<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<title>Governance on Tend and Flow</title>
		<link>https://tendandflow.com/tags/governance/</link>
		<description>Recent content in Governance on Tend and Flow</description>
		<generator>Hugo</generator>
		<language>en-gb</language>
		
		
		
		
			<lastBuildDate>Tue, 18 Aug 2026 08:15:42 +0100</lastBuildDate>
		
			<atom:link href="https://tendandflow.com/tags/governance/index.xml" rel="self" type="application/rss+xml" />
			<item>
				<title>Skill Safety</title>
				<link>https://tendandflow.com/journal/skill-safety/</link>
				<pubDate>Tue, 18 Aug 2026 08:15:42 +0100</pubDate>
				<guid>https://tendandflow.com/journal/skill-safety/</guid>
				<description>&lt;p&gt;&lt;a href=&#34;https://owasp.org/www-project-agentic-skills-top-10/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;OWASP&lt;span class=&#34;visually-hidden&#34;&gt; (opens in a new tab)&lt;/span&gt;&lt;/a&gt; recently published a community-driven project to catalogue the current types of threats posed by skills, calling out the high level of malicious skills being shared publicly out in the wild.  Their security &lt;a href=&#34;https://owasp.org/www-project-agentic-skills-top-10/checklist.html&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;checklist is here&lt;span class=&#34;visually-hidden&#34;&gt; (opens in a new tab)&lt;/span&gt;&lt;/a&gt;.  This is version one, written for developers and technical staff, and will no doubt change and improve over time.&lt;/p&gt;&#xA;&lt;p&gt;I thought there was real value in having a non-technical version.  In many organisations, non-technical users are writing their own skills and, most likely, sharing skills that others have written.  Feel free to repurpose my checklist below.&lt;/p&gt;</description>
			</item>
			<item>
				<title>AI Transparency Is Not Enough</title>
				<link>https://tendandflow.com/journal/ai-transparency/</link>
				<pubDate>Wed, 12 Aug 2026 12:44:31 +0100</pubDate>
				<guid>https://tendandflow.com/journal/ai-transparency/</guid>
				<description>&lt;p&gt;The general direction of AI legislation is to make AI use more transparent and maintain a clear line of accountability for the content.  The EU&amp;rsquo;s AI Act is now in force and while it mostly talks about the responsibilities of organisations making and deploying AI systems, it does also cover businesses using those systems (&amp;lsquo;deployers&amp;rsquo;).  In a very broad summary of &lt;a href=&#34;https://artificialintelligenceact.eu/article/50/&#34; target=&#34;_blank&#34; rel=&#34;noopener noreferrer&#34;&gt;the Act&lt;span class=&#34;visually-hidden&#34;&gt; (opens in a new tab)&lt;/span&gt;&lt;/a&gt;, deployers need to (a) follow the provider&amp;rsquo;s instructions in using the system, (b) ensure a sufficient level of AI literacy among staff involved in the operating of the AI system, and (c) inform individuals when interacting with the system (&amp;ldquo;unless it is obvious from the context&amp;rdquo;).  That last point extends further to specific use cases involving media content and so-called &amp;lsquo;high risk&amp;rsquo; systems being used to make decisions involving the public. The EU law now sets the baseline for transparency, but it is not governance.&lt;/p&gt;</description>
			</item>
			<item>
				<title>Designing Governance</title>
				<link>https://tendandflow.com/journal/designing-governance/</link>
				<pubDate>Thu, 06 Aug 2026 17:03:57 +0100</pubDate>
				<guid>https://tendandflow.com/journal/designing-governance/</guid>
				<description>&lt;h2 id=&#34;the-flood-of-policy-dressed-up-as-governance&#34;&gt;The flood of policy dressed up as governance&lt;/h2&gt;&#xA;&lt;p&gt;I have become troubled by how much AI governance turns out to be policy wearing a framework&amp;rsquo;s clothing.  Something goes wrong, or nearly does, and the response is reliably the same: a new document, a committee, a tweaked RACI chart.  Everyone relaxes.  Governance has been done.&lt;/p&gt;&#xA;&lt;p&gt;Except it hasn&amp;rsquo;t.  Nobody opens the document again until the next incident forces them to.  This is not laziness, the people writing these things mean well and work hard.  It is a design failure, and it becomes considerably more expensive the moment you point an AI agent at a real business process.&lt;/p&gt;</description>
			</item>
	</channel>
</rss>
