Welcome

Passionately curious about Data, Databases and Systems Complexity. Data is ubiquitous, the database universe is dichotomous (structured and unstructured), expanding and complex. Find my Database Research at SQLToolkit.co.uk . Microsoft Data Platform MVP

"The important thing is not to stop questioning. Curiosity has its own reason for existing" Einstein



Showing posts with label Responsible AI. Show all posts
Showing posts with label Responsible AI. Show all posts

Tuesday, 30 June 2026

AI Governance is a Hollow Framework Without Data Governance

The Hard Truth: We are trying to govern the outputs of frontier AI without establishing strict control over the inputs.

Imagine a near-future scenario: a frontier AI developer launches its next-generation model family. Within days, researchers uncover a zero-day jailbreak vulnerability that allows the model to map and exploit critical software vulnerabilities with unprecedented autonomy. In a scramble, the federal government issues an unprecedented emergency directive, forcing the developer to suspend global API access under the banner of national security.

While this sounds like a techno-thriller, the current geopolitical trajectory suggests this crisis is an inevitability. When governments eventually panic and react to high-risk algorithmic outputs, they will find that treating commercial AI models like sudden tactical threats is an unsustainable way to regulate technology.

AI models do not generate safety risks out of thin air; they learn them from data. Reactive government bans and real-time output filters are panic buttons. True thought leadership in this space requires looking upstream.

The Missing Link: Why Data Governance is AI Governance

Effective risk management for frontier models cannot rely on real-time safeguards alone. True resilience requires structural data governance built across three distinct operational pillars:

1. Data Provenance and Vulnerability Tracing

If a model can be steered into identifying critical software infrastructure vulnerabilities, we must ask: What specific datasets allowed it to map these exploits? Data governance mandates a transparent, verifiable ledger of training data. Regulators and developers must be able to audit what a model actually "knows" long before it is deployed to the public.

2. Dynamic Data Retention as a Defense Layer

When developers scramble to mitigate active exploits, they rely heavily on short-term telemetry retention policies to analyze user prompt interactions and track malicious behavior. Knowing exactly how user data is ingested, logged, and securely monitored is the only way to detect non-universal, highly sophisticated jailbreaks in real time.

3. Access Control and Data Sovereignty

Enforcing geographical or citizenship-based restrictions on a cloud-native, globally distributed API environment is a logistical nightmare. Without ironclad data access governance—restricting who can query the model and where that telemetry is stored—preventing unauthorized cross-border interaction with advanced reasoning systems is practically impossible.

Four Critical Questions for Tech Sovereignty

As the boundary between commercial technology and national security blurs, organizations and global regulators must confront the deeper systemic questions facing the ecosystem:

  • Who defines the threshold? Who determines when an advanced reasoning capability crosses the line from a massive commercial benefit to an existential national security threat?

  • What are the standards of validation? What transparent, independent, and technically grounded benchmarks must exist before a governing body can disrupt commercial ecosystems?

  • How do we prevent total fragmentation? If strict export controls dictate who can use the best models, how do we avoid a fractured digital world where access to advanced reasoning is determined entirely by geographical alignment?

  • What role does international cooperation play? When the regulatory actions of one nation can disable access for businesses worldwide, how do we build international institutions capable of managing global technological externalities?

Moving From Friction to Resilience

If we continue to treat AI safety as a series of sudden regulatory halts and reactive software patches, we will paralyze market innovation without actually making the digital estate any safer.

Responsible AI is the destination, but we cannot get there without two non-negotiable operational tracks:

  1. AI Governance: Providing the systemic oversight, legal compliance, and risk frameworks needed to manage model deployment.

  2. Data Governance: Securing the upstream integrity, tracing, and access controls of the information that shapes those models in the first place.

Reactive regulations are a sign of a system in deep friction. True leadership demands that we look upstream, securing the data infrastructure today so we can safely innovate the AI capabilities of tomorrow.



Sources & Further Reading (Alternative Options)

  • White House Policy: "Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence" — focusing on the mandates for safety testing and red-teaming for frontier models.

  • Geopolitical Precedents: Bureau of Industry and Security (BIS) guidelines on advanced computing and semiconductor export controls to showcase how the U.S. government actually restricts technology infrastructure.

  • Technical Frameworks: The NIST AI Risk Management Framework (AI RMF), which details the industry-standard pillars for measuring and governing AI risk, mapping beautifully to your data governance argument.

Wednesday, 24 June 2026

Microsoft Purview Security Tooling Blog Series

The biggest data security risk in Microsoft 365 isn't external attackers. It's the controls you think you've already implemented. Most organisations believe their data is secure because they have Microsoft 365. The reality is often very different. Over the last few weeks, I've written a series exploring the Microsoft Purview data security capabilities that organisations regularly purchase but don't fully implement, configure, or operationalise.


The common assumption is that data security is a technology problem. In practice, it's a visibility, governance, and control problem. Knowing where your sensitive data is, who has access to it, how it moves, and how you respond when something goes wrong requires much more than switching on a licence.

The series explores:

🔹 Information Protection – classifying and protecting what matters
🔹 Data Loss Prevention – turning classifications into enforceable controls
🔹 Insider Risk Management – understanding risky behaviours before they become incidents
🔹 Information Barriers – controlling who can collaborate with whom
🔹 Data Security Investigations – turning alerts into evidence and action
🔹 DSPM for AI and Data – exposing hidden risks and overexposure across your estate

If you're working in data governance, security, compliance, or responsible AI, these capabilities are becoming increasingly important as organisations seek to balance productivity with protection. The challenge isn't buying the technology. It is implementing the controls that make the technology effective.



You can read the full series here:


References

The Reality of Data Security in M365 (Purview Protection)

Microsoft Purview Information Protection: The Control Most Organizations Think They Already Have 

Microsoft Purview Information Barriers: Controlling Who Can Work With What

Microsoft Purview Data Security Investigations: When Alerts Become Evidence

Microsoft Purview DSPM: Unmasking Your True Data Risks

Microsoft Purview Data Loss Prevention: Where Classification Becomes Control

Microsoft Purview Insider Risk Management: When Data Movement Becomes Behaviour


Saturday, 6 June 2026

Microsoft Project Solara A New Category: Agent‑First Devices Built for the Enterprise

Project Solara introduces a hardware and software ecosystem where AI agents become the primary interface, not applications. Microsoft demonstrated two reference devices:

  • A desk companion that authenticates via facial recognition and acts as a gateway to cloud‑based Windows 365.  
  • An AI‑powered corporate badge with a touchscreen, fingerprint sensor, microphone array, and side‑facing camera enabling hands‑free documentation, contextual capture, and workflow automation. 
These devices run on the Microsoft Device Ecosystem Platform (MDEP), an enterprise‑grade OS built on the Android Open Source Project, managed through Intune and secured with Entra ID. 

This is not consumer hardware. It is a deliberate move to support industry‑specific workflows in healthcare, retail, logistics, and field operations with organizations like CVS Health, Levi’s, Target, and AccuWeather already exploring pilots. 

Why Project Solara Matters for Data Governance

Solara is not just a hardware announcement, it is a governance milestone.

1. Identity‑bound, policy driven access
Every Solara device authenticates through Entra ID and Windows Hello for Business, ensuring that AI agents operate within role‑based access controls and enterprise identity boundaries. 

2. Intune‑managed, enterprise grade device compliance
Because Solara devices are managed through Microsoft Intune, organizations can enforce:
  • Configuration baselines  
  • Conditional access  
  • Device compliance policies  
  • Remote wipe and lifecycle controls  
This brings agent‑first devices into the same governance perimeter as laptops, mobiles, and IoT endpoints.

3. Cloud centric intelligence, not local models
Solara devices intentionally do not run local AI models. All intelligence lives in Azure, reducing:

  • Data residency risk  
  • Model drift  
  • Shadow AI  
  • Unmonitored local inference  

This architecture aligns with enterprise governance expectations for centralised oversight and auditability. 

Responsible AI: Embedded in the Platform’s Design

While Microsoft has not yet published a standalone Responsible AI standard for Solara, the announcement and technical framing clearly align with Microsoft’s broader Responsible AI commitments.

1. Privacy first hardware controls
Solara devices include physical privacy features, such as hardware microphone mute switches. 

2. Context aware, role aligned Agent behaviour
In healthcare demonstrations, agents adapt to the user’s role and workflow supporting documentation, scanning medications, and verifying patient data. This reflects principles of:
  • Human‑centred design  
  • Transparency  
  • Safety in high‑risk environments  
3. Multi‑Agent, Open Ecosystem, not a single black box
Solara is explicitly designed as an open multi‑agent system, allowing organisations to integrate their own agents via:
  • Copilot Studio  
  • Microsoft 365 Agents SDK  
  • Azure Agent Framework  
This reduces vendor lock‑in and supports accountability, traceability, and custom governance controls. 

What This Means for Organisations

Project Solara signals a future where AI is:
  • Ambient present in every workflow  
  • Contextual aware of environment and role  
  • Governed bound by enterprise identity, policy, and compliance  
  • Responsible designed with privacy and safety in mind  
For data governance and responsible AI leaders, Solara represents the next frontier: governing AI not just in software, but in physical devices that operate across the enterprise landscape.

This is the beginning of a new category of agent‑first hardware and it will reshape how organisations design, deploy, and govern AI at scale.

Friday, 5 June 2026

Seen but Not Heard: The Age of Data Governance

There’s a phrase I remember being told as a child  “seen but not heard.”

At the time, it meant quiet compliance. Something present, something acknowledged, but not something that shaped the room or influenced what happened next. Strangely, that’s exactly how organizations have treated data governance for years. It has always been there, in the background. Policies exist, frameworks have been written, roles have been defined. If you look hard enough, every organization can point to where governance sits. It is visible. It is documented. It is technically present but it hasn’t truly been heard. It hasn’t influenced how systems are designed, how teams deliver, or how decisions are made in the way it should. Instead, governance has often been something that follows behind delivery as a correction, a control, a necessary inconvenience once the “real work” has already been done. That made sense, once but it doesn’t any longer.



What has changed is not governance itself, it is the world around it. We now operate in organizations where data is not a by-product of activity; it is the thing everything depends on. Strategy is built on it, operations are driven by it, and increasingly, decisions are delegated to systems that rely entirely on it. There is no part of a modern organization that sits outside of data anymore and yet, governance is still too often treated as if it does. That tension is becoming impossible to ignore because when every system depends on data, every issue becomes a governance issue. When numbers do not align between reports, when teams cannot agree on definitions, when ownership is unclear, when trust in outputs begins to erode these are not technical failures in isolation. They are symptoms of something deeper: a lack of embedded governance. You can see this play out repeatedly. Organizations invest in platforms, they modernise architectures, they implement analytics solutions, they adopt AI. Each initiative is presented as progress, and in isolation, it often is. But without governance woven into the fabric of these initiatives, complexity accumulates rather than resolves. Data spreads, inconsistency grows, and the ability to explain or trust what is being produced gradually diminishes. Governance, in those moments, has been seen but it was never allowed to shape the outcome.

The emergence of AI has brought this reality into sharper focus. For years, organizations could tolerate a degree of inconsistency in their data. It caused frustration, inefficiency, and occasionally risk, but it remained manageable. AI does not allow for that tolerance. It amplifies whatever it is given. Good data becomes insight at scale. Poor data becomes risk at scale. There is no neutral outcome. The old saying “garbage in, garbage out” still applies, but it now applies faster, at greater scale, and with far more impact than before. When decisions begin to be influenced or even made by systems fed on ungoverned data, the consequences are no longer contained within individual processes. They affect entire organizations. At that point, governance is no longer a supporting capability. It becomes the condition for whether anything works at all.

This is why the idea that governance can be added later no longer holds. It is not something that can sit alongside delivery or follow it. Governance determines what “good” looks like before anything is built. It defines ownership, establishes meaning, sets expectations, and ensures consistency. Without it, delivery moves forward, but coherence does not and that is the subtle but critical shift that is still being missed. We are not entering a stage where governance becomes more important as a standalone discipline. We are entering a stage where governance becomes inseparable from everything else. It is not another workstream to manage it is part of how every workstream operates. Every technology solution carries assumptions about data. Every integration defines how data flows. Every report reflects decisions about meaning, quality, and trust. Every AI model relies on choices about what data is used and how it is interpreted. In all of these cases, governance is already present. The difference is whether it has been made explicit, intentional, and embedded or whether it remains invisible until it fails.

One of the reasons organizations struggle with this shift is that governance has historically been framed in the wrong way. It has been positioned as a control mechanism, something that restricts or slows progress. It has been documented extensively, but lived infrequently. It has often been assigned to a function rather than understood as a shared organizational responsibility. As a result, it has been treated as optional in practice, even when it is mandatory in principle but when governance is embedded properly, it does not slow organizations down. It removes uncertainty. It allows decisions to be made with confidence because there is clarity around ownership, meaning, and quality. It reduces rework because expectations are clear from the outset. It enables innovation because it provides the guardrails that make experimentation safe. In other words, it makes progress sustainable.

The irony is that most organizations are already feeling the consequences of not doing this, even if they do not describe it in those terms. The questions that surface in meetings about which version of the truth to trust, about who is responsible for a dataset, about whether something can be used safely or compliantly are all governance questions. They just are not recognised as such and because they are not recognised, they are not addressed systematically. Instead, they are solved locally, temporarily, repeatedly. Governance remains visible in theory, but unheard in practice.

We are now at a point where that is no longer viable. If data is the thing that everything depends on, then governance must be the thing that everything contains. Not as an overlay, not as an afterthought, but as a standard, embedded part of how organizations operate. This is the age of data governance — not because governance is new, but because the absence of it is no longer survivable. The organizations that recognise this will not be the ones with the most advanced tools or the largest data estates. They will be the ones that understand their data well enough to trust it, control it, and use it consistently across every part of the business. They will be the ones that stop simply seeing data governance, and finally start listening to what it has been telling them all along.

Thursday, 4 June 2026

Microsoft Announces Scout: An Always‑On Autonomous Agent for Work

Microsoft has unveiled Scout, its first Autopilot agent, an always‑on, autonomous digital assistant designed to work across Microsoft 365, proactively coordinating tasks, managing workflows, and keeping work moving even when you’re not in the loop. What makes Scout different is its ability to operate with its own identity, act within organisational policies, and build long‑term context through WorkIQ, learning how you work and what matters most. But beneath the excitement, there’s a deeper story for those of us working in data governance and Responsible AI.

Where Scout Meets Data Governance

Microsoft has been explicit: Scout is built with enterprise‑grade security, policy enforcement, and auditability from day one. Key governance‑aligned capabilities include: Policy‑constrained identity Scout acts only within the permissions and boundaries your organisation sets. Execution containers & OS‑level sandboxing  reducing risk when agents access files, run code, or interact with networks. Continuous policy conformance checks every action is validated against organisational guidelines, producing an audit trail. This is a significant shift: AI agents are no longer “black boxes” running in user sessions, they’re governed, monitored, and contained as first‑class enterprise actors.

Responsible AI: Built Into the Foundation

Microsoft has also published Responsible AI documentation for Scout, reinforcing that it is part of a broader commitment to safe, transparent, and accountable AI systems. 

Highlights include:
  • Responsible AI FAQs explaining how Scout works, what data it accesses, and how system owners can shape behaviour.  
  • Tiered permission systems for file access, shell commands, and browser automation.  
  • Human‑in‑the‑loop expectations and environmental considerations for deployment.  
This aligns Scout with Microsoft’s AI principles of fairness, reliability, safety, privacy, security, inclusiveness, transparency, and accountability.

Why This Matters

For organisations already investing in data governance, AI assurance, and operational Responsible AI, Scout represents a new category of enterprise agent:
  • Autonomous enough to reduce coordination overhead  
  • Governed enough to meet compliance and risk expectations  
  • Context‑aware enough to become a durable part of the digital workforce

This is the moment where AI agents stop being assistants and start becoming accountable digital colleagues  operating within the same governance frameworks as humans and systems.

Wednesday, 3 June 2026

Microsoft Build 2026: The Moment Governance Became the Bottleneck, Not Innovation

If last year’s narrative was about what AI can do, Microsoft Build 2026 marked a noticeable shift: the conversation has moved firmly to what organizations must control.

Across two days of announcements, Microsoft made one thing clear. The next phase of enterprise AI will not be defined by better models or more copilots. It will be defined by whether organizations can operationalise data readiness, governance, and trust at scale.

And that is where the most important announcements sit.

From “AI Features” to “AI Systems That Act”

The headline innovation at Build wasn’t just new models, it was the emergence of autonomous AI agents as first-class enterprise actors.

Microsoft introduced Scout, an always-on AI agent capable of continuously operating across enterprise systems, taking actions rather than waiting for prompts.
This marks a fundamental shift from assistive AI to operational AIsoftware that executes tasks, interacts with systems, and makes decisions within workflows. 

But this also introduces a new governance reality.

When AI moves from generating content to acting on behalf of a business, the questions change:

  • Who is accountable for the action?
  • What data did the agent access?
  • What policies constrained its behaviour?

Microsoft’s answer is not a single tool but an emerging governance architecture for agents.

Governance Is Now Part of the Platform (Not an Add-On)

Across the announcements, governance was not positioned as a compliance afterthought. It was embedded into the core platform.

Three developments stand out.

Agent identity, control, and auditability

Agents are now designed with their own identities, permissions, and audit trails that essentially are becoming governed entities within enterprise systems.
This is a critical shift: governance is no longer about users accessing data, but about non-human actors operating within policy boundaries. 

The rise of the agent control plane

With capabilities such as Agent 365 and broader governance frameworks, Microsoft is building what can only be described as a control layer for AI agents covering access control, visibility, monitoring, and compliance. 

This moves governance from static policies to continuous oversight of autonomous systems.

Built-in safety, evaluation, and testing

The introduction of evaluation frameworks like ASSERT (for testing AI behaviour against policy expectations) signals a shift toward engineering governance into the development lifecycle itself. 

This aligns closely with emerging standards (ISO/IEC 42001, EU AI Act), where governance is expected to be designed, evidenced, tested and not assumed.

Data Governance Quietly Took Centre Stage

While the headlines focused on models and agents, the more important story sits underneath: data is now the limiting factor for AI.

Microsoft’s investment in Fabric including a GPU accelerated data warehouse positioned as an execution layer for AI workloads reflects a deeper truth: organisations don’t lack AI capability, they lack AI-ready data environments. 

This reinforces a theme many of us have been seeing on the ground:

The challenge is no longer can we use AI?
It is can we trust the data, control its usage, and scale it responsibly?

Even outside the keynote announcements, updates across Microsoft Purview continue to evolve around:

  • data quality management,
  • data loss prevention for AI interactions,
  • and governance across expanding AI estates. 

Taken together, this signals a more mature positioning that data governance is not supporting AI, it is enabling it.

A New Stack: AI, Data, and Governance as One System

Perhaps the most important architectural shift is how Microsoft is framing the AI stack.

At Build 2026, governance was explicitly treated as a foundational layer alongside compute, models, and tools. 

This is subtle but significant.

Previously, governance sat outside the stack:

  • something imposed after deployment,
  • owned by risk or compliance functions,
  • often disconnected from engineering.

Now, governance is:

  • integrated into runtime environments,
  • embedded in agent frameworks,
  • and enforced through platform capabilities.

This is a move toward operational governance, not theoretical governance.

What This Means for Businesses

For organizations, these announcements are less about new features and more about a change in expectations.

AI adoption will be constrained by governance maturity

The organizations that succeed will not necessarily be those with the most advanced models but those with:

  • clear data ownership,
  • defined policies for AI usage,
  • and the ability to monitor and control AI behaviour continuously.

Governance becomes a cross-functional discipline

AI governance can no longer sit solely with data teams or compliance functions. It now spans:

  • data governance,
  • security,
  • enterprise architecture,
  • and operational risk.

Tools alone will not solve the problem

While Microsoft is building an increasingly comprehensive governance ecosystem, the platform assumes something critical:

Organisations already understand their data, risks, and policies.

In reality, many do not.

This is where the gap and the opportunity sits.

The Real Announcement wasn’t a Product

If you step back, the most important announcement at Build 2026 wasn’t a model, a Copilot update, or even an agent.

It was a shift in narrative.

Microsoft is signaling that:

  • AI is no longer experimental.
  • Agents will become embedded in everyday business operations.
  • And governance is now the primary barrier to scale.

In other words, we’ve moved from the innovation phase of AI to the industrialisation phase.

And industrialisation always introduces the same question:

How do you scale safely, consistently, and with accountability?

That is not a tooling question. It is a Data and AI governance question.

References

forbes.com  dqindia.co  theneuron.ai  microsoft.github.io  pulse2.com 

forbes.com  learn.microsoft.com  theneuron.ai

Monday, 18 May 2026

Governing the agents not just the AI

The current wave of agentic AI is not just another iteration of automation, it is a shift from models that advise to systems that act. In the Fortune piece summarised via Yale Insights, the central risk is not capability but placement: where agents are deployed in the business and how close they operate to customers, decisions and trust. The “proximity framework” highlights that the closer an agent gets to irreversible, customer-facing decisions, the greater the governance burden becomes, with failures having disproportionate reputational impact. What is emerging consistently across follow-on work in banking, healthcare, retail and supply chain is that governance is lagging deployment, with organizations actively running agents across operations while still relying on fragmented or incomplete control models. This reinforces a point you often make in governance conversations: the problem is no longer whether AI works, but whether organizations can safely operationalise decision rights at scale. 

When you bring data governance into this, the conversation sharpens significantly. Multiple recent articles move beyond model governance and focus specifically on how agents access and use data, often autonomously and continuously. Agent Access Management reframes governance as a data problem, not just identity, because agents inherit permissions dynamically across APIs, workflows and services, often without visibility into what they can actually reach. Traditional access governance breaks here because it assumes static roles and human review cycles, whereas agents operate continuously and at machine speed, creating access patterns that are technically authorised but contextually inappropriate. This is why newer guidance emphasises data-aware controls, real-time monitoring and understanding not just who the agent is, but what data it is using and why. It aligns strongly with emerging audit expectations, where organizations must evidence which agents exist, what data they access, and how decisions are controlled and explained. 

What is becoming clear across the literature is that governance for agents is not an extension of traditional AI governance, it is a redesign of enterprise control models. Firms like IBM and McKinsey point out that governance needs to move from validating outputs to controlling actions, defining scope, ownership and accountability for autonomous decision-making. At the same time, platform and vendor ecosystems are converging on concepts like control planes, agent registries and data-centric governance layers to ensure visibility and enforce policy at runtime. The consistent thread across all of this is that trust in agentic AI is not built at the model layer, it is built at the data access and execution layer. That is where governance now has to operate, and it is where most organisations are still weakest. 

References

Fortune / Yale source 

Supporting governance and agentic AI articles

Agent governance frameworks and operating model shifts

Data access governance and agent-specific governance

Audit, compliance and enterprise deployment considerations

Friday, 1 May 2026

Operationalising Responsible AI: What Microsoft’s Approach Reveals

Responsible AI has become one of those phrases that organisations like to reference but rarely operationalise. It appears in strategy decks, risk registers, and conference panels, yet the practical mechanisms that make it real are often missing.  

Microsoft’s recent article on its internal responsible‑AI approach is useful not because it offers something radically new, but because it demonstrates what it looks like when a large organisation treats responsible AI as a discipline rather than a marketing narrative.

Below are the core lessons worth thinking about especially if you’re trying to move your organisation from aspiration to implementation.

1. Responsible AI is an organisational discipline, not a technical feature

The most important message is also the simplest: responsible AI only works when it is treated as a governing framework that shapes how AI is designed, deployed, and monitored.   This is not a “nice to have”. It is not a late‑stage review. It is not a compliance tick‑box.  It is a structural commitment that defines how decisions are made, how risks are surfaced, and how accountability is distributed. If organisations are still treating responsible AI as a technical add‑on, you will not scale safely.

2. A central authority is essential for coherence

Microsoft’s Office of Responsible AI functions as a single point of truth. It sets policy, interprets standards, and ensures that teams are aligned.  This matters because without a central authority, governance fragments. Different teams make different assumptions. Risk becomes inconsistent. Decisions become harder to audit. A central function does not need to be large, but it does need to be authoritative. It needs the mandate to say “no”, “not yet”, or “not like this”.

3. Distributed oversight is the only scalable model

A central team cannot carry the entire burden. Microsoft’s model. A senior council supported by a network of responsible‑AI champions is the only realistic way to scale oversight across a complex organisation. This mirrors how other disciplines have matured:  
- data protection officers and privacy champions  
- security teams supported by local security leads  
- governance functions with embedded practitioners  

The pattern is consistent with central clarity and distributed execution. If you want responsible AI to work, you need people embedded in delivery teams who understand the risks and know how to escalate them.

4. A unified workflow is the backbone of responsible AI operations

One of the most practical elements of Microsoft’s approach is its internal workflow tool. Every AI project is logged, assessed, and reviewed through a single structured process. This creates:  
- traceability  
- auditability  
- consistent risk categorisation  
- clear escalation routes  
- visibility across the portfolio  

Most organisations underestimate how much risk comes from fragmentation. If you don’t know what AI systems exist, you can’t govern them. A unified workflow is not optional. It is foundational.

5. Culture and process design matter more than tooling

The article makes a point that resonates strongly with anyone who has worked in governance, the tools support the work, but they do not define it. If you don’t have:  
- clear expectations  
- shared language  
- leadership commitment  
- a culture that values scrutiny  

no tool will save you. Responsible AI succeeds when the organisation behaves as if it matters — not when it installs a dashboard.

Thrre are some actionable steps for organisations to take to build their own responsible AI capability. These are the practical takeaways that any organisation can adopt immediately.

1. Start with a written standard
Define what “good” looks like. Set mandatory requirements. Clarify what triggers deeper review. This becomes your anchor.

2. Build a network of responsible AI practitioners. Identify people with the right instincts, governance‑minded, risk‑aware, delivery‑literate. Train them and Empower them.

3. Design the assessment process before you build tooling. Clarify the workflow:  
- What must every project declare?  
- Who reviews what?  
- How are risks escalated?  

Only then should you build or buy tools.

4. Integrate responsible AI checkpoints into delivery. Move away from late‑stage reviews. Embed assessments into initiation, design, and release readiness.

5. Treat bias detection and data quality as non‑negotiable. Bias is rarely intentional; it is inherited. Build structured checks into your evaluation pipeline.

6. Assign responsibility for monitoring regulatory change. Someone needs to track global AI regulation and translate it into internal practice. This prevents compliance surprises.

7. Use the open resources already available
Microsoft’s Responsible AI Toolbox, Human‑AI Experience guidance, and impact‑assessment templates provide a strong foundation. Use them to accelerate maturity.

Responsible AI is not about slowing innovation. It is about enabling it safely, predictably, and sustainably.  The organisations that will thrive in the next decade are those that treat responsible AI as a discipline with structure, clarity, and accountability, rather than a slogan.

Read more here.

Sunday, 26 April 2026

Inside Microsoft’s Responsible AI Framework: What Matters for Data Governance

Microsoft’s updated Responsible AI framework represents a significant evolution in how organisations are expected to approach AI oversight. While the principles themselves, fairness, reliability, safety, privacy, inclusiveness, transparency, and accountability are familiar, the operational expectations behind them have deepened. This isn’t a philosophical document; it’s a practical guide for embedding responsibility into the lifecycle of AI systems.

For data governance leaders, the most important shift is the emphasis on traceability. The framework makes it clear that organisations must be able to explain how data flows into models, how those models behave, and how decisions are made. This requires robust lineage, versioning, and monitoring. Without these, transparency becomes impossible.

Another critical element is human oversight. The framework reinforces that AI should augment, not replace, human judgement. This means governance must ensure that humans remain in the loop for high‑impact decisions, and that they have the context needed to interpret model outputs. Oversight is not a checkbox, it is a design requirement.

The framework also highlights the importance of data quality and representativeness. Poor data leads to poor models, and poor models lead to poor outcomes. Governance must ensure that training data is accurate, relevant, and free from harmful bias. This is where stewardship, classification, and quality controls become essential.

Finally, the framework calls for ongoing monitoring, not one‑time validation. Models evolve, data changes, and risks shift. Governance must be continuous, adaptive, and embedded into operational workflows.

Tracing my career journey though my blog

I was looking at my blog stats this morning and was really interested to see the geographical spread. I started writing my blog in 2011 and it has been read by 1.18m. I wanted to record all the technical tips I found and technology advancements which were useful to me and might be of use to help others. I started writing on SQL Server and the blog has migrated with me throughout my career through architecture, my PhD research and over the last few years I have been mostly writing on Data Governance, Microsoft Purview, AI Governance and Microsoft Fabric. 


I asked Copilot to share some interesting thoughts about my journey for my blog and here is what it thought.

Your blog reveals a journey defined by intellectual curiosity, data‑driven leadership, and a distinctive narrative voice. Here are five evidence‑based, genuinely interesting aspects of that journey.

1. You frame data leadership as a process of unlearning, not just learning

Your post “What data leaders must unlearn to lead in the Age of AI” argues that modern leadership requires shedding outdated assumptions, such as believing governance slows innovation or that documentation equals understanding. This reframing positions you as a thought leader challenging entrenched industry norms. 

2. You consistently connect research, industry practice, and philosophical curiosity

Your blog tagline “Chaos, complexity, curiosity and database systems” captures a rare blend: deep technical expertise paired with a reflective, almost philosophical lens on data systems. This fusion shapes your writing style and differentiates your professional voice. 

3. You document the shift from AI experimentation to AI industrialisation with governance at the centre

In your coverage of the Gartner Data & Analytics Summit, you highlight how governance has moved from a compliance checkbox to the engine of AI ROI. This shows your role as an interpreter of industry change, translating large‑scale trends into practical insights for practitioners. 

4. Your journey is grounded in both academic achievement and community leadership

Across external references, you are consistently described as a Microsoft Data Platform MVP, a PhD researcher recognised with the AOUG Will Swann Award, and a founder/organiser of Data Toboggan. This positions your blog as the narrative thread connecting your academic, professional, and community contributions. 

5. Your posts reveal a long‑standing commitment to making governance practical, accessible, and embedded

Whether discussing AI oversight, lineage, behavioural metadata, or Purview governance models, your writing emphasises practical implementation over theory. You repeatedly advocate for governance that is embedded, automated, and literacy‑driven, showing a consistent philosophy across years of posts. 





Saturday, 4 April 2026

GCRAI and the Rise of GRAICE™: A New Global Framework for Responsible AI Governance

The global conversation around responsible AI has been dominated for years by national strategies, corporate principles, and academic frameworks. But the launch of the Global Council for Responsible AI (GCRAI) and its GRAICE™ framework marks a shift toward something far more ambitious: a unified, cross‑sector, cross‑industry operating system for AI governance. Unlike many initiatives that focus on high‑level ethics, GCRAI positions itself as a mechanism for operationalising responsibility at scale. It’s an attempt to move responsible AI from aspiration to enforceable practice.

What makes GCRAI notable is its global footprint. With representation across dozens of countries and a network of ambassadors, it aims to create a governance ecosystem that transcends borders and industries. This matters because AI risk is not localised. Models trained in one region influence decisions in another. Data flows across jurisdictions. And the consequences of AI misuse rarely stay within organisational boundaries. A global framework is not just desirable, it is necessary.

The GRAICE™ framework, unveiled at Davos, is positioned as “humanity’s operating system for AI.” While the branding is bold, the intent is clear: create a standard that is actionable, measurable, and adaptable. GRAICE™ focuses on transparency, security, accountability, and human‑centric design. But what sets it apart is its emphasis on measurable compliance. Many frameworks articulate principles; GRAICE™ attempts to define behaviours. It seeks to bridge the gap between what organisations say about AI and what they actually do.

Running alongside GCRAI is the G.R.A.C.E. Global Council for AI, which articulates a complementary set of principles centred on human‑centred AI. Their pillars emphasise mission, vision, and the balance between technology, ethics, and humanity. While still evolving, the G.R.A.C.E. principles reinforce the idea that responsible AI is not just a technical discipline but it’s a societal one. They highlight the need for AI systems that enhance human capability rather than diminish it, and for governance that protects people as much as it protects organisations.

Together, GCRAI and G.R.A.C.E. represent a growing recognition that responsible AI cannot be solved by isolated efforts. Organisations need frameworks that are interoperable, globally recognised, and grounded in real‑world practice. They need standards that can be implemented, audited, and adapted as technology evolves. And they need governance models that reflect the complexity of modern AI systems and systems that learn continuously, behave unpredictably, and operate across boundaries.

For data and AI leaders, the emergence of GRAICE™ is a signal. The era of voluntary, principle‑only responsible AI is ending. The next phase is about operationalisation, measurement, and accountability. Whether organisations adopt GRAICE™ directly or use it as a benchmark, its influence will shape how responsible AI is defined, governed, and enforced in the years ahead. This is not just another framework but a part of a global shift toward responsible AI as a shared, enforceable standard.

G.R.A.C.E. is
GROUNDED
RESPONSIBLE
AUTHENTIC
COMPASSION
ETHICAL

Every decision involving AI should align with moral truth, respect for life, and integrity of purpose through moral align




https://www.graceglobalcouncil.com/
https://gcrai.ai/

Wednesday, 1 April 2026

How Responsible AI frameworks shape the future of AI Governance

The responsible AI landscape is shifting fast. Organisations are no longer looking for a single framework to rule them all; they’re looking for interoperability, clarity, and practical pathways to operational maturity. Two frameworks are increasingly shaping that conversation: GRAICE™, the new global framework from the Global Council for Responsible AI (GCRAI), and Microsoft’s Responsible AI Standard, one of the most established engineering‑level governance standards in the industry.

These frameworks are often discussed in the same breath, but they operate at different layers of the governance stack. Understanding that distinction is essential — because it’s precisely what makes them complementary rather than competitive.

GRAICE™: A Global Meta‑Framework for Cross‑Sector Alignment

GRAICE™ is designed as a global, cross‑sector framework. Its purpose is not to replace organisational or vendor standards, but to provide:

- a shared global vocabulary for responsible AI  
- a principles‑level structure that governments, industry, academia, and civil society can align to  
- a meta‑framework that organisations can map their internal standards against  
- a societal‑level lens that sits above implementation detail  

GRAICE™ is intentionally broad. It sets direction, coherence, and expectations at a global level — the “north star” rather than the engineering manual.

Microsoft’s Responsible AI Standard: Operational Discipline for Real Systems

Microsoft’s Responsible AI Standard sits at a different layer: the practical, engineering‑focused layer where teams build, evaluate, deploy, and monitor AI systems.

It provides:

- detailed lifecycle requirements  
- controls for data, evaluation, transparency, and oversight  
- guidance for product teams and engineering functions  
- mechanisms for translating principles into day‑to‑day practice  

Where GRAICE™ is global and principle‑driven, Microsoft’s standard is specific, actionable, and operational.

Complementary by Design

This is the critical point:  
GRAICE™ does not replace Microsoft’s Responsible AI Standard — or any other organisational framework.

Instead, the two frameworks operate in a layered model:

- GRAICE™ → global alignment, societal expectations, cross‑sector coherence  
- Microsoft RAI Standard → engineering discipline, implementation controls, operational maturity  

Together, they create a governance ecosystem that is:

- globally relevant  
- locally actionable  
- technically grounded  
- aligned with societal expectations  

This layered approach reflects where responsible AI is heading: ecosystems of interoperable frameworks, not a single universal standard.

Where They Converge

Despite their different scopes, both frameworks reinforce core responsible AI expectations:

- transparency as a foundation for trust  
- accountability and human oversight  
- continuous monitoring of evolving systems  
- responsible AI as an ongoing operational commitment  

These shared foundations show a field moving toward coherence, even when frameworks serve different purposes.

The Real Opportunity: Use Them Together

For organisations, the value lies in the combination:

- GRAICE™ provides the global direction and cross‑sector alignment.  
- Microsoft’s Responsible AI Standard provides the operational machinery to implement responsible AI in real systems.  

Using both gives organisations a governance model that is both strategically aligned and practically executable — exactly what mature AI governance requires.


Friday, 30 January 2026

Data Toboggan Winter Edition 2026

It is that time of year again when Data Toboggan is running another 12 hour conference with 3 tracks with speakers from around the world. There are some amazing sessions to learn from. The conference is free to attend as usual. 

I am speaking on something of interest and topical in my lightning talk in The Chalet on Data Literacy: The Human Advantage in an AI World.

AI is accelerating decision‑making across organisations, but it’s also accelerating how quickly mistakes can scale. This session explores how data literacy keeps humans in the loop, prevents over‑reliance on AI, and strengthens judgment, context, and critical thinking. Attendees will see real examples of AI hallucinations, learn how provenance and triangulation protect against bad outputs, and understand why cognitive skills weaken when tasks are automated. They will leave with a practical checklist for questioning AI outputs, a clear view of the risks of low data literacy, and a framework for building teams that use AI responsibly, confidently, and intelligently.



We have our usual Piste Maps with the agenda.






Wednesday, 28 January 2026

World Economic Forum 2026 in Davos Global Council for Responsible AI

At the 56th World Economic Forum 2026 in Davos between 19–23 January 2026 , the Global Council for Responsible AI officially unveiled GRAICE™ (Global Responsible AI Compliance & Ethics). It is designed as humanity’s operating system for AI. Introduced to global leaders and policymakers, GRAICE moves Responsible AI from principle to practice, integrating ethics, governance, compliance, and human-centric design into a unified, scalable framework. 

The framework is an integrated system rather than a collection of policies that are simple and repeatable.

  • Foundational values established non-negotiable ethical and human centred boundaries
  • Seven pillars translate values into operational requirements
  • Assurance tears verify that requirements are met with evidence
  • Governance structures assign accountability and decision authority

 The six foundational grounded values are  

  • Human dignity and autonomy
  • Accountability and governance 
  • Fairness and justice
  • Transparency an explain ability
  • Reliability and security
  • Inclusivity and social benefits

And the seven pillars for responsible AI define what responsibly I must achieve in practise

  • Ethical leadership
  • purpose driven innovation
  • Human centric use
  • responsible implementation
  • AI literacy and workforce readiness
  • Data governance and integrity



Sunday, 28 December 2025

What Responsible AI Actually Means for Data Leaders in 2026

Responsible AI has become a buzzword, but for data leaders it’s a practical discipline. It is not just about lofty principles or glossy frameworks. It is about ensuring that models behave predictably, ethically, and transparently. That requires more than good intentions. It requires operational governance. Data quality, lineage, access control, and policy enforcement are not side notes; they are the mechanisms that make responsible AI real.

The challenge is that many organisations still treat responsible AI as a compliance checkbox. They focus on documentation rather than behaviour, and on principles rather than practice. But responsible AI is not something you declare—it’s something you operationalise. It lives in your data pipelines, your monitoring processes, your access controls, and your governance culture.

For 2026, the organisations that thrive will be those that embed responsible AI into their data strategy. This means aligning governance with the lifecycle of AI systems, from data sourcing to model deployment to ongoing monitoring. It means treating transparency as a design requirement, not an afterthought.

Responsible AI isn’t a brake on innovation, it’s the steering mechanism. Without it, organisations risk building systems they cannot explain, defend, or trust. With it, AI becomes a strategic advantage rather than a liability.



Wednesday, 12 November 2025

From Steam to Silicon to Sentience: Four Industrial Revolutions and the Fragile Future of AI

The story of human progress is punctuated by revolutions, not just in technology, but in how we think, organize, and trust. From the steam engines of the 1840s to the generative models of the 2020s, each wave has promised liberation and delivered disruption. Today, as AI surges toward ubiquity, we must ask: what have we learned from past revolutions, and what must we safeguard before the bubble bursts.



Four Revolutions That Changed Everything

There are four revolutions that resulted in significant change where we can learn from the affects to help the AI revolution progress unhindered.

Era

Catalyst

Impact

Risk

Industrial Revolution (c. 1760 – 1840s)

Steam power, mechanization

Mass production, urbanization, labour displacement

Exploitation, unrest (e.g. Plug Plot Riots, 1842)

Digital Revolution (1950s – 1990s)

Mainframes, UK computing pioneers, PCs

Automation, global communication, software economies

Surveillance, fragmentation, digital exclusion

Cloud Revolution (2000s – 2020s)

Virtualization, SaaS, mobile-first

Scalable infrastructure, remote work, data centralization

Vendor lock-in, opaque governance, cyber risk

AI Revolution (2020s –)

Foundation models, generative AI

Cognitive automation, new interfaces, synthetic creativity

Hallucinations, bias, job loss, trust collapse

 During the industrial revolution there was a deep industrial economic depression. The Plug Plot Riots were a wave of industrial action and disturbances across Lancashire, Cheshire, and Yorkshire, triggered by severe wage reductions (often 20-25% in the cotton and coal industries). Many workers aligned with the Chartist movement advocating for political reform, responded by "plugging" mill boilers, removing drain plugs to flood engines and halt production which forced factories to close.   The Plug Plot Riots of 1842 led to some improvements for workers, notably the prevention of further wage cuts and the eventual passage of the Factory Act 1844, which introduced limited reforms. It introduced a reduction in working hours for women and children, some safety regulations in factories and a modest step toward better labour conditions.

The second revolution of computing was not just technical. It redefined abstraction, logic, and control. From the UK’s early computing pioneers to the rise of PCs, it laid the groundwork for cloud and AI. Yet it also introduced new vulnerabilities: fragmented standards, digital inequality, and the erosion of analogue memory.

Cloud as the Bridge: Infrastructure to Intelligence

Cloud computing connected digital and AI with its abstracted hardware, centralized data, and the capabilities to scale with ease. But as Satya Nadella emphasizes in his annual letter and Microsoft’s 2025 report, innovation without strategic purpose is fragile. Microsoft’s Secure Future Initiative and Quality Excellence Initiative reflect a shift: AI must be built on trust, not just talent.

Brad Smith’s AI Diffusion Report warns that AI is spreading faster than any prior technology but unevenly. The Global South, non-English languages, and underrepresented communities’ risk being left behind.

Data: The Fuel, the Flaw, the Future

AI’s power is unprecedented and has the power to improve or destroy depending on the algorithm development but also on the state of data. Poor quality, biased, or ungoverned data leads to hallucinations, misinformation, and systemic risk. As the BBC’s article on AI hallucinations shows, even the most advanced models can confidently fabricate facts, undermining journalism, science, and public trust. From the simplest things I have seen AI fabricate data, which is written so well, to the untrained eye it could be believed. Once the data is triangulated the output can be trusted. However, the data sources quality, the prompts and data that is behind paywalls will influence the outcome.

This is not a glitch it is a consequence of probabilistic systems trained on imperfect inputs. Without rigorous data governance, provenance tracking, and human oversight, AI becomes a mirror of our worst assumptions.

When the Bubble Bursts: Coping with the AI Comedown

Every revolution has its reckoning. The Plug Plot Riots of 1842, the dot-com crash, and the decline of post-industrial towns all reveal the cost of overhyped promises and underprepared systems. When the AI bubble bursts whether through regulation, disillusionment, or economic correction, organizations with strong data foundations, ethical frameworks, and human-centred design will endure.

Those who chased novelty without governance will falter.

Satya Nadella’s mantra is “thinking in decades, executing in quarters” is more than a business strategy. It’s a survival imperative. The AI era demands long-term vision grounded in short-term accountability. That means:

- Investing in data quality and lineage as core infrastructure

- Embedding responsible AI principles into every product and process

- Preparing workers for augmentation, not just automation

- Designing for resilience, not just scale

Conclusion: From Revolution to Renaissance

The Industrial Revolution reshaped labour. The digital revolution redefined logic. The cloud revolution scaled infrastructure. AI is now rewriting cognition. but without trust, transparency, and governance, even the most powerful tools will falter. As the socio-technical divide deepens and ecological systems strain, the cost of inaction grows, and we risk accelerating collapse socially and ecologically.

The disruption from AI is only just beginning. As Business Insider quoted, “Elon Musk said AI will make desk jobs feel like when workers used to make calculations by hand before the computer age.” This echoes the upheaval of 1842, when industrialisation redefined labour.

If we want AI to be a renaissance, not a reckoning, we must treat data as infrastructure, governance as strategy, and human ethics as non-negotiable. The future isn’t just what we build; it’s what we’re willing to steward.

We must draw a line: to protect data, embed meaningful guardrails, and confront the human cost of displacement. That means planning not only for the jobs we lose, but for the ones we must invent. It also means addressing the widening continental divide in AI development and its cascading impact on the environment and global economy.

References

'It's going to be really bad': Fears over AI bubble bursting grow in Silicon Valley 

https://www.bbc.co.uk/news/articles/cz69qy760weo

Satya Nadella annual letter: Thinking in decades, executing in quarters

https://www.microsoft.com/investor/reports/ar25/index.htmlhttps://www.linkedin.com/pulse/my-annual-letter-thinking-decades-executing-quarters-satya-nadella-7orpc?utm_source=share&utm_medium=member_android&utm_campaign=share_via

Brad Smith https://aka.ms/AIDiffusionReport

Elon Musk says the AI 'supersonic tsunami' will eliminate desk jobs 'at a very rapid pace'

https://www.businessinsider.com/elon-musk-ai-supersonic-tsunami-job-displacement-future-joe-rogan-2025-11

 Transparency: Written with the help of Copilot.