HomeArtificial Intelligence (AI)

Artificial Intelligence (AI)

How AI Risk Self-Assessment Drives Better Governance and Faster Decisions

Deloitte's 2026 State of AI in the Enterprise research and KPMG's Global AI Pulse survey show a widening gap between AI governance intent and board-level readiness, while the EU AI Act's August 2026 self-assessment requirement turns internal best practice into a filed, auditable record. This post asks whether your organisation's AI risk self-assessment is a live decision tool or just a document that says one exists.

Third-Party AI: Someone Else Built the Autopilot, but You’re Still Flying the Plane

APRA's April 2026 letter named third-party AI risk as the biggest gap in bank and insurer oversight — and weeks later, a compromised account at AI tooling vendor Context.ai gave attackers a path into Vercel's infrastructure. This piece uses both to show why vendor assurance paperwork isn't AI risk management, and what to ask instead.

How to Navigate AI Privacy Risk Beyond Generic Vendor Assessments

Generic vendor privacy assessments couldn't have flagged what happened at MediSecure or Latitude Financial — and that's the problem. This piece uses real breach and enforcement outcomes to show why a signed-off checklist isn't AI privacy control, and sets out the questions every organisation should be asking its AI vendors now.

Why AI Risk Management Must Prioritise Business-Led Accountability in Third-Party AI Use

When Air Canada's chatbot invented a bereavement discount, a Canadian tribunal made the airline pay $812.02 for it. New data from the Cyber Risk Institute's Treasury-backed AI framework and Ncontracts' 2026 Third-Party Risk Management Survey show why every organisation using vendor AI needs the same accountability before the mistake is theirs.

Beyond Model Risk: Managing AI Risks Embedded in Complex Vendor Ecosystems

Three real 2026 outages — AWS's cascading Middle East failure, Microsoft Copilot's five-hour blackout, and Claude's multi-model cascade — show why AI risk management can't stop at the vendor you signed with. With EU AI Act deployer obligations enforceable from August 2026 and Gartner naming \u201cfourth-party\u201d AI risk directly, boards need to map the AI hiding inside their vendors' vendors.

Why AI Policy Must Be Practical: Turning Guardrails into Actionable Risk Controls

Many organisations have AI policies, but these often fail to guide day-to-day decision making. To manage AI risks effectively, policies need clear guardrails that business teams can apply consistently. This article explains how to translate high-level AI principles into practical standards and controls that enable confident, accountable AI use.