Practical AI governance guides, regulatory analysis, and research, for enterprise leaders, businesses, and individuals navigating the AI landscape.
Boards, APRA, ASIC, controls & programmes
Start herePrivacy Act, ACCC consumer law, AI6 basics
Start hereFounder guide, investor due diligence, EU AI Act
Start hereYour rights, Right to Disconnect, AI at work
Start hereHow to comply with South Korea AI Basic Act (effective 22 January 2026): high-impact AI classification, transparency obligations, risk assessment requirements, and penalties.
Read article2026
Practical compliance guide for MAS AI Risk Management Guidelines: governance structures, risk assessment, model management, vendor governance, and customer outcomes monitoring.
2026
AI is fundamentally changing the outsourcing and BPO landscape, automating work that was previously offshored, creating new categories of vendor risk, and introducing cross-border data governance obligations that many organisations have not addressed. This is the governance guide for organisations that outsource work and the providers who deliver it.
2026
AR, VR, and mixed reality systems powered by AI collect unprecedented volumes of biometric, spatial, and behavioural data. Eye tracking, facial expressions, body movements, room mapping, and gaze patterns create privacy risks that existing frameworks were not designed for. What governance looks like for immersive AI.
2026
Neural data, information derived from brain activity and the nervous system, is now collected by consumer devices, workplace wearables, and medical implants. Four US states have enacted neural data privacy laws. UNESCO has adopted global neuroethics standards. This is the governance guide for the emerging neurotechnology landscape.
2026
AI-powered wearables, smart glasses, earbuds with real-time translation, health monitors with predictive AI, and workplace safety devices, collect continuous data about the wearer and their environment. The governance challenges are distinct from traditional AI: always-on collection, bystander privacy, biometric sensitivity, and the blurring of personal and employer-controlled data.
2026
When AI controls physical systems, industrial robots, surgical robots, autonomous drones, warehouse automation, delivery robots, governance moves beyond data and algorithms into physical safety, product liability, and human-robot interaction. The regulatory frameworks, liability questions, and governance requirements are fundamentally different from software-only AI.
2026
Employees at over 90% of organisations use personal AI accounts for work. Only 37% of organisations have AI governance policies. Shadow AI is the single biggest unmanaged AI risk in enterprise today, and prohibition does not work. This is the practical governance guide.
2026
AI copyright governance covers three intersecting questions: can AI training on copyrighted works constitute fair use, who owns AI-generated outputs, and what are an organisation's obligations when employees use AI to create content. The US Supreme Court denied certiorari on AI authorship in March 2026. Courts are drawing clear lines. Here is what organisations need to know.
2026
APRA and ASIC both identified board AI literacy gaps in their May 2026 letters. Directors do not need to understand neural networks. They need to understand what AI their organisation uses, what can go wrong, what the legal obligations are, and how to challenge management effectively. This is the practical guide.
2026
NYC Local Law 144 already requires annual bias audits for automated hiring tools. Colorado repealed and replaced its AI Act with SB 189 (effective January 2027), narrowing its bias-testing scope. The EU AI Act mandates bias monitoring for high-risk AI. This is the practical guide to testing AI systems for discriminatory outcomes before enforcement action forces you to.
2026
AI is now a material factor in M&A due diligence. Buyers need to assess AI governance maturity, regulatory compliance exposure, IP ownership of AI-generated assets, data licensing risk, and vendor dependency. Sellers need to disclose AI systems, training data provenance, and known governance gaps. The due diligence checklist for AI-era transactions.
2026
AI creates a dual ESG challenge: AI systems consume significant energy and resources (environmental), affect workers and communities (social), and require oversight structures (governance), while simultaneously being used to improve ESG measurement and reporting. Organisations need governance frameworks that address both sides.
2026
AI is changing the insurance landscape for directors, officers, and organisations. D&O insurers are incorporating AI governance maturity into underwriting. Cyber insurance policies may exclude AI-related incidents if governance is inadequate. Professional indemnity is being tested by AI errors. What risk managers, boards, and insurance buyers need to understand.
2026
Organisations using open-source AI models, Llama, Mistral, Falcon, Stable Diffusion, face unique governance challenges. The EU AI Act treats open-source GPAI differently from proprietary models. Licence terms, model provenance, security vulnerabilities, and accountability for outputs all require governance frameworks that most open-source deployments lack.
2026
Digital twins, AI-powered virtual replicas of physical systems, processes, or environments, are used in manufacturing, infrastructure, healthcare, and urban planning to simulate, predict, and optimise operations. When actions are taken based on digital twin outputs, governance must address model validation, data accuracy, decision accountability, and the gap between simulation and reality.
2026
AI governance platform spending is projected to reach $492 million in 2026 and surpass $1 billion by 2030. But choosing the right tools requires understanding what problems they solve, what they do not solve, and how they fit with your existing GRC and compliance infrastructure. The independent evaluation guide.
2026
Traditional IT procurement frameworks do not adequately cover AI-specific risks: model transparency, bias, data handling, ongoing monitoring, and accountability for AI-driven decisions. This is the AI procurement framework for government and enterprise organisations writing RFPs, evaluating vendors, and managing AI contracts.
2026
Most organisations using AI did not build their AI systems. They procured them from vendors, integrated them from cloud platforms, or embedded them from third-party APIs. The AI supply chain creates layered governance obligations, and APRA, the EU AI Act, and the Five Eyes guidance all now expect organisations to govern AI across their entire supply chain, not just within their own walls.
2026
Three major data protection frameworks, three different approaches to AI. How GDPR, the Australian Privacy Act, and Singapore PDPA compare on automated decision-making rights, consent requirements, cross-border transfers, and enforcement, and what organisations operating across these jurisdictions need to know.
2026
Australian, UK, and Singapore financial regulators are each setting AI governance expectations for banks, insurers, and asset managers. APRA published its AI industry letter in April 2026, the FCA relies on existing principles with AI-specific guidance, and MAS is finalising comprehensive AI risk management guidelines. How they compare and what firms operating across these markets need.
2026
The EU enacted comprehensive AI-specific legislation. Australia relies on existing law plus voluntary standards. Both approaches create real obligations. How they compare on scope, risk classification, penalties, and timeline, and what organisations subject to both need to do.
2026
An illustrative scenario showing how a mid-size fintech company with 15 AI systems across lending, fraud detection, and customer service implemented a governance framework aligned with APRA expectations and ISO/IEC 42001, from initial inventory to board reporting in 90 days.
2026
An illustrative scenario showing how a healthcare provider governing AI across clinical decision support, diagnostic imaging, patient triage, and administrative automation navigates the intersection of medical device regulation, privacy law, clinical safety standards, and AI governance frameworks.