The Loom

One thread a time, pulled until the pattern shows.

Twice a week, one AI governance event that happened, the pattern behind it, the knot it leaves for an organisation your size, and the stitch that closes it. Every source checked; every issue read by a person before it is published.

  1. Loom #6 · September 25, 2026

    Spain Just Logged the First Data Breach Run Entirely by an AI Agent

    An autonomous agent chained login, exploitation and data theft with no human in the loop. Here's what a human-speed playbook won't catch.

  2. Loom #5 · September 25, 2026

    ISO 42001 Audits Just Got Harder. Is Your Evidence Ready?

    A new standard for AI auditors, ISO 42006, is raising the bar for what counts as real evidence — right as more companies chase the ISO 42001 badge.

  3. Loom #4 · September 25, 2026

    The EU AI Board Met and Set No New Deadline — Read the Signal

    The EU AI Board's September meeting made no new law. What it built instead — enforcement coordination — is the part small AI adopters should read.

  4. Loom #3 · September 25, 2026

    Congress Can't Agree on AI Rules. Your Exposure Doesn't Wait.

    Four federal AI bills stalled in Congress this month. None of that changes what a customer questionnaire or an insurer asks you for right now.

  5. Loom #2 · September 18, 2026

    The AI questionnaire is the new security questionnaire

    Enterprise buyers have started asking suppliers to prove how they govern AI. Most companies under 500 people cannot answer yet. Here is what the questions ask, and what we built to answer them.

  6. Loom #1 · September 18, 2026

    AI can act now. A policy alone cannot keep up.

    Adoption ran ahead of governance. Then AI started taking actions. The answer is an operating loop of six steps, and seven questions you should be able to answer today.