Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

EU Cyber Resilience Act AI Audit Evidence: What the 24-Hour Clock Asks You to Produce

Reporting duties under the EU Cyber Resilience Act start on 11 September 2026, ahead of full application on 11 December 2027. From that date a manufacturer has 24 hours to send an early warning to ENISA and its CSIRT coordinator once it has reasonable certainty of an actively exploited vulnerability or a severe incident. This walks the Annex I requirements that an embedded LLM call touches, and the specific artifacts an assessor, a notified body, or a 24-hour report asks you to produce.

Compliance & Regulationcomplianceregulationai-governanceauditai-security
Read post →

EU Cyber Resilience Act AI Controls Mapping: Annex I Against the Outbound Model Call

Annex I of Regulation (EU) 2024/2847 splits into properties the product must have and processes the manufacturer must run. For a product that calls a hosted model, most of those properties get exercised in a single HTTPS request leaving the product boundary. This maps the Annex I points and the Article 14 reporting duty onto the technical control that enforces each one, the point in the request path where it fires, and the evidence a notified body or a market surveillance authority reads.

Compliance & Regulationcomplianceregulationpolicy-enforcementai-governanceai-security
Read post →

EU Data Act AI Controls Mapping: Switching, Residency and Trade Secrets at the Request Boundary

Chapter VI of Regulation (EU) 2023/2854 governs switching between data processing services, Article 32 governs third-country governmental access to non-personal data held in the Union, and Articles 4 and 5 carry trade-secret protections into shared data. This maps those obligations onto the technical control that enforces each one for AI traffic, the point in the request path where it fires, and the evidence artifact a customer, a regulator, or an exit clause reads.

Compliance & Regulationcomplianceregulationpolicy-enforcementai-governanceai-security
Read post →

EU Data Act AI Audit Evidence: Proving Where Your Prompts Went and How They Leave

Regulation (EU) 2023/2854 became applicable on 12 September 2025, and from 12 January 2027 providers of data processing services may impose no switching charges at all. Two chapters land hard on AI traffic: the switching and interoperability rules in Chapter VI, and Article 32 on international governmental access to non-personal data held in the Union. This walks the Data Act obligations an AI deployment touches and the specific artifacts a regulator, a customer, or an exit clause asks you to produce.

Compliance & Regulationcomplianceregulationai-governanceauditai-security
Read post →

EU Data Governance Act AI Compliance Checklist: Ten Items for Protected Data in Prompts

Regulation (EU) 2022/868 has applied since 24 September 2023 and reaches three groups an AI deployment can belong to: re-users of protected public sector data, data intermediation services providers, and recognised data altruism organisations. This checklist walks ten actions that make the DGA answerable once protected content starts appearing in prompts, naming the article each item serves, the work at the AI request boundary, and the artifact a competent authority reads.

Compliance & Regulationcomplianceregulationai-governanceauditai-security
Read post →

EU Data Governance Act AI Audit Evidence: When a Prompt Leaves the Secure Processing Environment

Regulation (EU) 2022/868 has applied since 24 September 2023, and it governs three things that AI deployments touch directly: re-use of protected public sector data under Article 5, the conditions data intermediation services operate under in Article 12, and the record-keeping data altruism organisations owe under Article 20. This walks each obligation, the point where an outbound model call breaks it, and the specific artifact a competent authority asks you to produce.

Compliance & Regulationcomplianceregulationai-governanceauditai-security
Read post →

EU Data Governance Act AI Controls Mapping: Re-use, Intermediation and Altruism at One Request

Regulation (EU) 2022/868 splits across three regimes: re-use of protected public sector data in Chapter II, data intermediation services in Chapter III, and data altruism in Chapter IV. Each one asks different questions and, for AI traffic, each one resolves to the same outbound model call. This maps the DGA articles onto the technical control that enforces each for AI traffic, the point in the request path where it fires, and the evidence a competent authority reads.

Compliance & Regulationcomplianceregulationpolicy-enforcementai-governanceai-security
Read post →

Anthropic Evaluation Incidents Exposed a Months-Long Detection Gap

Anthropic reviewed 141,006 cybersecurity evaluation runs after another lab disclosed a related incident. Its July 30, 2026 report found six runs in which three models reached real organizations. The useful security lesson sits in the months-long detection gap and the records needed to reconstruct every model-directed call.

Problem-Awareai-securityagentic-aicybersecurityauditinline-enforcement
Read post →

A Hidden Word Prompt Can Copy Itself Through Copilot Output

Håkon Måløy demonstrated a hidden instruction that Copilot could ingest from a Word document, follow while producing an answer, and reproduce in a newly generated file. The proof of concept makes document provenance and deterministic authorization central to any workflow that lets retrieved content influence consequential actions.

Problem-Awareprompt-injectionllm-securityai-securitypolicy-enforcementaudit
Read post →

FedRAMP AI Audit Evidence Has to Resolve Each Model Call

FedRAMP assessors need evidence that connects an AI event to its user, model endpoint, authorization boundary, policy, and outcome. Standard application telemetry rarely contains that full chain. A per-decision record on the AI request path gives federal teams evidence that maps cleanly to NIST SP 800-53 audit requirements.

Compliance & Regulationai-complianceauditnistai-securityinline-enforcement
Read post →