Knowledge base
Deep-dive articles on the AI Assured framework, controls and evidence.
-
AI incidents - what counts and what to log
What actually counts as an AI incident in 2026 - with worked examples, the EU AI Act Art. 73 serious-incident test, and the log structure reviewers expect.
-
Acceptable use & staff training
The policy and training that turn AI from a wildcard into a managed tool - what to put in the policy and how to evidence the training.
-
Stopping data leakage into AI tools on a small budget
Concrete controls a company without a security team can put in place this month, using licences you probably already hold.
-
The 2026 enterprise AI tools market
A snapshot of the enterprise AI tools that matter in 2026 - copilots, agent platforms, observability, governance, and where each fits.
-
What good evidence looks like
The difference between a document that satisfies a question and one that does not, with examples of strong and weak evidence for each control type.
-
Microsoft 365 Copilot - a governance playbook
How to roll out M365 Copilot without leaking sensitive content: tenant boundary, Restricted SharePoint Search, sensitivity labels, audit and DSR handling.
-
EU AI Act - the dates that drive your 2026 plan
The phased applicability of the EU AI Act through 2026-2027 in one calendar, plus what each milestone means for the work on your desk.
-
Welcome to the Knowledge Hub
Start here. How to use the Knowledge Hub, who in your company to pull in, and a lighter path if you are a small team.
-
What to include in your assessment scope
Write a defensible scope statement: which AI systems, teams, jurisdictions and data flows are in - and what is deliberately out.
-
Glossary of common terms
Plain-English definitions, each tied to the regulation that uses the term so you can use the right word in the right room.
-
Guidance for small companies
Right-size the framework for teams under 50 people: which controls are non-negotiable, which can be lightweight, and which to defer.
-
How the AI Assured Framework is structured
The AI Assured Framework in one page: five pillars, sixteen domains, and how they map to EU AI Act, NIST AI RMF 1.0 and ISO/IEC 42001.
-
Finding shadow AI - discovery tools and how to run a sweep
How to find the AI tools your staff already use, using the logs and licences you already own, plus what to do with what you find.
-
Recent updates to the AI Assured Framework
What changed in the framework and the regulatory landscape for 2026 - and what each change means for the work on your desk.
-
Building an AI inventory that stays current
What fields an AI system inventory needs, how to keep it fresh without a dedicated team, and the tools that suit each organisation size.