<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Edwin Luther — Insights</title>
    <link>https://www.edwin-luther.io/insights</link>
    <description>Practical notes on EU AI Act, DORA, ISO/IEC 42001, and AI governance for financial services boards, from Edwin Luther, Fractional FCC &amp; Enterprise Risk Leader.</description>
    <language>en-gb</language>
    <lastBuildDate>Thu, 03 Sep 2026 00:00:00 GMT</lastBuildDate>
    <atom:link href="https://www.edwin-luther.io/feed.xml" rel="self" type="application/rss+xml" />

    <item>
      <title>What UK Boards Need to Know About the EU AI Act in 2026</title>
      <link>https://www.edwin-luther.io/insights/eu-ai-act-2026-uk-boards</link>
      <guid>https://www.edwin-luther.io/insights/eu-ai-act-2026-uk-boards</guid>
      <description>Most high-risk obligations are now live. What your board needs in place, and the practical first step.</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>me@edwinluther.io (Edwin Luther)</author>
    </item>
    <item>
      <title>DORA Third-Party AI Risk: A Practical Checklist for Financial Firms</title>
      <link>https://www.edwin-luther.io/insights/dora-third-party-ai-risk-checklist</link>
      <guid>https://www.edwin-luther.io/insights/dora-third-party-ai-risk-checklist</guid>
      <description>What a board should ask an AI vendor before approval, and where unapproved AI quietly becomes a DORA problem.</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>me@edwinluther.io (Edwin Luther)</author>
    </item>
    <item>
      <title>Why "Compliance by Design" Beats Retrofitting AI Governance</title>
      <link>https://www.edwin-luther.io/insights/compliance-by-design-vs-retrofitting</link>
      <guid>https://www.edwin-luther.io/insights/compliance-by-design-vs-retrofitting</guid>
      <description>The asymmetry between building governance in from day one and bolting it on after a regulator forces the issue, in real numbers.</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>me@edwinluther.io (Edwin Luther)</author>
    </item>
    <item>
      <title>ISO/IEC 42001 Explained for Financial Services Boards</title>
      <link>https://www.edwin-luther.io/insights/iso-iec-42001-explained</link>
      <guid>https://www.edwin-luther.io/insights/iso-iec-42001-explained</guid>
      <description>The clearest available reference architecture for what good AI governance looks like, and why it matters before it's mandatory.</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>me@edwinluther.io (Edwin Luther)</author>
    </item>
    <item>
      <title>AI Compliance for SMEs: What You Need to Know</title>
      <link>https://www.edwin-luther.io/insights/ai-compliance-for-smes</link>
      <guid>https://www.edwin-luther.io/insights/ai-compliance-for-smes</guid>
      <description>What actually applies to a business without a compliance department, and what a proportionate response looks like.</description>
      <pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate>
      <author>me@edwinluther.io (Edwin Luther)</author>
    </item>
  </channel>
</rss>
