Learn
AI governance, explained properly
Technical explainers on governing what AI tools and agents are allowed to do — written for the people who have to implement it, not for a search engine. Each one opens with a direct answer, defines its terms, and cites its sources.
Fundamentals
What the terms mean, and how the pieces fit together.
What Is AI Governance?
What is AI governance, and what does it actually control?
AI governancePolicy enforcementCompliance5 min readRuntime AI Governance
What is runtime AI governance, and how is it different from an AI policy document?
AI governancePolicy enforcementAI security4 min readAI Governance vs AI Security
What is the difference between AI governance and AI security?
AI governanceAI securityCompliance4 min read
Threats
What actually goes wrong, and why the usual controls do not reach it.
Shadow AI: Finding Unsanctioned AI Use
What is shadow AI, and how do you find it without surveilling people?
Shadow AIAI governanceData loss4 min readPrompt Injection
What is prompt injection, and what actually defends against it?
Prompt injectionAI securityCoding agents4 min readSecuring AI Coding Agents
How do you secure AI coding agents that can run commands and edit files?
Coding agentsAI securityPolicy enforcement4 min read
Controls
What to put in the path of an action, and where to put it.
Operations
Running governance as a program: policy, evidence and measurement.
Enforcing an AI Acceptable Use Policy
How do you turn an AI acceptable use policy into something enforceable?
AI governancePolicy enforcementCompliance4 min readWhat Belongs in an AI Audit Trail
What belongs in an AI audit trail, and what should be left out?
Audit evidenceAI governanceCompliance4 min readMeasuring AI Governance Coverage
How do you measure whether an AI governance program is actually working?
AI governanceAudit evidenceCompliance4 min read