Internal documents that happen to be published.
Essays and field notes on AI-native operations, constitutional agent design, and the systems behind the work. No cadence promised. Each one makes a claim and defends it.
Featured
SelectedHow I govern AI agents using the same framework I use for employees
Most organizations treat AI governance as a new problem requiring new frameworks. I don't. I treat an AI session the same way I treat an employee. You give that employee roles and responsibilities. You give them scope. You put policies and controls around how they do their work. Then they use their know-how to get from A to B. A to B is what you measure. How they get from A to B—as long as they're within the bounds—the employee's good to go. The governance gap is organizational, not technolo
The oversight vacuum: why AI adoption without governance is tearing companies apart
I've watched the same pattern repeat across dozens of organizations in the past 18 months. A leadership team sees a demo. Someone in the room plays with ChatGPT over lunch. The conversation shifts from "should we" to "how fast can we" in a single meeting. The deployment begins before anyone checks what's actually under the hood. This isn't a story about technology moving too fast. This is about organizations moving faster than their ability to understand what they're deploying. The gap between
Browse by tag
- / 0126 August 2026
The call and the size
TL;DR: Elm Wealth ran eight language models through a real historical trading simulation with leverage. The models were credible at picking direction. They were catastrophic at sizing. The loss, in every case, came from the multiplier, not the view. This is a structural finding, not a statistical one. * Language models can form directional market views that beat human benchmarks. * They consistently over-leverage: average gross leverage near 30x against a defensible 7.5–15% volatility target.
- / 0222 August 2026
The Excel formula that belongs in your privacy policy
You have until 10 December to know where your software makes decisions about people TL;DR: APP 1.7 to 1.9 commence 10 December 2026. Every APP entity must disclose automated decision-making (ADM) in its privacy policy. The disclosure takes an afternoon to write. Finding what to disclose is a four-month programme. Almost no organisation has started. * "Computer program" covers Excel scorecards, rules engines, and legacy decision trees, not just AI models. * Human sign-off does not exempt you.
- / 0316 August 2026
Hidden reasoning is an information asset. You have not classified it.
Hidden model reasoning is an information asset you have not classified, cannot sanitise, and cannot verify. What the reasoning-trace extraction paper means for CPS 234, your retention obligations, and what counts as evidence in an AI system.
- / 042 August 2026
What banks are actually being asked to build right now
TL;DR: Two of the world's most powerful financial regulators publicly admitted, six days apart, that the governance framework for autonomous AI in regulated financial services doesn't exist yet. Firms that treat this as a compliance retrofit will spend 2027 explaining their certifications. Firms that treat it as an architecture problem will have the substrate in place before the rules land. * On 23 July 2026, the Bank of England's Deputy Governor signalled that agentic AI may require purpose-b
- / 0531 July 2026
Trust in AI is behavioural evidence, not code review
TL;DR: You can't trust an AI system by reading its documentation. Trust in AI comes from observed behaviour, not policy papers. The only artifact that proves your governance model works is a refusal log. Most regulated firms don't have one. * Agentic AI takes actions in production. The failure mode is behaviour that's already happened. * Regulators are now asking for demonstrated behaviour, not documentation. * A refusal log is the only evidence that policy is enforced, not just written. *
- / 064 July 2026
Your AI Policy Doesn't Fire When Your Agent Acts
I walk into firms with AI policies sitting in SharePoint. They get cited in board decks. They show up in audit binders. Then a model makes a decision, moves money, drafts client output, and the policy watches from the shelf. That gap is a wiring problem. Prose does not intercept a call. Prose does not sign an evidence record. Prose does not refuse an action because a control was not satisfied. The Difference Between a Document and a System A governance document describes what should happen
- / 0726 June 2026
The liability doesn't move: why AI governance can't be delegated to IT
I've watched this pattern repeat across financial services, investment operations, and regulated industries: the board approves an AI initiative, leadership assigns it to IT, and everyone assumes the governance problem is solved. It isn't. The legal accountability for AI decisions sits exactly where it always has—with the board, the company, and the individuals who deploy the system. The software can't be sued. The vendor can't absorb your liability. The AI can't appear in court. This isn't a
- / 0824 June 2026
How to make 'never' mean something: the enforcement problem in AI governance
I've been building AI governance systems for regulated environments where failure isn't just expensive. It's existential. The hardest part isn't writing the rules. That's the easy part. You sit down, map the regulatory requirements, identify the prohibited behaviors, document the constraints. CPS 234 says this. ISO 42001 requires that. The EU AI Act prohibits these specific practices. Done. The hard part is making those rules enforceable at runtime. Not aspirational. Not documented in a poli
- / 0922 June 2026
If you can't name the fear, you're not ready for the tool
I've watched organizations rush AI deployment like it's a competitive sprint. The urgency is real. The preparation is not. The conversation always starts the same way: "We need AI." I ask what they're trying to achieve. The answer is usually a category, not an outcome. "Efficiency." "Innovation." "Staying competitive." These aren't drivers. They're placeholders for thinking that hasn't happened yet. The diagnostic question most organizations skip Before you touch the technology, answer thre
- / 1019 June 2026
The void that opens when you can't explain what happened
I've watched organizations lose millions because they couldn't answer a simple question: why did you decide that? Not what did you decide. Not what was the outcome. Why. The decision was made. The system executed. The output was delivered. But the reasoning that connected input to action disappeared the moment the session closed. What's left is a black hole where accountability should be. Auditability is not memory Most people treat auditability like a storage problem. Keep the data. Archi
Get these as they’re published.
Long-form on AI governance in regulated firms — what the control gap actually is, what regulators are asking for, and what the evidence has to look like. Roughly monthly. No pitches.