COMING MAY 2026

TrustedIntelligence

The AI Governance Playbook for Growing Regulated Businesses

Your organisation is already using AI. Some of it you sanctioned. Some of it you did not. All of it carries risk.

This is the practical, jurisdiction-aware guide to governing the AI you actually have. Not the AI that appears in conference presentations.

No spam. Early access, launch discounts, and governance resources.

THE REALITY

Your AI governance programme has not caught up with your AI use.

The mid-market enterprise in 2026 faces five overlapping AI realities. None of them are waiting politely for a governance framework to arrive.

Too large to be ignored by regulators. Too lean to have a dedicated AI governance team. Too commercially pressured to slow down. This book was written precisely for that position.

01

Generative AI is everywhere

Every employee with access to Microsoft 365 Copilot, ChatGPT, or Gemini is using a system that produces non-deterministic outputs. Your organisation has not assessed most of them.

02

Copilots blur accountability

When a copilot drafts advice that an employee sends to a client, who is accountable for its accuracy. Your current governance framework probably does not say.

03

RAG creates new data risks

Retrieval-augmented generation puts new pressure on what data you hold, what enters the retrieval index, and what comes back in responses. Most organisations have not mapped that exposure.

04

Agents take real-world action

AI that plans multi-step tasks and executes them without human intervention at each step is entering the enterprise. Defining what an agent can do, and ensuring it does not exceed that boundary, is a governance challenge most organisations are not yet equipped to handle.

05

Shadow AI is your biggest unmanaged risk

Employees across every function are using AI tools the organisation has not sanctioned, assessed, or even identified. It is not malicious. It is the natural response of capable people to powerful free tools. But it is carrying risk your governance framework is not covering.

WHO THIS BOOK IS FOR

Written for the people who have to make the decision.

Not data scientists. Not AI engineers. Senior leaders and governance professionals at mid-market enterprises in regulated sectors, who need to act and need to be able to justify that action to a board.

PRIMARY

Senior Leaders

CEOs, CROs, CCOs, CFOs, and Heads of Digital Transformation at organisations with 250 to 5,000 employees and ยฃ50m to ยฃ500m revenue in regulated sectors. Intelligent, time-pressured, commercially minded, and done with vague governance advice.

SECONDARY

Governance Professionals

AI governance consultants, risk professionals, and compliance officers who work with mid-market clients and need a credible, structured framework they can implement alongside their clients. Not just present to them.

TERTIARY

Board Members

Non-executive directors and board members who need enough grounding to ask the right questions, hold management accountable, and understand whether the assurances they are receiving are credible.

WHAT YOU WILL GET

Finish this book on a Friday. Brief your board on Monday.

Every chapter leaves you with something concrete. Not theory to sit with. Tools to use, frameworks to apply, and decisions you can make before the week is out.

๐Ÿ—บ

A complete picture of your AI exposure

The AI Exposure Diagnostic shows you exactly which categories of AI risk your organisation carries. Including the AI you did not sanction and the vendors who shipped it to you anyway.

โš–

Clarity on what regulations actually require

EU AI Act, UK sector regulators, UAE frameworks, ISO 42001. Not a legal textbook. A plain-language answer to four questions: what applies, what it requires, when it kicks in, and what happens if you ignore it.

๐Ÿ›

A board paper you can submit

The Board Paper Template lets you make the business case for AI governance investment in a format the board will read and the audit committee will understand.

๐Ÿ› 

Twenty practical governance tools

Every chapter includes at least one tool, template, or checklist โ€” all downloadable. An AI inventory, a risk register, a shadow AI response playbook, a vendor assessment, an agent governance framework, and more.

๐Ÿ“

A sector-specific governance blueprint

Dedicated chapters for financial services, healthcare, professional services, and public sector. Each one addresses the exact AI deployments, regulatory pressures, and liability questions relevant to your industry.

๐Ÿ“…

A 90-day implementation roadmap

Week by week. Starting from no dedicated governance team and limited budget. Phase 1 gets you defensible. Phase 2 gets you structured. Phase 3 gets you audit-ready and board-reportable.

THE A.C.E. FRAMEWORK

One architecture. Every AI system you operate.

The A.C.E. Framework is the book's proprietary governance architecture. It does not change across AI types. What changes is how each layer is operationalised โ€” whether you are governing a credit scoring model, a Microsoft 365 Copilot deployment, or an autonomous claims processing agent.

A
ALIGN
A

Strategy, Policy and Inventory

The foundation layer

Governance begins before deployment. Connect AI to organisational purpose. Establish the AI inventory, foundation model policy, acceptable use policy, and shadow AI discovery. This is the foundation everything else rests on.

C
CONTROL
C

Risk, Oversight and Guardrails

The operational layer

Risk assessment, human oversight design, technical guardrails, copilot governance, RAG governance, vendor management, and the shadow AI response playbook.

E
EVIDENCE
E

Documentation, Monitoring and Audit

The assurance layer

You cannot reproduce a specific LLM output. Traditional audit trails do not work for non-deterministic systems. EVIDENCE addresses this with a documentation architecture mapped to ISO 42001 and the EU AI Act.

BOOK STRUCTURE

17 chapters. 4 parts. One implementation programme.

Built around a deliberate structure: understand your exposure, make the business case, apply the framework, implement it in your sector, and launch your governance programme in 90 days.

INTRODUCTION

The Tuesday Morning Test

A composite scenario. The morning it all surfaces at once.
Introduction
PART ONE

The Case for Governing AI Now

Why governance, why you, why now โ€” and how to secure board buy-in.
Ch 1: The AI You Already HaveCh 2: What Governance Failure Actually CostsCh 3: The Regulatory ReckoningCh 4: Making the Case to Your Board
PART TWO

The A.C.E. Framework

The architecture of AI governance โ€” what to build, in what order.
Ch 5: Framework OverviewCh 6: ALIGN โ€” Strategy, Policy and InventoryCh 7: CONTROL โ€” Risk, Oversight and GuardrailsCh 8: CONTROL โ€” Data, Vendors and Shadow AICh 9: EVIDENCE โ€” Documentation and Audit Readiness
PART THREE

Governing AI in Your Sector

Sector-specific guidance for regulated industries.
Ch 10: Financial ServicesCh 11: Healthcare and Life SciencesCh 12: Professional ServicesCh 13: Public Sector and Government
PART FOUR

Building Your Governance Programme

From framework to operating reality.
Ch 14: Governing AI AgentsCh 15: The 90-Day RoadmapCh 16: Governance as Competitive AdvantageCh 17: What Comes Next
CONCLUSION

Trusted Intelligence

The standard you set today determines the trust you earn tomorrow.
Conclusion and Appendices
20 GOVERNANCE TOOLS

Every chapter ships with tools you can use the same week.

Not decorative templates. Practical instruments sized for mid-market teams โ€” all downloadable from the companion website.

From a 15-question AI Exposure Diagnostic to a week-by-week 90-Day Implementation Roadmap. Every tool is designed to be usable without external guidance.

01AI Exposure Diagnostic โ€” 15-question self-assessment
02Governance Cost Calculator
03Regulatory Exposure Matrix (EU, UK, UAE)
04Board Paper Template โ€” one-page, fill-in-the-blank
05AI Inventory Template โ€” all AI types covered
06Foundation Model Policy Template
07Shadow AI Discovery Checklist
08AI Risk Register Template โ€” with GenAI-specific fields
09Human Oversight Design Template
10Guardrail Design Template
11RAG Governance Checklist
12Vendor AI Assessment Template
13Shadow AI Response Playbook
14Governance Evidence Architecture
15Board Reporting Template โ€” quarterly one-pager
16Audit Readiness Checklist
17Agent Governance Framework
18Copilot Deployment Governance Checklist
19AI Governance Spectrum โ€” visual reference
2090-Day Implementation Roadmap โ€” week by week
ABOUT THE AUTHOR

I have never governed AI at one of the world's largest companies. That is exactly why this book needed to be written.

GD
Gurpreet Singh DhindsaAI GOVERNANCE SPECIALIST
  • โ€บCEO, Enterprise SaaS Startup
  • โ€บResponsible AI Director, Aligne
  • โ€บCo-founder, Altrum AI Platform
  • โ€บIBM Subject Matter Expert, six years
  • โ€บISO 42001 Implementor Certified
  • โ€บAIGP, IAPP
  • โ€บCIPP/E, IAPP
  • โ€บAI Ethics and Governance, Oxford Saรฏd
  • โ€บOperating across UK, EU, UAE
gurpreetdhindsa.com ยท London, Dubai, India

Gurpreet Singh Dhindsa has spent three years sitting across the table from the organisations that the big-firm governance leaders have never spoken to. Mid-market businesses in regulated industries, deploying AI with real commercial pressure, lean teams, and no clear playbook. He has seen what governance failure looks like before it reaches the regulator, and what it costs when it does.

His background is deliberately cross-disciplinary. As CEO of an enterprise SaaS startup, Responsible AI Director at Aligne, and co-founder of the Altrum AI governance platform, he operates across financial services, healthcare, professional services, and public sector clients in London, Dubai, and India. He is not a theorist presenting frameworks designed in a vacuum. Every tool in this book has been tested in practice.

His credentials span the technical, the legal and ethical, and the commercial. That combination is rare in AI governance. It is what makes the advice in this book usable, not just credible.

JOIN THE WAITING LIST

Be the first to know when it launches.

Join the waiting list for early access, launch-week pricing, exclusive governance resources, and chapter previews before publication.

No spam. Early access and governance resources only. Unsubscribe any time.