Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

FedRAMP AI Compliance Checklist for Request-Level Controls

A FedRAMP AI compliance review should test the authorization boundary, model inventory, identity propagation, least-privilege rules, data classification, event logging, evidence integrity, and continuous monitoring. This checklist translates those requirements into request-level tests an assessor can repeat.

Compliance & Regulationai-compliancenistauditpolicy-enforcementai-governance
Read post →

HITRUST AI Audit Evidence Needs Identity at the Model Call

HITRUST AI audit evidence should connect each model request with the authenticated principal, protected data classification, approved destination, policy version, and enforcement result. That event-level chain gives healthcare and regulated teams testable proof beyond screenshots and application status logs.

Compliance & Regulationai-complianceaudithipaaai-securityidentity-and-authorization
Read post →

Illinois AI Video Interview Audit Evidence for Hiring Teams

Illinois hiring teams using AI analysis of applicant video interviews need evidence connecting notice, consent, approved sharing, deletion handling, and each model interaction. Request-level records can support technical reconstruction, while the application remains responsible for candidate notices and consent workflows.

Compliance & Regulationai-complianceregulationauditai-governanceidentity-and-authorization
Read post →

HITRUST AI Controls Mapping at the Request Boundary

HITRUST AI controls mapping should connect access control, information protection, logging, communications security, vendor management, and configuration practices to observable model requests. A narrow request-boundary map gives assessors clear mechanisms and evidence owners.

Compliance & Regulationai-compliancehipaaauditarchitectureidentity-and-authorization
Read post →

Seven Model Backends Behind One Autonomous Attack Framework

Unit 42 documented a Hermes Agent campaign with seven interchangeable model backends and more than 460 targets. The useful defensive lesson sits at the model egress boundary: authorize the identity and destination for every outbound AI request, then preserve the decision record independently of the chosen provider.

Problem-Awareai-securityagentic-aicybersecurityinline-enforcementpolicy-enforcement
Read post →

Illinois AI Video Interview Act Controls Mapping

Illinois Artificial Intelligence Video Interview Act creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

Compliance & Regulationai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

Illinois AI Video Interview Act Compliance Checklist

Illinois Artificial Intelligence Video Interview Act creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

Compliance & Regulationai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

India DPDP Act Audit Evidence for Enterprise AI

India Digital Personal Data Protection Act, 2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

Compliance & Regulationai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

India DPDP Act AI Controls Mapping

India Digital Personal Data Protection Act, 2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

Compliance & Regulationai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

India DPDP Act AI Compliance Checklist

India Digital Personal Data Protection Act, 2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

Compliance & Regulationai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 23894 AI Compliance Checklist

ISO/IEC 23894:2023 creates concrete governance work for enterprise AI: identify the processing, bind each request to identity and purpose, enforce data and model policy before transmission, preserve request-level evidence, and test deletion, incident, and exception paths. This guide turns the requirement into controls an assessor can inspect.

Compliance & Regulationai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →