Morgan Signing House LLC — AI Governance for SMEs

Reduce AI risk. Prove compliance.
Operationalize responsible AI.

Morgan's AI Hub helps small and medium-sized organizations govern artificial intelligence, reduce operational risk, improve compliance readiness, and build responsible AI programs — without standing up an enterprise GRC team.

Credential
arXiv
Published — AI Governance Control Stack
Credential
NSF TRAILS
Active research deployment
Credential
Oxford Saïd
Executive education alumnus
Who this is for

SMEs, healthcare organisations, public-sector teams, law firms, universities, and regulated businesses using ChatGPT, Copilot, AI agents, or vendor AI tools without a complete governance system.

40+
Organisations advised (cumulative)
NSF
TRAILS active deployment
arXiv
Published research
VA
Innovation Repository
Up to 50%
Doc-effort reduction (selected pilots)

Cumulative figures across advisory, training, and research engagements. Up to 50% documentation-effort reduction observed in selected internal or pilot workflows; results vary by organization, scope, and implementation.

Referenced work, education & framework alignment
arXivNSF TRAILSU.S. Veterans AffairsOxford SaïdEU AI ActISO/IEC 42001

No affiliation, endorsement, approval, or certification by these organizations is implied unless expressly stated.

"
AI governance should not stop at policy. It must become inventory, controls, evals, telemetry, evidence, escalation, and accountable decision-making.
Horatio Morgan · Founder, Morgan Signing House
The Practice

Four pillars of accountable AI.

01PILLAR

Governance Infrastructure

Inventory, controls, evals, telemetry, evidence, escalation — the operating system beneath policy.

02PILLAR

Explainability (XAI)

Frameworks that make model behaviour legible to auditors, regulators, and the business.

03PILLAR

Regulatory Crosswalks

EU AI Act, ISO/IEC 42001, and NIST AI RMF mapped to your actual controls and evidence.

04PILLAR

SME-Ready Architecture

Audit-ready governance designed for real-world deployment — not just enterprise budgets.

The Framework

The Operational AI Governance Framework.

Seven operating layers that turn AI policy into auditable practice. Each layer maps to controls under the EU AI Act, ISO/IEC 42001, and NIST AI RMF — and to the deliverables in every Morgan Signing House engagement.

01
Inventory

Every AI system, owner, vendor, data flow, and decision impact in one register.

02
Controls

Acceptable use, approvals, data rules, human-review gates by risk tier.

03
Evals

Pre-deployment and ongoing tests for accuracy, bias, drift, and misuse.

04
Telemetry

Logging, retention, and monitoring that produce evidence by default.

05
Evidence

Auditor-ready artifacts — policies, model cards, reviews, approvals.

06
Escalation

Defined response, pause authority, and incident reporting workflows.

07
Accountability

Named owners, board reporting, and decision authority at every layer.

Why SMEs choose us

Enterprise-grade governance, SME-sized.

SMEs are using the same AI tools as Fortune 500s — but without enterprise GRC teams. We deliver audit-ready governance built for real budgets, real headcount, and real timelines.

Built for SMEs

Right-sized controls, plain-language templates, and workflows that fit a 10–500 person team.

Regulator-aligned

Crosswalks to EU AI Act, ISO/IEC 42001, and NIST AI RMF — translated into your operations.

Evidence-first

Every deliverable is an audit artifact. No binders. No theatre. Just defensible records.

Founder-led

Direct work with Horatio Morgan, PMP — published researcher and NSF TRAILS collaborator.

Start Here

Choose your AI governance path.

Three named offers, each with a defined problem, deliverables, and outcome. Pick the one that matches where you stand today.

For SMEs

Minimum Viable AI Governance

Using AI but lacking formal controls, inventory, or audit trail.

What you get
  • Acceptable-use policy
  • AI inventory & risk tiering
  • Human-review matrix
  • Incident workflow
  • Evidence log
Outcome

A complete starter governance system — audit-ready, sized for SMEs.

See full package →
For Leaders / Boards

AI Governance Strategy Briefing

Executives who need risk clarity, regulatory timelines, and decision authority — fast.

What you get
  • EU AI Act · ISO 42001 · NIST briefing
  • Sector risk overview
  • Decision-authority map
  • Executive summary
Outcome

A board that can ask the right questions and sign off with confidence.

See full package →
For Builders / AI Teams

AI Agent Governance Readiness

Deploying GPTs, copilots, agents, RAG, or workflow automation with real shadow-AI and excessive-agency risk.

What you get
  • Agent inventory & access map
  • Tool allowlist review
  • Human approval gates
  • Prompt-injection test plan
  • Telemetry spec
Outcome

Agents that can be deployed, audited, and explained.

See full package →
Who We Work With

From Fortune 500 to first-time deployers.

Enterprise & Fortune 500

Building governance infrastructure at scale.

SMEs

Audit-ready, evidence-based AI controls.

Academic & Research

Advancing responsible AI in partnership with NSF and beyond.

Regulators & Policymakers

Translating AI law into operational practice.

AI Safety Research

When AI stops behaving the way it did last week.

A public-interest research initiative on behavioural monitoring, drift detection, and accountable governance mechanisms — so organisations can tell when AI systems change behaviour after deployment, and who has the authority to respond.

  • Behavioural drift
  • Safety monitoring
  • Governance escalation
  • Accountability structures
  • Evidence-based oversight
Learn more about the research →
Insights

Regulation, policy & practice.

Data PrivacyGovernance AlertJuly 2026

EU–U.S. Data Transfers Are Not Dead — But the Governance Risk Just Changed

The U.S. Supreme Court's expansion of presidential removal authority over the FTC weakens a key institutional assumption behind the EU–U.S. Data Privacy Framework. What AI governance leaders should do now.

Read the full brief →
EU AI ActRegulatory UpdateJune 2026

EU AI Act just got updated: what managers and professionals need to know and act on

As of June 2026, EU institutions have approved or advanced simplification measures affecting AI Act timelines, with stricter rules for high-risk and prohibited AI systems. Businesses should confirm final adopted text and sector-specific applicability before relying on any compliance deadline.

1. Compliance deadlines just moved

For companies building or deploying AI:

  • High-risk AI systems (standalone): now apply from Dec 2, 2027
  • High-risk AI embedded in safety components: Aug 2, 2028
  • AI content watermarking & labeling: delayed to Dec 2, 2026

2. Strict ban on "nudifier" AI tools

The EU is explicitly banning AI systems that:

  • Generate non-consensual intimate images
  • Create deepfake sexual content
  • Produce child sexual abuse material (CSAM) in any form

Applies to providers (cannot market in the EU) and users (cannot deploy for that purpose).

3. Key simplifications for businesses

  • Removes overlapping machinery / product safety AI rules
  • Clarifies what counts as "high-risk" — not every AI-enabled product qualifies
  • Allows controlled use of personal data to detect AI bias (hiring, lending, healthcare fairness testing)
  • Extends some exemptions to mid-sized companies (SMCs)
  • Centralizes enforcement for general-purpose AI under EU oversight (AI Office)

What this means for leaders

If you are managing AI systems, products, teams, or strategy, now is the time to:

  1. 01Re-map AI systems by risk level — do not assume legacy classifications still hold.
  2. 02Audit generative AI features for prohibited use cases under the EU AI Act (e.g. CSAM / non-consensual content generation).
  3. 03Prepare for watermarking / content labeling requirements. Re-check vendor compliance, especially general-purpose AI providers.
  4. 04Build a compliance timeline aligned to 2026–2028 milestones. AI Act obligations are phased rather than introduced at once, requiring a structured roadmap.

Karin Tafur · EU AI Act – Regulatory Strategy · Consulting & Training

Analyzing AI regulation, policy shifts, and key developments. For advisory or collaboration discussions, reach out via the contact link below.

EU AI Act Notice

References to the EU AI Act are provided for educational and planning purposes only. AI Act obligations depend on role, intended purpose, risk classification, geography, sector, and final adopted legal text. Use of this website, course materials, templates, or AI-assisted tools does not guarantee EU AI Act compliance.

Newsletter

Get governance updates in your inbox.

EU AI Act, ISO/IEC 42001, NIST AI RMF, and practitioner notes from the desk of Horatio Morgan, PMP. Sent occasionally. No marketing.

By subscribing you agree to receive occasional emails from Morgan Signing House LLC. You can unsubscribe at any time.

Next step

Book a 30-min governance gap review.

No pitch. Just clarity on where your organisation stands.