Practical AI governance guides, regulatory analysis, and research, for enterprise leaders, businesses, and individuals navigating the AI landscape.
Boards, APRA, ASIC, controls & programmes
Start herePrivacy Act, ACCC consumer law, AI6 basics
Start hereFounder guide, investor due diligence, EU AI Act
Start hereYour rights, Right to Disconnect, AI at work
Start hereUS employers using AI in hiring, monitoring, or employment decisions face EEOC enforcement, NYC Local Law 144, state AI hiring laws, and growing plaintiff's bar attention. Here is the compliance framework.
Read article2026
Singapore has a sophisticated AI governance framework led by PDPA obligations and IMDA's AI Verify programme. Here is what individual rights exist when AI affects you, in hiring, financial decisions, or consumer contexts.
2026
Singapore employers are increasingly using AI in hiring, performance management, and monitoring. Here is what rights employees have under the PDPA, TAFEP advisories, and Fair Consideration Framework when AI affects employment.
2026
Singapore SMEs using AI face PDPA compliance requirements and can benefit from IMDA's AI Verify framework and government AI support programmes. Here is the practical starting point for responsible AI use in Singapore.
2026
Singapore's Personal Data Protection Act applies to all AI tools that process personal data of Singapore residents. Here is what PDPA compliance looks like in practice, from chatbots to hiring tools to customer analytics.
2026
India's Digital Personal Data Protection Act 2023 fundamentally changes the data governance landscape for organisations processing data of Indian residents, including through AI systems. Here is the compliance framework to build.
2026
India's financial regulators, RBI, SEBI, and IRDAI, have published guidance on AI governance that financial services firms must incorporate. Here is the regulatory landscape for AI in Indian financial services.
2026
India's Digital Personal Data Protection Act 2023 creates data rights for Indian residents, including rights over personal data used in AI systems. Here is what those rights are and how to use them.
2026
The EU AI Act is often discussed from a business perspective. But it creates important protections for individuals, rights to explanation, human review, and protection from the most harmful AI uses. Here is what it does for you.
2026
EU workers have strong AI-related rights across two complementary frameworks: GDPR's automated decision-making protections and the EU AI Act's high-risk AI requirements for employment AI. Here is the complete picture.
2026
UK employees have specific rights when employers use AI, automated decision-making rights under UK GDPR, Equality Act protection against algorithmic discrimination, and consultation obligations.
2026
UK small businesses using AI tools face UK GDPR obligations and ICO enforcement. Here is what actually applies and what to prioritise without the complexity of the EU AI Act.
2026
US workers have a patchwork of AI-related rights, EEOC guidance on algorithmic hiring, Illinois and NYC AI laws, NLRA protection for collective action, and growing state worker surveillance laws.
2026
US small businesses face FTC enforcement on deceptive AI practices, growing state consumer privacy laws, and sector-specific obligations in healthcare, finance, and education.
2026
Most EU AI Act analysis targets large enterprises. This guide covers what small businesses and SMEs actually need to do, which obligations apply, which exemptions exist, and what the real compliance burden looks like.
2026
GDPR applies to every AI tool that processes personal data, and most business AI does. This guide covers the practical obligations for European SMEs: lawful basis, automated decision rights, DPIAs, and the biggest compliance mistakes.
2026
AI-generated deepfakes are increasingly used to harass, defraud, and defame individuals. Here is what legal protections exist globally and what you can do if you are a victim.
2026
Global AI enforcement shifted from guidance to penalties in 2023-26. Regulators in Australia, the EU, UK, and US moved against biometric AI, AI hiring tools, and AI consumer practices. Here are the enforcement actions that set today's compliance expectations.
2026
AI governance is now a board-level responsibility. Directors who cannot demonstrate meaningful oversight face personal liability exposure, regulatory scrutiny, and institutional investor pressure.
2026
Most enterprise AI is now procured, not built. Third-party AI creates governance obligations you must own, you cannot outsource AI accountability to your vendor. Here is the due diligence framework.
2026
AI systems fail differently from conventional software, systematic bias, model drift, hallucination. When they do, the response has legal, regulatory, and reputational dimensions that standard incident response playbooks do not address.
2026
Australia's Privacy Act 1988 and the 13 Australian Privacy Principles (APPs) govern how personal information is handled, including by AI systems. Here is what organisations need to know.
2026
APRA's CPS 230 Operational Risk Management standard (effective July 2025) applies to all APRA-regulated entities and has significant implications for AI governance, particularly for material business processes, third-party AI, and AI incident response.
2026
Data governance and AI governance are distinct but interconnected. Good data governance is a prerequisite for good AI governance, you cannot govern AI well without governing the data it uses.