FL Fredrik Lindstrom


Decision guide

ISO/IEC 42001: what it certifies, what it costs, and what it does not cover

Nearly every page ranking for this standard is published by a firm selling readiness consulting. This one prices the alternatives without a stake in which you pick, and says the part they leave out — including the Colorado safe harbour that several competitor pages still cite after its repeal.

Cost table · alternatives compared · five questions answered · no email gate

Decision guide

Answering the AI section of a customer security questionnaire

Enterprise procurement added AI modules to standard vendor security reviews in 2026, and the deal now stops in legal review rather than in the demo. What buyers are actually asking, why a policy document does not close it, and the four artifacts that do.

Four artifacts as text · what to do in week one · four questions answered · no email gate

Table

Not all bad data is the same kind of bad

“Fix the data first” treats one word as one problem. It is at least four, and they have different handlers. Three can be handled where the AI runs. The fourth — the plausible error no model, no boundary and no human reviewer catches — takes a process redesign upstream.

All four kinds as text · one-page PDF · no email gate

Typology

Open weights is not open source

The G7 agreed shared language for AI openness on 29 May 2026 — four tiers across five components, not an open/closed binary. Two boundaries run through them, reproducibility and permission, and one word is doing the work of both.

All four tiers as text · one-page PDF · no email gate

Corrective

Governance is not the bottom brick

The data-foundation diagram — courses of data work stacked up, AI waiting on top — gets its prose right and its picture wrong. A foundation is something you finish. The three concerns that decide whether AI governance holds never report done.

Both panels as text · one-page PDF · no email gate

Crosswalk

EU AI Act × NIST AI RMF × ISO 42001

Every cell of the columns grid mapped to the article numbers that actually apply. Thirteen rows, verified July 2026 against primary sources, with the confidence level stated per framework rather than implied across all three.

All twelve cells as text · one-page PDF · no email gate

Crosswalk

A regulator drew columns and called them pillars

Singapore’s IMDA published the first national framework written specifically for agentic AI. It organises controls by lifecycle stage, but two of its four pillars are not stages at all — they run across every one.

All four pillars as text · one-page PDF · no email gate

Governance game

You cannot govern what you cannot name

A board is asked to certify “governed, enterprise-grade AI” for a population nobody has ever enumerated. Four options scored — and the reason a policy published this week governs nothing, while a dated, owned discovery does.

All four options as text · one-page PDF · no email gate

Corrective

A Venn diagram is a claim about overlap

Data governance, AI governance, AI security, AI ethics: four overlapping circles carrying sixty items, every one of them placed inside a circle rather than in an intersection. A corrective on the overlapping-domains genre.

All four domains as text · one-page PDF · no email gate

Scenario

Logs are not a leash

An accounts-payable agent, four months unattended, five forms of observability and zero enforcement. The board scenario that separates a governed agent from a watched one, with all four options scored.

All four options scored as text · one-page PDF · no email gate

Matrix

Columns Not Layers: the matrix

Three columns that never finish, four layers that do. Twelve cells, each needing a named owner and a cadence. A blank cell is not a gap in the drawing — it is where a column stopped running.

All twelve cells as text · one-page PDF · no email gate

Status board

The tells expired. The checklist didn’t.

The Economist ran 1.2m words of model output against sixty years of human prose. Half the "how to spot AI writing" checklist is stale, em-dashes have inverted, and the two strongest remaining tells appear on almost no list. Detection is already a control in hiring and procurement — it needs an owner and an expiry date.

All eight tells as text · one-page PDF · no email gate

Matrix

The agent halt matrix

Agent buyer checklists grade capability on one axis: does it keep going without being re-prompted. The axis they leave off is halt authority — whether a named person can stop the agent before it does something binding. Score on capability alone and the highest score goes to the one nobody can stop.

All four quadrants as text · one-page PDF · no email gate

Board briefing

Cyber terms for the boardroom

Thirteen cybersecurity terms every director should know, defined for oversight rather than for the SOC — each paired with the single question to put to management before the next incident, not in the post-mortem.

All 13 terms as text · one-page PDF · no email gate

Chart

What each AI tier actually decides

Six capability tiers against the decisions they actually make, their EU AI Act exposure, and whether the decision can be undone. Regulatory exposure tracks the consequence of the decision, not the sophistication of the technique.

Full table as text · one-page PDF · no email gate

Diagram

Artificial intelligence: what actually contains what

A corrected taxonomy of the AI capability stack. Generative AI sits inside deep learning, inside machine learning, inside AI — and agents are an architecture wrapped around a model, not a fourth stage of intelligence.

Full taxonomy as text · one-page PDF · no email gate