Insights
Regulatory developments,
Regulatory developments,
read as obligations.
Not news summaries. Each piece takes a development a client will hear about anyway and works out what it actually changes about someone's duty, evidence, or exposure — including the frequent answer that it changes less than the headline suggests.
White Papers
Long-form arguments, free and ungated. No form, no email required.
Aug 2026
PDF · 20 pp · 114 KB
PDF · 20 pp · 114 KB
AI Governance as Organizational Design
Structure determines the location of decision-making power, and AI now sits inside that location — which makes governance a structural question before it is a policy one. Human oversight fails at predictable rates unless four conditions hold, and the decision, not the system, is the unit that has to be governed.
Aug 2026
PDF · 15 pp · 110 KB
PDF · 15 pp · 110 KB
The AI Control Layer
Why every AI-enabled organization ends up building one, and what it costs to build it late. A control is a mechanism that can intervene in a live system — and most organizations, asked whether anything can stop an AI system over the objection of the team that owns it, have to answer no.
Analysis
Jul 23, 2026
DC's AI Values Have Never Been Enforced. The Window to Fix That Is Closing.
A framework becomes credible the first time its consequence lands on someone. DC's six values have not had that moment — and the bodies that would make it a citable precedent expire December 31, 2026.
Jul 17, 2026
Illinois Didn't Just Add an AI Law. It Changed Who Gets to Grade the Homework.
SB 315 replaces self-attestation with independent third-party audit — the SOX playbook applied to catastrophic-risk claims. The penalties target frontier developers; the diligence pressure lands on everyone buying from them.
Jul 17, 2026
The CMMC Suspension Didn't Lower Your Risk. It Moved It.
The suspension removed a verification step, not the obligation under it. NIST 800-171, DFARS 252.204-7012, and SPRS attestation all survive — and DoW cannot suspend DOJ's False Claims Act authority.
Jul 13, 2026
Default-On Consent Isn't a PR Risk. It's a Compliance Case Study.
The exposure in AI image generation sits in biometric and minor-safety statutes, not general AI law — and most teams have that backwards.
Each piece was originally published on LinkedIn; the version here is the same text with its source link. Regulatory positions are stated as of the publication date and are not updated in place — where a development has since moved, a later piece says so rather than a silent edit.