Knowledge base
Deep-dive articles on the AI Assured framework, controls and evidence.
-
AI incidents — what counts and what to log
What actually counts as an AI incident in 2026 — with worked examples, the EU AI Act Art. 73 serious-incident test, and the log structure reviewers expect.
-
Acceptable use & staff training
The policy and training that turn AI from a wildcard into a managed tool — what to put in the policy and how to evidence the training.
-
Microsoft 365 Copilot — a governance playbook
How to roll out M365 Copilot without leaking sensitive content: tenant boundary, Restricted SharePoint Search, sensitivity labels, audit and DSR handling.
-
The 2026 enterprise AI tools market
A snapshot of the enterprise AI tools that matter in 2026 — copilots, agent platforms, observability, governance, and where each fits.
-
EU AI Act — the dates that drive your 2026 plan
The phased applicability of the EU AI Act through 2026–2027 in one calendar, plus what each milestone means for the work on your desk.
-
Welcome to the Knowledge Hub
Start here. How to use the Knowledge Hub, who in your company to pull in, and a lighter path if you're a small team.
-
Glossary of common terms
Plain-English definitions, each tied to the regulation that uses the term so you can use the right word in the right room.
-
How the AI Assured Framework is structured
The AI Assured Framework in one page: five pillars, sixteen domains, and how they map to EU AI Act, NIST AI RMF 1.0 and ISO/IEC 42001.
-
What to include in your assessment scope
Write a defensible scope statement: which AI systems, teams, jurisdictions and data flows are in — and what is deliberately out.
-
Guidance for small companies
Right-size the framework for teams under 50 people: which controls are non-negotiable, which can be lightweight, and which to defer.
-
Recent updates to the AI Assured Framework
What changed in the framework and the regulatory landscape for 2026 — and what each change means for the work on your desk.