Writing on AI governance, evidence, and control
Page updated August 3, 2026
Plain-language explainers and positions for the people who have to answer for AI: what the terms mean, what the rules require, and where control actually belongs.
What has to be preserved when an officer uses AI to draft a report?
Keep what the tool was given, the AI's first draft, and who used it. California requires keeping the draft and an audit trail; Utah requires a disclaimer.
Read the postWho keeps the transcript from an ambient scribe?
Unless the contract says otherwise, the scribe vendor holds the transcript. What HIPAA requires of the BAA, and what to ask before PHI reaches the model.
Read the postWhat evidence does an auditor expect for AI use in a state agency?
The GAO and NIST AI frameworks point an auditor to three things: a current AI inventory, proof your AI policy was followed, and a running record of AI use.
Read the postAgentic AI governance: control the action, not the prompt
Agents act on their own at machine speed. Why agentic AI governance must move to the action boundary, and why the signed record is the only witness.
Read the postAn AI acceptable use policy is not enforcement
Most institutions have an AI acceptable use policy. Few can show it held. AI policy enforcement means decisions at execution, plus a record that proves it.
Read the postCJIS compliance and AI: what the CJIS Security Policy requires before staff use AI tools
What the CJIS Security Policy requires before CJI touches an AI tool, what auditors will ask, and what a defensible record looks like.
Read the postIs ChatGPT HIPAA compliant? What healthcare teams need to know
No AI tool is HIPAA certified, because no such certification exists. What a business associate agreement covers, what it does not, and how PHI stays governed.
Read the postWhat is an AI audit trail, and what makes one trustworthy
An AI audit trail records who used which AI tool, what was sent and returned, when, and whether policy held. What separates evidence from a text file of logs.
Read the postWhat is shadow AI? A plain guide for regulated institutions
Shadow AI is the AI in use that no one approved and no one can see. Why it grows, why bans fail, and how shadow AI detection leads to one enforced policy.
Read the postA question a post did not answer? Ask us.
Tell us your sector and what you need to prove. We'll point you at the right document, or write the missing one.