Draxion briefings

AI governance, written
by the people who build it.

Practical guidance on shadow AI, regulatory compliance, and enterprise AI governance — no vendor theatre, no recycled analyst copy.

Desk record
Published
7 briefings
Cadence
Weekly
Desk
Draxion Team
Latest
May 22, 2025

Lead briefing

EU AI Act

EU AI Act Article 9: What ‘appropriate risk management’ actually means for your AI governance program

Most organizations interpret EU AI Act Article 9 as requiring a risk management system for high-risk AI. What it actually requires is significantly more specific — and most compliance teams are not meeting the standard they think they are.

Draxion TeamMay 20, 20258 min read

The index

Every briefing, in order of publication.

Filter by topic. Each entry carries its date, read time and desk classification so you can decide what is worth your next ten minutes.

06 / 06 briefings

01May 22, 20256 min read
Shadow AI

Why 56% of employees use AI tools their IT team has never approved

The data is consistent across every organization we have spoken to. The question is not whether your employees are using unapproved AI — it is how many tools, which data, and what your liability is.

Draxion Team

02May 18, 20259 min read
EU AI Act

EU AI Act enforcement starts in August 2026: Is your organization ready?

The prohibited AI provisions of the EU AI Act became enforceable in February 2025. The high-risk AI obligations come into force in August 2026. Most organizations are not ready. Here is what you need to do.

Draxion Team

03May 15, 20257 min read
Compliance

The difference between a GDPR policy and GDPR compliance

Having a written AI acceptable use policy is not GDPR compliance. It is evidence that you identified the risk. Here is what actual compliance looks like — and how regulators test for it.

Draxion Team

04May 12, 20255 min read
Shadow AI

ChatGPT is not your biggest shadow AI problem

Organizations spend their governance energy on ChatGPT because it is visible. The real exposure is in the 15–20 other AI tools your employees are using that you have never heard of.

Draxion Team

05May 8, 20258 min read
GDPR

GDPR Article 28 and AI vendors: What your DPA must cover

Every AI vendor your employees use is a data processor under GDPR Article 28. Most enterprise AI vendor contracts do not satisfy Article 28 requirements. Here is what to look for.

Draxion Team

06May 5, 202510 min read
Security

How to build an AI governance program in 30 days

A practical, step-by-step guide for IT security and compliance teams who need to demonstrate AI governance to their board or auditors — without a six-month project timeline.

Draxion Team

Coverage

Five topics. Nothing outside them.

We write about the areas we build against every day. If a subject does not affect how an organization detects, documents or defends its AI usage, it does not get a briefing.

Shadow AI

2 briefings

Which unapproved tools are in use, who is using them, and what leaves the building with them.

EU AI Act

2 briefings

Risk classes, Article-level obligations, and the enforcement clock running to August 2026.

Compliance

1 briefing

What auditors actually test for — and why a written policy is evidence, not compliance.

GDPR

1 briefing

Processor obligations, Article 28 data processing agreements, and AI vendor contracts.

Security

1 briefing

Practical governance programs an already-stretched security team can actually run.

Weekly dispatch

Get the latest on AI governance.

Weekly insights on shadow AI, regulatory updates, and enterprise governance — from the Draxion team.

No spam. Unsubscribe any time.

From reading to evidence

Reading about shadow AI is not the same as seeing yours.

Every briefing above describes a problem Draxion measures directly. See it against your own organization instead of ours.

Written by the team that builds the platform. Published weekly.