Insights
Notes from the field.
Short, practical writing on AI governance, data sovereignty, and what regulated firms can actually defend to a supervisor.
Every prompt is a data-export decision
For a regulated firm, sending a prompt to an external AI model is not merely a productivity choice. It is a decision to export data, and it should be treated like one.
A contractual promise is not an operating control
Contracts matter, but regulated AI also needs technical controls, customer-owned operations and evidence of what actually happened.
DORA and the case for fewer AI vendors
Every AI tool you add is another third party to oversee. DORA changed the maths on that, and self-hosting is one possible answer.
Open by choice: why a compliance tool should be auditable
A product that asks regulated firms to trust it with their data should let them read its code. Open source is not a giveaway here. It can underpin the exit plan.