Essays and briefings on privacy, data, AI regulation, board governance, incident response, and regulated-business risk.
Privacy functions have become very good at producing evidence that the work was done, and much less good at showing that a decision came out any different because they were there.
Adoption isn't behaviour change. The test is whether risk decisions actually differ.
02AI is where you find out whether the operating model actually reaches the work.
03Independent challenge matters, but it cannot make the business own a privacy, data or AI decision it was never required to make properly.
04Privacy training can improve knowledge without building the judgement people need to shape a consequential decision together.
05Board papers can show that AI governance exists. Rehearsal shows whether management can make, challenge and evidence an AI decision before the organisation is already committed.
Privacy job ads increasingly ask for operational judgement, AI governance and cross-functional influence, while many roles remain scoped around advice, documentation and compliance delivery.
How boards should see privacy, data, cyber and AI exposure before it becomes an incident, a penalty, or a public failure.
Making AI governance actually operate: ownership, the capability it needs, and where it clashes with other controls.
Privacy, data, and the operating models that turn adopted frameworks into decisions the business actually makes.
Privacy Act reform, AI regulation and the operational choices regulated businesses have to make now.