Insights
Analysis.
From the evidence layer.
Clinical AI. Pharmaceutical fact. Federal and defense AI governance.
AI on the GMP Line: What the EU AI Act and Draft Annex 22 Now Ask You to Prove
The EU's draft GMP Annex 22 is the most concrete AI rulebook regulators have written yet, model version, inputs, output, and human override, per decision.
Sovereign AI in Qatar: Keeping the Evidence in the Country That Asked for It
Qatar's framework is risk-based, and in its most regulated sectors the AI decision record increasingly has to stay in the country.
ISO 42001 in Production: What the Auditor Actually Tests
An ISO 42001 certificate proves your AI management system exists. It does not, on its own, prove a single decision your AI made last week.
Sovereign AI in the UAE: What You Have to Be Able to Prove
The federal PDPL, the Central Bank's AI guidance, and the DIFC's rules all ask for accountability and evidence you can produce, and increasingly, evidence that stays in-country.
DIFC Regulation 10: What You Must Be Able to Show for AI
DIFC Regulation 10 requires human-intervention triggers, a register of use cases, and the ability to explain processing with supporting evidence. Defensibility, written into law.
AI Governance in Qatar: What the Regulator Wants You to Show
The PDPPL, the NCSA's secure-AI guidelines, and the Qatar Central Bank's 2024 rules all ask the same thing: show what your AI did.
What Defensible AI Means in a Regulated Environment
Defensible AI means you can prove a single AI decision followed the rule, before a regulator, auditor, or court. How it differs from being "compliant."
AI in genomics and R&D: the evidence gap nobody talks about
The AI debate lives in the clinic. The deeper deployment is upstream, in research. Decisions made there surface years later, inside a regulatory submission. That is where the gap gets expensive.
Even the advisors need evidence. Especially the advisors.
In October 2025, a Big Four firm refunded part of a AU$440,000 fee: an assurance review with a fabricated court quote, traced to generative AI. The firms whose product is judgment deployed it without evidence.
"The model is opaque" is not a defense. The regulator said so in writing.
Every institution reaches the same comfortable excuse: the model is too complex to explain. The regulator answered in writing, and the answer travels beyond lending.
The rubber stamp isn't oversight.
A human who only waves automated decisions through doesn't legally count as human involvement. What effective oversight actually requires, and what it must leave behind.
Pharmacovigilance is where AI evidence gets real.
Classification, algorithm version, confidence score, pharmacovigilance regulation demands the most concrete AI audit trail anywhere. It is the preview of what every industry will require.
AI compliance in the GCC: the region that regulates by evidence.
QCB, CBUAE, PDPPL, DIFC, Gulf supervisors don't ask for policies. They ask for demonstrable control, in-region. What that means for any institution running AI in the Gulf.
AI resilience isn’t uptime. It’s what you can prove after the incident.
Every institution has a continuity plan for servers and clouds. Almost none has one for the layer now making decisions. AI resilience has two halves — most organizations build only the first.
Securing agentic AI, what an unprotected output can actually do
When AI only wrote text, a bad output was an embarrassment. Agentic AI acts. The case record is no longer theoretical, 344 verified agent-inflicted damage cases, 188 without any attacker.
What evidence does the EU AI Act actually require for high-risk AI?
Most coverage talks about risk categories and fines. The operational question is narrower: what must you produce when someone asks? Article by article, the answer is evidence.
When clinical AI states a dose: enforcing the rule at the moment of output
When an AI system in a clinical workflow states a dose, assigns a code, or proposes a diagnosis, that output doesn't stay hypothetical, it can flow into a patient record, a claim, an order.
Plausible isn't correct: enforcing pharmaceutical fact at runtime
In pharma, the dangerous AI output is not the obviously broken one, it's the one that reads perfectly and is wrong. A dose that fits the sentence but not the patient.
Governing AI where it can't reach the internet
In a federal or defense setting, an AI governance failure isn't a support ticket, it can be a national-security event. The systems are sensitive, the data can't leave the boundary.