Governance latency and contextual debt in AWS Context Ontology Accelerator…
To what extent does the human-in-the-loop governance requirement in the Amazon Web Services (AWS) Context Ontology Accelerator (COA) workflow exacerbate the stability-plasticity dilemma for agents con…
What constitutes cohesive and coherent organisational governance for aligned,…
What constitutes good cohesive and coherent organisational governance, meaning the specific configurations, principles, mechanisms, and performance thresholds that reliably produce aligned, high-veloc…
Decision governance for decentralized execution
How do large, established organizations deliberately design, implement, and continuously recalibrate the interdependencies among (1) decision governance systems (allocation of strategic versus operati…
How Do Enterprise AI Maturity Frameworks Map onto the LLM Consumption Ladder?
How do theoretical frameworks of enterprise Artificial Intelligence (AI) / generative AI maturity map onto the observed, practice-driven progression of large language model (LLM) consumption strategie…
What is an Enterprise Architect?
What does an Enterprise Architect (EA) do, what do they explicitly not do, and how is the role distinguished from Business Architect and Domain Architect roles, including what they own, what they gove…
Governance and operating models for safe-to-fail experimentation in regulated…
In highly regulated industries such as financial services, healthcare, and pharmaceuticals, how do organisations design governance structures, team models, and operating practices that enable safe-to-…
Autonomous knowledge curation and truth maintenance for agentic ontologies
What mechanisms exist, or are under active research, to enable Artificial Intelligence (AI) agents to autonomously curate which extracted knowledge is worth retaining in a long-term ontology, detect a…
Privacy-preserving long-term memory for Artificial Intelligence agents
How can Artificial Intelligence (AI) agents preserve the utility of long-term memory for personalisation and historical context while enforcing privacy, security, and data-sovereignty controls strong…
AWS AgentCore and AWS-native Knowledge Context Layer
What Amazon Web Services (AWS) AgentCore capabilities and AWS-native services are required to design and operate a Knowledge Context Layer (KCL) that continuously acquires, curates, evolves, and serve…
How should the balance between standardized and customized internal tooling…synthesis
How should the balance between standardized and customized internal tooling shift across industries, organisation sizes, maturity levels, and Artificial Intelligence (AI) agent adoption patterns, and…
What benefits, risks, and lifecycle costs of shadow Information Technology (IT)…
What benefits, risks, and lifecycle costs of shadow Information Technology (IT) and custom local tooling are documented, and which governance approaches successfully transition covert local solutions…
At what scale or under what operating conditions do the aggregate costs of…
At what scale or under what operating conditions do the aggregate costs of fragmented local tooling exceed the productivity gains from customization, and which metrics let organisations detect that cr…
AI productivity, quality, and governance open questions
What empirical evidence can distinguish sustainable Artificial Intelligence (AI)-enabled software delivery gains from short-lived throughput effects and hidden quality or governance costs in productio…
TOGAF motivation architecture
What does The Open Group Architecture Framework (TOGAF)'s motivation architecture say about the dependency chain from business driver to goal to requirement: does it specify validation rules, or only…
SRE: establishing SLOs as contractual capability boundaries
How do Site Reliability Engineering (SRE) practices establish what a system can safely do, expressed as a contractual boundary rather than an observed average: specifically, how are Service Level Obje…
ITIL capacity management
What does IT Infrastructure Library (ITIL) capacity management specify as the measurement practice for establishing a platform capability baseline, and where does it rely on assertion rather than tele…
GORE: translating strategic intent to scoped delivery objectives
How does Goal-Oriented Requirements Engineering (GORE) handle the translation from strategic intent to scoped, time-bounded delivery objectives: what decomposition rules does it specify, and where do…
Goal specification: minimum schema and completeness validation
What properties must a Goal specification carry for an automated system to determine whether it is complete enough to act on -- specifically, what is the minimum schema, and what happens when fields a…
Model-based requirements engineering
Is there evidence from model-based requirements engineering on how scope changes to a Goal propagate to the constraint surface: specifically, does constraint re-enumeration happen automatically, or do…
Goal fragmentation: signals distinguishing salami-slicing from legitimate…
When a Goal is a fragment of a larger intent (salami-sliced deliberately or accidentally), what signals distinguish it from a legitimately scoped sub-goal?
Capability claim vs. production telemetry
When a team's capability claim conflicts with production telemetry, what arbitration mechanism produces a reliable baseline, and is there empirical evidence on which approach (telemetry override, stru…
Enterprise software pricing concessions, switching costs, and exit leverage
How do enterprise software vendors use upfront pricing concessions to increase switching costs over contract lifecycles, and what abstraction or architectural investment strategies demonstrably reduce…
Q6: Leading indicators of instability in split-authority flow systems
Which metrics best predict unsafe queue growth, rising delivery risk, or hidden demand accumulation in a split-authority delivery system, where "split-authority" means a context in which authority is…
Q5: Control model for the best throughput-risk trade-off
When should the system use pre-approval, bounded delegation with guardrails, or post-hoc review and exception escalation?
Q4: Decision rights that should move closer to execution
Which decisions about sequencing, scope, reliability, technical debt, local spend, and incident response must sit with delivery teams to reduce delay without losing control?
Q3: Routing design that isolates exceptions from routine flow
What intake, triage, queueing, escalation, and routing model allows routine work to move quickly while isolating high-risk or ambiguous work?
Q2: Demand segmentation for fast-path vs controlled-path flow
Which work items are low-risk, standard, and reversible enough for fast-path handling, and which require slower expert review or tighter controls?
Q1: Dominant flow constraint in split-authority delivery systems
What is the dominant source of delay and instability in split-authority delivery systems: capacity shortage, dependency coupling, approval latency, funding gates, or fragmented decision rights?
A spl…
Operating model synthesis for split-authority delivery systemssynthesis
What operating model improves throughput while reducing delivery risk in a split-authority environment, where "split-authority environment" means a delivery context in which authority is divided among…
Funding authority and delivery-risk accountability split
What governance and commercial structures best preserve delivery velocity, delivered quality, delivered risk control, delivery cost, and total cost of ownership when funding authority sits with a part…
Barriers to governance reform, leadership failure modes, and reform mechanisms…
What institutional and organisational barriers prevent effective governance reform in regulated enterprises, through what leadership failure modes are dysfunctional controls perpetuated, and by what m…
Failure mechanisms of internal governance controls
Through what mechanisms do internal governance controls in regulated enterprises transition from coordination cost minimisers to sources of bureaucratic inefficiency and informal circumvention, and wh…
Conditions under which internal governance controls minimise coordination costs…
Under what institutional and transaction-specific conditions do internal governance controls in regulated enterprises function as genuine minimisers of coordination costs rather than sources of bureau…
What is the most practical enterprise design for a five-pillar knowledge…synthesis
What capability architecture, control model, and operating system of work best implement a five-pillar agentic, meaning tool-using and semi-autonomous, Knowledge Management (KM) model for Artificial I…
What Institutional Designs Create Low-Cost Help-Seeking Without Embarrassment,…
Which institutional design choices create persistently low-cost help-seeking spaces where workers can ask questions, admit uncertainty, and seek guidance without expecting embarrassment, punishment, o…
How Do Formal Governance Structures Distort Cross-Department Knowledge Flows?
How do formal governance mechanisms such as hierarchy, reporting lines, and mandatory protocols reshape cross-department knowledge flow, and when do they unintentionally raise cross-department transac…
Why Do Trust-Based Institutions Outperform Incentive Schemes for Knowledge…
Why do explicit transactional incentives for sharing often decay or backfire, while trust-based institutions, stable rules and norms that make repeated sharing safe and expected, sustain lower long-ru…
Flexibility vs. Predictability
In a production pipeline with uncontrolled inputs, how does the trade-off between the flexibility of an agentic system and the predictability of a deterministic execution model affect the auditability…
What Are We Losing and Gaining by Inserting Autonomous Tool-Using Artificial…synthesis
What are we concretely losing and gaining, across the dimensions of capability, reliability, auditability, explainability, and organisational risk, by inserting autonomous tool-using Large Language Mo…
Are Multi-Step Large Language Model-Based Systems Inherently Less Explainable…synthesis
Are multi-step Large Language Model (LLM)-based systems inherently less explainable than equivalently scoped deterministic software systems, or does production-scale distributed-system complexity make…
Visibility and exit outcomes
How often does vendor-supplied temporary operational automation produce materially worse visibility and exit outcomes than internally governed temporary operational automation?
Datasets for measuring conversion from demand for local workaround tools to…
What public or internal datasets can validly measure the rate at which demand for local workaround tools, such as local apps, flows, lists, or spreadsheets, is converted into formal central Informatio…
Governance designs where explicit integrator rights substitute for co-location…
Under which governance designs do explicit integrator rights fully substitute for structural co-location of risk, cost, and benefits, and under which conditions do these designs fail?
LLM-First Policy Clarification and Institutional Knowledge Atrophy
How does shifting from peer policy clarification to Large Language Model (LLM)-first interaction affect institutional memory transfer, mentoring, and long-term policy expertise?
Policy Quality Degradation and Cross-Institution Blind Spots When New Policy…
What policy-quality degradation and systemic blind-spot risks emerge when organisations draft new policy versions from Large Language Model (LLM) interpretations of previous policy versions?
LLM Response Style and Confidence Signalling
How do Large Language Model (LLM) response style and self-reported confidence change how accurately users judge uncertainty and downstream risk when interpreting ambiguous policy and compliance requir…
LLM Training Prior Contamination in Compliance Interpretation
What failure modes emerge when Large Language Models (LLMs) combine generic public legal knowledge with proprietary organisational policy in compliance interpretation tasks?
Cognitive Closure Under Ambiguity and Confirmation Bias
How do pressures to reach a quick, definite answer under ambiguity and iterative prompt refinement influence acceptance of flawed Large Language Model (LLM) policy interpretations?
De Facto Policy Drift From Repeated Unverified LLM Interpretations
How quickly do repeated unverified Large Language Model (LLM) interpretations create de facto policy norms that diverge from executive intent and board-level risk appetite?
Adversarial prompting risks in policy assistants
How vulnerable are corporate compliance Large Language Models (LLMs) to adversarial prompting that reframes restrictive policy as permissive guidance, and which controls detect or contain deliberate m…
AI-Assisted Policy Interpretation and Accountability Displacement
How does integration of Large Language Models (LLMs) into policy-ambiguity resolution change liability allocation, escalation behaviour, and an organisation's ability to justify the resulting decision…
Policy enforcement and formal verification as Energy-Based Model (EBM)…
How can discrete policy engines and formal verifiers be translated into continuous or structured optimization signals that guide Energy-Based Model (EBM) search while preserving the original natural-l…
Layered reasoning stack interfaces
What state abstraction boundaries and interface protocols are most effective for mapping Large Language Model (LLM) candidate outputs into Energy-Based Model (EBM) evaluation state spaces while preser…
ServiceNow Artificial Intelligence (AI) Control Tower
What is the complete set of features, functions, and capabilities offered by ServiceNow AI Control Tower, and how do those capabilities address enterprise Artificial Intelligence (AI) governance, obse…
Microsoft Copilot Studio
What is the complete set of features, functions, and capabilities offered by Microsoft Copilot Studio, and how do those capabilities support enterprise-grade Artificial Intelligence (AI) agent develop…
Microsoft Foundry (formerly Azure Artificial Intelligence (AI) Foundry)
What is the complete set of features, functions, and capabilities offered by Microsoft Foundry, and how do those capabilities support the full Artificial Intelligence (AI) development lifecycle, from…
Amazon Web Services (AWS) Bedrock platform capabilities
What is the complete set of features, functions, and capabilities offered by Amazon Web Services (AWS) Bedrock, including its model access, agent building, knowledge bases, guardrails, evaluation, and…
Amazon Bedrock AgentCore and related suite
What is the complete set of features, functions, and capabilities offered by Amazon Bedrock AgentCore and its related suite, including AgentCore Gateway, AgentCore Memory, AgentCore Identity, and the…
Governance structures that support investment in delivery capability without…
Under what governance conditions can investment in building durable delivery capability be made reliably without placing risk, cost, and benefits accountability under one owner, and what minimum autho…
Reference architecture definition, framework landscape, and required detail…
What should a practical reference architecture include, which established architecture frameworks define or structure it, and how much detail should be specified across capabilities, components, flow…
Universal Entity Lifecycle Governance Framework (UELGF) 8-layer organisational…
What is the most suitable knowledge representation architecture for evolving the Universal Entity Lifecycle Governance Framework (UELGF) 8-layer organisational context model from static classification…
Declaration of the Independence of Cyberspace
What are the historical origins and core claims of John Perry Barlow's *Declaration of the Independence of Cyberspace*, how have those claims influenced modern research and technology governance, and…
Empirical evidence on rollout of organisation-wide low-code and no-code programs
What does peer-reviewed and independently verified empirical evidence reveal about the outcomes, success factors, governance models, and failure modes of organisation-wide low-code or no-code (LCNC) p…
Vendor Non-Compliance With or Absence of Implementation Standards
What failure modes have been empirically observed in organisations where vendors do not comply with established implementation standards, or where implementation standards are absent or insufficiently…
Separated Risk, Cost, and Benefits Accountability Across Business Units
What failure modes have been empirically observed in organisations where accountability for risk, operational cost, and benefits realisation are held in separate business units (BUs) rather than co-lo…
Project-Based Demand Governance With Product-Structured IT Teams
What failure modes have been empirically observed in organisations where demand is managed through a project-based model while information technology (IT) teams are structured and operated as product…
Customer-Segment Demand Prioritisation Against Domain-Based IT Teams
What failure modes have been empirically observed when organisations prioritise information technology (IT) work through customer segments, for example consumer, enterprise, or government cohorts, but…
Overlapping and Absent Accountability at Strategic and IT Layers
What failure modes have been empirically observed in organisations where accountability is either overlapping, two or more parties hold the same accountability, or absent, no party owns a given area,…
When Retrieval-Augmented Generation source documents change after agent build…
When the source documents indexed in a Retrieval-Augmented Generation (RAG) pipeline change after an agent has been built and tested, what failure modes and behavioral regressions can result in produc…
Open Digital Rights Language (ODRL) policies in Knowledge Graphs for…
How can the World Wide Web Consortium (W3C) Open Digital Rights Language (ODRL) be used to encode access control, usage policies, and governance constraints within or alongside a Knowledge Graph (KG)…
Knowledge Graph as a data product
What does it mean to treat a Knowledge Graph as a data product in a data mesh architecture, and how should data product principles, including domain ownership, data contracts, discoverability, interop…
Data product ontology
What is the data product ontology, which organisations and communities use it, how is it applied in practice within data mesh and data management architectures, and is it still current relative to com…
International Organization for Standardization (ISO) and International…
What is International Organization for Standardization (ISO) and International Electrotechnical Commission (IEC) 42001:2023 for an Artificial Intelligence Management System (AIMS), and which specific…
Security, Compliance, and Governance Risks of Using Generative AI (GenAI) Tools…
What are the documented security, compliance, and governance risks of using Generative Artificial Intelligence (GenAI) tools such as Microsoft 365 (M365) Copilot for drafting memos, reports, and other…
Control deficiencies from bypassing designated workforce record platforms
What control deficiencies are most common when designated workforce record platforms are bypassed by spreadsheet, presentation, and list-based shadow workflows?
Taxonomy criteria: process inefficiency versus hidden control and dependency…
Which explicit criteria best distinguish ordinary process inefficiency from hidden control and dependency risk in workforce-capacity and skill-tracking workflows?
Process-Risk-Control (PRC) scoring impacts from unstandardized workforce…
How should inherent risk, meaning exposure before relying on controls, and control effectiveness, meaning the demonstrated reliability of the mitigating control, scores in a PRC library change when wo…
Language Server Protocol (LSP)-style policy surfaces and workforce taxonomies…
How can workforce-capacity and skills-taxonomy structures integrate with a Language Server Protocol (LSP)-style policy diagnostic surface to detect persistent capability mismatches automatically in en…
National Institute of Standards and Technology (NIST) Special Publication (SP)…
How do missing provenance, lineage, and change-history controls in Microsoft Lists, Excel, and PowerPoint workforce artifacts conflict with NIST SP 800-53 Rev. 5 integrity-related controls?
Key-person dependency and Basel execution, delivery, and process-management…
How should key-person dependency in workforce-critical processes be mapped to execution, delivery, and process-management risk categories in Basel Committee framing?
Control Objectives for Information and Related Technologies (COBIT) and…
What minimum process-definition conditions do COBIT 2019 and CMMI require before mitigation of workforce-process risk can be considered effective and sustainable?
Basel Committee on Banking Supervision (BCBS), International Organization for…
How do Basel Committee on Banking Supervision (BCBS), International Organization for Standardization (ISO) 31000, and National Institute of Standards and Technology (NIST) frameworks classify risk whe…
Implementation Patterns for Regulatory Compliance in Artificial…
What specific implementation patterns, including externalized machine-executable policy rules (Policy-as-Code (PaC)), rules engines, input, tool-use, and output safety controls (guardrails), output va…
Practical Limits of Large Language Model (LLM) Determinism
What are the practical limits of making LLM (Large Language Model)-based decisions or policy enforcement deterministic, even with temperature=0, fixed seeds, and constrained prompts?
Hybrid Architecture Design
How should hybrid architectures be designed so that probabilistic LLMs handle interpretation and insight generation while deterministic layers enforce final governance, compliance, and high-stakes dec…
Governance Policy Application
To what extent must governance policy application be deterministic, consistent, reproducible, and auditable, versus allowing stochastic or probabilistic elements when Artificial Intelligence (AI) or L…
Data Governance Standards and Regulations Applied to Artificial Intelligence…
How do established data governance standards, including International Organization for Standardization and International Electrotechnical Commission (ISO/IEC) 38505, DAMA-DMBOK (Data Management Body o…
Extending Traditional Data Governance Frameworks to Address Large Language…
How can traditional data governance frameworks be extended or mapped to address the inherent non-determinism and uncertainty about whether deployed behavior remains aligned with intended use in modern…
Compliance Risks of Relying on Stochastic Large Language Model (LLM) Outputs…
What evidence or guidance exists on the compliance risks of relying primarily on stochastic Large Language Model (LLM) outputs for governance, privacy, or regulatory decisions?
Orthogonality thesis under modern Large Language Model (LLM) training and…
How should the orthogonality thesis be interpreted for modern Large Language Models (LLMs) given current pre-training and post-training methods, and what does that imply for enterprise risk when agent…
What are the primary behavioural and structural drivers of unsanctioned AI…
What are the primary behavioural and structural drivers of shadow Artificial Intelligence (AI) adoption, meaning unsanctioned use of AI tools without formal approval or oversight, in enterprises after…
What tiered human oversight models maintain meaningful human-in-the-loop (HITL)…
Under high-volume deployment of multi-step Artificial Intelligence (AI) systems, what factors cause human-in-the-loop (HITL) oversight to degrade into rubber-stamping, meaning approval without genuine…
What metrics beyond code acceptance rates best capture net organisational value…
What metrics beyond code acceptance rates and lines of code best capture net organisational value when Artificial Intelligence (AI) coding tools such as GitHub Copilot are adopted with productivity ma…
How do coupled enterprise risks manifest differently in agentic Artificial…synthesis
How do the coupled enterprise risks, capability debt, incentive-driven shadow Artificial Intelligence (AI) adoption, skill decay, and oversight failure, manifest differently in agentic AI, meaning aut…
How can organisational capability debt be rigorously defined and measured as a…
How can capability debt, the accumulated organisational deficit in review quality, judgment, process maturity, and skill inventory, be rigorously defined, measured, and tracked as a leading indicator…
To what degree does over-reliance on AI tools accelerate measurable skill decay…
To what degree and through what mechanisms does over-reliance on Artificial Intelligence (AI) tools, particularly tools that can plan or act across multi-step workflows, accelerate measurable skill de…
Updating the enterprise Artificial Intelligence ecosystem capability reference…synthesis
How should the enterprise Artificial Intelligence (AI) ecosystem capability reference architecture (as expressed in `2026-04-22-enterprise-ai-capability-model`, `2026-05-05-enterprise-ai-capability-st…
Production incidents linked to Artificial Intelligence systems
What documented production incidents over the last five years were caused or materially contributed to by Artificial Intelligence (AI) systems, and what recurring failure modes and mitigations were id…
Artificial Intelligence (AI) regulatory guidance delta checksynthesis
Since the completion of `2026-04-24-ai-agent-regulation-global-financial-services`, what newly issued regulatory advice, policy, guidance, or supervisory statements have been published on Artificial I…
Five Eyes stance on Artificial Intelligence risk and policy advice
What is the current stance of the Five Eyes intelligence alliance (Australia, Canada, New Zealand, United Kingdom, United States) on Artificial Intelligence (AI) risks, and what concrete policy and op…
Integrating 2026-05 security and supply chain findings into the enterprise…synthesis
How should the enterprise Artificial Intelligence (AI) ecosystem capability reference architecture (as expressed in `2026-04-22-enterprise-ai-capability-model` and the `2026-05-05-enterprise-ai-capabi…
How do open-weight policy enforcement reasoning models, exemplified by OpenAI's…
How do open-weight, meaning released-weight and self-hostable, policy enforcement reasoning models, exemplified by OpenAI's gpt-oss-safeguard, classify text against strict, customizable policies, and…
What is the minimal viable schema for an Artificial Intelligence bill of…
What is the minimal viable set of schema properties required to describe Artificial Intelligence (AI) system dependencies for systems that use prompts, retrieval knowledge bases, memory, and tools in…
Why does Software Bill of Materials (SBOM) fail as a complete inventory model…
Why do traditional Software Bill of Materials (SBOM) concepts fail to adequately describe the dependency, provenance, and runtime composition of agentic Artificial Intelligence (AI) systems, and what…
How can a runtime-observed Artificial Intelligence Bill of Materials (AIBOM) be…
How can a dynamic, runtime-observed Artificial Intelligence Bill of Materials (AIBOM) be generated for an agentic Artificial Intelligence (AI) system, capturing execution traces, transient Retrieval-A…
How do you capture a runtime-observed Artificial Intelligence Bill of Materials…
How do you instrument a real agentic Artificial Intelligence workload, meaning a tool-using workload that plans or acts across multiple steps, to capture a runtime-observed Artificial Intelligence Bil…
How does the European Union (EU) AI Act and related international AI governance…
- [fact; source: https://owaspaibom.org/] Artificial Intelligence Bill of Materials (AIBOM) is used here in the Open Worldwide Application Security Project (OWASP) sense of an artifact intended to mak…
What introspection, export, and control surfaces actually exist across…
What logs, traces, audit Application Programming Interfaces (APIs), Artificial Intelligence Bill of Materials (AIBOM) export capabilities, version-pinning mechanisms, allowlists, and policy hooks actu…
How should identity, delegation chains, and permission scopes be formally…
How should identity, delegation, and permission scopes be formally represented in an Artificial Intelligence Bill of Materials (AIBOM) schema to enable end-to-end attribution, "who authorized what", a…
What security and governance risks can a declared and runtime-observed…synthesis
What categories of security and governance risk can an Artificial Intelligence Bill of Materials (AIBOM), an artifact intended to make artificial intelligence systems transparent, auditable, and secur…
How do you construct a declared design-time Artificial Intelligence Bill of…
How do you extract and construct a declared design-time Artificial Intelligence Bill of Materials (AIBOM), covering model, prompt or system instruction, tools, Retrieval-Augmented Generation (RAG) kno…
What measurement systems and frameworks exist for quantifying Information…
What measurement systems and frameworks exist for quantifying Information Technology (IT) system legibility, defined here as the ability to reason about, understand, and comprehensively characterise t…
What does the 2026 Harvard Business Review trendslop study and related…
What does the March 2026 Harvard Business Review (HBR) "trendslop" study reveal about positional bias, prompt-framing sensitivity, and context-insensitive bias in Artificial Intelligence (AI)-generate…
What architectural capabilities and contractual conditions are required to…
What architectural capabilities and contractual conditions are required for an enterprise to maintain multi-platform portability and mitigate Artificial Intelligence (AI) vendor lock-in risk from: Mic…
What capability and control design is needed to mitigate incentive…
What capability and control design is needed, at enterprise scale, to mitigate incentive misalignment (where individuals are rewarded for bypassing governance), shadow Artificial Intelligence (AI) (AI…
How should human-in-the-loop (HITL) design be adapted when AI review volume…
How should human-in-the-loop (HITL) design be adapted when Artificial Intelligence (AI) review volume reaches the point where human reviewers become a throughput bottleneck or default to rubber-stampi…
What security capabilities are required in an enterprise Artificial…
What security capabilities are required in an enterprise Artificial Intelligence (AI) system, beyond basic Application Programming Interface (API) access controls and audit logging, to address prompt…
Vendor-agnostic enterprise Artificial Intelligence (AI) capability model
What is the complete set of architectural capabilities required to run Artificial Intelligence (AI) safely at scale in a regulated enterprise, how do Microsoft's Copilot family (Microsoft 365 Copilot…
What principles and governance practices enable sustainable, high-quality…synthesis
What principles and governance practices, spanning harness design, task selection, human oversight, and open-source software (OSS) ecosystem health, enable sustainable, high-quality software developme…
What strategies are effective for open-source software maintainers dealing with…
What strategies are effective for open-source software (OSS) maintainers in filtering, managing, and sustaining project health against a rising volume of low-quality Artificial Intelligence (AI) agent…
What is the evidence for human oversight as an effective quality gate in…
What is the empirical evidence that human oversight, specifically the human bottleneck property of limited throughput and pain response, functions as an effective quality gate, meaning the control poi…
How do errors compound in Artificial Intelligence (AI)-agent-heavy codebases,…
How do errors ("boooos") compound in codebases developed with high volumes of AI agent-generated code, including how local patches cause global regressions, and what review and governance strategies c…
What criteria define tasks where Artificial Intelligence (AI) coding agents…
What empirically grounded criteria define the characteristics of software development tasks where Artificial Intelligence (AI) coding agents reliably add value, versus tasks where agent autonomy intro…
Deterministic weighted scoring models for customer risk rating under MLR 2017
To what extent do deterministic weighted scoring models (based on the four main risk factors: customer, geographic, product/service, and delivery channel) effectively support a proportionate risk-base…
Anthropic Claude Teams or Enterprise vs Microsoft 365 Copilot Coworksynthesis
How do Anthropic Claude, specifically the Team and Enterprise plans, and Microsoft 365 (M365) Copilot Cowork compare across capability, pricing, user experience, and guardrails, and what are the secur…
The orthogonality thesis in Artificial Intelligence (AI) alignment
What is the orthogonality thesis in Artificial Intelligence (AI) alignment, what is the current evidence for and against it, and what are its practical implications for Explainable Artificial Intellig…
Human cognitive bias toward Artificial Intelligence (AI) correctness and…
To what extent do humans systematically over-trust AI-generated explanations, and what mechanisms, automation bias, RLHF-induced sycophancy in post-training, and the polysemantic nature of internal mo…
Explainable Artificial Intelligence (XAI)
What is the current state of Explainable Artificial Intelligence (XAI) research, who leads it and what are the primary techniques, and how does XAI intersect with regulatory obligations, audit require…
Alternative Continuous Integration and Continuous Delivery pipeline platforms…
What alternative Continuous Integration and Continuous Delivery (CI/CD) pipeline platforms, specifically Harness, Amazon Web Services (AWS) CodeBuild and CodeDeploy, and Jenkins, can serve as the gove…
Universal Entity Lifecycle Governance Framework (UELGF) extension
What concrete reference architecture and tooling specification, covering policy-as-code engines such as Open Policy Agent (OPA) and Cedar, observability pipelines such as OpenTelemetry (OTel), and mod…
Universal Entity Lifecycle Governance Framework (UELGF) extension
What explicit human oversight and accountability requirements, covering named human owners for every governed entity, defined escalation paths for high-risk autonomous actions, accountability designat…
Universal Entity Lifecycle Governance Framework (UELGF) extension
What agentic Artificial Intelligence (AI)-specific risk categories, specifically emergent behaviour, goal misalignment, multi-agent interaction failures, and hallucinations in decision loops, are insu…
How do academic and scientific publishing systems handle post-publication…
How do established academic and scientific publishing systems (journal publishers, preprint servers, living review platforms) handle post-publication corrections, amendments, retractions, and formal c…
ServiceNow workflow orchestration and agentic Artificial Intelligence (AI)…
What workflow orchestration and governance capabilities does ServiceNow currently provide for Artificial Intelligence (AI) agent workloads, specifically its identity resolution, permissions, audit tra…
Governance-as-moat thesis and prior research implications
How does the thesis advanced in the April 2026 Liam Hyland and Leonis Capital ServiceNow analysis, that governance is the durable, non-replicable value layer in AI-augmented enterprise technology stac…
Enterprise data stack value-distribution frameworks
What frameworks - specifically the seven-layer enterprise stack and the Software Repricing Matrix described in the April 2026 Liam Hyland ServiceNow analysis video, together with comparable frameworks…
Universal Entity Lifecycle Governance Framework (UELGF)
What is the complete specification of the Universal Entity Lifecycle Governance Framework (UELGF), integrating foundational definitions and principles, entity taxonomy and Confidentiality, Integrity,…
Universal Entity Lifecycle Governance Framework (UELGF)
How should the UELGF specify the runtime feedback loop, covering signal taxonomy, signal aggregation and evaluation mechanism, automated response taxonomy proportionate to signal severity, re-evaluati…
Universal Entity Lifecycle Governance Framework (UELGF)
What policy architecture, covering Policy Administration Point (PAP), Policy Decision Point (PDP), Policy Enforcement Point (PEP), and Policy Information Point (PIP), and what 8-layer organisational c…
Universal Entity Lifecycle Governance Framework (UELGF)
How should the UELGF specify governed golden rails for each entity type and Confidentiality, Integrity, and Availability (CIA) tier such that the rail is generative, with a complete governed scaffold…
Universal Entity Lifecycle Governance Framework (UELGF)
What are the foundational definitions, formal principles, and architectural properties required to specify the Universal Entity Lifecycle Governance Framework (UELGF) such that it applies consistently…
Universal Entity Lifecycle Governance Framework (UELGF)
What canonical entity taxonomy and Confidentiality, Integrity, and Availability (CIA) classification system should the UELGF use to determine governance intensity, ensuring that every entity type, fro…
Universal Entity Lifecycle Governance Framework (UELGF)
How should the UELGF formally specify the decommission lifecycle, including a complete trigger taxonomy, procedural requirements differentiated by CIA tier, a ghost-entity detection and remediation me…
Invariant-based anomaly detection in the Policy Information Point (PIP)
How can the Policy Information Point (PIP) detect when a governed asset's transient operating context is being used, intentionally or through task creep, to suppress or obscure a permanent invariant,…
Universal policy synchronisation and integrity
What mechanism ensures that the Policy Decision Point (PDP) evaluates a governed asset against logically identical policy at every lifecycle phase, such that a soft gate in Development and a hard gate…
Policy Administration Point (PAP) dynamic policy profiling and proportionality
How can a Policy Administration Point (PAP) dynamically map a governed asset's metadata, specifically its invariants and Confidentiality, Integrity, and Availability (CIA) ratings, to a proportional a…
Out-of-band policy invalidation and remediation
What consistency model governs [Policy Administration Point (PAP)](https://docs.oasis-open.org/xacml/3.0/xacml-3.0-core-spec-os-en.html)-to-[Policy Enforcement Point (PEP)](https://docs.oasis-open.org…
Cryptographic preservation and runtime evaluation of original intent
What representation of original intent, captured at the Getting Started phase, is simultaneously cryptographically verifiable and semantically stable enough to function as a meaningful evaluation base…
What is the strongest evidence-based argument that investing in software…
What is the strongest evidence-based argument - drawing on Yann LeCun's primary sources, the formal methods literature, the systems capability debt research already in this corpus, and empirical evide…
What is the precise technical distinction between code generation and other…
What is the precise technical distinction between code generation and other Large Language Model (LLM)-generated outputs in terms of external verifiability, specifically, that code operates in a forma…
What does synthesising LeCun's architectural critique of Large Language Models…
What does the synthesis of Yann LeCun's architectural critique of Large Language Models (LLMs), no causal world model, no consequence reasoning, verifiable only in formal systems, with the systems cap…
What constraints do vendor platforms impose on governance, and how should…
What governance constraints are imposed by major vendor Artificial Intelligence (AI) and low-code platforms, specifically, what governance capabilities are natively supported versus where external con…
When and how should human intervention be incorporated into Artificial…
When and how should human intervention be incorporated into AI-driven and automated workflows, specifically, what trigger conditions, intervention thresholds, escalation procedures, response time expe…
How can enterprise data governance frameworks be consistently enforced within…
How can enterprise data governance frameworks be consistently enforced within Artificial Intelligence (AI) and visual, minimal-code application environments, specifically, how should data classificati…
How should AI and low-code governance integrate with existing software…
How should Artificial Intelligence (AI) and low-code governance integrate with existing software development and platform engineering practices, specifically, how should governance controls be integra…
How should Artificial Intelligence (AI) and low-code use cases be classified…
What structured risk classification framework is appropriate for AI and low-code use cases in enterprise environments, specifically, how should categories such as informational, decision-support, and…
How can enterprise Artificial Intelligence (AI) and low-code governance…
How can enterprise Artificial Intelligence (AI) and low-code governance frameworks be aligned with external regulatory and compliance obligations, specifically, what is the mapping between governance…
What observability and telemetry model is required to govern Artificial…
What observability and telemetry model is required to govern AI and low-code systems at scale, specifically, what must be logged, at what frequency, and at what level of granularity, including prompt…
What lifecycle management model is required for Artificial Intelligence (AI)…
What comprehensive lifecycle management model is required for AI models, prompts, and low-code applications, covering versioning strategies, deployment controls, rollback mechanisms, ownership trackin…
What maturity model best describes the evolution of governance capabilities for…
What maturity model best describes the evolution of governance capabilities for AI and low-code in enterprises, specifically, what are the clearly defined maturity stages, capability benchmarks, and p…
Where should governance enforcement points be implemented within enterprise…
Where should governance enforcement points be implemented within enterprise architecture for Artificial Intelligence (AI) and low-code systems, specifically, at which architectural layers (Application…
What are the primary failure modes in enterprise Artificial Intelligence (AI)…
What are the primary failure modes in enterprise Artificial Intelligence (AI) and low-code deployments, including data leakage, conflicting automations, unintended actions by AI agents, and loss of au…
How should decision rights, accountability, and liability be structured for…
How should decision rights, accountability, and liability be structured for AI systems and low-code applications in enterprise environments, specifically, who should be empowered to approve new use ca…
How do organisational incentives, culture, and behaviour influence adherence to…
How do organisational incentives, culture, and behaviour influence adherence to governance in Artificial Intelligence (AI) and low-code environments, specifically, what conditions drive teams to bypas…
What is the cost, performance, and delivery impact of governance controls on AI…
What is the cost, performance, and delivery impact of governance controls on AI and low-code development, specifically, what economic model quantifies the trade-offs between governance strength and de…
What identity and access management model is required for Artificial…
What identity and access management (IAM) model is required for non-human actors, AI agents and low-code artefacts, operating within enterprise systems, specifically: how should machine identities be…
What control-plane architecture is required to manage Artificial Intelligence…
What control-plane architecture is required to manage AI agents and low-code systems as distributed, semi-autonomous actors within enterprise environments, specifically, how should policies be created…
Implicit rate-limiting controls removed by agentic Artificial Intelligence (AI)
Prior to agentic Artificial Intelligence (AI), the blast radius of ungoverned citizen development was implicitly bounded by human speed, attention, fatigue, and working hours, controls that are not do…
Deployment pipeline as the only enforceable control gate for citizen-developed…
In an environment where citizen development tooling is already licensed and accessible to non-technical staff, and where the distinction between personal productivity and production automation has col…
Access control amplification under agentic operations
Agents do not inherit a user's typical behaviour, they inherit the worst-case interpretation of that user's full permission set, because they operate without fatigue, attention limits, or working hour…
Policy coherence as a machine-checkable prerequisite
Contradictory or outdated policy documents are a chronic governance failure that organisations tolerate because the consequences under human operation are slow-moving. Under agentic operation, agents…
Permission-safe Retrieval-Augmented Generation (RAG) in enterprise information…
What are the technical constraints on permission-safe Retrieval-Augmented Generation (RAG) in an enterprise information architecture with incoherent access controls, collaboration groups created ad ho…
Dependency ordering of foundational conditions for safe agentic Artificial…
The foundational conditions for safe agentic AI deployment in a regulated financial institution are not independent, they form a dependency graph in which policy coherence is a prerequisite for inform…
Systems capability debt as the root cause of citizen development
What empirical evidence exists that systems capability debt, the accumulated gap between what people need from their systems and what those systems deliver across integration, functionality, data acce…
Systems capability debt, citizen development, and agentic AI risk
Does the synthesis of technical debt literature (Cunningham, Kruchten), systems capability research, transaction cost economics (Coase, Williamson), operational risk frameworks (Basel III/IV, Risk and…
Regulatory and standards preconditions for deployment of Artificial…
Under applicable regulatory and standards frameworks, including Australian Prudential Regulation Authority (APRA) CPS 230, the European Union (EU) Digital Operational Resilience Act (DORA), Payment Ca…
Multi-provider AI control planes
Which platforms or architectural designs provide multi-provider Artificial Intelligence (AI) control planes that unify discoverability, oversight, logging, security, data-access control, Financial Ope…
What is Microsoft 365 Copilot Cowork and what are its enterprise governance…
What is Microsoft 365 (M365) Copilot Cowork, how does it technically differ from custom Microsoft Copilot Skills, and what are the governance, legal, and shadow Information Technology (IT) risks it in…
Global artificial intelligence agent regulation in financial services
What regulatory obligations do financial-services regulators globally, including the European Union (EU), Australia, New Zealand (NZ), the United States (US), and the United Kingdom (UK), impose on Ar…
Business-led low-code agent governance
Under what conditions does business-led low-code Artificial Intelligence (AI) agent creation produce durable organisational value versus technical debt and governance fragmentation, and what foundatio…
Historical technology adoption patterns as analogues for enterprise Artificial…
What can organisations learn from retrospectives of prior technology introductions, specifically personal computing, Enterprise Resource Planning (ERP), cloud computing, Robotic Process Automation (RP…
Knowledge curation governance as an enterprise AI capability in regulated…
What operational models exist for governing authoritative knowledge as a managed enterprise capability for Artificial Intelligence (AI) consumption in regulated financial institutions, covering domain…
Enterprise AI use-case routing frameworks
What decision frameworks do enterprises use to route Artificial Intelligence (AI) use cases to the appropriate platform, implementation pattern, and risk tier, distinguishing low-code business-led, pr…
Enterprise AI platform operating models
What organisational structures do enterprises use to operate multiple Artificial Intelligence (AI) platforms simultaneously, and what trade-offs emerge between (a) a single unified AI platform team, (…
Automated governance assurance and change control verification patterns for…
What technical patterns exist for automating governance assurance and change control verification in Artificial Intelligence (AI)-assisted delivery pipelines, specifically audit evidence generation, p…
Latest developments history
What trends, themes, and directional shifts are visible in the source material at `Latest-developments-/history` and related public sources, and what are the most plausible evidence-grounded speculati…
Against bureaucracy: dismantling control systems to focus on value and…
What does the synthesis of the Anti-Bureaucracy Manifesto and James Burnham's *The Managerial Revolution* reveal about how organisations can dismantle control systems and system waste while refocusing…
Bureaucracy growth and the boomer generation hypothesis
Who has written or researched the idea that the growth of bureaucratic functions — specifically Human Resources (HR), Finance, and Procurement — was led or significantly amplified by the baby boomer g…
Public sentiment on AI in banking and high-trust institutions
What does current (2024–2025) survey data reveal about customer sentiment toward Artificial Intelligence (AI) in banking and high-trust Financial Services (FS) institutions — in Australia, across Asia…
Cross-Scanner Compliance Evidence and Waiver Normalisation in GitHub Actions
How should an organisation running multiple compliance scanners in GitHub Actions normalise evidence, severity, waiver handling, and developer-facing output so that heterogeneous tools behave like one…
Compliance Scanning via GitHub Actions — Broad Policy as Code Across a…
How can GitHub Actions (with GitHub Advanced Security (GHAS) and CodeQL already enabled) be extended to enforce a broad, organisation-wide compliance policy — covering naming conventions, architectura…
Technology Capability Models
What established and emerging IT capability models define a complete, multi-level set of technical capabilities - such as authentication, networking, Application Programming Interface (API) gateways,…
Adaptive Policy-Based Authorization (APBA)
How does Adaptive Policy-Based Authorization (APBA) align with the dynamic access-control requirements of National Institute of Standards and Technology (NIST) Special Publication (SP) 800-53 and ISO/…
Invariants in Software as a Service (SaaS) Banking Software
What capabilities do enterprise Software as a Service (SaaS) banking platforms (principally Salesforce Financial Services Cloud (FSC) and nCino) provide as true invariants - independent of customer im…
Prompt injection threat landscape
What is the current state of the prompt injection threat in agentic artificial intelligence (AI) systems: who is exploiting it, who is defending against it, and what does the research community consid…
Adam Smith, Organisational Design, Desire Paths, and AI Strategy
What can Adam Smith's insights into human nature and morality - drawn from *The Theory of Moral Sentiments* (ToMS) and *The Wealth of Nations* (WoN) - teach us about designing organisations that align…
Ricardian Contract model
What is the Ricardian Contract model proposed by Ian Grigg in 1996, how has it evolved over the past three decades, who is actively building with it today, and what does the latest academic and applie…
Can organisational intent be expressed as a formally structured specification…
Can organisational intent — mission, values, strategy, resource allocation — be expressed as a formally structured specification from which human-readable artefacts are derived, and against which Obje…
Best practices in financial forecasting for IT operational run costs
What are the established best practices for financially responsible forecasting of Information Technology (IT) operational run costs — covering cost estimation by technology and infrastructure type, r…
The Nature of the Firm
Why do organisations (firms and business units) exist when markets are theoretically efficient? What are the fitness functions and invariants that determine when organisational form is the correct coo…
AI concept classification taxonomy
What is a coherent, internally consistent classification taxonomy for the core concepts in AI-assisted and agentic systems — covering prompt types, instruction types, prompt/content/intent engineering…
Better Business Cases
What is the Better Business Cases (BBC) Five Case Model framework, what are the requirements and standards for each of the five cases, and how should an AI agent apply this framework to author, review…
ServiceNow Process Mapping
What options exist within ServiceNow for documenting, mapping, and maintaining business and IT processes — and which approaches are sustainable enough in practice to stay meaningful, current, and actu…
ServiceNow Platform Strategy
Given the findings from the Common Service Data Model (CSDM) data modelling, process mapping, and AI capability research, how should an organisation develop a coherent, practical ServiceNow platform s…
ServiceNow CSDM: Practical Data Modelling Across ITSM, APM, SPM, IRM, and FSO
How should organisations model their enterprise data in ServiceNow to meet the CSDM standard while keeping the model maintainable and accurate — and what are the practical patterns for aligning IT Ser…
How organisations practically implement IT RUN vs BUILD cost allocation
How have organisations actually implemented a working RUN vs BUILD IT cost allocation — specifically: how did they agree on what counts as an "application", how did they get consistent work-item taggi…
AI capability is not a data problem - why the data/analytics department is the…
What is the strongest case - technical, architectural, organisational, legal, and regulatory - that an organisation's AI capability should NOT be owned by or coupled to its data/analytics department o…
Guiding Headless Agents via LSP-Like Mechanisms for Org Policy Conformance
Who is building solutions that allow headless autonomous coding agents to be guided in real time by LSP-like mechanisms — rather than CI gates or pre-commit hooks — to conform to an organisation's sec…
RBNZ AI Supervisory Expectations
What are the Reserve Bank of New Zealand's specific supervisory expectations for AI use by regulated entities, and how do these align with or diverge from the expectations of comparator regulators (AP…
Exploit versus explore Artificial Intelligence (AI) investment classification
How should organisations distinguish between exploitation and exploration AI investments in practice, and what diagnostic criteria and portfolio tools enable that distinction to be applied at budget a…
Artificial Intelligence (AI) security strategy
Which organisations have developed coherent AI strategies with security as the primary objective — either using AI to enhance security posture or governing the security risks that AI systems themselve…
Artificial Intelligence (AI) risk-reduction deployments in financial services
Which organisations have developed AI strategies explicitly framed around risk reduction — operational risk, credit risk, fraud, compliance, model risk — and what governance structures, outcome metric…
Enterprise Artificial Intelligence (AI) efficiency programme outcomes
Which published AI strategies — corporate, national, or sector-specific — are explicitly designed around business efficiency as the primary objective, what measurable outcomes have they produced, and…
Artificial Intelligence (AI) agents in financial services line 1 and line 2…
Who is currently building or deploying AI agents specifically positioned to operate within the three lines of defence model — line 1 (business/operational risk management) and line 2 (risk and complia…
AI for Control Testing, Gap Identification, and Policies/Standards Reviews
Which organisations are using AI to automate control testing, identify control gaps, or conduct policies and standards reviews — and what does the current vendor, practitioner, and regulatory landscap…
Transaction Cost Economics
What are the foundational concepts of transaction cost economics (Coase → Williamson → North → Ostrom), and how might the analytical framework map onto software engineering organisation, AI agent desi…
AI Strategy: global and NZ examples, policy frameworks, regulations, and…
What do leading global AI strategies look like, how does New Zealand's regulatory and policy landscape (RBNZ, DIA, MBIE, and others) compare, and what use-case typology — from human augmentation throu…