<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Nalgo · Production AI · Built, shipped and governed</title><description>Nalgo assesses, builds and governs production AI, agents, automation and the software around them, for companies that need it to ship and stay compliant.</description><link>https://nalgo.co.uk/</link><language>en-us</language><item><title>ISO 42001 Clause 10 explained: improvement</title><link>https://nalgo.co.uk/blog/iso-42001-clause-10/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-10/</guid><description>Clause 10 is what makes the AI management system a living thing rather than a snapshot. It commits you to continual improvement and gives you a disciplined way to handle things that go wrong: nonconformity and corrective action. Here is what Clause 10 requires, and why it closes the loop.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>ISO 42001 Clause 5 explained: leadership</title><link>https://nalgo.co.uk/blog/iso-42001-clause-5/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-5/</guid><description>Clause 5 is where AI governance either gets real or stays a slide deck. It puts three duties on top management: lead and commit, set an AI policy, and assign clear roles and authority. Here is what Clause 5 actually requires, and why auditors treat weak leadership as a fail.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>ISO 42001 Clause 6 explained: planning and AI risk</title><link>https://nalgo.co.uk/blog/iso-42001-clause-6/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-6/</guid><description>Clause 6 is the engine room of ISO 42001. It is where you assess AI risk, treat it, produce a Statement of Applicability against Annex A, assess system impact, and set measurable objectives. This is the clause auditors spend the most time on. Here is what it actually requires.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>ISO 42001 Clause 7 explained: support</title><link>https://nalgo.co.uk/blog/iso-42001-clause-7/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-7/</guid><description>Clause 7 is what makes the plan runnable. It covers the resources, competence, awareness, communication and documented information the AI management system needs to actually function. Neglect it and a well-designed system quietly stops working. Here is what Clause 7 requires.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>ISO 42001 Clause 8 explained: operation</title><link>https://nalgo.co.uk/blog/iso-42001-clause-8/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-8/</guid><description>Clause 8 is where the plan meets reality. It requires you to run the processes you designed, and to actually perform your AI risk assessment, risk treatment and impact assessment, not just once at build time, but on a schedule and whenever things change. Here is what Clause 8 requires.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>ISO 42001 Clause 9 explained: performance evaluation</title><link>https://nalgo.co.uk/blog/iso-42001-clause-9/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-9/</guid><description>Clause 9 is how you find out whether the AI management system actually works. It requires you to monitor and measure it, audit it internally, and have leadership review it. This is where governance stops taking its own word for it. Here is what Clause 9 requires.</description><pubDate>Mon, 20 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>Eval metrics that actually matter (beyond accuracy)</title><link>https://nalgo.co.uk/blog/eval-metrics-that-matter/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/eval-metrics-that-matter/</guid><description>Accuracy is the metric everyone reaches for and the one that hides the most. If you want to know whether an AI system is safe to ship, these are the metrics that predict how it behaves in the real world: faithfulness, relevance, safety, calibration, task success, and the operational numbers underneath them.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>Evaluation</category><category>Production</category><category>Governance</category><author>John Bagnall</author></item><item><title>ISO 42001 Clause 4 explained: context of the organization</title><link>https://nalgo.co.uk/blog/iso-42001-clause-4/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-clause-4/</guid><description>Clause 4 is where an AI management system starts. It asks you to define your context, your interested parties, your role in the AI value chain, and the scope of the system. Get it wrong and everything built on top inherits the mistake. Here is what Clause 4 actually requires, in plain terms.</description><pubDate>Sun, 19 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>ISO 42001 checklist: what you actually need in place</title><link>https://nalgo.co.uk/blog/iso-42001-checklist/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-checklist/</guid><description>A practical ISO 42001 checklist, grouped the way the standard is: scope and leadership, your AI inventory, risk and impact assessment, the Annex A controls, competence, monitoring and audit. Use it as a gap analysis to see what you have and what is missing before you certify.</description><pubDate>Fri, 17 Jul 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>Human oversight in practice (EU AI Act Article 14)</title><link>https://nalgo.co.uk/blog/human-oversight-in-practice/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/human-oversight-in-practice/</guid><description>Human oversight is the most-claimed and least-delivered AI control. The EU AI Act (Article 14) makes it a legal requirement for high-risk AI, but a human who rubber-stamps the output is not oversight. Here is what the Act actually asks, and what meaningful oversight looks like in practice.</description><pubDate>Thu, 16 Jul 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>Governance</category><category>Human oversight</category><author>John Bagnall</author></item><item><title>Agents vs workflows: when you actually need an agent</title><link>https://nalgo.co.uk/blog/agents-vs-workflows/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/agents-vs-workflows/</guid><description>&quot;Build an agent&quot; is the default answer to every AI problem right now. It is usually the wrong one. Most tasks are better served by a workflow, cheaper, more predictable, easier to trust. Here is the real distinction, and how to tell when a task genuinely needs an agent.</description><pubDate>Wed, 15 Jul 2026 00:00:00 GMT</pubDate><category>AI agents</category><category>Automation</category><category>Production</category><author>John Bagnall</author></item><item><title>Why AI pilots fail (and how to be the exception)</title><link>https://nalgo.co.uk/blog/why-ai-pilots-fail/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/why-ai-pilots-fail/</guid><description>Most AI pilots never reach production. An MIT study in 2025 found 95% of enterprise generative-AI pilots delivered no measurable impact on the bottom line. The reasons are boringly predictable, and fixable. Here is why pilots die, and how to be the 5% that ships.</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>Production</category><category>AI adoption</category><category>Strategy</category><author>John Bagnall</author></item><item><title>AI assurance: what it is, and how to get assurance-ready</title><link>https://nalgo.co.uk/blog/ai-assurance-explained/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/ai-assurance-explained/</guid><description>AI assurance is how you prove your AI is trustworthy: measuring, evaluating and communicating it so a customer, regulator or board can place justified trust in it. It is fast becoming a condition of selling AI. Here is what it is, the techniques involved, and how to get assurance-ready.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><category>Governance</category><category>AI assurance</category><category>ISO 42001</category><category>EU AI Act</category><author>John Bagnall</author></item><item><title>GPAI: what general-purpose AI obligations mean for you</title><link>https://nalgo.co.uk/blog/gpai-obligations-explained/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/gpai-obligations-explained/</guid><description>The EU AI Act puts a whole set of obligations on general-purpose AI (GPAI) models like GPT, Claude and Gemini. The good news for most businesses: those duties fall on the model makers, not on you. Here is what the GPAI rules actually are, and the one trap, fine-tuning, that can put them on your plate.</description><pubDate>Mon, 13 Jul 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>Governance</category><category>GPAI</category><author>John Bagnall</author></item><item><title>How to run an AI impact assessment (ISO 42005 and the EU AI Act FRIA)</title><link>https://nalgo.co.uk/blog/how-to-run-an-ai-impact-assessment/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/how-to-run-an-ai-impact-assessment/</guid><description>An AI impact assessment asks who your AI could harm, and how badly, before it goes live. It is required by ISO 42001, detailed by ISO 42005, and, for some organisations, made law by the EU AI Act as a FRIA. Here is what it is, how it differs from a DPIA, and how to actually run one.</description><pubDate>Sun, 12 Jul 2026 00:00:00 GMT</pubDate><category>Governance</category><category>ISO 42001</category><category>EU AI Act</category><category>Risk</category><author>John Bagnall</author></item><item><title>How to stop AI hallucinations in production (guardrails that actually work)</title><link>https://nalgo.co.uk/blog/stop-ai-hallucinations-in-production/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/stop-ai-hallucinations-in-production/</guid><description>You cannot fully eliminate LLM hallucinations, but you can engineer them down to a rate you can live with. The trick is to stop treating it as a prompt problem and build a layered system: ground the model, make it cite, verify the answer, and gate what ships. Here is what actually works in production.</description><pubDate>Sat, 11 Jul 2026 00:00:00 GMT</pubDate><category>Production</category><category>RAG</category><category>Evaluation</category><category>AI agents</category><author>John Bagnall</author></item><item><title>How to write an AI policy (with a template)</title><link>https://nalgo.co.uk/blog/how-to-write-an-ai-policy/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/how-to-write-an-ai-policy/</guid><description>An AI policy is the top-level document that sets how your organisation uses AI. Under ISO 42001 it is the anchor of your AI Management System, not a standalone PDF. Here is what to put in one, a template you can adapt, and how to make it stick.</description><pubDate>Wed, 08 Jul 2026 00:00:00 GMT</pubDate><category>Governance</category><category>ISO 42001</category><category>AIMS</category><category>AI policy</category><author>John Bagnall</author></item><item><title>RAG in production: why retrieval is where it breaks</title><link>https://nalgo.co.uk/blog/rag-in-production/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/rag-in-production/</guid><description>When a RAG system gives wrong or vague answers in production, the model is almost never the problem. It is retrieval: the system fetched the wrong context, too little, or none at all. Here is where retrieval breaks and how to make it reliable.</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>RAG</category><category>Production</category><category>AI agents</category><author>John Bagnall</author></item><item><title>AI literacy: the EU AI Act&apos;s Article 4 duty, in practice</title><link>https://nalgo.co.uk/blog/eu-ai-act-ai-literacy/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/eu-ai-act-ai-literacy/</guid><description>Article 4 of the EU AI Act requires providers and deployers to ensure a sufficient level of AI literacy among the people using AI on their behalf. It has applied since February 2025, it is not limited to high-risk AI, and it is one of the easiest duties to meet, and to overlook.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>AI literacy</category><category>Governance</category><author>John Bagnall</author></item><item><title>How to evaluate an AI vendor</title><link>https://nalgo.co.uk/blog/how-to-evaluate-an-ai-vendor/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/how-to-evaluate-an-ai-vendor/</guid><description>Most AI risk now comes from tools you buy, not models you build. Evaluating a vendor well is how you avoid buying a liability: what happens to your data, how it is secured, whether it locks you in, and whether it helps or hinders your own compliance. Here is a practical way to do it.</description><pubDate>Sat, 04 Jul 2026 00:00:00 GMT</pubDate><category>AI vendors</category><category>Procurement</category><category>Governance</category><author>John Bagnall</author></item><item><title>AI agents, explained: what they are and what they can do</title><link>https://nalgo.co.uk/blog/ai-agents-explained/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/ai-agents-explained/</guid><description>An AI agent is a system that takes a goal and pursues it: reasoning, using tools, and taking multi-step actions in your systems, not just answering a question. Here is what that means, how they work, and where they earn their place in a business.</description><pubDate>Fri, 03 Jul 2026 00:00:00 GMT</pubDate><category>AI agents</category><category>Automation</category><category>Production</category><author>John Bagnall</author></item><item><title>The AI system register: what to actually track</title><link>https://nalgo.co.uk/blog/ai-system-register/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/ai-system-register/</guid><description>An AI system register is the single, maintained inventory of every AI tool, model and feature your organisation uses. It is the foundation the rest of AI governance sits on. Here are the fields that actually earn their place, and how to keep it from rotting.</description><pubDate>Thu, 02 Jul 2026 00:00:00 GMT</pubDate><category>Governance</category><category>AIMS</category><category>ISO 42001</category><author>John Bagnall</author></item><item><title>How to classify your AI systems by risk</title><link>https://nalgo.co.uk/blog/classify-ai-systems-by-risk/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/classify-ai-systems-by-risk/</guid><description>Risk classification is how you decide which AI systems need heavy controls and which need almost none. It is the step that turns an AI inventory into a governed one, and both ISO 42001 and the EU AI Act depend on it. Here is a practical method.</description><pubDate>Wed, 01 Jul 2026 00:00:00 GMT</pubDate><category>Governance</category><category>Risk</category><category>ISO 42001</category><category>EU AI Act</category><author>John Bagnall</author></item><item><title>ISO 42001 vs the EU AI Act: how they fit together</title><link>https://nalgo.co.uk/blog/iso-42001-vs-eu-ai-act/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/iso-42001-vs-eu-ai-act/</guid><description>The EU AI Act is law that tells you what you must do with AI. ISO 42001 is a voluntary standard that tells you how to organise to do it. They are complementary, not alternatives, and a well-run ISO 42001 system gives you most of the machinery the Act expects.</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>EU AI Act</category><category>Governance</category><author>John Bagnall</author></item><item><title>Shadow AI: finding the tools you don&apos;t know you&apos;re using</title><link>https://nalgo.co.uk/blog/shadow-ai-finding-the-tools/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/shadow-ai-finding-the-tools/</guid><description>Shadow AI is the AI tools your staff use for work without approval or oversight. It is now the norm: staff at over 90% of companies use personal AI tools, while only 40% have sanctioned ones. Finding it is the first step to governing it.</description><pubDate>Mon, 29 Jun 2026 00:00:00 GMT</pubDate><category>Shadow AI</category><category>Governance</category><category>ISO 42001</category><author>John Bagnall</author></item><item><title>What an AI Management System (AIMS) actually contains</title><link>https://nalgo.co.uk/blog/what-an-aims-contains/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/what-an-aims-contains/</guid><description>An AIMS is the running set of policies, roles, processes and records you use to govern AI, defined by ISO 42001. It is not one document; it is a system you operate: an AI policy, an inventory, risk classification, controls, accountability, oversight, monitoring and an evidence trail.</description><pubDate>Sun, 28 Jun 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>Do you need ISO 42001? An honest answer</title><link>https://nalgo.co.uk/blog/do-you-need-iso-42001/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/do-you-need-iso-42001/</guid><description>ISO 42001 is the international standard for managing AI responsibly. You need it if customers demand it or you sell AI and must prove governance. Most other organisations need the governance it describes, but not the certificate yet.</description><pubDate>Thu, 25 Jun 2026 00:00:00 GMT</pubDate><category>ISO 42001</category><category>Governance</category><category>AIMS</category><author>John Bagnall</author></item><item><title>What the Model Context Protocol (MCP) is for</title><link>https://nalgo.co.uk/blog/what-mcp-is-for/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/what-mcp-is-for/</guid><description>MCP is an open standard that lets AI assistants connect to your tools and data through one common interface. Build the connection once, and any MCP-compatible AI can use it.</description><pubDate>Wed, 24 Jun 2026 00:00:00 GMT</pubDate><category>MCP</category><category>AI agents</category><category>Production</category><author>John Bagnall</author></item><item><title>AI agent vs automation: do you need an agent, or just automation?</title><link>https://nalgo.co.uk/blog/ai-agent-vs-automation/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/ai-agent-vs-automation/</guid><description>If the task follows the same rules every time, you need automation. If it needs judgement on inputs that vary, you need an agent. Most business processes need automation more often than teams expect.</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>AI agents</category><category>Automation</category><category>Production</category><author>John Bagnall</author></item><item><title>EU AI Act deadlines, in plain English</title><link>https://nalgo.co.uk/blog/eu-ai-act-deadlines/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/eu-ai-act-deadlines/</guid><description>The EU AI Act phases in over several years. AI literacy and banned practices are in force now; the core duties for high-risk AI land on 2 August 2026, with some pieces in 2027.</description><pubDate>Mon, 22 Jun 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>Governance</category><author>John Bagnall</author></item><item><title>The EU AI Act for deployers: what you actually have to do</title><link>https://nalgo.co.uk/blog/eu-ai-act-for-deployers/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/eu-ai-act-for-deployers/</guid><description>If you use AI rather than build it, you are a deployer, and the EU AI Act still gives you real duties: AI literacy and banned-practice rules now, and high-risk obligations from August 2026.</description><pubDate>Sat, 20 Jun 2026 00:00:00 GMT</pubDate><category>EU AI Act</category><category>Governance</category><author>John Bagnall</author></item><item><title>Build the evaluation harness before you ship</title><link>https://nalgo.co.uk/blog/evaluation-harness-before-you-ship/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/evaluation-harness-before-you-ship/</guid><description>You can&apos;t improve what you can&apos;t measure, and you can&apos;t ship AI safely without a way to catch regressions. Here is why the eval harness comes first.</description><pubDate>Thu, 28 May 2026 00:00:00 GMT</pubDate><category>Evaluation</category><category>Production</category><category>Governance</category><author>John Bagnall</author></item><item><title>What &quot;governed agentic AI&quot; actually means</title><link>https://nalgo.co.uk/blog/what-governed-agentic-ai-means/</link><guid isPermaLink="true">https://nalgo.co.uk/blog/what-governed-agentic-ai-means/</guid><description>Agentic systems take actions, not just produce text. Governance is what makes those actions safe to ship. Here is the working definition we build against.</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>Governance</category><category>Agentic AI</category><category>Production</category><author>John Bagnall</author></item></channel></rss>