Insights
Guidance for people who have to actually do it
No think-piece filler. Practical columns on ISO 42001 and the EU AI Act, written by BigJay Jang — former IBM & Deloitte strategy consultant — for non-developers at mid-sized companies.
ISO/IEC 42001
What ISO/IEC 42001 actually is — an AI management system in plain language
It's a management system, not a checklist. The clause structure, the Annex A controls, and why “risk-based” changes everything.
Read the column →
Audit-ready vs certified: what Stage 1 and Stage 2 audits really check
Two different finish lines. What an auditor opens first, and how to walk in prepared instead of hopeful.
Read the column →
Writing an AI policy top management will actually sign
Short, specific and signed at the top — or it's a mandatory gap. What belongs in it, and how to get genuine sign-off.
Read the column →
The AI risk register that survives an audit
Inherent vs residual, likelihood × impact, owners and dates — the three things most registers get wrong.
Read the column →
The Statement of Applicability: justifying every Annex A control
The auditor's index. How to justify every inclusion — and, the risky part, every exclusion.
Read the column →
Human oversight, logging and incident response: the operating core of an AIMS
The procedures an auditor watches actually run — the parts you can't fake the night before.
Read the column →
Management review and continual improvement: keeping certification, not just getting it
Certification is a snapshot; the standard is a habit. The Clause 9–10 machinery that keeps your AIMS alive.
Read the column →
Scoping ISO 42001 for the mid-market: audit-ready without a six-figure engagement
Most of the enterprise cost is scope you don't need. Scope tightly, do the work yourself, buy only judgement.
Read the column →
ISO 42001 without a consultant: the 5 documents that do the heavy lifting
Five documents carry most of the weight — what they are, and the order to build them in.
Read the column →
EU AI Act
The EU AI Act by the calendar: every date that actually applies to you
The Act phases in over years, and only a slice touches any one company. The dates that matter.
Read the column →
Provider or deployer? The one question that decides most of your obligations
Almost everything follows from your role — and you can be both. How to tell which you are, per system.
Read the column →
Is your system high-risk? Reading Annex III without a lawyer
High-risk is a defined category, not a vibe. How to do a credible first classification yourself.
Read the column →
Labelling AI-generated content: the machine-readable marking teams get wrong
“Label it” is half the obligation. The machine-readable marking that a visible caption doesn't satisfy.
Read the column →
The high-risk obligation set, decoded: risk management, data governance, human oversight
The whole Chapter III list in plain language — and why a deployer's slice is far shorter than a provider's.
Read the column →
Annex IV technical documentation: the file a conformity assessment expects
The living dossier that proves conformity — what's inside, and why deployers should care too.
Read the column →
The fundamental-rights impact assessment (FRIA): who owes it, and how to run one
The obligation that lands on deployers, not builders. Who's in scope, and how to run one that means something.
Read the column →
Penalties and enforcement: what €35M / 7% actually means for a mid-sized company
How the tiers work, why the percentage is the scary part, and how enforcement is likely to land.
Read the column →
The transparency deadline that didn't move: a deployer's checklist for 2 December 2026
If you deploy a chatbot or generate synthetic content, exactly what has to be true by 2 December 2026.
Read the column →