Private Practice

AI Governance

Executive frameworks for managing the technical risk associated with Generative AI and automated systems. We align organizational AI deployment with the NIST AI RMF 1.0 to ensure safety, algorithmic accountability, and regulatory compliance in the age of agentic AI.

All FISMA & NIST RMF FedRAMP CMMC Federal AI Governance GovCon Compliance Federal Cybersecurity Federal Zero Trust Federal GRC Engineering AI Governance GRC Engineering Cybersecurity Cloud Security HIPAA SOC 2
AI Governance

Multi-Agent System Governance: When Agents Manage Agents

Multi-agent system governance is becoming the defining challenge of enterprise AI deployment. KPMG deployed 50 AI agents through its Workbench platform in June 2025, with additional agents in development [KPMG Jun 2025]. These are not...

Read the Guide
AI Governance

EU AI Act Human Oversight: Article 14 Compliance for High-Risk AI Systems

The greatest risk in high-risk AI is not the algorithm. It is the human approving the algorithm's output without reading it. A 2025 systematic review of studies involving thousands of participants confirmed what practitioners already...

Read the Guide
AI Governance

EU AI Act Risk Management System: Article 9 Implementation Guide

Seventy-seven percent of organizations report active AI governance programs. Half lack a systematic inventory of AI systems in production. Eighteen percent of deployed AI systems are confirmed high-risk under the EU AI Act [appliedAI Enterprise...

Read the Guide
AI Governance

EU AI Act High-Risk Compliance Checklist: All Requirements Before August 2026

Organization A treats August 2, 2026 as the EU AI Act high-risk compliance deadline. Its compliance team classifies every AI system against Annex III, builds a risk management system under Article 9, drafts technical documentation...

Read the Guide
AI Governance

EU AI Act Conformity Assessment: Article 43 Procedures for High-Risk AI Systems

The EU Medical Device Regulation entered full application in May 2021. By the deadline, 20% of medical devices had achieved certification. Queues at notified bodies stretched 18 months. Audit costs tripled. The industry had five...

Read the Guide
AI Governance

Agentic AI Governance: The 2026 Framework for Autonomous AI Systems

Who governs an AI agent governing itself? Not a chatbot responding to prompts. Not a model scoring risk on a spreadsheet. An autonomous system calling APIs, accessing databases, delegating tasks to other agents, and making...

Read the Guide
AI Governance

EU AI Act Penalties: EUR 35M Fines for Prohibited Practices

Your AI vendor sends a routine product update. Buried in the changelog: a new feature scoring job applicants on behavioral patterns inferred from social media activity, active across three EU subsidiaries for six weeks. The...

Read the Guide
AI Governance

EU AI Act Deployer Obligations: Article 26 Compliance Roadmap for 2026

Your head of product deployed a third-party AI screening tool for customer onboarding across European markets six months ago. The vendor provided a 40-page user manual, a conformity declaration, and a support email address. Last...

Read the Guide
AI Governance

EU AI Act High-Risk Classification

Your product team deployed an AI-powered resume screening tool six months ago. HR reports 40% faster candidate processing. The CTO presents it at the quarterly board meeting as a win. Then your EU legal counsel sends...

Read the Guide
AI Governance

EU AI Act Compliance Timeline

Your general counsel forwards a regulatory alert from the EU AI Office. The subject line reads: eight months until high-risk AI system rules take effect. Your HR team uses an AI-powered screening tool to filter...

Read the Guide
The Authority Brief

One compliance analysis per week from Josef Kamara, CPA, CISSP, CISA. Federal and private compliance, written for practitioners.