Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

NYDFS AI Compliance: Applying Part 500 Access, Audit, and Third-Party Controls to LLM Traffic

The NYDFS Cybersecurity Regulation, 23 NYCRR Part 500, requires covered financial entities to enforce least-privilege access, maintain audit trails, monitor authorized user activity, and govern third-party service providers. When employees and AI agents send data to LLMs, those requirements apply to the prompt traffic. NYDFS issued specific guidance in October 2024 on AI-related cybersecurity risks, and it maps to controls already in Part 500. This piece walks the Part 500 sections that land on AI inference traffic and shows how to enforce access and produce the audit trail the regulation requires.

Industry Verticalsnydfscompliancefinancial-servicesai-securityidentity-and-authorizationai-audit-loggingthird-party-risk
Read post →

GLBA AI Compliance: How the Safeguards Rule Applies When Customer Data Reaches an LLM

The FTC Safeguards Rule under GLBA requires financial institutions to run a written information security program with access controls, monitoring of authorized user activity, and oversight of service providers. When an employee or an AI agent pastes customer nonpublic personal information into an LLM prompt, that data becomes AI traffic to a third party, and the Safeguards Rule follows it there. This piece walks the specific Safeguards Rule provisions that land on AI inference traffic, where standard controls miss it, and how to enforce access and produce the audit record the rule expects.

Industry Verticalsglbacompliancefinancial-servicesai-securityidentity-and-authorizationai-audit-loggingdata-protection
Read post →

Agent-to-Agent Authorization: Deciding What a Delegated Agent May Do Before It Calls the Next Model

When one AI agent hands work to another, or calls a tool or a model on a user behalf, authentication proves which agent is calling and authorization decides whether that agent may take this action with this data right now. Many agent stacks solve the first and skip the second, so a delegated agent inherits the full permissions of whatever credential it holds. This piece walks the authorization decision on agent-to-agent traffic, the delegated-authority and action-lineage requirements behind it, and how to enforce and record it on the HTTP calls the agents actually make.

Problem-Awareagentic-aiidentity-and-authorizationai-securityai-agentspolicy-enforcementnist-ai-rmfinline-enforcement
Read post →

CMMC AI Compliance: Applying the Access Control and Audit Families to LLM Traffic Handling CUI

The CMMC Program, established by the DoD final rule at 32 CFR Part 170 effective December 16, 2024, requires defense contractors handling Controlled Unclassified Information to meet the NIST SP 800-171 controls, with Level 2 assessed against those requirements. The Access Control and Audit and Accountability families apply directly when a contractor employee or agent sends CUI into an LLM prompt. This piece walks the 800-171 control families that land on AI inference traffic, where standard controls miss it, and how to enforce access and produce the audit record an assessor samples.

Industry Verticalscmmccompliancegovernmentai-securityidentity-and-authorizationai-audit-loggingcontrolled-unclassified-information
Read post →

LLM Hallucination Controls: The Layer That Reduces the Rate and the Layer That Contains the Damage

A hallucinated answer is a confident, well-formed claim the model invented. Two moments in February 2024 made the cost concrete: a Canadian tribunal held Air Canada liable for a chatbot that invented a refund policy, and a New York court had already sanctioned lawyers who filed six fake cases ChatGPT produced. The controls that reduce hallucination frequency sit upstream in retrieval and prompt design. The controls that contain the damage and produce an accountable record sit at the request boundary. This walks both layers and marks which one enforces.

Problem-Awarellm-securityai-securityai-governanceinline-enforcementllm
Read post →

Australia Privacy Act AI Compliance Checklist: Ten Items Before a Prompt Carries Personal Information

A working checklist for Australian organisations running AI over personal information under the Privacy Act 1988 and the Australian Privacy Principles, with the automated decision-making transparency obligations landing 10 December 2026. Each item names the obligation, the concrete action, and the evidence to produce, so the list doubles as an audit-readiness pass rather than a set of intentions. Ordered by what an OAIC inquiry reaches for first.

Compliance & Regulationcomplianceai-governanceregulationauditai-security
Read post →

Australia Privacy Act AI Audit Evidence: What the OAIC Asks For and Where Each Artifact Comes From

Australia has no dedicated AI Act. AI that processes personal information is governed under the Privacy Act 1988 and the Australian Privacy Principles, enforced by the OAIC, with new automated decision-making transparency obligations from the Privacy and Other Legislation Amendment Act 2024 taking effect 10 December 2026. When the OAIC opens an inquiry, it asks for evidence, not intent. This walks the specific artifacts an AI privacy review produces and marks which system each one has to come from.

Compliance & Regulationcomplianceai-governanceregulationauditai-security
Read post →

Brazil LGPD AI Audit Evidence: What the ANPD Expects When a Prompt Carries Personal Data

Brazil governs AI through the LGPD (Law 13.709/2018) while its dedicated AI bill, PL 2338/2023, moves through the Chamber of Deputies after the Senate approved it on 10 December 2024. The ANPD enforces the LGPD, and its 2025 technical note on automated decisions signals where scrutiny is heading. This walks the specific evidence an LGPD review of an AI system expects, from Article 20 automated decisions to Articles 33 to 36 international transfers, and marks which system each artifact has to come from.

Compliance & Regulationcomplianceai-governanceregulationauditai-security
Read post →

Australia Privacy Act AI Controls Mapping: Australian Privacy Principles to Enforcement Points

The Australian Privacy Principles were written for personal information handling in general, and they apply to AI traffic without a translation layer. This maps the APPs that bite when a prompt carrying personal information leaves your network, plus the automated decision-making obligations effective 10 December 2026, to the specific technical control and enforcement point that satisfies each one. The mapping is deliberately concrete: obligation, where it applies in the request flow, the control, and the evidence the control produces.

Compliance & Regulationcomplianceai-governanceregulationpolicy-enforcementai-security
Read post →

Brazil LGPD AI Compliance Checklist: Ten Items Before a Prompt Carries Personal Data

A working checklist for organisations running AI over personal data under the LGPD (Law 13.709/2018), enforced by the ANPD, while PL 2338/2023 advances through the Chamber of Deputies. Each item names the article, the concrete action, and the evidence to produce, so the list functions as an audit-readiness pass rather than a statement of principles. Ordered the way an ANPD review moves: identity and records, then legal basis, then transfers, then automated decisions.

Compliance & Regulationcomplianceai-governanceregulationauditai-security
Read post →

California SB 942 AI Audit Evidence: What a Deployer of Covered Generative Systems Has to Show

The California AI Transparency Act (SB 942) takes effect 2 August 2026 after AB 853 delayed it from January, and it puts content-provenance obligations on covered providers of generative image, video, and audio systems with more than one million monthly users. Watermark generation sits at the model layer, outside an HTTP proxy. The evidence an enterprise deploying or licensing those systems has to produce sits in the traffic. This walks the audit artifacts that are actually visible at the request boundary and names what is not.

Compliance & Regulationcomplianceai-governanceregulationauditai-security
Read post →

Brazil LGPD AI Controls Mapping: LGPD Articles to Enforcement Points

The LGPD (Law 13.709/2018) governs AI in Brazil today, and each of its articles attaches to a concrete moment in the AI request flow. This maps the LGPD obligations that bite when a prompt carrying personal data leaves your network, from the Article 6 accountability principle to Article 20 automated decisions and the Articles 33 to 36 transfer rules, onto the technical control and enforcement point that satisfies each. The mapping stays concrete: article, where it applies, the control, and the evidence produced.

Compliance & Regulationcomplianceai-governanceregulationpolicy-enforcementai-security
Read post →