Original analysis on AI governance and security.

Long-form, evergreen-leaning writing in Andrew's own voice — distinct from News (dated, external current-awareness) and Resources (annotated external links).

Flagship exhibit

Can four people actually govern and steward a bank's AI?

The Thought Experiment is a UK-regulated retail bank scenario, built on the FCA's Mills Review: an evolving public investigation into whether a small human core can govern AI agents performing the rest of the operation, tested against a named organisational structure, a regulatory floor, and a ledger-integrity model.

8 articles

Latest writing

28 August 2026

Model Drift, Performance Regression and Versioning: Telling Them Apart

Three terms, three different things, and conflating them means monitoring the wrong one. Drift is the world moving. Regression is a measurement getting worse. Versioning is the artefact changing. For most LLM deployments the dominant cause of behaviour change is none of the classic ones. It is the model provider shipping an update you were not told about.

28 August 2026

LLM Governance: What It Actually Means Operationally

Most AI governance programmes produce a policy, a committee and a register, then discover none of it touches the thing that actually changes: the assembly of model version, prompt, retrieval corpus and tool permissions that determines what the system does. LLM governance is an operations problem wearing a policy costume.

28 August 2026

Prompt Injection and System Prompt Hardening: What Actually Works

System prompt hardening is worth doing and will not save you. The achievable goal is not a model that cannot be tricked, since natural language offers no way to build that. It is a system where being tricked does not matter much. OWASP's 2026 revision makes the same point: the biggest mover was not the attack, it was what the model was allowed to do afterwards.

28 August 2026

Third-Party AI Risk: Model Provenance and Vendor Due Diligence

Most AI vendor questionnaires are security questionnaires with "AI" added to the headings. The useful version asks for the specific documentation the EU AI Act already obliges the provider to hold, and establishes in writing whether your own configuration has quietly made you the provider.

28 August 2026

AI Governance in UK Financial Services: The Regimes That Already Apply

The UK has decided not to write an AI Act for financial services. That is not the relief it sounds like. Five existing regimes already bind AI in regulated firms, one of them has required a board-approved model risk appetite since May 2024, and UK lenders and insurers serving EU customers sit inside the EU AI Act whatever Westminster does.

28 August 2026

AI Impact Assessments: DPIA, FRIA and AIA Compared

Three different assessments answer to the phrase "AI impact assessment", and only one of them may actually bind your organisation. The EU AI Act's fundamental rights impact assessment reaches a narrower set of deployers than most coverage suggests. For those inside it, completing the assessment is only half the obligation, because Article 27 also requires you to file it with a regulator.

28 August 2026

Setting an AI Risk Appetite: A Practical Framework for Boards

Most organisations already have a risk appetite statement. Almost none of them survives contact with an AI system, because one sentence about "low appetite for operational risk" cannot tell you whether a 4% error rate is acceptable. A usable AI risk appetite is a matrix, and every threshold in it needs a trigger attached.

28 August 2026

Undisclosed AI Interaction: The Article 50 Obligation That Was Not Delayed

The Digital Omnibus deferred the AI Act's high-risk obligations by more than a year. It left Article 50 alone. The transparency duties that took effect on 2 August 2026 apply now, to almost every organisation running a chatbot, a synthetic voice agent, or a generative content pipeline, and they carry fines of up to €15 million or 3% of worldwide turnover.