Books from CodeDebate Press on adopting AI and living with the consequences: what it costs, who decides, who checks the output, and who signs. Fourteen titles across three series and one standalone. All of them are on my Amazon author page.
Who Approved This?
Enterprise AI Governance and the Decisions Nobody Owns
Book one of Scaling AI in the Enterprise
Someone asks who approved the AI system, and the room goes quiet — not because nobody has an answer, but because there are too many and they contradict each other. The build team points to the business sponsor. The sponsor points to the risk committee. The risk committee has minutes, but no decision.
Enterprise AI rarely fails on the technology. It fails on the questions nobody asked in the room: who decided this, on what basis, and who is watching it now? This is the operating manual for the executive who has to sign off on AI systems and then defend that decision — to a board, to a regulator, or to a customer harmed by something nobody quite owned.
143 Field Kit tools ship inside the chapters: decision-rights maps, go/no-go gates, review templates, the questions a board should be asking. Each sits next to the reasoning that produced it, because a tool separated from its argument becomes a form somebody fills in.
The cases are composites drawn from regulated environments; no organization is named. The book makes no prediction about where regulation lands — it teaches the operating system underneath, the part that still holds when the rules move.
Built from In Practice: AI in the Enterprise, ninety field notes published every working day from March to July 2026. 318 pages, 105,000 words.
Scaling AI in the Enterprise
Every organisation adopting AI arrives at the same questions, and not one of them is technical.
Who approved this, and on what evidence? What is it costing us, measured against what? How do we buy it from people whose profession is demonstrating well? How does it get past the functions whose profession is saying no? And when the first phase ends, what argues for the one after it?
The series is written for the people who answer those questions with their name attached: executives and boards, finance and procurement leaders, operations owners, risk and control functions, and the consultants who sell into all of them. The anchor volume, above, is a full-length treatment; the four that follow are short, worked, and built around artifacts you can use tomorrow.
Are We Paying Too Much?
Scaling AI FinOps in the Enterprise Jungle · Book two
Your AI bill went up again this month. Is that success or failure? You cannot tell from the bill, because AI spend rises whether the technology works or not. More usage, more cost. More failures and retries, also more cost. “Are we paying too much?” stays malformed until you choose a denominator and defend it.
This one is a fable. The cast are animals and the setting is a jungle: the Crow runs finance, the Fox leads the AI programme, the Tortoise speaks for compliance, and the Peacock sells. The form is deliberate — it keeps the argument on mechanics rather than on anyone’s employer, and it makes the politics of a cost conversation legible in a way a case study cannot.
The mechanics underneath are real. The book builds the AI FinOps Operating Loop — Inform, Optimize, Operate — on the principle that cost and quality must be operated together, in the same forum, by the same people. Its working artifacts:
- The Denominator Definition — a unit of work you own and defend for two years
- The Value Ledger — append-only, claimed benefit against realized benefit, with decay assumptions stated
- The Allocation Rule — fixed floor and variable band, published before the first allocated number, so people can accept or reject a rule instead of fighting each figure
- The Conversion Chain — technical unit to business outcome, with every link marked measured or assumed
- The Tagging Standard, for request-level instrumentation by team and business purpose
- Sunset Criteria written at launch, so retirement is a threshold rather than an argument
- The Pilot Cost Count and the Variance Report — total pilot cost including setup tax; claimed against realized, gap shown
For the people who share the AI bill: finance, engineering, and the business owners between them. No FinOps background assumed.
By the end you will defend your maxims with numbers of your own, run the drills against your own spend and logs, and tell project funding from capability funding — which is where most of the argument actually lives.
The Demo Was Flawless
Buying Enterprise AI, from the Wrong Side of the Table · Book three
Of course the demo was flawless. It was built to be — rehearsed on curated data, run down a script that visits every strength and no weakness, with a safety net you never saw. The demo is not evidence about the product. It is evidence about the demo team.
Enterprise AI gets bought in the gap between a performance and a product, and the bill arrives later wearing the buyer’s name: the model that drifted after go-live, the “integration” that was a roadmap item, the accuracy claim that was true on the vendor’s data, at the vendor’s threshold, under conditions the contract never mentioned.
This is the buyer’s side of the table, step by step:
- The three signature checks — certificate of incumbency, board resolution, sample signature — because knowing who is authorised to bind the other party is the cheapest diligence there is
- Demo deconstruction into its four layers: the story, the data, the click map, and the safety net, recorded while you watch
- Translating capability claims (“our model detects X”) into performance claims with numbers and conditions attached
- The readiness gap audit: every task verb in the statement of work given a single owner and a hard date, so the gaps surface before signature
- Data preparation costed line by line, hours and rates and owners, including your own people’s time
- Pilots you own — success criteria, kill decisions and dates set in advance — and an eight-week bake-off on real data
- Evaluations designed to produce evidence of failure, which is the only kind that tells you anything
- The exit playbook, the behavior SLA for model changes, contract redlines, the licence pricing engine modelled, and an honest cost model that yields your walk-away number
Written for COOs, procurement leaders, operations owners and legal teams. No machine-learning background required; scepticism supplied.
The vendor controls the demo. You control the evaluation — if you claim it. This book is the claiming.
The Second Line Would Like a Word
Shipping AI in Financial Services Before the Use Case Retires · Book four
The model works. The business case is signed. The team is ready to ship. And then — validation, compliance, audit, risk. By the time it clears, the use case that justified the project has quietly retired, undeployed.
In financial services, the technology is rarely what kills an AI initiative. What kills it lives in the seam: the gap between the team that builds the model and the control functions that must accept it. Builders speak in performance metrics; reviewers in evidence and precedent. Each side does its job well, and between them the use case dies of latency.
This book is a field guide to shipping AI across that seam — written for both sides of it:
- The seam map: every handoff between first and second line — registration, documentation, independent validation, ongoing monitoring — with what each checkpoint actually needs, in the reviewer’s language
- Evidence built while you build: the documentation habits that make validation a review instead of an archaeology dig
- Where to register a use case, when, and what a registration that survives challenge contains
- Independent validation from the inside: what validators test, what makes a finding, and the difference between a finding you fix and one you rebut with evidence
- Monitoring that satisfies the letter and the intent: thresholds, escalation, and the reports risk actually reads
- Sketches from both chairs — the builder’s and the reviewer’s — drawn as openly illustrative scenes, claiming nothing you could not check in your own institution
For practitioners preparing the evidence, leaders funding the work, and the second line itself.
The argument of this book is that shipping is not a modelling problem — it is what happens when the seam is treated as part of the engineering. The technology is ready. This book is about making the process ready before the use case retires.
We’ll Firm That Up in Discovery
Scoping, Pricing and Delivering AI Advisory That Reaches Phase 2 · Book five
You did not lose the engagement when they saw your price. You lost it three weeks earlier — when the scope stayed soft, the decision-maker stayed unmapped, and everyone agreed to firm things up in discovery. Discovery arrived. Nothing was firm. The engagement ended at Phase 1, politely, permanently.
AI advisory has a structural problem: Phase 1 is easy to sell and Phase 2 is where the money is, yet Phase 1 is usually designed as a deliverable instead of as an argument for Phase 2. The client receives a competent document, thanks you sincerely, and shelves it. The document was the product. It should have been the case.
This book is the operating manual for the other way:
- Qualification with teeth: the signals that a deal cannot close no matter how good the work is — and the discipline to walk away while it is still cheap
- Mapping the real decision-maker: the person who can fund Phase 2, who is rarely the person who hired Phase 1, and how to reach them without going around your sponsor
- Exit criteria that are binary: conditions written into the Phase 1 scope that make the Phase 2 decision a reading of results rather than a fresh sales cycle
- Pricing the decision, not the days: what Phase 1 is worth when it de-risks the commitment behind it
- The Phase 1 deliverable as an argument: structured so its final section can only be answered by a decision
- Templates for the proposal skeleton, the exit-criteria table, and the one-page Phase 2 case
For independent consultants, boutique partners and fractional executives selling into large organisations.
The phrase “we’ll firm that up in discovery” is where margins go to die. By the end of this book you will have a Phase 1 that either converts — or tells you early, in writing, that it never would have. Both outcomes pay.
Who Signs for This
An AI system does something in your company’s name. A customer is told the wrong thing, a refund goes out that should not have, a decision gets made at three in the morning by software nobody was watching. The question that follows is always the same, and it is never answered by the technology: who signs for this?
The series is written for the people whose names are on the answer: board members and executives, risk and operations leaders, and the managers accountable for what a system produces while they are in a meeting. The three books move from the boardroom to the incident to the individual delegation.
Duly Noted
The Five AI Decisions Your Board Actually Owns · Book one
Somewhere in your last board pack was an AI item. It was probably approved. And if you asked each director afterwards exactly what was decided — what risk was accepted, what spend was authorised, what happens when it goes wrong — you would get polite variations of “we noted it.”
Noting is not owning. Boards and executive teams approve AI initiatives while the five decisions that actually govern them go unmade — not rejected, just never surfaced as decisions at all. Then the incident happens, or the auditor asks, or the disclosure question lands, and the answer turns out to be nobody’s.
Duly Noted names the five decisions and puts them in plain language:
- Risk appetite — which AI failures you are choosing to accept, stated before they happen
- Spend authority — who can commit money to AI, at what threshold, against what evidence
- Disclosure — what you tell customers, regulators and staff about where AI touches them, and who owns that story staying consistent across every surface
- Incidents — what counts as an AI incident, on a definition tight enough that alerts mean something
- Accountability — the named owner for each system that acts in your company’s name
For each: what the decision actually is, the questions that force it into the open, what owning it costs, and what leaving it unowned has cost others — told through composite cases, invented to teach, with the mechanics kept honest.
Written for board members, executives, and the people who prepare their materials. No technical background assumed; no technology hype tolerated.
By the end you will be able to audit your own organisation’s AI claims across every surface where they appear, define an incident before you need the definition, and walk into the next AI agenda item knowing precisely which of the five decisions is on the table — and declining to leave until it is made.
It’s Probably Fine
The AI Incident Playbook for the Day It Very Much Is Not · Book two
Your organisation rehearses infrastructure failure. It improvises AI failure. There is a runbook for the dead server and a group chat for the day the model starts confidently doing the wrong thing.
The difference is not negligence. AI failure is behavioural rather than mechanical: nothing crashes, no alert fires, and the system keeps answering beautifully while being wrong in a way that compounds — bad outputs becoming inputs, invented facts getting actioned, and the humans who would normally notice reassured by a long run of it working.
This playbook closes that gap in five stages, each one building a piece of the response mechanism:
- Detection — what “something is off with the model” looks like before a customer says it
- The failure taxonomy — incident types specific to your system, so a hallucination and a policy violation stop sharing a name
- Containment — the kill-switch protocol: who holds authority to disable the system, and the technical method for doing it, decided while everyone is calm
- Communications and evidence — the severity matrix mapping incident types to response levels (a minor drift takes a ticket; a safety violation takes a war room), plus templates for internal alerts and external holding statements, so nobody writes under pressure
- Playbook and exercise — the one-page checklist that lives where your on-call team will find it, and a ninety-minute tabletop that walks your team through a simulated incident and finds the gaps while they are still cheap
For heads of AI or engineering, risk and operations leaders, CISOs, and founders wearing all three hats. Composite scenarios, invented to teach.
You will not prevent every AI failure; that option is not offered. What you can decide now, cheaply, is whether the day it very much is not fine finds an organisation with a playbook and a rehearsed team — or one improvising in a group chat while the system keeps answering.
Who Told It to Do That?
A Manager’s Guide to AI Agents, for When the Answer Is You · Book three
The agent cancelled the order, emailed the customer, and logged the refund. Nobody told it to. Except — somebody did: whoever gave it that scope, those permissions, and no rule saying otherwise. When an AI agent acts in your company’s name, “who told it to do that?” has an answer, and the answer is the manager who delegated to it.
That reframe is the whole book. Agent failures are delegation failures, not model failures — and delegation is something managers already know how to do well. You would never hand a new hire the customer database, payment authority and an unmonitored inbox on day one. The discipline you would apply — scoped duties, graduated permissions, review proportional to risk — is exactly the discipline agents need, applied with the same seriousness.
The framework is Scope, Permission, Review:
- Scope: decompose the workflow into delegable pieces — inputs, outputs, decisions made, systems touched, and who does it today — so you delegate steps, never vague outcomes
- Permission: the authority map for each step — what the agent may do alone, what it proposes for approval, what it must never touch — with the irreversible actions fenced first
- Review: checkpoints sized to risk, sampling that actually samples, and the escalation path for the day the output looks wrong
Plus the operating rules that keep the framework honest: every production agent has a name and an owner; propose-only comes before autonomy; permissions are raised one step at a time on evidence; and the worksheets taught through the chapters turn a workflow into a delegation plan you can hand to someone.
Written for managers accountable for output, not for engineers. No model internals, no prompt tricks — management, applied to a new kind of report.
The agents are coming to your team either way. The only question is whether they arrive as well-managed delegates or as unsupervised strangers with your password. This book makes it the first.
Check the Machine
The machine is fluent. That is the whole problem.
It produces clean paragraphs, confident summaries and plausible citations at a speed no checking habit was built for, in exactly the register your training taught you to trust. Very little of what goes wrong is dramatic. It is a summary that reads well and says something its source did not. It is a number that entered a document three drafts ago and cannot be traced to anything.
The series is written for the individual practitioner: the person checking what the machine just handed them, whatever their industry. Each book teaches one routine, demonstrates it on real working documents, and ends with a drill you run on yours.
Close Enough to Be Wrong
Why AI Summaries and Meeting Notes Quietly Change What Was Actually Said — and the One-Minute Check That Catches It · Book one
The summary was accurate. Every sentence traced back to something real. And the decision you made from it was wrong — because “suggests” had hardened into “shows,” “some customers” had widened into “most customers,” and the one caveat that would have changed your mind was squeezed out for length.
This is drift, and it is the failure nobody checks for. AI summaries and meeting notes rarely fabricate; they compress. And compression has a direction: hedges vanish, quantifiers inflate, correlation hardens into cause, and dissent disappears. The document as a whole ends up saying something nobody in the room actually said — while passing every spot-check you would think to run, because each sentence, alone, is close enough.
Close Enough to Be Wrong is for anyone who asks a machine to make long things short three or more times a week: summarize this thread, key points from this call, what did they decide. It teaches one habit:
- The three-three-one check — in about a minute, take the three claims you would act on or repeat, trace each to its source sentence, and compare three words: the qualifier, the quantifier, and the causal verb
- The upgrade directions drift follows (suggests→shows, some→most, coincided with→caused), so you read summaries the way an editor reads a proof — right to left, against the original
- The omission question for the costliest claim: would anything in the surrounding paragraph have changed how I read this? — and the five things summaries reliably lose: the limitation, the dissent, the condition, the cost, the rejected alternative
One chapter, one worked example at a time, from email threads to board minutes, ending with a printable card of the whole method.
You will not stop using AI summaries — nor should you. But a minute of tracing, on the claims that matter, is the difference between a summary that saved you an hour and one that cost you a quarter.
Ghost Words
A 10-Minute Daily Habit to Catch AI Fabrications in Your Working Documents · Book two
They read fine. That is the problem.
The vendor claim that nobody ever actually promised. The citation that leads nowhere. The specific-sounding number that entered the document three drafts ago and cannot be traced to anything. Ghost words — text that carries the shape of verified fact without the substance — have always existed in working documents. AI drafting multiplied them, because the machine produces confident, well-formed, plausible text at a speed no checking habit was built for.
This book installs the checking habit: ten minutes a day, with a timer, before your work goes out.
The habit works because of what the timer does. After hours inside a document you are in hunting mode — finishing, polishing, defending. The ten-minute timer switches you to judging mode: you step back and read your own work the way the person who has to approve it will. The gap you could not see becomes obvious. Then the timer rings, and the fixing — which is a different job — begins.
Inside:
- The daily habit itself: what to read, what to ask, when to stop
- The vendor-claims inventory: sorting what you have been told into hard promises, soft promises, and assumed facts — before the contract, not after
- Four passes for any significant draft: structure, evidence, voice, and gates — each pass one question, each question answerable in minutes
- The escalation rule: which documents get the full treatment and which get the short version
- Worked examples from procurement, operations and document-heavy work — composites, invented to teach — with the ghost words found and shown
For professionals who move documents, vendors and decisions all day, and whose name is on what goes out.
Ten minutes is short enough to survive contact with a real calendar — which is the point. A verification habit you skip protects nothing. This one you will keep, because it fits before the send button, and because the first ghost word it catches in your own work will make the case better than this description can.
The Chatbot Didn’t Go to Your School
Professional Judgement in the Age of the Confident Machine · Book three
You spent years learning your field — the qualification, the supervised practice, the mistakes that taught you what the textbook could not. The chatbot did none of that. It read everything and understands nothing: a machine that predicts the next word well enough that its output is indistinguishable, at a glance, from knowledge.
At a glance is the problem. Professionals now work beside a tool that produces fluent, confident, sometimes-wrong text in exactly the register their training taught them to trust. The hazard is not that the machine replaces your judgement; it is that it quietly borrows your authority. Its draft becomes your document. Its guess becomes your advice. Its leak becomes your breach.
The spine of the book is the Check Routine — five questions you run on your own work, because a routine beats vigilance, and vigilance is just intent, which is invisible on the page:
- Does the first paragraph match the decision?
- Is the summary number the same as the source number?
- Did I name the person who must act?
- What if the opposite of my claim is true?
- Am I sending this because it is ready, or because I am done?
Around it, the habits that keep the machine outside your professional obligations:
- The two-tap pause, and the three words that turn a safe question into a data leak, before anything gets pasted
- The fax-machine rule: treat the box like a fax line to a stranger’s office and you will know instantly what never goes into it
- The highlight audit — every fact in an AI draft checked against source material before it moves
- The pre-flight check before signature, and the plain-text paste that stops metadata travelling with your document
Worked scenes span contracts, clinical notes, management and study — composites, invented to teach, each ending in a check you can run on your own work today.
Whoever drafted it, you own the signature. This book is about being able to.
Great Essay. Who Wrote It?
Knowing Who Wrote What, When AI Drafts First and the Detector Is Guessing · Book four
The draft is excellent. Clear structure, confident prose, correct conclusion. One question remains, and it is suddenly hard to answer: who wrote it?
When AI drafts first, provenance stops being obvious — and a detector’s confidence score is a number whose meaning you have not established. Edited output, mixed authorship, a translated passage, a careful writer: the conditions that make provenance hard are the conditions under which a score is hardest to read. If your decisions about trust, credit, grading or sign-off rest on that number, you should know what it is worth first.
This book replaces the detector with judgement — specific, practised, defensible judgement:
- Calibration drills: testing a tool’s confidence scores against outcomes you can verify, so its numbers mean something before you act on one
- The provenance distinctions that matter: mechanical polish versus generative assistance versus fabricated judgement — where each is legitimate, where each must be disclosed, and how to tell them apart from the text itself
- The three-pass prompt audit for work you commission, run before the output enters your workflow
- Attribution rules you can state in advance: what your name goes on, what gets a disclosure line, what gets declined
- Worked cases from contracts, vendor reviews, reports and assignments — composites, invented to teach — each traced to a decision
Written for professionals who receive, commission or approve drafted work — managers, reviewers, editors, educators — and for anyone whose signature makes a document true.
The uncomfortable premise, stated plainly: fluency is no longer evidence of anything. The machine is fluent by construction. What remains scarce, and therefore valuable, is the ability to say what a piece of text is, where its claims came from, and whose judgement stands behind it — and to say it without a guessing machine as your witness.
By the last chapter, “who wrote it?” becomes a question you can answer — or decline to certify — with reasons you can defend.
Because the Robot Said So
Asking the Follow-Up Question When the AI Sounds Sure · Book five
The answer arrived instantly, in complete sentences, with a confident tone and a plausible number. So you used it. And now that number is in the deck, the deck is with your client, and the machine that produced it was never asked the one question that would have exposed it.
Language models predict words. They do not know facts. That gap — between an answer that sounds right and a claim that is verified — is where working professionals get hurt: the contract summary that invented a clause, the vendor comparison with a fabricated certification, the client update quoting a statistic no one can find. The machine was not lying. It was doing exactly what it is built to do: continue text plausibly.
This book teaches the follow-up question as a working habit. Not prompt engineering, not AI theory — verification drills for people who use AI tools on real work every week.
Inside:
- The four places a confident answer slips: the invented number, the fabricated source, the confident guess, and the misread question — with the tells for spotting each
- The two-part follow-up to ask whenever the machine sounds sure, and what a trustworthy answer to it looks like
- Verification drills you run on your own workflow: contracts, vendor checks, client communications, research
- Which claims must be traced to a source before they leave your desk, and which can ride
- How to keep the speed of the tool without inheriting its confidence
Each chapter ends with a drill run against your own work — so by the final page you have not read about verification, you have practised it.
The machine will keep sounding sure. That is its nature. Your job is to be the person in the room who asks the follow-up question — because the answer to “why did we send this?” can never be “because the robot said so.”
Standalone
Suddenly Everyone’s an AI Expert
A Small Business Owner’s Guide to the Three Workflows That Actually Pay
The consultant has a deck. The vendor has a demo. Your competitor has a press release, your nephew has opinions, and everyone is suddenly an AI expert. Meanwhile you have a business to run, real margins, and a suspicion that much of what you are being sold would cost you more than it saves.
This book is about the cases where it does not — the three workflows where AI pays in a small business:
- Paper into data — invoices, forms and orders turned into records, with an exception log that tracks what the machine could not read and sets your tiering rules
- First drafts that are never the final word — quotes, replies and routine writing drafted for a human to finish, with a fail log that turns recurring errors into a checklist
- The business locked in one person’s head — the decisions that live with your longest-serving operator, captured in a decision grid so the next person finds them instead of rebuilding them
Around the workflows, the buying discipline that keeps vendors honest:
- Three sentences before you contact any vendor — task, outcome, constraint — which sort sellers into those addressing your problem and those addressing your budget
- A costing sheet comparing loaded costs against actual work across buy, connect, run and leave, and a payback sheet that discounts cash flows over the life of the thing
- A pilot charter with a metric, a baseline, a kill threshold and a kill date, agreed before the pilot starts
- A subscription ledger with a named owner per line, because the tool nobody cancelled is the cheapest saving you will ever find
Worked examples run the arithmetic honestly on composite businesses, invented to teach. No product names, no futurism, no “transformation.”
You do not need to become an AI expert; the supply is ample. You need three workflows that pay, the discipline to buy them well, and the confidence to decline everything else.
In progress
Building an AI Company
Starting and scaling an AI company, written from inside a live build and anchored to the documents a founder produces or receives — the certificate of incorporation, the first model provider invoice, the security questionnaire, the term sheet.
The source series is serialising now, twenty lessons every working day through August 2026.
Bulk orders
Quantity orders are available for leadership programmes, board education and team reading. If you want copies for a group, get in touch and tell me how many and roughly when you need them. Use the contact form on the About page.













