Arguments made in public.
Commentary on AI regulation, security assurance, procurement and the practical distance between policy language and system behavior. Longer essays appear on Between Systems.
5 items
July 29, 2026
Clock is ticking on Colorado's new AI rules(opens in a new tab)
Colorado's automated decision-making law creates obligations that most organizations inside its scope have not begun to operationalize. The compliance work required is longer than the runway remaining.
AI governance & policy InformationWeekJuly 7, 2026
Why AI-built tools are threatening SaaS vendor renewals(opens in a new tab)
Internal teams can now assemble in days what they previously licensed. That shifts the renewal conversation from feature comparison to a question about whether the vendor relationship is still worth its cost.
Enterprise technology University of the CumberlandsJune 4, 2026
Bridging AI and ethics: a vision for trustworthy innovation(opens in a new tab)
A profile on carrying Responsible AI work from Microsoft Security Copilot into doctoral teaching. Covers how compliance was reframed as a design discipline rather than a gatekeeping function.
Profiles & media Federal News NetworkMay 2026
Addressing the CMMC evidence gap(opens in a new tab)
Remarks from the 2026 Risk & Compliance Exchange on why organizations fail assessments they should pass. The control usually exists; the evidence that it operated on the relevant dates does not.
Cybersecurity & public-sector assurance The Colorado SunMay 14, 2026
Colorado's small defense suppliers are about to disappear(opens in a new tab)
CMMC compliance costs land hardest on the smallest firms in the defense industrial base, which are also the hardest to replace. Colorado has policy options and a narrowing window in which to use them.
Cybersecurity & public-sector assuranceBetween Systems
A newsletter for technical program managers, security leaders and AI governance practitioners: longer arguments about the space between what a policy says and what a system does.