AI governance

carolina principles us press g20 light touch ai regulation a solid raised boom gate barrier arm

US to Press G20 on Light-Touch AI Regulation: Inside the Carolina Principles

At the G20 Innovation Ministerial in Chapel Hill on 1–2 September 2026, the United States is asking the world’s largest economies to sign the Carolina Principles: a non-binding pact to reserve new AI regulation for genuinely novel issues and to avoid creating new AI regulators. This article sets out what the principles say, who is in the room with Musk, Altman, Huang and Hassabis, why Washington wants the pact now, the counter-arguments from the Hugging Face breach and the UN panel, how it compares with the G20’s own AI record, and what it means for UK and EU businesses.

Read more
frontier ai access uk national security a solid toggle switch lever

Frontier AI Access Is a Growing National Security Question for the UK

A University of Surrey white paper published on 27 August 2026 argues that frontier AI access has become part of UK national cyber defence — and that the June 2026 US export-control order, which forced Anthropic to disable Claude Fable 5 and Mythos 5 for every customer worldwide until 1 July, proved that access can be withdrawn without warning. This breakdown covers what Professor Alan Woodward and Dr Andrew Rogoyski actually argue, the NCSC’s measurement of a £65 automated attack, AISI’s 4.7-month capability doubling time, the five recommendations the paper sets out, why open-weight models are a weaker fallback than they look, and what UK organisations should put on their own risk registers.

Read more
bill gates ai warning turbulent era a hand bell with handle

Bill Gates Is Deeply Worried About AI, and He’s No Longer Staying Quiet

On 26 August 2026 Bill Gates published “A turbulent AI era — and critical choices to make”, a roughly six-thousand-word essay on Gates Notes, alongside interviews with Axios, GeekWire and MIT Technology Review. The technology industry’s most reliable optimist for fifty years now says the AI transition will be one of the most turbulent periods in human history, that the industry has already crossed every safety threshold it named for itself — bio, cyber, psychosocial, job destruction and control — and that no coordinated plan exists. This breakdown separates the essay from the headlines: the five thresholds and what crossing each one means, the three proposals Gates puts forward (new national and international institutions, a category of “Human Reserved” work kept for people, and a tax on AI tokens and robots), the numbers he attaches to them, his objection to the June 2026 executive order on model testing, what he says AI companions are doing to children, where he still expects AI to do more good than harm, and the questions he openly admits he has not answered. It closes with what a business buying AI this year should actually do about it.

Read more
automated decision-making - automated decision making under the duaa a branching decision node

Automated Decision-Making: Essential DUAA Rules to Avoid Risk

Section 80 of the Data (Use and Access) Act 2025 deleted Article 22 of the UK GDPR and replaced it with Articles 22A to 22D, commenced on 5 February 2026. The prohibition became a permission with conditions: for ordinary personal data you may now make solely automated significant decisions, provided you notify the individual, accept representations, provide genuine human intervention and allow a contest. This guide sets out the two-part test, what the ICO now means by meaningful human involvement, the special category data rules that did not relax, where automated decisions hide inside ordinary business software, the EU divergence that catches exporters, the evidence pack a regulator will ask for, seven failure patterns and a 60-day plan.

Read more
ai assurance vs ai governance a two interlocking puzzle blocks

AI Assurance vs AI Governance: Essential Guide to Avoid Risk

AI governance sets the rules, roles and decision rights for the AI you run. AI assurance is the evidence that those rules were followed and that the system behaves as claimed. The two words are used interchangeably, and the confusion costs money: policies nobody tests, or tests nobody asked for. This guide separates them cleanly with a side-by-side comparison table, the assurance techniques that actually produce evidence a buyer or regulator will accept, a RACI grid for who owns what, what the UK’s assurance-led approach and the EU AI Act each demand, realistic cost profiles, a 90-day plan to stand both up, and the mistakes that make an assurance programme worthless.

Read more
prompt injection risk assessment business ai a hexagonal shield upright

Prompt Injection Risk: Essential Safe Assessment Guide

Prompt injection is the one attack class against business AI that has no structural fix, because instructions and data reach a language model through the same channel. This guide turns that into something you can manage: where injected instructions actually enter a business system, how to scope an assessment so it finishes in days, a ten-question likelihood and impact matrix anchored to observable facts, a control map showing which measures leave a low residual and which depend on the model behaving, how to build an injection corpus and test the boundary rather than the model, how to record findings in a register an auditor can follow, who owns the risk and what UK and EU regulators expect, realistic costs, and a 90-day plan.

Read more
ai agent security tools and system access a padlock shackle shut

AI Agent Security: Essential Guide to Safe Tool Access

The moment you connect a language model to a ticketing API, a finance system, a mailbox or a shell, you stop shipping a chat feature and start shipping a new class of privileged user. This guide covers the engineering work that keeps that user contained: how to classify and scope tools into risk tiers, why an agent needs its own identity and short-lived credentials rather than a shared service account, how to contain the blast radius of a single compromised run with sandboxing and default-deny egress, where to place human approval gates so they are decisive rather than theatre, what actually works against indirect prompt injection arriving through retrieved content, what to log so an incident is investigable, how to test the controls before launch, and a 90-day rollout plan with realistic costs and named owners.

Read more
AI red-teaming - ai red teaming what to test before launch a hexagonal shield upright

AI Red-Teaming: Essential Tests to Run Before a Safe Launch

Most AI systems reach launch having been tested only by people trying to make them work. Adversarial testing asks the other question: what happens when someone actively tries to make the system misbehave. This guide sets out what to test before go-live — how to scope the exercise and define harm in your own domain, the five attack classes that matter for business deployments, whether to run it internally, buy it in or automate it, how to score findings so severity cannot be renegotiated after the fact, which fixes actually hold, what the work costs in person-days and pounds, and the evidence pack that answers an enterprise security questionnaire and maps onto the EU AI Act, ISO 42001 and the NIST AI Risk Management Framework.

Read more
CHAT