Category: Uncategorized

  • Your Marketing Copy as Conduct Control

    A financial services firm’s website is much more than a brand asset that happens to mention products. It is a conduct record. Every headline, testimonial, calculator, performance chart and call to action can create a representation about the firm, its services, internal controls, a financial product, a likely outcome, or the level of risk involved. The relevant regulatory question is not whether each sentence is technically defensible in isolation, but whether the communication, viewed as a whole and received by the audience likely to see it, creates a false, misleading or deceptive impression.

    ASIC’s updated Regulatory Guide 234, Advertising financial products and services (including credit), sets the standard. RG 234 is directed to promoters of financial products and financial advice services, and to publishers of advertising. Its core requirements are straightforward: statements must be true, accurate and capable of being substantiated; predictions about future returns or risk require reasonable grounds; and an intention not to mislead does not prevent a communication from being misleading. The overall impression matters as much as the individual words. The audience reached matters as much as the audience intended.

    That framing has a direct compliance implication and marketing review should be treated as a front-end conduct control, integrated into the AFSL holder’s broader system of supervision, monitoring, record-keeping and accountability. A polished approval workflow is not enough if published claims remain unbalanced, unsupported or impossible to reconstruct after the fact.

    ASIC’s June 2026 Update Changes What Firms Must Review

    On 9 June 2026, ASIC reissued RG 234, the first substantial rework of the document since it was introduced in 2012. The revision drew on more than a decade of enforcement and regulatory action and followed a public consultation that ran from November 2025 to January 2026. The biggest structural change is the absorption of Regulatory Guide 53, The use of past performance in promotional material, into RG 234. RG 234 is now the single reference point for ASIC’s advertising expectations, with no stated transition period. Which means the revised guidance is now in effect.

    The update also added AI-generated content, AI specific claims, and a greenwashing enforcement example, expanded guidance on the distinction between required warnings and general disclaimers, clarified the performance-period comparison rules for products with less than five years of history, and added further commentary on what constitutes an “ordinary and reasonable person” when assessing how an advertisement lands.

    The practical message is that the firm must ensure that any communication is fair, balanced, clear, accurate and supported by evidence, with qualifications presented in a way that an ordinary member of the intended audience can notice and understand. A disclaimer cannot reliably fix a dominant headline that communicates an inconsistent promise.

    A Claim-Level Benchmark Makes Regulatory Exposure Visible

    A useful approach to marketing review does not attempt to declare a breach or confirm that copy is free from risk. It identifies individual claims, maps them to relevant risk themes and assigns a triage status. A report of this type might present a result such as 79 out of 100 across 42 claims, with 23 green, 18 yellow and 1 red. The value lies less in the numbers than in the audit trail behind it detailing the exact wording, the page location, the issue classification, the evidence required, the accountable owner and the remediation status.

    As a concrete example, a sentence such as “It is this level of total care that ensures expert advice to get you where you need to be” may warrant a red classification because “ensures” may convey an absolute guarantee about both the quality of advice and the outcome.

    A report of this type should be treated as an internal screening tool, not as an ASIC-issued finding or an independently verified legal conclusion. Its governance value is that it converts a large body of website text into a prioritised remediation queue.

    Benchmark resultGovernance interpretationTypical next step
    GreenNo issue identified against the benchmark criteria, subject to supporting evidence and ongoing change control.Retain evidence and include in periodic re-review.
    YellowWording, context, qualification, substantiation or audience fit may create elevated risk.Assign an owner, obtain evidence, revise wording or add prominent context, then re-approve.
    RedAn absolute, guarantee, unsupported prediction, material omission or other high-risk element may require urgent attention.Escalate to compliance or legal; consider pausing or removing the content; document the decision and check related channels.

    The thresholds for green, yellow and red should be written down and calibrated to the firm’s risk appetite. A firm that treats a yellow finding as an acceptable residual is making a deliberate decision. A firm that discovers its yellow findings are proliferating across channels is detecting a systemic pattern. The score is a diagnostic, not a verdict and shows where the lines sit and how often the firm crosses them. What the firm does next is the real test of its governance.

    Three Failure Patterns Appear Repeatedly in AFSL Marketing

    Misleading promotional claims understate what the firm is promising

    Absolute words such as “guaranteed”, “ensures”, “always”, “never”, “risk-free”, “best” or “no downside” deserve immediate scrutiny. They may be acceptable in a narrow factual context. In financial services marketing, however, they can imply certainty about an investment outcome, the quality of advice, the suitability of a strategy or the absence of risk.

    The review should test the net impression the claim creates. “Helping clients pursue their objectives” is materially different from “ensuring clients achieve their objectives”. “We provide tailored advice” is different from “our advice will get you where you need to be”. The second formulation in each pair may require proof the firm cannot realistically provide and may overstate what advice can achieve.

    A sound review examines adjacent text, page design, imagery, testimonials and calls to action together. A modest qualification buried below a bold guarantee may not change the overall impression. A claim can also mislead through omission if a reasonable consumer would need material information to understand its significance.

    Disclaimers that are present but ineffective provide false comfort

    Disclaimers are not a universal safe harbour. They can be important where a communication needs context, but they must be specific, readable, proximate and consistent with the main message to carry any protective weight. A generic statement such as “past performance is not indicative of future performance” does not, by itself, explain fees, volatility, relevant time periods, portfolio composition, assumptions, conflicts or the possibility of loss where those matters are material to the impression created.

    The review should distinguish between a missing disclaimer and an ineffective one. A disclaimer may be present yet ineffective if it is hidden behind a link, placed far from the claim it qualifies, displayed in unreadable type, contradicted by the headline, or drafted in language the audience is unlikely to understand. The firm should record not only the disclaimer text but also its location, formatting, presentation across device types and relationship to the specific claim. Any advice business copy should also be checked against the boundary between factual information, general advice, personal advice and a promotional invitation to engage.

    Performance statements create an incomplete picture

    Performance content carries a high risk of presenting a partial account. A favourable return figure may be technically correct yet misleading if the period, benchmark, fees, tax treatment, volatility, drawdowns, assumptions or risk of loss are unclear. Cherry-picked periods and isolated success stories can produce a stronger impression than the underlying evidence supports.

    The June 2026 update consolidates all past-performance advertising guidance into RG 234. A practical review should ask: what exactly is being measured, and over what period? Is the result gross or net of fees? Is the comparison like-for-like? Are negative or less favourable periods relevant to understanding the claim? Is the benchmark appropriate? Are forecasts or projections clearly distinguished from historical results? Can the firm reproduce the data and methodology that generated the number?

    The same discipline applies to testimonials and case studies. A statement such as “we helped this client retire early” may imply a typical or repeatable outcome even if it describes one client’s experience. The firm should assess whether the example is representative, whether material qualifications are needed, and whether the audience could mistake an individual result for a promise.

    A Defensible Claim-Review Process Starts With a Complete Inventory

    A firm that reviews its marketing reactively, one page at a time, when someone raises a concern, is not running a control but responding to incidents. A defensible review process starts with a complete inventory of every public-facing channel: the main website, landing pages, calculators, downloadable guides, newsletters, paid search copy, social channels, adviser biographies, webinars, podcasts, third-party profiles and any influencer content. ASIC monitors for misleading or deceptive representations and unlicensed financial services, which supports treating digital channels as part of the controlled perimeter rather than as informal exceptions.

    Each piece of content should then be decomposed into claims, that might not be limited to a sentence. It may be a number, superlative, visual comparison, implied promise, omission, testimonial or a combination of headline and design. The reviewer should capture the precise wording, URL or channel, screenshot or archived version, date observed, intended audience, product or service involved, risk theme, evidence required, decision and owner.

    Review questionEvidence to retain
    What does the audience reasonably take away?The full page or post, including headline, imagery, buttons and nearby qualifications.
    Is the claim factual, predictive, comparative or opinion-based?Source documents, calculations, benchmark definitions, assumptions and approval records.
    Can the firm substantiate it now?Dated evidence, data lineage, research, client-file samples where appropriate and sign-off.
    Is important context prominent and understandable?Screenshots across desktop and mobile, disclaimer placement and readability checks.
    Does the claim remain accurate over time?Review date, expiry trigger, owner, change log and monitoring result.
    Does the communication create advice, distribution or target-market issues?Product scope, audience analysis, advice classification and relevant disclosure and DDO assessment.

    Classification rules should be written down before review begins. A red rule might include an absolute guarantee, an unsupported future-return prediction, a material misstatement, a claim contradicted by available evidence, or a missing qualification that would change the audience’s likely decision. Yellow might include unclear scope, weak substantiation, poor disclaimer prominence, stale data, ambiguous comparisons or an outcome-oriented testimonial. Green should mean “no issue identified under the tested criteria”, not “approved forever”.

    The Pattern of Findings Tells You More Than the Score

    The most valuable question after a review is not “What was our score?” It is “What does the pattern of findings say about our controls?” If most yellow items relate to missing context, the problem may sit in the copy template or brand guidelines. If red items are concentrated in adviser biographies, the training and approval process may be underperforming. If stale performance numbers recur, ownership and review triggers may be unclear. If the same issue appears on the website and across social channels, the content management process may lack a single source of truth.

    A governance committee or responsible manager should review aggregate results alongside remediation ageing, repeat findings, approval exceptions, complaints, incidents and regulatory changes. Management information should distinguish between newly detected issues, accepted residual risk, items awaiting evidence and items closed after independent verification. A numerical score should never conceal a serious single issue: one unqualified guarantee can warrant more attention than many low-risk wording observations.

    Control areaWhat the firm should be able to demonstrate
    OwnershipEvery public claim has a business owner and a compliance escalation path.
    Pre-publication reviewHigher-risk claims receive documented compliance or legal review before release.
    SubstantiationEvidence is current, traceable and sufficient for the specific wording and audience.
    Disclosures and qualificationsMaterial context appears prominently and is tested in the actual publication format.
    Change managementCopy is re-reviewed when products, fees, performance, law, guidance or audience changes.
    SurveillancePublished content is periodically scanned, sampled and compared with the approved version.
    RemediationRed and yellow issues have deadlines, accountable owners, decisions and closure evidence.
    LearningRepeat findings feed back into templates, training, controls and risk appetite.

    Red and Yellow Findings Require Concrete Action, Not Just Documentation

    A red finding should trigger prompt containment. The firm should preserve the relevant version of the content, confirm whether it is still live, assess the channels and audiences affected, and escalate under its incident and breach-reporting framework where appropriate. It should then decide whether to remove, pause, correct or qualify the communication, documenting the rationale and approval.

    For yellow findings, the response should be proportionate and concrete. The firm may need to obtain evidence, narrow the claim, replace certainty language, add context, correct a comparison, improve disclaimer prominence or introduce an expiry date. The revised copy should be tested as a whole, because adding words at the bottom of a page may not fix the impression created at the top.

    In both cases, remediation should include a look-back. Search for similar wording, related claims and syndicated versions across web pages, social posts, PDFs, email journeys and third-party channels. A review is most useful when it reveals a pattern that can be corrected systematically, not a single sentence that is edited in isolation.

    Marketing Review Is a Control System, Not a One-Time Exercise

    ASIC’s advertising guidance places the emphasis on substance and overall impression. For AFSL firms, that means marketing-copy review must be integrated with evidence management, approvals, disclosure controls, monitoring and remediation. It cannot be treated as a one-off brand exercise or an annual tidy-up.

    A benchmark result, whether 78 out of 100 or any other score, provides a useful starting point for management discussion. Its real value is the claim-level detail underneath: which words create risk, what evidence is missing, how prominent the qualification is, who owns the fix and whether the control environment learns from the result. Used that way, marketing review becomes more than a surveillance exercise. It becomes a practical test of whether the firm’s governance and review processes are producing the outcomes the firm expects, before a regulator asks the same question.

    Contact us to explore how to automate your marketing review process.

    References

    [1] ASIC, RG 234 Advertising financial products and services (including credit), issued 9 June 2026. https://www.asic.gov.au/regulatory-resources/find-a-document/regulatory-guides/rg-234-advertising-financial-products-and-services-including-credit/

    [2] ASIC, INFO 269 Discussing financial products and services online. https://www.asic.gov.au/regulatory-resources/financial-services/giving-financial-product-advice/discussing-financial-products-and-services-online

  • Building AI in a Financial Advice Business: Design the System First

    The most reliable path to AI is to build a clean operating system for the business, then use AI and automation to make that system faster, clearer, and easier to govern.

    For most financial advice businesses, AI looks like a fast productivity win. It can read client documents, summarise meetings, prepare drafts, answer internal questions, and cut repetitive administration. The temptation is to pick a tool, connect some files, and let the team experiment.

    That is rarely the right starting point. If client information is spread across spreadsheets, email, task boards, shared drives, and specialist platforms, AI will not remove the complexity but increase it. It may generate polished language or save time on a specific task, but it cannot determine which record is authoritative, whether a document is current, who owns the next decision, or whether the required evidence has been captured and with each added tool complexity, mistakes, and gaps increases.

    The more durable approach treats AI implementation as a systems-design programme. First, design the operating environment: its workflows, data, ownership, permissions, and records. Then introduce AI on top of that clean foundation. The result is an implementation that improves efficiency without sacrificing the consistency, traceability, and professional accountability that advice businesses require.

    ASIC’s October 2024 report, Beware the Gap, reviewed 624 AI use cases across 23 Australian financial services licensees and found that AI adoption is outpacing the governance frameworks meant to manage it. Nearly half of licensees had no policies addressing consumer fairness or bias. ASIC’s conclusion was direct: build the governance before you build the capability.

    This six-step sequence provides a practical roadmap to build the governance, as you build the . The order is deliberate and prevents the practice from automating disconnected work or giving AI access to poorly governed data.

    StageWhat it createsWhat it prevents
    1. Map every workflowA shared picture of how work actually happens.Digitising an imagined process rather than the real one.
    2. Consolidate the stackA purposeful technology backbone with fewer duplicate tools.Fragmented client records and repeated manual entry.
    3. Design the source of truthOne governed model of clients, entities, advice, documents, and controls.Competing versions of the same information.
    4. Move the team into one homeGenuine adoption of the central system before automation.Building automations around poor data and shadow processes.
    5. Add AI agentsUseful AI grounded in controlled, permissioned business data.Scaling stale, incomplete, or unauthorised information.
    6. Automate the backgroundContinuous handling of routine handoffs, reminders, and filing.Staff spending time chasing status updates and administrative tasks.

    Step 1: Map every workflow before touching anything

    Before writing code, buying software, or selecting an AI vendor, map the firm’s full operation. The aim is to understand the advice lifecycle as one connected system: how a prospect becomes a client, how data is collected, how advice is prepared and reviewed, how documents are issued, how client actions are implemented, and how ongoing review obligations are managed.

    The map should follow work from the initial trigger to the final outcome. It needs to show every handoff, decision, system touchpoint, data re-entry, approval, wait state, and exceptions. It should also show where important evidence is created, stored, amended, or lost.

    The most important practical rule: walk each process with the person actually doing the work. The practice principal may describe onboarding as a clear, linear sequence. The client services officer may reveal a different operational reality: information copied from a fact find into a spreadsheet, then entered into planning software, then checked against documents in a shared drive, with missing information chased by email. Both perspectives matter but the detailed operational view is the one that should shape the future system.

    Workflow questionWhat to identifyWhy it matters for later AI use
    What starts the work?Referral, client enquiry, review date, life event, adviser request, or compliance finding.Defines when and how a workflow, automation, or AI assistant may be invoked.
    Who performs the work?Adviser, client services officer, paraplanner, compliance manager, client, or external provider.Establishes accountability, permissions, and escalation paths.
    Which data is required?Client details, entities, tax information, superannuation data, portfolios, documents, and instructions.Defines the data scope and quality needed for reliable AI assistance.
    Where does data move?Planning systems, email, forms, spreadsheets, shared drives, and manual exports.Exposes duplicate entry points and data-reconciliation risks.
    Where is judgement applied?Suitability checks, document review, advice preparation, exception handling, and compliance sign-off.Identifies decisions where human responsibility must remain explicit.
    What proves completion?Approved documents, meeting records, client acceptance, completed tasks, or review evidence.Defines the records the central system must retain.

    The output is a prioritised workflow inventory. You will find issues but do not attempt to fix everything immediately. Start with the department or journey losing the most manual hours, generating the most rework, or creating the greatest operational risk. In many practices, client onboarding, review preparation, advice-document production, and post-meeting administration are sensible early candidates.

    Step 2: Consolidate the stack, absorb, keep, and kill

    Workflow mapping nearly always reveals an overlapping technology stack. Team members may initiate work through email, track it in Monday.com or Trello, maintain client information in spreadsheets, store documents in a shared drive, and then re-enter the same information into planning or accounting software. Individually, each tool may appear useful. Together, they obscure ownership and create significant manual coordination overhead.

    The next step is to sort the stack into three categories: absorb, keep, and kill.

    CategoryTypical examplesPractical action
    AbsorbSpreadsheets, Monday.com, Trello, form tools, internal wikis, disconnected task lists, and lightweight databases.Bring their work-management function and relevant records into the central system wherever practical.
    KeepCore financial-planning software, accounting packages, portfolio or custody systems, and other specialist products with material operational value.Retain these as specialist systems and connect them through controlled integrations.
    KillUnused subscriptions, duplicate platforms, unofficial tools, and applications holding isolated records.Preserve any necessary records, define an archive approach, and decommission them promptly.

    Consolidation does not require replacing every specialist system with one giant platform. Advice businesses will continue to need purpose-built tools for planning, portfolio management, accounting, and related functions. The aim is to create a central operating environment that coordinates work, holds the core relationships, manages permissions, and gives the team a reliable view of each client and process.

    A simple design question provides a useful test: where should a team member go to understand the current state of a client, task, document, review, or exception? If the answer is “it depends”, the stack is not ready to support AI effectively.

    Step 3: Build a single source of truth

    A central system is valuable only when its data model is clear. The third step is to define the core nouns of the practice and the relationships between them. This is the foundation of the single source of truth.

    For an advice business, those core nouns include clients, households, entities, advisers, portfolios, accounts, advice engagements, Statements of Advice, invoices, meeting notes, documents, approvals, obligations, exceptions, and remediation actions. Each item needs a unique identity, a clear owner, a defined lifecycle, appropriate access rules, and a history of material changes.

    The relationships matter as much as the nouns.

    RelationshipWhy it matters operationally
    Client → Household / EntityPrevents an incomplete view of the client relationship and associated structures.
    Client or Entity → Account / PortfolioConnects advice activity to the relevant financial record.
    Advice engagement → SOA → Approval → Client acceptanceCreates a traceable document and decision lifecycle.
    Task → Owner → Status → Due dateShows who is responsible for an action and whether it is progressing.
    Compliance review → Finding → RemediationTurns review work into owned, visible corrective action.
    Document → Client / Entity → Version → SourcePreserves context and reduces doubt about which document is current.

    The governing rule is this: if client information belongs in the central system, it must not also be maintained in an uncontrolled side spreadsheet. This does not prohibit reporting exports or specialist-system records. It means the practice must be able to identify the authoritative record, secure it, update it in one place, and trace material changes.

    This structure also makes governance easier, producing exactly what ASIC expects. When core relationships are explicit, the practice can show what is associated with a client, which document version was approved, who made a decision, and what follow-up work remains outstanding. Without this structure, AI will retrieve only fragments of the story.

    Step 4: Move the team into one home before adding anything else

    Only after the central system and its data model are ready should the practice migrate teams. Move one department at a time, starting with the function carrying the greatest manual load or experiencing the most rework.

    This is not simply a data-migration project but a change-management exercise. Each team needs views that match how it thinks about work. A client services officer may need a queue of missing information, documents awaiting filing, forthcoming review activity, and tasks blocked by a client response. An adviser may need a client-centric view of meetings, outstanding actions, portfolios, advice documents, and review dates. A compliance manager may need visibility of higher-risk cases, incomplete evidence, overdue reviews, and unresolved remediation work.

    The immediate objective is adoption. People should be able to complete their normal work from the central environment without maintaining a parallel process elsewhere. This requires clean data, useful views, clear ownership, sensible access permissions, and active support during the transition.

    Do not automate anything yet. Clean the data and make the central system the team’s home first.

    Premature automation is understandable when a team is already overloaded, but automation built on inconsistent records or unclear responsibility simply repeats poor process more quickly. Establish a stable operating rhythm first: staff trust the data, leaders can see the work, and exceptions are recorded rather than hidden. Only then should automation be introduced.

    Step 5: Add AI agents once the data is ready

    Once the practice has one working home, reliable data, defined records, and appropriate permissions, AI can become useful by augmenting and expanding the decision making. It can retrieve information from the governed environment, prepare drafts, identify missing information, and support routine work without requiring staff to search across disconnected systems.

    Early AI use cases should be narrow, high-value, and easy to supervise. The focus should be on reducing repetitive administrative effort and improving access to existing information, not on replacing accountable professional judgement.

    AI agentPractical roleRequired control
    Document-ingestion agentReads client PDFs and extracts relevant tax, superannuation, entity, or account data into a review queue.Retain the source file, show extracted fields for verification, and require authorised approval before changing records.
    Generation agentDrafts scopes of work, meeting minutes, client correspondence, and first-pass advice-document sections from approved templates and data.Treat output as a draft and preserve review, approval, versioning, and record-keeping steps.
    Operational QA agentLets authorised users query the practice database in plain English, identifying overdue reviews or incomplete client records.Return traceable results, respect permissions, and avoid unsupported conclusions.
    Workflow-assistance agentIdentifies missing evidence, suggests the next task, and prepares process-stage checklists.Recommend and route work. Never silently override workflow or accountability.

    Every agent should have a defined purpose, approved data scope, bounded actions, visible source traceability, an audit history, and a named human owner. Users should understand which sources informed an answer, what may be incomplete, and how to correct a record or escalate a concern.

    The line between assistance and accountability must remain clear. An agent can retrieve, draft, classify, summarise, check, and route. Decisions with material client, professional, legal, or compliance consequences must remain within appropriately authorised and reviewable human processes.

    Step 6: Automate the background so the foreground stays human

    Once the central workflows are established and AI is operating inside clear boundaries, automate the background work that keeps the practice organised. This is where the operating system eliminates low-value coordination without removing visibility or control.

    Examples include status updates, compliance reminder triggers, review scheduling, document filing, requests for missing information, task creation, approval routing, exception-expiry notices, and data-quality checks. These processes should run quietly in the background while making the need for human attention clear when a decision or exception arises.

    Background automationPractical outcome
    Status updates and routingCompletion of one task updates the relevant record and creates the next owned action.
    Compliance remindersResponsible staff are notified before a review, document, evidence item, or exception becomes overdue.
    Review schedulingReview work is created according to agreed service cadence, client circumstances, or engagement status.
    Document filingApproved records are linked to the correct client, entity, engagement, and process stage using structured rules.
    Data-quality checksMissing fields, duplicate identifiers, or inconsistent relationships enter a managed exception queue.
    Management visibilityLeaders see current workload, client pipeline, outstanding obligations, and operational bottlenecks.

    Each automation should be observable and governed. The practice should be able to see what ran, what changed, what failed, and who owns the resulting exception. Background processes reduce administrative burden. They must not become invisible black boxes.

    A useful by-product of working through this sequence is that AI governance develops naturally alongside it. Identification of the use cases, classifying data clearly, identifying the owner and where a human-in-the-loop is required, understanding what third-party vendor tools actually do, and establishing logging, validation, and audit trails are not separate governance tasks. They emerge from building the system correctly in the first place and allows producing effective Governance guidelines, policies, and procedures that regulators expect easy.

    The sequence works because daily utility drives adoption

    Systems change and software adoption is rarely a training problem. It is more often a daily-utility problem. Staff adopt systems that simplify their work, help them find the right information, and remove unnecessary follow-up. They resist systems that add another place to log activity or create obligations without making the work easier.

    This sequence changes the experience of work before it adds intelligence. First, it maps reality. Then it removes duplicate tools, establishes one source of truth, and moves teams into a practical home. Only after the operating environment is stable does it add AI and background automation.

    For a financial advice and other regulated businesses, this is the practical path to AI implementation: design the operating system, establish the data foundation, move the team into one home, then automate and augment with control. The result is not only a more modern technology stack. It is a more coherent, usable, and scalable practice. If your practice is ready to build this foundation, get in touch and we can help you design and implement each step.

  • When AI Goes Quiet: A Guide to Model Vital Signs

    In 2024, Air Canada lost a court case because their chatbot gave a customer incorrect information about bereavement travel discounts. The chatbot was confidently wrong and still running, still responding, still appearing to work. Nothing in their monitoring stack flagged the problem. Air Canada was held legally liable for what their AI said.

    This is AI drift in its most expensive form.

    Unlike traditional software, which fails loudly with error messages, system crashes, alerts – AI models degrade quietly. A model performing well in January can be generating hallucinations or biased outputs by June, and nothing will tell you. No alarms fire. No tickets are raised. Your system just gradually becomes less reliable, and you find out when a customer complains or a court rules against you.

    This is the central challenge of AI in production: not building it but keeping it trustworthy over time.

    What AI Drift Actually Is

    Drift is the umbrella term for any change that causes a model’s performance to degrade after deployment. It takes three main forms.

    Data drift occurs when the inputs your model receives in production no longer resemble its training data. Customer demographics shift. Upstream data pipelines change. New product categories appear. The model was built for a snapshot of your world, not for the world as it is now.

    Concept drift is more insidious. Here, the relationship between inputs and outputs changes even when the data itself looks similar. A spam filter trained on 2022 phishing patterns will increasingly miss 2026 phishing tactics. The inputs still look like emails. The model’s understanding of what “spam” means is just no longer accurate.

    Feature drift involves structural changes in your data pipelines: renamed columns, altered categorical encodings, new data sources. This one is often detectable through validation but catastrophic when missed.

    For large language models, drift manifests differently again. Decreased response relevance, inconsistent tone, incomplete task execution. Critically, the non-deterministic nature of LLM outputs means a successful API call can still deliver hallucinated or harmful content. The model “works”, it just doesn’t work correctly.

    Why Silent Failure Is the Real Risk

    Most AI monitoring in organisations focuses on infrastructure: uptime, latency, error rates. These metrics tell you whether your model is responding. They don’t tell you whether it’s right.

    This gap creates the conditions for silent failure. Performance erodes gradually. Users notice before engineers do. Users stop trusting the system, work around it, or act on incorrect outputs. By the time the problem surfaces, it may have been compounding for weeks.

    The consequences follow a predictable sequence: eroded customer trust, rising operational costs as human intervention fills the gap, and legal exposure of the kind Air Canada experienced. The harder problem is that hallucination risk compounds with drift. As a model’s semantic consistency weakens, it becomes more likely to produce plausible-sounding outputs that are factually wrong, and harder to distinguish from correct ones.

    You don’t need better incident response. You need earlier detection.

    The AI Vital Signs Dashboard

    The solution is to track AI vital signs; measurable indicators that reveal what’s happening beneath the surface before it becomes a crisis. CTOs managing AI in production should track a number of metrics weekly, each functioning as a vital sign for model health. Some examples are below, and can vary depending on what systems you’re monitoring.

    1. Hallucination Rate

    A hallucination is when your model generates a confident, plausible-sounding response that is factually incorrect or unsupported by any source it has access to. For LLMs, this is the most visible form of drift, and the most legally exposed.

    Monitoring hallucination rate requires more than infrastructure tooling. Effective approaches combine automated scoring systems, external knowledge-base verification, and human review of sampled outputs. LLM-as-judge frameworks where one model evaluates another’s outputs against a ground truth, are increasingly used in production environments. What matters is that you have a weekly number, established trends, and a threshold that triggers investigation.

    2. Latent Drift in Conversations

    In conversational AI, drift can occur within individual interactions as well as across them. As a context window fills, or as a conversation extends across multiple turns, the model’s internal reasoning can subtly shift resulting in losing track of earlier context, becoming less coherent, or drifting from the intended purpose of the interaction.

    The signal for this is often indirect: rising conversation abandonment rates, increased follow-up questions, users repeating themselves. More precisely, tracking how the semantic distribution of model outputs changes over time by using a similarity measure to compare outputs from one period to the next can surface drift before it becomes visible in user behaviour.

    3. Drift Across Conversations

    Where latent drift measures what happens within a conversation, this metric tracks change across your entire user base over time. Are response lengths shifting? Is sentiment changing? Are the same prompts producing meaningfully different outputs week to week?

    This is the macro view of model health. Monitoring output variance such as response length distributions, topic patterns across outputs, how similar prompts perform over time, reveals whether your model’s core behaviour is stable or drifting. Version-controlling your prompts and system instructions is a prerequisite for this analysis. Without it, you cannot isolate model changes from prompt changes.

    4. Token Cost-to-Value

    This is the economic vital sign that can be used to capture many other unmonitored aspects. LLMs charge by token, and costs can escalate quickly and quietly. But cost is relative to the value the model generates.

    Track token usage per request and per feature. Then correlate those costs against business outcomes: conversion rates, support ticket resolution times, task completion rates, revenue attributed to AI-powered features. When cost-to-value deteriorates, shown through rising costs while outcomes remain flat or fall, this is often an early signal that model performance is degrading in ways other metrics have not yet caught.

    What to Do with an AI Vitals Dashboard

    The dashboard described here is not a one-time audit. It is an ongoing operating rhythm.

    Set thresholds for each metric. Define what acceptable looks like for hallucination rate, conversation drift signals, output variance, and cost-to-value. When a metric breaches that threshold, that is your trigger for systematic diagnosis through structured investigation rather than panic. Is the model drifting, or has something changed in the data pipeline? Are prompts being updated without version control? Has an upstream data source changed?

    The organisations that manage AI reliably do not necessarily have better models. They have better systems around their models. Monitoring is what separates AI that erodes quietly from AI that stays accountable.

    Your models will drift. The question is whether you find out first.

  • The AI Maturity Scale: A Framework for Secure and Responsible AI Adoption

    Most AI programmes don’t fail because the model was wrong. They fail because the organisation wasn’t ready to fully support the model.

    A model that recommends biased lending decisions at scale is worse than no model at all. A system that no one can audit when something goes wrong isn’t trustworthy. Data that isn’t properly curated sends the model in the wrong direction. The gap between a promising AI pilot and a responsibly deployed system is almost never technical. It’s organisational.

    The AI Maturity Scale gives you a structured way to assess where you actually stand and what you need to do before you move forward. This article maps the key dimensions of that assessment, the stages organisations progress through, the governance and technical checkpoints that mark real progress, and the risks that shift and compound, as AI becomes more deeply embedded in operations.

    Throughout, the analysis integrates with the Galdren SECURE-AI framework, which provides the ethical and operational structure for responsible adoption at each stage.

    The Six Dimensions That Determine AI Readiness

    AI maturity isn’t a single measure. It spans six interconnected capabilities, each of which can advance or constrain the others.

    Strategy: Does Your AI Serve the Business, or the Other Way Around?

    AI maturity begins with a clear strategy that connects AI initiatives to real business objectives. Organisations at early stages often pursue AI because it’s available or visible, not because it solves a defined problem. Higher-maturity organisations maintain a prioritised portfolio of use cases with established metrics for measuring business impact. They know which AI investments are working and which aren’t, and they have the systems to tell the difference.

    Data Readiness: Garbage In, Liability Out

    AI systems produce outputs that reflect the quality of their inputs. Data readiness covers availability, quality, accessibility, and the ethical use of data. Mature organisations maintain robust governance frameworks, comprehensive data pipelines, and clear processes for data annotation, validation, and lifecycle management. They treat data privacy and security as requirements from day one, not compliance tasks bolted on at the end.

    Technology and MLOps: The Infrastructure That Keeps AI Reliable

    Scalable, reliable AI requires more than a well-trained model. It requires the infrastructure to deploy, monitor, and maintain that model as conditions change. This means automated CI/CD/CT (Continuous Integration, Continuous Delivery, Continuous Training) pipelines, version control, and real-time monitoring. Higher-maturity organisations can detect model degradation, redeploy updated versions, and trace outputs back to specific data and model configurations. Lower-maturity organisations often discover problems through customer complaints.

    Governance and Controls: Ethics Embedded, Not Audited After the Fact

    Governance and controls determine whether an organisation can demonstrate that its AI is ethical, compliant, and accountable. This includes the policies and standards governing AI development, clear definitions of who owns decisions (and who answers when something goes wrong), and audit mechanisms that create verifiable records. At lower maturity levels, governance is reactive and incomplete. At higher levels, it’s designed into the system from the start, not added under pressure when something fails.

    Talent and Operating Model: AI Is a Team Sport

    The technical quality of an AI system is bounded by the capability of the people building and operating it. This dimension assesses whether organisations have the right mix of skills – data scientists, ML engineers, AI ethicists, business translators – and whether those people work in structures that support good decisions. High-maturity organisations build cross-functional teams by design, not by accident, and establish career pathways that retain AI expertise rather than cycling it out.

    Risk Management: Know What You Don’t Know

    AI introduces specific risks that traditional risk management frameworks weren’t built to handle. Bias, model drift, adversarial attacks, and privacy exposure all require dedicated assessment and mitigation. Mature organisations integrate risk review throughout the AI lifecycle rather than treating it as a pre-deployment checkpoint. They also maintain incident response plans. Because the question for production AI systems isn’t whether something will go wrong, but whether you’ll know quickly enough to respond.

    The Five Stages of AI Maturity

    Organisations typically move through five recognisable stages, from ad-hoc experimentation to fully embedded, governed production. Progress is neither automatic nor guaranteed and each stage has distinct characteristics and requires deliberate work to advance.

    Maturity StageCharacteristicsAI StatusKey Focus
    UnawareNo established processes for data or AI; informal relationships; no visibility into data quality.Experimental / ad-hocBuilding basic understanding of AI’s potential and limitations.
    AwareRecognition of AI risks; reactive and inconsistent responses; manual reviews of some datasets.Early experimentationAddressing immediate risks; informal governance beginning to form.
    EmergingBuilding systematic approaches; formalising AI data governance; limited automation.Pilot projectsEstablishing foundational processes and success criteria.
    ManagedEstablished processes and governance; increasing automation; comprehensive AI data governance programmes.Production with oversightProactive risk management; measurable accountability.
    OperationalAI trust embedded in operations; fully automated governance infrastructure; real-time monitoring and enforcement.Fully embedded productionSeamless, governed, and adaptive AI deployment.

    The journey from Unaware to Operational is not primarily a technology investment. It’s an organisational one. The technical capabilities tend to follow when the strategy, governance, and operating model are built correctly.

    Two Types of Gates: Governance and Pipeline

    Advancing through the maturity scale requires passing two distinct types of checkpoints. Governance gates are human decisions. Pipeline gates are automated or semi-automated technical controls. Both are necessary. Neither is sufficient on its own.

    Governance Gates: The Questions You Must Answer Before Moving Forward

    Governance gates are structured decision points where stakeholders assess the ethical, legal, and business implications of an AI solution before it advances. They ensure that AI development reflects organisational values and regulatory obligations, not just technical capability.

    Value Scoping Gate: Is this worth building? This gate assesses business impact, data availability and ethical use, deployment context, social implications, and initial risk. Many AI projects that consume resources for months should have been stopped here.

    Solution Design Gate: How will this be built? This gate defines whether to build, buy, or use third-party AI, refines business specifications, and confirms that success criteria are measurable and agreed upon.

    Model Validation Gate: Does it actually work as intended? Rigorous testing, performance evaluation, and bias detection before anything moves toward deployment.

    Deployment Approval Gate: Is it ready for production? This reviews security, scalability, integration requirements, and operational readiness.

    Operational Transition Gate: Can the business run this without the project team? This ensures documentation, handover to operational teams, and ongoing support structures are in place.

    Model Lifecycle Management Gate: Should this model continue, be retrained, redesigned, or retired? This gate runs throughout the model’s operational life, not just at deployment. Skipping it is how organisations end up running models that are months or years behind their operating environment.

    Pipeline Gates: Automated Controls That Catch What Humans Miss

    Pipeline gates are the automated checkpoints embedded in the MLOps pipeline. They enforce quality, performance, and compliance standards consistently without depending on someone remembering to check.

    Code Quality Gate: Automated checks for code style, bugs, and security vulnerabilities before code is merged.

    Data Validation Gate: Verifies data quality, schema integrity, and the absence of bias in inputs.

    Model Performance Gate: Automated evaluation of accuracy, precision, recall, and other task-relevant metrics against predefined thresholds.

    Bias and Fairness Gate: Detects algorithmic bias before it reaches production. This gate exists because human reviewers, operating under time pressure, consistently miss what automation finds reliably.

    Security Vulnerability Gate: Scans models and dependencies for known security weaknesses.

    Compliance Gate: Automated checks against regulatory requirements and internal policy.

    Monitoring Configuration Gate: Confirms that logging, alerting, and monitoring are properly configured before deployment completes.

    How Risk Changes Across Maturity Stages

    The nature of AI risk shifts as organisations mature. At lower stages, risks are mainly from ignorance and exposure. At higher stages, the stakes of failure are greater precisely because AI is more deeply embedded in operations.

    Risk CategoryUnaware / AwareEmerging / ManagedOperational
    ReputationDamage from failed experiments; perception of irresponsible AI use; limited transparency.Negative public reaction to biased models; data breaches; ethical missteps with limited accountability structures to respond.Systemic failures at scale; widespread ethical violations; regulatory non-compliance; sustained loss of public trust.
    SecurityBasic vulnerabilities; unauthorised data access; insecure development practices.Expanded attack surface; data poisoning; model evasion attacks; insider threats; insecure APIs.Sophisticated attacks targeting AI infrastructure; supply chain compromise; large-scale breaches of systems with critical dependencies on AI outputs.
    Compliance and EthicsUnintended bias; privacy violations; absent documentation; exposure to emerging regulations.Non-compliance with GDPR, CCPA, and other data protection frameworks; lack of auditability; limited accountability.Severe regulatory penalties; legal challenges; class actions; systemic discrimination; inability to demonstrate ethical AI practices to regulators or the public.

    The pattern here is consistent with systems thinking: problems that go unaddressed at early stages don’t stay small. They get embedded, scaled, and eventually visible in the worst possible context.

    Mature Governance Isn’t an Audit. It’s a Design Principle.

    At higher maturity levels, governance isn’t something that happens to an AI system after it’s built. It’s designed into the system from the start.

    This is the distinction that separates organisations that say they take responsible AI seriously from those that actually do.

    Integrated governance means:

    Design-by-ethics: Fairness and ethical constraints are scoped at the start of a project, not retrofitted when a model produces uncomfortable outputs.

    Automated policy enforcement: MLOps tooling enforces data governance policies, access controls, and compliance checks without depending on human memory or discipline.

    Continuous monitoring and auditing: Real-time monitoring tracks model performance, bias, and drift. Automated audit trails provide transparency and accountability that can survive personnel changes and regulatory scrutiny.

    Cross-functional collaboration by structure, not goodwill: Permanent mechanisms for business, technical, legal, and ethics teams to maintain oversight together. Not ad-hoc meetings when a problem surfaces.

    Adaptive governance: Frameworks that evolve as AI technology, regulation, and societal expectations change. Governance that was fit for purpose two years ago may not be fit for purpose today.

    Where to Start

    The AI Maturity Scale is a diagnostic. The value is knowing your organisation is at stage two or four and which specific capabilities are limiting your progress and what you need to do to address them.

    Most organisations will find gaps across multiple dimensions simultaneously. That’s normal. The organisations that get this right don’t try to advance all dimensions at once. They identify the capabilities that are creating the most risk or limiting the most value, and they build from there, systematically, with governance embedded from the beginning rather than added when the regulator asks for it.

    The Galdren SECURE-AI framework provides the structure to guide that work. But the first step is an honest assessment of where you actually stand.

  • A Critical Guide for Businesses Navigating AI Data Privacy

    You’re using AI. So is your competitor. So is your supplier, your client, and the contractor you onboarded last quarter. What’s less certain is whether any of you know exactly what’s happening to your data once it leaves your systems.

    As artificial intelligence becomes embedded in business operations, the questions that matter are about custody. Where does your data go? Who can access it? Is it being used to train the model you’re paying to use? And when regulations evolve, who carries the liability?

    This guide addresses those questions directly, and closes with a due-diligence checklist your team can use today.

    What Happens to Your Data Depends on Which Product You’re Using

    A primary concern for leveraging AI is the extent to which your data – particularly proprietary or client-sensitive information – is exposed to third-party AI models. The answer depends almost entirely on which tier of a provider’s product you’re using and what your contract actually says.

    OpenAI explicitly states that business data submitted through ChatGPT Enterprise, Business, Edu, and Healthcare is not used for training their models by default. Data sent via their API is also generally not used for training. OpenAI’s data retention policy for API usage defaults to 30 days for abuse monitoring, but clients can request Zero Data Retention (ZDR) for eligible endpoints.

    Microsoft Azure OpenAI Service ensures that customer data remains within the Azure environment and is not used to train their models. Customers can select specific regions for data storage, which helps address data residency requirements.

    AWS Bedrock guarantees that customer data is never shared with model providers and is not used to train foundation models. When fine-tuning models on Bedrock, private copies are created, ensuring proprietary data remains isolated.

    Anthropic’s Claude follows a similar pattern. Consumer-tier products may use conversation data to improve models unless users opt out. Their enterprise and API commercial terms, however, include provisions that explicitly prohibit training on client data, consistent with the other providers above.

    The common thread: consumer products carry more risk than enterprise agreements. The critical step is confirming which tier you’re actually on, and what the contract says, not what the marketing page implies.

    Cross-Border Data Transfers Are the Hidden Compliance Risk

    For businesses operating in regulated industries or across multiple jurisdictions, the question of where data is processed matters as much as where it’s stored.

    Data sovereignty means that data is subject to the laws of the nation where it’s collected or processed. This becomes complex when AI models are hosted in a different country from where the data originates. A common situation with cloud-based AI services.

    Azure and AWS both offer regional endpoints that allow businesses to keep data within specific geographical boundaries (the EU, US, UK, and others) to comply with local data residency laws. However, even with data stored in a specific region, processing by an AI model running in another jurisdiction can trigger cross-border data transfer obligations.

    Mechanisms such as Standard Contractual Clauses (SCCs) are commonly used to facilitate legal data transfers across borders. But their validity is subject to ongoing legal scrutiny and evolving international agreements. SCCs are not a set-and-forget solution, they require active monitoring.

    Your Privacy Policy May No Longer Reflect Reality

    Many privacy policies were drafted before generative AI became a standard business tool. A policy that was accurate 18 months ago may now misrepresent how your organisation actually handles data, not because of bad intent, but because the technology moved faster than the documentation.

    If an AI provider’s data practices, such as using data for model training or retaining it beyond expected timeframes, contradict your published privacy policy, that policy becomes a liability rather than a safeguard. Regulators under frameworks like GDPR and CCPA don’t accept “we didn’t know” as a defence.

    Privacy policies need to be treated as living documents. Schedule regular reviews that specifically account for your current AI tool stack, and update them whenever you onboard a new provider or change your usage tier with an existing one.

    Governance as a Practice

    Effective AI data governance requires more than a policy document. It requires consistent operational practice across four areas.

    Governance means establishing clear, documented procedures for how AI data is collected, stored, processed, and deleted, and who is responsible for each stage.

    Access control means ensuring that only authorised personnel and systems can interact with sensitive data used by AI models. This includes reviewing which employees have access to AI tools that connect to sensitive systems.

    Auditability means maintaining comprehensive logs of all data interactions with AI systems. Without this, accountability is impossible and incident response becomes guesswork.

    Downstream processing means understanding how data processed by one AI model might flow to subsequent models or connected services. Many AI platforms integrate with third-party tools, each integration is a potential data pathway that needs to be mapped.

    AI Due-Diligence Checklist

    The following questions should be asked of every AI provider before onboarding, and revisited at each contract renewal.

    Checklist ItemDescription
    Data capturedWhat exact data classes are captured, including prompts, files, attachments, connectors, logs, and metadata?
    Retention and trainingDoes the specific plan or API endpoint use zero retention and no training?
    Subprocessors and providersWhich subprocessors and model providers can receive the data?
    Data storage and processingWhere is data stored, processed, and backed up?
    Cross-border transfersCan data leave your jurisdiction, and under what transfer mechanism?
    Data deletionIs deleted data actually deleted, and on what timeline?

    The Work Starts Before You Need It

    The organisations that navigate AI data governance well won’t be the ones with the most sophisticated legal teams. They’ll be the ones that built their governance frameworks before they needed them.

    The checklist above isn’t a one-time exercise but a repeating process. AI providers update their terms of service. Regulations evolve. New subprocessors appear in contracts that previously didn’t include them. The questions you ask today need to become the questions you ask every time you onboard a new tool, renew a contract, or expand into a new jurisdiction.

    The risks outlined in this guide – data used for model training without consent, cross-border transfers that breach local regulations, privacy policies that no longer reflect actual practice – are predictable. Predictable risks can be managed. But only if the system to manage them is already in place when the situation arises.

    Start with the checklist. Build it into your procurement and governance process. Revisit your privacy policy against your current tool stack. Know exactly where your data goes, under what terms, and with what protections in place.

    That’s the work. And the time to do it is now.

  • Claude Code Leak: Security Lessons Learned

    On 31 March 2026, Anthropic, one of the world’s leading AI safety companies, accidentally published the source code for its Claude Code command-line tool. A packaging error bundled a debug map file into a public npm update, exposing approximately 500,000 lines of code across nearly 1,900 files. Anthropic confirmed no customer data or credentials were compromised, but the leak revealed proprietary techniques and instructions at the heart of their AI coding agent.

    This was not a sophisticated attack. No adversary breached their perimeter. A human made a routine deployment error, and as AI agents perform more work, these events will happen more often. A single missing control turned it into a public incident.

    That distinction matters. Because if a company built entirely around AI safety, with the world class resources, talent, and incentives to get security right, can have a packaging error become a front-page story, the question for every other organisation is not “could this happen to us?” It already can, the only real question is: how ready are you when it does?

    A Single Layer of Defence Is Never Enough

    The Anthropic incident is a textbook case for security in depth – the practice of building multiple, independent security controls so that no single failure becomes a catastrophe.

    Most organisations think about security as a perimeter. Keep attackers out, and you are safe. But the Anthropic leak did not involve an attacker at all. It involved an insider, following a normal process, making a human error. The perimeter was irrelevant.

    Security in depth acknowledges this reality. Each layer operates independently, so a failure at one level, say application packaging, does not automatically compromise everything else.

    LayerWhat it protectsExamples
    PhysicalHardware and infrastructureAccess controls, surveillance
    NetworkTraffic and access pointsFirewalls, intrusion detection, VPNs
    HostServers, workstations, devicesEndpoint protection, OS hardening
    ApplicationSoftware and deployment processesSecure coding, release controls, security testing
    DataInformation at rest and in transitEncryption, access controls, data loss prevention

    The Anthropic failure occurred at the application layer – specifically in the release packaging process. A pre-release security scan of outbound npm packages, or an automated check for debug artefacts, could have caught it. That control was missing.

    One absent control at one layer produced one very public incident. As we move to a more AI agents performing work, these layers will become even more important.

    Preparation That Performs Under Pressure

    Knowing the layers of a security framework is useful. Having a tested response plan is what actually limits damage when something goes wrong.

    A crisis response plan (CRP) is not a document filed in a drawer for legal purposes. It is a practised capability. The organisations that navigate breaches well are not the ones who improvise better, they are the ones who have rehearsed this scenario until the response is automatic.

    The core phases of an effective data breach response are:

    Preparation. Establish an incident response team with defined roles before anything happens. Run simulations. Develop notification templates. Identify who has authority to make decisions at 3am. This is the only phase you have complete control over.

    Identification and assessment. When a potential incident is detected, verify it, scope it, and understand what was affected. Good monitoring tools and forensic capability determine how quickly you move from suspicion to certainty.

    Containment. Stop the spread. Isolate affected systems, revoke compromised credentials, pull problematic packages from distribution. Anthropic acted quickly here, the package was removed promptly once the issue was identified. Speed in this phase directly limits the impact.

    Eradication and recovery. Find the root cause, not just the symptom. Patch the vulnerability, rebuild affected systems, and implement the control that was missing. A phased return to normal operations is preferable to rushing and missing something.

    Notification and communication. Legal obligations around notification vary by jurisdiction and data type. Beyond compliance, how you communicate with affected parties – customers, partners, regulators – shapes whether trust survives the incident. Transparency and clarity matter as much as speed.

    Post-incident review. Once the immediate crisis is resolved, the most valuable work begins. What failed? What worked? What needs to change in the process, not just the technology? A single incident, treated as a learning opportunity, should permanently improve the system. The same incident occurring twice is a signal that the learning did not happen.

    Where to Start

    The Anthropic incident is a useful prompt, but not because Anthropic is unusual. It is useful because the cause was ordinary: a human error in a routine process that a missing control did not catch.

    That description fits most data incidents. Which means the most productive question to ask right now is not “what would we do if we were breached?” but “which of our routine processes has no independent control to catch a human or AI error?”

    Start there, mapping the answer. Then build the control that is missing.

    A crisis response plan is worth nothing if it has never been tested. Schedule a simulation. Find the gaps in your plan before an incident does.

    The Anthropic team moved quickly to contain and communicate. That is what preparation looks like in practice. It does not prevent the human error. It determines what happens next.

  • Why Practical AI Ethics Training Is Your Next Strategic Investment

    Your organisation is almost certainly using AI. The question is whether your people know how to use it responsibly – and what it’s costing you that they don’t.

    Most organisations treat AI ethics as a compliance exercise: a set of principles pinned to the intranet that nobody reads. Meanwhile, their teams are prompting generative AI tools with sensitive data, accepting outputs without verification, and making decisions with no clear accountability. The gap between having AI principles and practising them is where risk lives, and where real competitive value is lost.

    The organisations closing that gap are doing something specific. They’re investing in structured, role-based training that turns abstract ethical commitments into daily behaviours. And the evidence suggests this investment pays for itself.

    AI Ethics Training

    The Business Case Is No Longer Theoretical

    Research published in the California Management Review by Domin et al. (2024) presents a holistic framework showing that organisations with mature AI governance generate returns through two pathways: reducing direct costs (regulatory fines, compliance failures, reputational damage) and building indirect value through stronger capabilities and stakeholder trust. The researchers found that organisations frequently justify ethics investments reactively – responding to regulatory pressure or market events – but those who invest proactively unlock broader strategic value.

    PwC’s 2025 Responsible AI Survey reinforces this finding. Nearly 60% of executives reported that responsible AI practices directly improved ROI and operational efficiency, while 55% cited improvements in customer experience and innovation. Organisations at the most mature stages of responsible AI adoption were roughly 1.5 to 2 times more likely to rate their governance capabilities as effective compared to those still building foundations.

    This is building an organisational capability that compounds over time.

    One Training Program Doesn’t Fit Every Role

    A blanket AI training session might raise awareness, but it won’t change behaviour. The person using an AI writing assistant daily faces different risks than the manager approving an AI-powered workflow, who faces different risks again from the governance specialist auditing model outputs.

    Effective training recognises these distinctions. A tiered approach ensures each group receives training that is relevant to their actual responsibilities and decision-making authority:

    TierAudienceFocusWhat They Learn
    A: All StaffGeneral AI usersFundamentals, risks, and daily behavioursCore AI principles, common risk identification, responsible day-to-day use
    B: ManagersProduct owners, team leads, operations managersOversight, approvals, and risk-based decisionsOversight workflow design, accountability structures, informed risk assessment
    C: SpecialistsRisk, legal, data, and governance teamsGovernance frameworks, lifecycle controls, and auditsGovernance implementation, lifecycle controls, alignment with external standards

    This structure means the frontline user learns to spot risks in their own context, the manager learns to design oversight that actually works, and the specialist builds the governance architecture that holds it all together.

    What the Training Should Actually Cover

    The curriculum needs to move beyond slides about AI principles and into practical, role-specific competence. Four interconnected areas form the foundation.

    Teach people to recognise risk before it becomes a problem

    The starting point is building a shared language for discussing AI across the organisation. Every employee should understand what generative AI is, how it works at a functional level, and where the common failure points sit, such as bias, privacy breaches, hallucination, and over-reliance on automated outputs. Critically, this isn’t about abstract risk categories. It’s about training people to identify these risks within their own operational context, using their own tools, in their own workflows.

    Make human oversight practical, not theoretical

    “Human-in-the-loop” is a phrase that appears in every AI governance document. Far fewer organisations have defined what it actually looks like in practice. Training should equip managers with concrete models for oversight, such as when a human reviews every output, when a human monitors patterns and intervenes on exceptions, and when full automation is appropriate. Practical exercises like building RACI charts for AI projects translate accountability from a principle on paper into an operational reality.

    Embed governance across the full AI lifecycle

    For managers and specialists, the programme should cover the complete AI lifecycle: from initial problem definition through development, deployment, monitoring, and eventual retirement. This includes integrating AI-specific controls into existing policies and aligning with established frameworks such as the NIST AI Risk Management Framework or ISO/IEC 42001. The goal is to embed ethical considerations at every stage, not bolt them on as a final review before launch.

    Address generative AI use directly

    Generative AI is already in your organisation, whether you’ve formally approved it or not. Every employee needs specific guidance on responsible prompting, output verification, and data handling. This means clear rules about what information can and cannot be entered into AI tools, and practical skills for critically evaluating the accuracy and appropriateness of AI-generated content before acting on it.

    Why This Investment Compounds

    The returns from structured AI ethics training extend well beyond avoiding the next headline-making AI failure.

    Organisations that build genuine responsible AI capability protect their bottom line through prevention. The Berkeley research highlights that the most valuable returns are often indirect – stronger brand reputation, deeper client trust, and reusable governance infrastructure that improves efficiency across the organisation. PwC’s data shows these benefits are already measurable for organisations that have moved beyond the foundational stage.

    There is also a talent and trust dimension. In a market where every organisation claims to use AI responsibly, the ability to demonstrate that commitment through trained teams, documented processes, and genuine accountability becomes a meaningful differentiator. Customers, partners, and prospective employees notice the difference between a policy statement and an organisation that actually operates by its principles.

    Perhaps most importantly, a workforce trained in responsible AI is a workforce that feels confident experimenting. When people have clear guidelines and understand the boundaries, they are more likely to explore new applications, identify efficiencies, and propose innovations. You don’t get that from a compliance checkbox. You get it from genuine capability built through deliberate practice, because you don’t rise to the occasion, you fall to your level of preparation.

    Start With What You Can Control

    You can’t control the pace of AI regulation. You can’t control what your competitors do. But you can control how prepared your organisation is to use AI responsibly and effectively.

    A structured, role-based training programme is the most direct path from ethical principles to operational practice. It turns good intentions into daily behaviours, and daily behaviours into sustainable business value.

    The organisations that invest in this capability now won’t just be better prepared for the next regulatory requirement. They’ll have built something far more valuable: a culture where responsible AI isn’t a separate initiative, but simply how the work gets done.


    References

    Domin, H., Rossi, F., Goehring, B., Ganapini, M., Berente, N., & Bevilacqua, M. (2024). On the ROI of AI Ethics and Governance Investments: From Loss Aversion to Value Generation. California Management Review. https://cmr.berkeley.edu/2024/07/on-the-roi-of-ai-ethics-and-governance-investments-from-loss-aversion-to-value-generation/

    PwC. (2025). 2025 US Responsible AI Survey: From Policy to Practice. https://www.pwc.com/us/en/tech-effect/ai-analytics/responsible-ai-survey.html

  • The Silent Sabotage: Why Employee Resistance is a Threat

    The current wave of artificial intelligence promises unprecedented productivity gains, yet for many business leaders, the reality proves far more complex than projections suggest. An often overlooked barrier to successful implementation is not technological complexity or cost, but a crisis of trust manifesting as employee resistance and outright sabotage. This phenomenon, driven by the existential fear captured in the question “Who is going to be motivated to adopt if they know the intent is to replace them?”, demands a fundamental shift in leadership strategy.

    Silent AI Sabotage

    The Anatomy of AI Resistance

    Recent research reveals a significant portion of the workforce actively undermining their organisation’s AI initiatives. A comprehensive survey found that 31% of employees admit to actively sabotaging their company’s AI strategy, a figure that rises to 41% among Millennial and Gen Z workers. This resistance extends beyond passive non-compliance into deliberate, often covert actions designed to slow or discredit the technology.

    The forms of sabotage target the metrics and outputs that validate AI’s value proposition:

    Category of ResistanceSpecific Employee ActionsStrategic Impact
    Performance TamperingManipulating data or metrics to make AI-driven processes appear to underperform or failUndermines the business case for AI investment and adoption
    Output DegradationIntentionally generating low-quality inputs or outputs when using AI toolsCreates a perception that the AI is unreliable or produces poor results
    Refusal and AvoidanceRefusing to use new generative AI tools, declining mandatory training, or slowing work to demonstrate human necessityCreates bottlenecks and prevents the realisation of efficiency gains
    Shadow AIUsing unauthorised, out-of-pocket AI tools for work tasks, often entering sensitive company data into unapproved platformsIntroduces significant data security and compliance risks

    The root cause of this behaviour is not technological fear, but fear of diminished value and job displacement. Approximately one-third of employees believe AI will diminish their creativity or value, and nearly 30% worry it will take over their job. When leadership fails to articulate a clear, human-centric vision for AI, employees rationally conclude their role is under threat, making resistance a form of self-preservation.

    Lessons from Contrasting Approaches: Gaming Versus Finance

    The tension between aggressive AI mandates and employee morale is starkly illustrated across different industries, offering clear lessons on what works and what fails.

    The Gaming Industry’s Cautionary Tale

    The gaming sector has become a flashpoint for AI backlash, where rapid AI content generation has met widespread internal and public condemnation. Korean publisher Krafton, known for PUBG, declared its intention to become an “AI-first” company in late 2025, investing over 130 billion won ($88 million) in AI infrastructure. Weeks later, the company launched a voluntary resignation program offering substantial buyouts.

    While framed as voluntary, the message was clearly that the company’s future centred on AI. This move, coupled with a hiring freeze except for AI-related roles, has created a toxic environment where AI automation is making developers “miserable” and fuelling public backlash against “AI slop”. The consequence is a loss of institutional knowledge, declining morale, and public relations crises that damage brand relationships with core customers. Reports suggest several studios have cancelled titles due to the negative reception of AI-generated content.

    The Extreme End: Mass Replacement

    The most extreme example comes from IgniteTech CEO Eric Vaughan, who laid off nearly 80% of his staff over a year because they “refused to adopt AI fast enough”. Vaughan’s rationale was that “changing minds was harder than adding skills”, and he replaced the resistant workforce with “AI Innovation Specialists”. While he claims extraordinary financial results, this radical replacement strategy serves as a warning. It is a high-risk, high-cost maneuver that sacrifices years of employee loyalty and institutional knowledge for rapid, painful transformation.

    The Proactive Model: Citigroup’s Strategic Reskilling

    In contrast, the finance sector offers a model for measured, human-led transition. Citigroup CEO Jane Fraser has taken a public stance on AI-driven job change, responding with mass reskilling rather than mass replacement. Citigroup mandated AI training for its entire workforce of 175,000 employees across 80 locations, encouraging them to “reinvent themselves”.

    Fraser’s message combines clear-eyed realism with empowerment:

    “Not that AI is going to take your job away, but someone using AI is going to probably be better at your job than you are. So, how do we equip you to use [AI tools]?”

    By framing AI as a necessary co-pilot and investing in mandatory, adaptive training – such as prompt engineering – Citigroup achieved widespread adoption of its proprietary tools across 180,000 employees. This approach transforms the conversation from job elimination to career evolution, leveraging existing talent and institutional knowledge rather than discarding it.

    Beyond the Hype: A Balanced View of AI’s Value

    To overcome resistance, leaders must first temper AI hype. The technology is not a panacea; it is a tool that augments human capability. Overstating immediate value or presenting AI as a magic bullet for cost-cutting only validates employees’ fear of replacement.

    A balanced perspective recognises AI’s true value lies in automating the mundane and repetitive, freeing human capital for strategic, creative, and empathetic work. This augmentation argument must be the foundation of all internal communication.

    An Actionable Framework for Trust and Co-Creation

    The antidote to sabotage is inclusion. Leaders must move beyond top-down mandates and create a culture of co-creation where employees are part of the solution. The following framework provides actionable steps for building trust and driving successful AI adoption:

    PhaseActionable StepStrategic Rationale
    Radical TransparencyClearly and honestly communicate the AI strategy, specifying which roles will be augmented, which will be transformed, and where job reductions are possiblePreempts fear and speculation, replacing uncertainty with a clear path forward
    Invest in ReskillingMandate and fund comprehensive training programs focused on AI literacy, prompt engineering, and the new skills required to work with AITransforms employees from potential victims into empowered partners, as demonstrated by Citigroup
    Co-Creation and FeedbackInvolve frontline employees in the selection, testing, and deployment of AI tools. Create internal forums for feedback and allow employees to champion the tools they find most effectiveAddresses tool quality complaints and prevents the proliferation of risky “Shadow AI”
    Redefine PerformanceAdjust performance metrics to reward effective use of AI for strategic outcomes, rather than simply measuring output volume. Focus on the quality of human-AI collaborationEliminates the incentive for employees to sabotage metrics to prove AI’s failure
    Nurture AI ChampionsIdentify and reward employees who are enthusiastic about AI. Empower them to serve as internal trainers and advocates, demonstrating AI’s value in real-world workflowsBuilds organic, peer-to-peer adoption and shows that AI proficiency leads to career advancement

    The Path Forward: Transformation Through Trust

    The challenge of employee resistance to AI is fundamentally a leadership challenge. A test of an organisation’s commitment to its people. The contrast between Krafton’s aggressive displacement approach and Citigroup’s strategic reskilling illustrates two divergent paths forward.

    By shifting the narrative from replacement to reinvention, and by including employees in decisions that affect their jobs and livelihood, business leaders can transform a threat of sabotage into an opportunity for collective, accelerated growth. The question is not whether AI will change work, it’s already happening. The question is whether leaders will choose to bring their people along for the transformation or leave them behind.

    The most successful AI adoptions will be those that treat technology integration as a human challenge first. People, Process, Technology, in that order is the mantra. In this approach lies both the greatest difficulty and the greatest opportunity for lasting competitive advantage.

  • The AI Agent Risk Check

    AI agents represent the most significant shift in workplace technology since the internet. These autonomous systems already execute complex, multi-step tasks across professional environments – from managing sensitive corporate documents to conducting financial analysis. The productivity potential is impressive, but deploying them without proper safeguards risks privacy, security and competitive advantage.

    The scale of adoption demands your immediate attention. Approximately 30% of AI agent queries involve professional tasks within sensitive environments. This is happening in your industry today. That means you face a critical choice: Become someone who harnesses AI agent power safely, suffer the consequences of inadequate preparation, or just fall behind.

    AI Agents execute complex, multi-step tasks, but deploying them without proper safeguards risks privacy, security and competitive advantage

    Security and Privacy is Often Overlooked

    AI Agents differ from traditional AI systems. They don’t just process information, they act on it. AI agents actively work within Google Docs, email platforms, and professional networking sites like LinkedIn, often handling confidential corporate data. This capability creates an entire new category of risk that traditional AI safety protocols weren’t designed to address.

    Consider the exposure: An unsupervised AI agent inadvertently shares confidential documents, sends email containing sensitive data, or access system beyond its intended scope. This is a real risk, already being exploited in the wild.

    These risks become manageable through systematic implementation of foundational controls. For example, stringent access controls that limit agent permissions to essential functions, comprehensive activity logging that creates audit trails, and human-in-the-loop verification for any high stakes decision or data handling.

    The Cognitive Partnership Decay

    Beyond the security concerns lies the erosion of critical thinking through over-reliance. Researchers have identified compelling “cognitive gravity” that draws users from simple tasks towards complex cognitive work including financial analysis and software development. This reveals the AI’s power and potential peril. The shift to cognitive partner creates the temptation for us to increasingly rely on them. Degrading our ability to critically evaluate agent recommendations and allowing errors in agent reasoning to cascades into real-world consequences.

    Success requires establishing collaborative frameworks that augment rather than replace human intelligence. You will get more ongoing benefit if training programs promote healthy scepticism and verification habits. If you design workflows where agents handle data processing and initial analysis, but human retain decision authority for outcomes.

    Access and Competitive Advantages

    Current adoption patterns reveal significant differences with AI agent usage concentrated among high-GDP countries and tech-savy knowledge workers, particularly in sectors like technology, finance, and academia. This concentration creates compound advantages for early adopters while widening gaps with laggards.

    This extends beyond productivity gains. Organisations using AI agents process information faster, analyse complex scenarios more thoroughly, and execute workflows with more consistency than their competition. As agent capabilities keep advancing, these advantages will compound exponentially. This creates both opportunity and urgency. Developing AI agent competency now offers a closing window for first-mover advantage.

    Accountability in an Autonomous World

    Traditional AI governance focuses on expandability – why did the system make that choice? AI agents require a shift towards outcome based accountability – auditing what agents accomplish. This transition from recommendation to action creates accountability challenges that existing governance frameworks can not adequately address.

    This is compounded in multi-step agent sequences. When an agent executes errors across several interconnected actions, determining responsibility becomes much more complex and traditional audit approaches are insufficient.

    Effective governance requires purpose-built accountability frameworks combining things like: sophisticated logging system that provide comprehensive audit trails, legal and ethical guidelines designed for autonomous systems, and culture emphasising shared responsibility across developers and users.

    Using the Risk as Competitive Advantage

    Organisations that thrive with AI agents approach deployment strategically rather than reactively. They build comprehensive guardrails and safety protocols before it’s necessary. They establish clear governance frameworks while agent capabilities are still developing. Most importantly, they create a culture of responsible innovation that balances opportunity capture with prudent risk management.

    This approach treats AI agent risks as a design constraint that inform better implementation rather than an obstacle to overcome. This means higher productivity while maintaining security, enhanced capability while preserving human judgement, and establish technological leadership.

    AI agents are part of your future. If you implement AI agents systematically with proper safeguards and master the balance between opportunity and risk, you will find yourself with significant advantages. If you delay or approach deployment carelessly, you will find yourself managing crises while the competition pulls ahead.

    Book a call to discuss how we can help setup the framework for Safe, Sane, and Secure Agent use.

    Reference: Yang, J., et al. (2025). The Adoption and Usage of AI Agents: Early Evidence from Perplexity. Harvard Business School Working Paper, 26-040. Retrieved from https://arxiv.org/abs/2512.07828

  • Get Your Data Ready for AI

    The Uncomfortable Truth About AI Projects

    The most sophisticated algorithms cannot compensate for poor-quality, fragmented, or inaccessible data. Yet most organisations charge headfirst into AI development without understanding whether their data foundation can support their ambitions. This oversight wastes resources and sets AI programmes back while competitors advance.

    The solution requires no complex technology: conduct a data audit before you begin. This systematic examination reveals whether your data assets can support AI applications, identifies critical gaps, and establishes the foundation for sustainable AI success.

    Get Your Data Ready for AI

    Why Your Data Audit Can’t Wait

    Data auditing means systematically examining your organisation’s data assets to assess their AI suitability. This process identifies inconsistencies, gaps, and potential roadblocks that could derail AI development. More importantly, it reveals the true preparation scope required before productive AI work can begin.

    The audit doesn’t require months of enterprise effort. Most organisations complete their initial assessment in 1-3 weeks with focused work. The insights gained during this period determine whether your AI initiatives deliver transformational value or become expensive lessons in preparation failure.

    Understanding this timeline matters: data preparation typically consumes 60-80% of any AI project’s resources. Organisations that audit first reduce this burden significantly by addressing systematic issues before they become project-specific crises.

    The Four-Point Data Readiness Assessment

    This assessment framework examines the critical areas where data problems derail AI initiatives. Each point builds toward a complete picture of your organisation’s AI readiness, revealing both immediate obstacles and hidden opportunities.

    1. Map Your Data Universe

    Most organisations scatter their data across multiple systems, departments, and locations. This fragmentation creates silos, duplication, and conflicting versions of truth, which are all fatal to AI initiatives. Understanding what data you actually possess becomes the first challenge in AI preparation.

    Your Action: Conduct data inventory across all systems. Include enterprise resource planning (ERP) platforms, customer relationship management (CRM) systems, data warehouses, cloud storage, legacy databases, departmental spreadsheets, email archives, backups, and external data feeds.

    Create a centralised catalogue that details each data source’s location, ownership, purpose, and access protocols. This inventory becomes your map for AI planning, revealing both opportunities and obstacles before development encounters them.

    Success Indicator: You can answer “Where is our customer data?” or “What sales information do we have?” with specific system locations and access procedures, not departmental guesswork.

    2. Assess Data Consistency and Quality

    AI models demand uniformity to function effectively. Data variations in format, layout, and content force extensive preprocessing that consumes 60-80% of project resources. Organisations with inconsistent data often discover this reality only after AI development begins, creating costly delays and reduced accuracy.

    Your Action: Sample five random data files from different sources and examine them systematically. Do dates follow consistent formatting? Do customer identifiers remain stable across systems? Do similar fields maintain identical structure?

    Document discrepancies in data types, naming conventions, and structural layouts. Establish organisation-wide data standards that define common models, validation rules, and integration requirements. Address these inconsistencies systematically rather than project-by-project.

    Success Indicator: Data from different systems can be combined without extensive transformation, and you can predict the effort required to integrate new data sources.

    3. Implement Data Version Control

    Data evolves continuously, and AI models trained on different versions produce dramatically different results. Without proper version control, organisations risk building models on outdated information or losing track of which data produced specific outcomes. This creates unreproducible results and undermines confidence in AI systems.

    Your Action: Establish data version control protocols that track every significant change to datasets, schemas, and processing logic. Assign unique version identifiers to each change and integrate versioning into your data pipelines.

    Ensure data scientists and AI developers always know which data version they’re using. This traceability protects against inconsistent results and enables rapid problem diagnosis when models behave unexpectedly.

    Success Indicator: You can recreate any AI model’s training environment months later using the exact data version originally used.

    4. Unlock Text-Based Information

    Many organisations store valuable information in PDF documents – reports, contracts, research, and historical records. However, image-based PDFs are virtually useless for AI applications without expensive and error-prone optical character recognition preprocessing. This barrier eliminates entire categories of valuable data from AI consideration.

    Your Action: Test a random sample of 10 PDF documents by attempting to highlight text within them. If you cannot select text, the PDF is image-based and requires conversion to searchable format.

    Invest in solutions that convert existing image-based documents to text-searchable formats and establish processes ensuring future PDFs are text-accessible from creation. The information locked in these documents often represents years of institutional knowledge critical for AI applications.

    Success Indicator: Historical documents can be searched and analysed automatically, and new documents are consistently created in text-accessible formats.

    Your Next Steps: From Assessment to Action

    These four assessment areas reveal your organisation’s AI readiness within weeks, not months. The gaps you discover are opportunities to build competitive advantage through superior data foundation.

    Complete this audit before beginning AI development and you’ll consistently deliver projects faster, with higher accuracy, and at lower cost than those who discover data issues mid-project. More importantly, they avoid the reputation damage that comes from AI implementations that fail to meet expectations.

    The competitive window for AI advantage narrows daily, but it remains open if you prepare systematically rather than optimistically. Begin your data audit immediately.