Author
Katya Savenkova
Director of Operations
With extensive experience across IT project management, customer success and relationship management, Katya leads Sphere’s operations and SAP practice. Outside of work she enjoys time with family, travel through South America, cycling, and exploring new technologies.
28 posts by this author

21 Lessons from 21 Years in Technology
When Sphere started in 2005, the first iPhone was still two years away. Twenty-one years later, the biggest lessons turned out not to be about technology at all.
Read the article
Conformity Assessment for AI: What "Ready" Looks Like Before the Audit
A conformity assessment checks that a high-risk AI system meets its requirements before it goes to market. Most of the pain is producing the evidence. Here's what 'ready' looks like — and how to be in that state before the assessor arrives.
Read the article
Why "We Log Everything" Is Not the Same as Auditable AI
Logging captures what happened. Auditable means someone else can verify it, unaltered, in scope. The four properties that separate a pile of logs from AI you can actually audit — and why most stacks have only the first.
Read the article
From Annual SOC 2 Scramble to a Continuous Query
Periodic security and compliance audits turn into a multi-week evidence scramble because the evidence is gathered after the fact. When controls record their own operation continuously, readiness becomes a standing query.
Read the article
The Audit Binder Is Dead: Continuous Evidence for AI Decisions
Compliance teams still assemble evidence into a binder for a point-in-time audit. AI decisions happen continuously, and the gap between the binder and reality is where enforcement lives. Continuous evidence closes it.
Read the article
eDiscovery for AI: Producing an AI Conversation That Holds Up
When an AI interaction becomes evidence in a dispute or investigation, you have to produce it in a form that holds up — complete, unaltered, and verifiable by someone who doesn't trust you. Here's what that takes.
Read the article
ISO 42001 vs the EU AI Act: What Overlaps and What Does Not
ISO 42001 and the EU AI Act are often mentioned together and are genuinely different things: one is a voluntary management-system standard, the other is law. Here's where they overlap, where they don't, and why one set of controls can serve both.
Read the article
One Ledger, Four Readers: Scoping Disclosure to Each Audience
A complete AI record raises a fair objection: not everyone should see everything. The answer is scoped disclosure — one tamper-evident ledger, four different views, each showing a reader exactly what they're entitled to and no more.
Read the article
A Model Registry a Regulator Can Read
You can't govern AI you can't list. A model registry catalogs every model you run — its purpose, data, limits, version, and owner — in a form a regulator can actually read, and keeps it current instead of letting it rot in a spreadsheet.
Read the article
A DPIA That Stays Current: A Living Data-Protection Impact Assessment
A data-protection impact assessment written in Word is accurate the day it's signed and drifting from reality by the next sprint. When the processing it describes is captured by the runtime, the DPIA can be a query against what's actually happening.
Read the article
Technical Documentation by Construction: The Annex IV File That Writes Itself
The EU AI Act's Annex IV technical file is usually written by hand, after the fact, from memory. Much of it can instead be assembled from what the system already records — turning documentation into a byproduct rather than a project.
Read the article
Article 50 in Practice: Auto-Generating the AI Disclosure Block
Article 50 asks you to tell people when AI is in the loop. A policy that depends on someone remembering will have holes; a disclosure the system emits wherever AI was used will not — and it proves itself.
Read the article
The 30-Day Statutory Clock, Answered in Ninety Seconds
A data-subject request starts a statutory clock, and for AI decisions most organizations spend it scrambling across systems. When the record is complete and queryable, the same request becomes a lookup instead of a race.
Read the article
Answering an Article 22 Complaint: "What Did Your AI Decide About Me?"
Under GDPR Article 22, a person subject to an automated decision can demand an explanation. Most organizations can't answer truthfully or quickly. Here's how a complete, verifiable record turns that dreaded request into a query.
Read the article
Signed Decision Receipts: Letting Anyone Verify an AI Outcome Offline
A signed decision receipt is a portable, cryptographically verifiable record of what an AI decided and why. Anyone holding it can check it against a published key — offline, with no access to your systems and no need to trust you.
Read the article
Provenance for Every Answer: Citation, Retrieval, and Redaction on the Record
An AI answer without provenance is an opinion. With it, every answer carries what it was based on — which sources, under what access, with what redactions — so a decision can be traced back to its inputs.
Read the article
The High-Risk AI Obligations Checklist You Can Actually Execute
The EU AI Act's obligations for high-risk AI systems read like a compliance essay. This checklist does the opposite: it maps each obligation to a runtime control you can operate and demonstrate — not a document you write once and hope no one tests.
Read the article
Change Management for Enterprise RAG: Getting Employees to Actually Use It
You can nail the architecture, pass every evaluation, and still fail — because the people it was built for don't use it. Adoption, not accuracy, is where enterprise RAG quietly dies. Here's the change-management half of the project: why employees distrust AI answers, and the four tools that earn adoption — citations, phased rollout, champions, and feedback loops.
Read the article
Governing Shadow AI Without Banning It
Shadow AI — employees using unsanctioned AI tools with company data — is the governance problem every organization has and few admit. The instinct is to ban it. But bans don't stop the usage; they hide it, pushing sensitive data into consumer tools you have no visibility into. The move that actually works is to make the sanctioned path more useful than the shadow one.
Read the article
RAG Pipeline Monitoring: What to Watch After Go-Live
A RAG system doesn't fail loudly — it degrades silently, giving confident, well-formatted answers that are quietly getting worse. Here's what to monitor after go-live: retrieval quality, answer faithfulness, data freshness, and cost and security telemetry, so drift shows up as a dashboard blip instead of an executive complaint.
Read the article
Company Brain for Onboarding: How AI Cuts New Hire Ramp Time by Half
New hires do not just need training content. They need the context behind the content — the acronyms, the workflow exceptions, the customer history, and the unwritten rules about who-to-ask-for-what. A Company Brain shortens both the new hire's ramp time and the senior employees' interruption tax at once.
Read the article
Why Enterprise Wikis, Intranets, and SharePoint Fail to Preserve Institutional Knowledge
Most enterprises already own a wiki or SharePoint — and employees still walk to a colleague's desk. Why documentation theater happens, what distinguishes a true AI-native knowledge layer, and why connecting existing systems beats replacing them.
Read the article
AI Audit Logs as Compliance Evidence: What to Capture, Retain, and Present to Regulators
Most AI platforms log conversations. Regulators need something different: a record of every governance control action the platform took. EU AI Act Article 12 mandates a minimum 6-month retention period for high-risk AI system logs. Here is what that log must contain and how to use it when inspectors ask questions.
Read the article
How to Choose an Enterprise AI Platform: 8 Questions Every Compliance and IT Leader Must Ask
Enterprise AI vendor evaluations are dominated by model benchmarks and UI quality. The questions that actually determine whether a platform is deployable in a regulated organisation concern governance architecture, security depth, compliance tooling, and audit capability — criteria most platforms fail before the demo ends.
Read the article
Enterprise AI Cost Control: Token Budgets, Per-Team Limits, and Real-Time Budget Alerts
Giving 250 employees unrestricted access to frontier AI models without cost controls is how you generate a $40,000 monthly API bill in week three. Here is how enterprise AI cost governance actually works — and why model choice alone creates a 25× cost variance per query.
Read the article
Engram: How Persistent AI Memory Turns Every Interaction Into Organisational Intelligence
Enterprise AI is stateless by design — each session starts from zero regardless of how long the platform has been running. Engram fixes this with 9 memory types, 4 maturity stages, and self-organising gravity wells that accumulate institutional knowledge permanently.
Read the article
How RAG Works in Enterprise AI — And Why Your Knowledge Base Architecture Determines Answer Quality
Enterprise AI vendors describe their knowledge base feature as "your AI trained on your documents." It is not. The accuracy of every answer depends on five architectural decisions about chunking, embedding, retrieval, and generation — most of them invisible to users.
Read the article