Thought Leadership

Null

What the FCA’s frontier AI review means for firms

Findings from the U.K. regulator's review into frontier AI usage and risk give firms vital guidance for building operational resilience.

How can Nordics firms stay ahead of frontier AI risk?

Frontier AI, vendor risk, and DORA- practical steps for financial firms to build resilience and meet regulators' growing expectations on AI-driven cyber risk.

The 5 mistakes that sabotage mobile compliance proof of concepts

A guide to the five most common mistakes procurement teams make during a mobile compliance proof of concept, from architecture and data capture gaps to monitoring shortcomings and vendor support limitations.

How to run a successful POC for communications compliance software

A successful communications compliance POC requires clearly defined success criteria, early stakeholder alignment, end-user education, infrastructure readiness, and rigorous active evaluation to avoid common process failures.

Full steam AI-head: What’s the U.K. government and FCA AI adoption plan?  

The U.K. government and FCA AI adoption plan has laid out 10 recommendations for how regulators and the industry can reinforce governance as increasingly advanced models become accessible and integrated into core operations.

What does CIRO’s 2026 enforcement report mean for compliance teams?

A breakdown of CIRO's 2026 enforcement report and what its shift toward fewer but larger firm-level sanctions means for compliance, supervision, and recordkeeping.

Is data security a board-level priority for Nordics firms?

For Nordic compliance teams evaluating surveillance vendors, the critical questions are not just about features, they are about who controls the infrastructure, who can access the data, and what happens to it once an AI model has touched it.

How does voice surveillance differ from other forms of communications surveillance?

As regulators encourage firms to effectively supervise business communications to deter misconduct and maintain compliance, what are the main differences to watch for when monitoring voice communications versus written digital communications?

Article

Ready, set, resilience: Reassessing cyber resilience in the AI era

Regulators and authorities globally are advising organizations of the increasing risks posed by frontier AI models such as Claude Mythos. This begs the question: what are the essential steps to strengthen cyber defenses and remain operationally resilient amidst a transforming industry?

How can Nordic firms prepare for the EU AI Act?

With the EU AI Act about to enter its next phase, how can Nordic firms gain operational value from their AI investment while ensuring responsible, compliant implementation?

Article

How compliance teams can prepare for state-level AI governance laws

Compliance leaders can't wait for federal AI rules. Discover how to prepare for state-level AI governance laws, including Colorado SB 26-189 requirements.