Blog
Plain notes on getting an organisation up to date on AI governance, written for the person who has to work it out.
Can you put client data into ChatGPT? A UK GDPR answer
Free and Plus can train on what staff paste, and your firm has no contract with OpenAI. What Business and Enterprise change, and what to do if it has happened.
Do you need a DPIA for an AI tool? A UK screening test
Five common AI uses run through the UK GDPR test for a data protection impact assessment, and what to write down when you decide one isn't needed.
Who is responsible for AI governance in a company?
In most UK organisations under 250 staff, one named person runs AI governance and the board stays accountable. When a committee is worth it, and who sits on it.
Do we actually need an AI policy?
When an AI governance policy is worth writing, when it is premature, and what it is really for once your staff are already using AI at work.
How much does ISO 42001 certification cost?
Why published price ranges for ISO 42001 mislead, what actually drives the cost, and how to size your own scope before you ask anyone for a quote.
7 questions to ask before you approve a new AI tool
A short checklist for whoever signs off AI tools: seven questions that keep data leaks, shadow AI and EU AI Act duties in view before you say yes.
5 signs your organisation is ready for ISO 42001
Five signals that ISO 42001 is worth starting now, and what a readiness check looks at before you commit to the AI management standard.
5 things UK businesses still get wrong about the EU AI Act
The July 2026 omnibus moved the EU AI Act timeline. Five assumptions UK organisations still make, and what the amended Regulation actually says.
Where to start with AI governance when it lands on your desk
A practical first move for the person who has just been asked whether the organisation is on top of its AI, before anyone spends money.