Articles & Insights

Thinking Out Loud
About AI Governance

Analysis, frameworks, and field notes from the people building independent AI certification. Not corporate marketing — actual reasoning, made public.

The Digital Omnibus and the Certification Window

High-risk obligations pushed to December 2027. Sectoral safety to August 2028. Market expectations didn’t move. The opportunity is in the gap.

Why the Big Four Cannot Certify AI

Auditing what you advised on isn’t auditing — it’s self-review with a different filename. Sarbanes-Oxley solved this for finance. AI is next.

Cyber Insurance Is Already Pricing AI Governance

Underwriters are quietly adding AI riders, exclusions, and capacity limits. By the time the standard market follows, the certified will be paying less.

What “UL for AI” Actually Means

Underwriters Laboratories created a category by being independent, technically rigorous, and never selling products. Clause5afe is following the same architecture.

Shadow AI: The Compliance Risk No One Is Naming

Untracked AI tools embedded in workflows are the next data breach. Internal policy documents don’t solve what no one has inventoried.

Self-Certification Is Not Certification

Trusting an AI vendor’s attestation that their own AI is compliant is exactly the conflict that destroyed Arthur Andersen. The market will not stay confused for long.

Get the next one in your inbox.

Roughly one piece a month. AI governance, regulation, certification, written for people who already work in the field.

Need certification, not commentary?

If your organization is preparing for EU AI Act enforcement, ISO 42001, or NIST AI RMF, we’d be glad to walk you through the process.

Schedule Discovery Call →