Among the themes carried through the drafts is digitalization, with reliable data treated


Applying PDCA to the Obligation-Promise Cycle
PDCA Applied to Obligation/Promise Cycle An obligation is a requirement the organization must fulfil. It may be mandatory or voluntary, external or internal, and it stays active for as long as it is imposed or adopted. A promise is a voluntary commitment made by an agent about its own behaviour. Obligations give rise to promises. That is how an obligation becomes operational. The cycle runs between them. Obligations produce promises, promises are kept through operational capa


Why Compliance Fails to Advance
Every so often I take stock of where compliance actually is as a discipline, compared to where the effort we pour into it says it should be. The honest answer has bothered me for some time, and I want to work through it with you here. Compliance has never had more resources. More frameworks, more software, more staff, more attention from the board than at any point in my career. By almost any measure of activity, the field has grown enormously. And yet, measured the only


𝗛𝗼𝘄 𝗪𝗲 𝗙𝗿𝗮𝗺𝗲 𝗜𝗻𝘁𝗲𝗹𝗹𝗶𝗴𝗲𝗻𝗰𝗲 𝗧𝗲𝗰𝗵𝗻𝗼𝗹𝗼𝗴𝘆 𝗪𝗶𝗹𝗹 𝗗𝗲𝘁𝗲𝗿𝗺𝗶𝗻𝗲 𝗪𝗵𝗮𝘁 𝗜𝘀 𝗕𝘂𝗶𝗹𝘁
The information technology era is ending, at least in part. It collected data and moved it to where it was needed. Intelligence technology is different. What that era becomes is not settled. It is being decided now, in procurement decisions and architecture reviews, by the answers being given to questions like these. 🔸 𝗔𝗱𝗼𝗽𝘁𝗶𝗻𝗴 𝗔𝗜 𝘃𝗲𝗿𝘀𝘂𝘀 𝗘𝗻𝗴𝗶𝗻𝗲𝗲𝗿𝗶𝗻𝗴 𝗔𝗜 Adoption selects a vendor and measures uptake. Engineering establishes that a system is safe, r


Two Kinds of AI Strategy: Adopt or Adapt?
Which one will you choose? Digital transformation has always been a challenge. Re-engineering a business to use new technology carries real risk, and more so when the benefits aren't easily realized. That is the part the current AI conversation keeps skipping. There are two ways to bring AI into a business, and they are not the same thing. You can adopt it: take the technology as given and fit the business around it. Or you can adapt it: start from the business you already ha
bottom of page
