Thinking & Perspectives

AI Strategy Insights

Practical perspectives on AI strategy, agentic systems architecture, and governance — from the advisory practice at Imagine Works.

29 articles
AI Governance8 min read

OWASP LLM05: Improper Output Handling (Formerly LLM02): Enterprise Guide

The 2025 OWASP Top 10 for LLM Applications renamed "Insecure Output Handling" (LLM02:2023) to "Improper Output Handling" (LLM05:2025) — but the underlying enterprise vulnerability is the same and, in most deployed LLM-integrated applications, it is still not fixed. Model output that gets rendered, executed, or interpolated downstream without sanitisation is how prompt injections cross the threshold from "the model said a bad thing" to XSS, SSRF, and remote code execution. Here is what LLM05 actually is, how it differs from prompt injection, and the controls that neutralise it.

25 August 2026Read article
AI Governance9 min read

AI Literacy: The EU AI Act Obligation Every Employer Now Faces

The EU AI Act's AI-literacy obligation entered into force on 2 February 2025, but 2 August 2026 was the moment enforcement architecture activated across EU sectoral regulators. The obligation applies whether or not the AI systems in question are high-risk, and whether the employer is a provider or a deployer. Here is what Article 4 actually requires, how the European Commission expects "sufficient" to be interpreted, and what a defensible programme looks like.

22 August 2026Read article
AI Governance10 min read

AI Audit: What Enterprise Leaders Should Actually Ask For

AI audit has moved from a niche practice to a board-level expectation. ISO/IEC 42006 gave auditors a formal accreditation standard in July 2025, KPMG became the first Big Four firm to earn ISO 42001 certification in November 2025, and EU AI Act enforcement architecture activated on 2 August 2026. Here is what enterprise leaders should ask for when they commission — or prepare for — an AI audit.

11 August 2026Read article
AI Governance10 min read

AI Red Teaming: What Enterprise Leaders Should Actually Ask For

AI red teaming has moved from a research-lab activity to a boardroom expectation. The EU AI Act now requires adversarial testing of general-purpose AI models with systemic risk. Microsoft has red-teamed 100+ generative AI products since 2018. NIST published a formal adversarial-ML attack taxonomy in March 2025. Here is what enterprise leaders should ask for when they commission — or evaluate — an AI red team engagement.

8 July 2026Read article
AI Governance10 min read

The NIST AI Risk Management Framework: What Enterprise Leaders Need to Understand

The NIST AI Risk Management Framework (AI RMF 1.0) has quietly become the most widely adopted enterprise AI governance framework in the United States — 57–67% of CISOs use it according to the 2026 Hitch Partners Global CISO Leadership Report. Voluntary, but load-bearing. Here is what the framework contains, how the 2024 Generative AI Profile extends it, and why it endured a change of US administration when the executive order that popularised it did not.

24 June 2026Read article
AI Governance10 min read

Prompt Injection: The Enterprise Security Risk That Cannot Yet Be Filtered Away

Prompt injection has been the number-one risk on the OWASP Top 10 for LLM Applications since 2023, and in June 2025 it produced the first publicly documented zero-click enterprise AI vulnerability — CVE-2025-32711, EchoLeak, in Microsoft 365 Copilot. UK NCSC's December 2025 guidance is direct: prompt injection cannot be fully mitigated; focus on reducing impact. Here is what enterprise leaders need to understand and do.

10 June 2026Read article
AI Strategy Insights & Articles | Imagine Works