Resources
Reference material you can take into the room.
Diagrams and downloads built for board packs and briefing decks. Ungated — these work by being shared.
Decision guide
ISO/IEC 42001: what it certifies, what it costs, and what it does not cover
Nearly every page ranking for this standard is published by a firm selling readiness consulting. This one prices the alternatives without a stake in which you pick, and says the part they leave out — including the Colorado safe harbour that several competitor pages still cite after its repeal.
Decision guide
Answering the AI section of a customer security questionnaire
Enterprise procurement added AI modules to standard vendor security reviews in 2026, and the deal now stops in legal review rather than in the demo. What buyers are actually asking, why a policy document does not close it, and the four artifacts that do.
Table
Not all bad data is the same kind of bad
“Fix the data first” treats one word as one problem. It is at least four, and they have different handlers. Three can be handled where the AI runs. The fourth — the plausible error no model, no boundary and no human reviewer catches — takes a process redesign upstream.
Typology
Open weights is not open source
The G7 agreed shared language for AI openness on 29 May 2026 — four tiers across five components, not an open/closed binary. Two boundaries run through them, reproducibility and permission, and one word is doing the work of both.
Corrective
Governance is not the bottom brick
The data-foundation diagram — courses of data work stacked up, AI waiting on top — gets its prose right and its picture wrong. A foundation is something you finish. The three concerns that decide whether AI governance holds never report done.
Crosswalk
EU AI Act × NIST AI RMF × ISO 42001
Every cell of the columns grid mapped to the article numbers that actually apply. Thirteen rows, verified July 2026 against primary sources, with the confidence level stated per framework rather than implied across all three.
Crosswalk
A regulator drew columns and called them pillars
Singapore’s IMDA published the first national framework written specifically for agentic AI. It organises controls by lifecycle stage, but two of its four pillars are not stages at all — they run across every one.
Governance game
You cannot govern what you cannot name
A board is asked to certify “governed, enterprise-grade AI” for a population nobody has ever enumerated. Four options scored — and the reason a policy published this week governs nothing, while a dated, owned discovery does.
Corrective
A Venn diagram is a claim about overlap
Data governance, AI governance, AI security, AI ethics: four overlapping circles carrying sixty items, every one of them placed inside a circle rather than in an intersection. A corrective on the overlapping-domains genre.
Scenario
Logs are not a leash
An accounts-payable agent, four months unattended, five forms of observability and zero enforcement. The board scenario that separates a governed agent from a watched one, with all four options scored.
Matrix
Columns Not Layers: the matrix
Three columns that never finish, four layers that do. Twelve cells, each needing a named owner and a cadence. A blank cell is not a gap in the drawing — it is where a column stopped running.
Status board
The tells expired. The checklist didn’t.
The Economist ran 1.2m words of model output against sixty years of human prose. Half the "how to spot AI writing" checklist is stale, em-dashes have inverted, and the two strongest remaining tells appear on almost no list. Detection is already a control in hiring and procurement — it needs an owner and an expiry date.
Matrix
The agent halt matrix
Agent buyer checklists grade capability on one axis: does it keep going without being re-prompted. The axis they leave off is halt authority — whether a named person can stop the agent before it does something binding. Score on capability alone and the highest score goes to the one nobody can stop.
Board briefing
Cyber terms for the boardroom
Thirteen cybersecurity terms every director should know, defined for oversight rather than for the SOC — each paired with the single question to put to management before the next incident, not in the post-mortem.
Chart
What each AI tier actually decides
Six capability tiers against the decisions they actually make, their EU AI Act exposure, and whether the decision can be undone. Regulatory exposure tracks the consequence of the decision, not the sophistication of the technique.
Diagram
Artificial intelligence: what actually contains what
A corrected taxonomy of the AI capability stack. Generative AI sits inside deep learning, inside machine learning, inside AI — and agents are an architecture wrapped around a model, not a fourth stage of intelligence.