top of page
BLOG


Principles for Using AI Agents to Keep Your Commitments
As organizations plan for 2027, many are deciding what work AI agents will take on next year. Successful businesses take ownership of their obligations and make commitments to meet them. These commitments are promises that must be kept. That is the lens worth bringing to AI: how can AI agents help us keep the promises we have made? Obligations and promises Over the last year in our Elevate Compliance Huddles, we have walked through the Operationalized Obligation model, which
ย


The AI Prediction Trap
When Prediction Becomes the Plan AI agents are being built to act on the predictions of AI models. That should give us pause. The belief behind this is simple. The model predicts the future, and the agent acts on that prediction as if it were reality. When an agent acts on a prediction, it helps make that prediction real. Its actions shape what happens next. The future arrives looking the way the model said it would. The model appears to have been right, and we trust it a lit
ย


Digital Engineering as Strategy for AI in High-Risk Organizations
Digital Engineering as Strategy Organizations in high-risk industries are under pressure to adopt AI. They also carry commitments to regulators, workers, customers and the public. AI can help keep those commitments when it is engineered to do so. That requires being able to answer three questions at any time: - Are we on mission? - Are we operating between the lines? - Are we ahead of risk? Most organizations answer these after the fact, through audits, reports and reviews. A
ย


It's Time for AI to Deliver the Goods
When we talk about AI adoption, most people mean efficiency. Making existing processes faster. Swapping one process stack for another. Here's the thing. With what has been borrowed against AI, efficiency does not come close to settling the account. Because that is what this is. A debt. We have directed much of the world's capital into a single technology and away from everything else it could have funded. That capital was not free. It was borrowed against a promise. And capit
ย


Audit Will Not Make AI Safe
Audit Will Not Make AI Safe Ask almost anyone in compliance where the field ought to be heading and the answer comes back the same. Compliance should become proactive. It should anticipate risk rather than react to it. It should build the capability to meet obligations, not merely the paperwork to prove them. The obligations themselves have already moved. Regulation and standards have shifted toward risk-based and outcome-based designs, and they now ask organizations to conte
ย


Investing in the Opportunity to Succeed
Investing in the Opportunity to Succeed Every business creates value under uncertainty. Some of that uncertainty can be reduced. It comes from what the organization does not yet know. About its processes. Its risks. Its obligations. The conditions it works in. Learning reduces it. So does capability. This is uncertainty you buy down. Some of it cannot be reduced. Variation is part of real conditions, and no amount of learning removes it. This is uncertainty you contend with b
ย


Forward Assurance for AI Systems
Forward Assurance for AI Systems Audit looks backward. It verifies that something was done. Forward assurance is confidence that a system will keep its promises in operation โ and that confidence cannot be inspected in after the fact. It is engineered in, by design. The gap AI is adopted when it can be trusted with the work that matters. We trust a mission critical system because we trust the people who design and build it, and the discipline they follow. That is what has to
ย


Why AI is Used to Govern AI
Governance is a form of regulation. Cybernetics is the study of regulation in machines and living systems. It gives us two rules that matter here. First, the regulator must model the system it regulates. This is the Conant-Ashby theorem. Every good regulator of a system must be a model of that system. Second, the regulator must hold at least as much variety as the system it controls. This is Ashby's Law of Requisite Variety. Only variety can absorb variety. A set of finite co
ย


THE FUTURE OF LEAN COMPLIANCE
Elevate Compliance Huddle ยท Session 100 THE FUTURE OF LEAN COMPLIANCE Elevate Compliance Huddle ยท Session 100 Monday, September 14 ยท Noon ET ยท Live on Zoom In our last webinar we explored what the future of compliance might look like in the age of intelligence. Obligations moving from rules to outcomes. AI arriving in the value chain, in the products organisations make, in their suppliers' processes, and in the compliance function itself. The message was this: compliance
ย


What Stops Compliance From Improving
I have used the same Compliance Program Scorecard for ten years. No one has ever disagreed with their score. That tells me the scorecard is reliable at evaluating compliance. People see where their compliance stands and they recognize it. What the scorecard gives them is where and how to improve. The reason that matters more now is AI. It does not change what compliance is. It changes what it takes to produce it. Obligations do not disappear when work moves to machines. They
ย


The Future of Compliance in the Age of Intelligence
Most conversations about AI and compliance go one of two ways. Either they are about technology, which tools to buy and what to monitor with them. Or they are about regulations, which rules now apply and how to map controls to them. Both are worth having. Neither is the one I think we are missing. Buying the right tools and knowing the right rules will not be enough, because underneath both is a culture and capability problem that AI is exposing rather than creating. AI adopt
ย


We Built Fences and Called It Governance
Structural governance asks: are we inside the line? Directional governance asks: are we going to make it? Nearly every governance instrument we have answers the first question. The risk register. The control matrix. The attestation. The RAG dashboard. The assurance map. Not one of them answers the second. A ship inside its shipping lane is not thereby on course. Four years ago I wrote about bounded-set and centred-set compliance. A bounded set is defined by a boundary and you
ย


๐๐ผ๐ ๐ช๐ฒ ๐๐ฟ๐ฎ๐บ๐ฒ ๐๐ป๐๐ฒ๐น๐น๐ถ๐ด๐ฒ๐ป๐ฐ๐ฒ ๐ง๐ฒ๐ฐ๐ต๐ป๐ผ๐น๐ผ๐ด๐ ๐ช๐ถ๐น๐น ๐๐ฒ๐๐ฒ๐ฟ๐บ๐ถ๐ป๐ฒ ๐ช๐ต๐ฎ๐ ๐๐ ๐๐๐ถ๐น๐
The information technology era is ending, at least in part. It collected data and moved it to where it was needed. Intelligence technology is different. What that era becomes is not settled. It is being decided now, in procurement decisions and architecture reviews, by the answers being given to questions like these. ๐ธ ๐๐ฑ๐ผ๐ฝ๐๐ถ๐ป๐ด ๐๐ ๐๐ฒ๐ฟ๐๐๐ ๐๐ป๐ด๐ถ๐ป๐ฒ๐ฒ๐ฟ๐ถ๐ป๐ด ๐๐ Adoption selects a vendor and measures uptake. Engineering establishes that a system is safe, r
ย


Two Kinds of AI Strategy: Adopt or Adapt?
Which one will you choose? Digital transformation has always been a challenge. Re-engineering a business to use new technology carries real risk, and more so when the benefits aren't easily realized. That is the part the current AI conversation keeps skipping. There are two ways to bring AI into a business, and they are not the same thing. You can adopt it: take the technology as given and fit the business around it. Or you can adapt it: start from the business you already ha
ย


Should You Adopt ISO 42001 or ISO 5338?
ISO 42001 has quickly become a standard organizations reach for when they want to take AI seriously. It is the first international management system standard for artificial intelligence โ a framework for governing AI across an organization, built in the same family as ISO 9001 for quality and ISO 27001 for information security. It is a genuine step forward, and for many businesses it can help. But before adding it to the shelf alongside your other management systems, it is wo
ย


Managing Requisite Context for AI Workflows
Many organizations are adopting AI in their business, whether as generative AI or as AI agents. In all cases, the AI needs a context to work from, and for the AI to be effective that context must be requisite. An AI model knows nothing about your organization. Everything it produces on your behalf rests on the context supplied at the moment of use. If that context covers what the task requires, the workflow can be trusted. If it doesn't, the model fills the gaps with public d
ย


Regulating AI with Institutional Knowledge
Today many organizations use AI that is general. It was trained on the public record, not on any one sector or business. It does not know your mission, your values, your goals, your processes, your protocols, or your standard operating procedures. When you ask it a question, it answers from what is common across everyone, not from how that knowledge applies to the particulars of what you do. In a regulated, high-risk domain this is a problem. The general model gives you the
ย


Engineered Regulation for AI Systems
In every industry where failure is consequential, we learned to engineer control into a system before we trusted it to run. With AI, we are skipping that step. The discipline we are missing has a name: engineered regulation. Engineered Regulation for AI Systems No one runs a refinery with a big red button and good intentions. Before the plant starts, engineers design the control loops that hold temperature and pressure where they belong. They add independent safety systems th
ย


Is AI Causing Your Mission to Drift?
Compliance is now vulnerable. Every promise you've made โ privacy, security, quality, financial integrity, legal adherence, ethical values โ now runs through systems that are unreliable, uncertain, and unable to align with your mission. So ask the hard questions: Does your AI know your obligations, your values, your promises? Does it follow your processes, your standard operating procedures, your policies? Will it cost you your legal license โ or your social license โ to oper
ย


AI Adoption Is Leading to Greater Efficiency, Not Innovation
There is a quiet assumption running underneath the loudest investment of our age, and Sunday is a good day to bring it into the light. We are building compute. Enormous, almost unimaginable quantities of it. We are miniaturizing computers at one end โ fabricating features measured in handfuls of atoms โ and scaling them up at the other into hyperscale clouds that span continents. The capital is real, the engineering is genuine, and the people doing it are among the most capab
ย


What Full-Text Search Already Taught Us About AI
We have been here before. In the enterprise, there have always been two kinds of searches. The first looks for the exact answer you get from a query (deterministic). The second looks for the closest answer you can find through full-text search (probabilistic). We knew the difference, and we learned how to use each kind. Full-text search gave us the approximate answers. It returned a ranked list of the most relevant results โ useful when you are browsing, less so when you need
ย


Why Compliance Must Speak Up About AI
Just because AI may not yet be regulated does not mean compliance should sit on the sidelines. Compliance has always struggled to know how it creates and preserves value. AI now presents both the opportunity and the necessity to do so. Here is why. Organizations everywhere are adopting AI. Many are slowly realizing that adoption is not the objective: AI must create value. But this prompts a question few are asking. Not what value is AI creating, but what value is it losing? T
ย


Introducing the Record of Assurance
The regulatory landscape has changed, as I have been writing about for almost a decade. For a long time, compliance asked one thing of an organization: that procedures were in place, and that there was evidence they had been followed. That's procedural compliance, and it's well served. A certificate or an audit gives you exactly that โ confirmation of procedural integrity. It's useful, honest work, and it isn't going away. But increasingly, boards, stakeholders and regulators
ย


You're Not Using AI. AI Is Using You.
When we use AI in its most common form, we come to realize something about it. The large language models (LLMs) behind it have been trained on public knowledge, not on the knowledge your organization, business, or institution owns. We can provide a model with our documents to process, but this does not change the model. It does not learn that way. The exchange is one-directional in a way that is easy to miss. The model answers our prompts and forgets us, but the data we send
ย
bottom of page
