Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

Wealth Management AI and FINRA Compliance

Broker-dealers and RIAs are wiring AI into research, client communications, and portfolio workflows, but FINRA supervision and books-and-records duties attach to the output. This walks through the obligations and the per-decision records that supply supervisory evidence.

Industry Verticalsai-compliancecomplianceregulationai-governanceauditai-security
Read post →

Utah's AI Disclosure Law: Requirements and Evidence

Utah's Artificial Intelligence Policy Act made generative-AI disclosure a legal duty, with tighter rules for regulated occupations. This walks through what the law requires, how it sits beside the California and Texas laws, and why a disclosure duty implies a per-decision audit trail.

Industry Verticalsregulationcomplianceai-complianceai-governanceauditai-security
Read post →

Telehealth AI and HIPAA Compliance

Telehealth platforms are wiring AI into visit summaries, triage, and scribing, which pushes PHI into LLM prompts that network DLP cannot read. This walks through the HIPAA obligations at the AI call boundary and the identity-aware policy and per-decision records that satisfy them.

Industry Verticalshipaaai-compliancecomplianceregulationai-governanceaudit
Read post →

The SaaS Guide to AI Security Questionnaires

Enterprise buyers now send SaaS vendors AI-specific security questionnaires about how AI features are governed, logged, and attributed. This walks through what they ask, why promises fail an auditor, and the architecture that lets a vendor answer with evidence.

Industry Verticalsai-securityai-governanceai-compliancecomplianceauditshadow-ai
Read post →

Pharma GxP AI Compliance: Part 11 Audit Trails for AI

GxP pharma workflows are wiring LLM calls into validated systems, but 21 CFR Part 11 audit-trail and ALCOA+ data-integrity expectations do not stop at the application log. This walks through where AI calls sit under Part 11 and how an external per-decision record supplies attributable, tamper-evident evidence.

Industry Verticalsai-compliancecomplianceregulationauditai-governanceai-security
Read post →

Medical Device AI and FDA Compliance

FDA oversight of AI-enabled medical device software keeps widening, yet the audit trail for the LLM calls clinical software makes over HTTP is usually missing. This walks through what FDA expects, where on-device inference sits outside the boundary, and how identity-bound policy plus per-decision records close the gap.

Industry Verticalsai-compliancecomplianceregulationai-governanceauditai-security
Read post →

Protecting Attorney-Client Privilege When Lawyers Use AI: Control the Disclosure, Keep the Record

When a lawyer pastes privileged material into an external AI tool, the concern is disclosure to a third party and the risk that raises to attorney-client privilege and work-product protection. Privilege determinations belong to courts and counsel. What a firm controls is which privileged content reaches which model endpoint, and whether there is a record of it. Both are decisions on the AI request path.

Industry Verticalslegal-aiattorney-client-privilegeai-egressai-audit-traildata-protection
Read post →

AI Underwriting Under the EU AI Act: Life and Health Pricing Is High-Risk

The EU AI Act names AI used for risk assessment and pricing in life and health insurance as high-risk under Annex III. That brings automatic logging, human oversight, and traceability duties to underwriting models. This article walks the obligations, separates the actuarial fairness work from the record-keeping work, and shows which duties a policy gateway produces evidence for on the AI request path.

Industry Verticalseu-ai-actinsurance-aiunderwritinghigh-risk-aiai-audit-trail
Read post →

Illinois AI Employment Law: The Notice and Non-Discrimination Duties Need a Record

Illinois House Bill 3773 amended the Illinois Human Rights Act, effective January 1, 2026, to make it a civil-rights violation for an employer to use AI that discriminates in employment decisions, and to require notice when AI is used. Both duties turn on evidence: proving what the AI was asked and what it returned. This article shows where that record gets written.

Industry Verticalsillinois-ai-lawai-employmentai-audit-trailcompliancestate-ai-law
Read post →

HR Hiring AI Under the EU AI Act: The Bias Question Becomes a Logging Question

The EU AI Act classifies AI used to screen and evaluate job candidates as high-risk under Annex III, which brings record-keeping, logging, and human-oversight duties. Bias mitigation is model and data work, but proving a hiring decision was accountable is a logging problem. This article separates the two and shows which obligations a policy gateway produces evidence for on the AI request path.

Industry Verticalseu-ai-acthr-aihigh-risk-aiai-audit-trailcompliance
Read post →

AI Medical Scribes and HIPAA: The PHI Leaves With the Prompt

An AI medical scribe listens to a patient encounter and drafts the clinical note, which means protected health information flows into an LLM on every visit. HIPAA compliance for that workflow turns on three things a policy gateway can enforce on the AI request path: a Business Associate Agreement covering the model endpoint, minimum-necessary control over what PHI is sent, and an audit record of every call.

Industry Verticalshealthcare-aihipaaphiai-audit-trailai-egress
Read post →

The Security Layer in Agentic AI Architecture Sits at the Model-Call Boundary

Most agentic AI architectures diagram the planner, memory, tools, and model, then add security as a wrapper around the application. That places enforcement above the layer where agent decisions become actions. The load-bearing security layer is the model-call boundary itself, where identity, policy, and audit apply to every request an agent makes to a model.

Problem-Awareagentic-aiai-architectureai-control-planeinline-enforcementai-audit-trail
Read post →