Practical AI governance guides, regulatory analysis, and research, for enterprise leaders, businesses, and individuals navigating the AI landscape.
Boards, APRA, ASIC, controls & programmes
Start herePrivacy Act, ACCC consumer law, AI6 basics
Start hereFounder guide, investor due diligence, EU AI Act
Start hereYour rights, Right to Disconnect, AI at work
Start hereAn AI ethics policy articulates principles for AI use. A credible one has specific commitments, red lines, and enforcement mechanisms, not generic statements of values that amount to ethics-washing.
Read article2026
Indian businesses using AI face obligations under the DPDP Act 2023 and IT Act, without the complexity of a comprehensive AI-specific law. Here is the practical starting point for Indian SMEs.
2026
Large organisations in India using AI face overlapping obligations from the DPDP Act, sector regulators, and the IT Act. Here is the enterprise governance framework for AI compliance in India.
2026
UK insurers using AI in underwriting, pricing, and claims face obligations from FCA Consumer Duty, PRA model risk expectations, the ICO's UK GDPR guidance, and the FCA's pricing practices rules. Here is the complete governance framework.
2026
EIOPA's Consultative Expert Group on Digital Ethics published a report on AI Governance Principles in June 2021, and EIOPA itself published a formal Opinion on AI Governance and Risk Management in August 2025. Combined with Solvency II model risk obligations and the EU AI Act, EU insurers face a layered AI governance framework. Here is the complete picture.
2026
US insurance is state-regulated, but the NAIC's 2023 Model Bulletin on AI establishes a national baseline. Here is the governance framework US insurers need, covering NAIC expectations, state insurance commissioner requirements, and CFPB oversight of credit insurance.
2026
Singapore insurers using AI in underwriting, claims, and distribution face MAS expectations through the FEAT principles and Veritas framework, PDPA obligations on personal data, and MAS Notice 133 consumer protection requirements.
2026
Insurers worldwide use AI to set premiums, assess claims, and detect fraud. These AI systems can make mistakes, perpetuate bias, and produce decisions you have not been given adequate reasons for. Here is what rights individuals have globally.
2026
An AI controls framework defines the specific controls, preventive, detective, and corrective, that govern AI risk across an organisation. Here is how to design, implement, and evidence an AI controls framework that satisfies internal audit, external regulators, and boards.
2026
AI is now a material risk for most organisations, but few internal audit functions have developed the methodology to audit it effectively. Here is the framework for auditing AI, what to test, how to test it, and what good AI audit evidence looks like.
2026
Model risk management frameworks, originally designed for quantitative financial models, are being extended to cover AI. Here is the AI model risk control framework that financial services regulators and internal audit functions expect to see.
2026
Financial services regulators globally, APRA, FCA, Federal Reserve, MAS, ECB, have all published guidance that implies or explicitly requires AI controls. Here is the complete controls framework for financial services firms, mapped to regulatory expectations.
2026
Enterprise AI controls frameworks are designed for large organisations with dedicated risk and compliance teams. SMEs using AI need a proportionate, practical approach. Here is a working AI controls checklist for organisations without specialist risk infrastructure.
2026
Most enterprise AI risk is third-party AI risk, AI embedded in software you buy, not AI you build. Vendor AI governance requires specific controls beyond standard vendor management. Here is the framework.
2026
Your rights when an AI system produces an incorrect result, credit, hiring, insurance, healthcare, or benefits. What to do, who to contact, and what the law says.
2026
Whether your employer can legally use AI to monitor your work, track productivity, analyse communications, or make performance decisions, by jurisdiction.
2026
The legal requirements for using AI in recruitment and hiring, bias audits, disclosure obligations, anti-discrimination law, and what candidates can do.
2026
China's layered AI regulatory framework: PIPL, Cybersecurity Law, Data Security Law, CAC algorithm filing, deep synthesis rules, and generative AI measures. What foreign and domestic companies must comply with.
2026
New Zealand's AI governance framework: Privacy Act 2020, Algorithm Charter, government AI guidance, and what organisations operating in NZ need to know.
2026
A practical overview of AI governance obligations across the Asia-Pacific region: Australia, Japan, South Korea, Singapore, India, China, New Zealand, Hong Kong, and ASEAN member states.
2026
Hong Kong's sector-led AI governance: PDPO data protection, PCPD Model Framework for AI, HKMA banking AI requirements, and practical compliance guidance for organisations.
2026
Your rights when AI is used in your workplace across Australia, Singapore, Japan, South Korea, Hong Kong, India, and New Zealand. Monitoring, hiring, performance reviews, and termination.
2026
Sector-specific AI governance in India: RBI expectations for banks and fintechs, CDSCO requirements for healthcare AI, and compliance for IT services companies deploying AI.
2026
What non-Japanese companies need to know about AI compliance in Japan: APPI data protection, METI/MIC Guidelines, government procurement requirements, and practical implementation.