Why Your Chatbot Vendor's EU AI Act Compliance Doesn't Cover Your Article 50 Disclosure Duty
Chris Cook Chris Cook

Why Your Chatbot Vendor's EU AI Act Compliance Doesn't Cover Your Article 50 Disclosure Duty

Article 50 of the EU AI Act takes effect on August 2 and requires any AI system interacting with people to disclose that fact from the first exchange. Most compliance teams assume their chatbot vendor's contract language covers this, but Article 3 splits the obligation by role, and the vendor is not automatically the provider for your deployment. This issue walks through the decision tree for determining provider status across customer-facing, HR, and IT chatbots before the deadline.

Read More
AI Proxy Advisors Are Already Voting Against Management: What Your Board Needs to Test Now
Chris Cook Chris Cook

AI Proxy Advisors Are Already Voting Against Management: What Your Board Needs to Test Now

J.P. Morgan replaced its ISS and Glass Lewis subscriptions in January 2026 with a proprietary AI voting engine, and Kekst CNC's analysis of four major AI models found they backed the activist slate or a split card in 59 to 77% of contested meetings tested -- well above the historical ISS and Glass Lewis management support rate. The models doing that scoring aren't stable either, with re-runs of identical queries changing the vote in 38% of contests. This issue explains what your General Counsel and Head of Investor Relations need to run before your next proxy season, and what the AI is actually being scored against.

Read More
Before You Enable AI in Your Audit Management Platform, Check What Your Data Is Doing
Chris Cook Chris Cook

Before You Enable AI in Your Audit Management Platform, Check What Your Data Is Doing

Workiva, Diligent, and AuditBoard all made AI-centered product announcements at IIA GAM in March 2026, promising to draft process narratives, generate audit plans, and surface board-ready risk insights. What none of them addressed is whether the data inside your platform is clean enough to make those outputs reliable -- and Workiva's own 2025 survey found only one in three practitioners has data of sufficient quality for AI use. This issue explains what a structured data readiness assessment requires before any AI feature gets turned on.

Read More
Why Your AI Governance Committee Needs a Confirmed Inventory Before Approving New Use Cases
Chris Cook Chris Cook

Why Your AI Governance Committee Needs a Confirmed Inventory Before Approving New Use Cases

Most organizations have a governance committee, an acceptable use policy, and a working sense of which AI tools are in use -- but 88% of firms deployed AI before a formal inventory existed, according to McKinsey, which means every approval decision is being made against a picture no one has fully confirmed. Waiting to build the inventory until the Head of AI role is filled trades program speed for a clean handoff, and the deployment acceleration that governance is supposed to enable never arrives. This issue explains who should commission the baseline inventory today and what a complete use case card requires.

Read More
Why Legal Sign-Off on AI Claims Doesn't Satisfy SEC Disclosure Control Requirements
Chris Cook Chris Cook

Why Legal Sign-Off on AI Claims Doesn't Satisfy SEC Disclosure Control Requirements

The SEC's first AI washing enforcement action against Presto Automation made two distinct charges, and the second one didn't require proving any AI statement was false. It only required showing no process existed to verify the claims before publication, which is exactly the gap that legal sign-off alone leaves open. With 72% of S&P 500 companies now disclosing AI as a material risk, this issue lays out the five-part test for whether your firm has a real disclosure control or just a legal review habit.

Read More
Why Unaudited AI Claims in a PE Exit CIM Create Post-Close Warranty Liability
Chris Cook Chris Cook

Why Unaudited AI Claims in a PE Exit CIM Create Post-Close Warranty Liability

Mid-market PE firms are building AI narratives into exit materials to capture valuation premiums, but the claims in a Confidential Information Memorandum travel with the deal as representations that survive closing. The SEC charged two registered investment advisers in 2024 for overstating AI capabilities, and AI-related securities class action filings hit a record pace in the first half of 2025, establishing the enforcement template that is now migrating into R&W insurance claims. This issue explains what documentation a portco must produce before any AI claim goes into sale materials, and why buy-side diligence is increasingly equipped to find the gaps.

Read More
C-Suite AI Risk Divergence Is a Board Governance Problem, Not a Management Communication Problem
Chris Cook Chris Cook

C-Suite AI Risk Divergence Is a Board Governance Problem, Not a Management Communication Problem

Grant Thornton's 2026 AI Impact Survey found that more than half of COOs are concerned about regulatory and compliance failure from agentic AI, while fewer than one in five CIOs and CTOs share that concern. With 83% of S&P 500 companies now disclosing AI as a material risk, a board that receives only the consensus management view has no way to demonstrate active oversight when litigation discovery or a regulatory inquiry arrives. This issue explains why the audit committee is the right standing mechanism to surface that divergence, and the four structural requirements that make it functional.

Read More
Why Your AI Vendor Contract Is Not a Substitute for Independent Model Verification
Chris Cook Chris Cook

Why Your AI Vendor Contract Is Not a Substitute for Independent Model Verification

Courts have already rejected the argument that vendor terms of service shield deploying enterprises from liability -- Air Canada and the Workday and Eightfold AI cases made that clear. A SOC 2 report tells you a vendor controls their operating environment; it says nothing about whether their model produces biased outputs against your specific customer population or drifts from its approved behavior. This issue explains the three independent verification capabilities every regulated enterprise needs to build before the next model update.

Read More
Prepackaged AI Agents Are Not a Governance Shortcut for Regulated Financial Firms
Chris Cook Chris Cook

Prepackaged AI Agents Are Not a Governance Shortcut for Regulated Financial Firms

Anthropic, OpenAI, and Microsoft have all released prepackaged AI agents targeting core regulated financial workflows, and the deployment timelines are genuinely compressed. What is not compressed is your firm's accountability under OCC SR 11-7, EU AI Act Article 9, and NYC Local Law 144, all of which assign risk management obligations to the deploying institution regardless of who built the agent. This issue explains the two paths to compliant configuration and why neither one is free from governance work.

Read More
Why Your Head of AI Role Needs a Controller Mandate, Not an Innovator Profile
Chris Cook Chris Cook

Why Your Head of AI Role Needs a Controller Mandate, Not an Innovator Profile

Most firms hire a Head of AI to drive adoption and assume governance comes along for the ride. It does not. When regulators ask who owned an AI decision end-to-end and where the evidence is, an adoption-first mandate produces no satisfactory answer. This issue makes the case for writing the role specification around a controller model, with four discrete criteria that determine whether you actually have governance or just a well-intentioned org chart entry.

Read More
Who Can Pull the Plug on a Harmful AI System Without a Committee Vote?
Chris Cook Chris Cook

Who Can Pull the Plug on a Harmful AI System Without a Committee Vote?

Most AI governance frameworks define approval as a collective act requiring a quorum. They leave halting undefined or orphaned. When no one has documented authority to stop a system, the person who deployed it keeps it running — and the person living with the consequences has no mechanism to intervene.

Read More
Your AI Policy Approves the Tool. It Doesn't Approve the Use Case.
Chris Cook Chris Cook

Your AI Policy Approves the Tool. It Doesn't Approve the Use Case.

Approving an AI tool and approving an AI use case are two different governance decisions. When HR uses a policy-approved LLM to inform workforce reduction targets, the governance layer that blessed the tool didn't conduct a bias audit, make required AEDT disclosures, or document human oversight.

Read More
Shadow AI Is a CCO Problem, Not an IT Problem
Chris Cook Chris Cook

Shadow AI Is a CCO Problem, Not an IT Problem

Your firewall catches the endpoints IT has catalogued. It doesn't catch browser extensions, personal device usage, or AI features quietly added to sanctioned SaaS tools. Shadow AI governance fails at the org chart, not the policy.

Read More