Blog

Analysis on enterprise AI governance, inline policy enforcement, agentic AI security, and regulatory compliance.

OWASP Agentic Top 10 AI Compliance Checklist: 12 Items With an Objective Completion Test

The OWASP Top 10 for Agentic Applications landed on 9 December 2025 and most teams read it, agreed with it, and filed it. This is a twelve-item checklist that turns the framework into work with a completion test on each item, ordered by dependency rather than by risk rank, and split between the items a platform team can close and the four that belong to application engineering.

Compliance & Regulationai-securityagentic-aicomplianceai-governanceauditpolicy-enforcement
Read post →

PIPEDA AI Audit Evidence: What the OPC Asked OpenAI For and Will Ask You For

On 6 May 2026 the Privacy Commissioner of Canada published findings from a joint investigation with Quebec, British Columbia and Alberta into OpenAI, running the analysis against appropriate purposes, consent, openness, accuracy, access, retention and accountability. The findings read as a list of the artifacts a Canadian organisation deploying AI should be able to produce. This walks each one and separates what a record on the request path establishes from what it does not.

Compliance & Regulationcomplianceregulationai-governanceai-complianceauditdata-privacy
Read post →

PIPEDA AI Compliance Checklist: 12 Items With an Objective Completion Test

The Privacy Commissioner of Canada published joint findings into OpenAI on 6 May 2026 and opened complaints against X Corp. and X.AI on 15 January 2026, both analysed against the ordinary PIPEDA principles. This is a twelve-item checklist for a Canadian organisation deploying AI, in dependency order, each with a test somebody outside the privacy team could run, and honest about the four items that stay with your governance and business teams.

Compliance & Regulationcomplianceregulationai-complianceai-governancedata-privacyaudit
Read post →

Saudi PDPL AI Audit Evidence: What SDAIA Asks For After 48 Enforcement Decisions

The Saudi Data and Artificial Intelligence Authority moved from grace period to enforcement when the PDPL transition window closed on 14 September 2024, and its specialised committees have since issued 48 decisions against organisations found in violation. The common failures were legal basis, unauthorised disclosure, and absent technical safeguards. This walks the evidence an organisation running AI in the Kingdom should be able to produce against each.

Compliance & Regulationcomplianceregulationai-governanceai-complianceauditdata-privacy
Read post →

PIPEDA AI Controls Mapping: The Ten Schedule 1 Principles Against AI Traffic

PIPEDA carries ten fair information principles in Schedule 1, written in 2000 and applied to AI deployments without amendment. Seven of the ten change shape when the processing is a prompt sent to a third-party model, and three do not move at all. This maps each principle to the control that satisfies it for AI traffic, names the owner, and gives an honest coverage verdict rather than ten green rows.

Compliance & Regulationcomplianceregulationai-governanceai-compliancedata-privacypolicy-enforcement
Read post →

Saudi PDPL AI Controls Mapping: Each Obligation Against the Control That Satisfies It

Saudi Arabia enforces the PDPL through SDAIA, the same authority that holds the national AI mandate, and its committees have issued 48 decisions since the transition period closed on 14 September 2024. This maps the operative obligations, legal basis, records of processing, impact assessment, cross-border transfer, safeguards, breach notification and data subject rights, to the control that satisfies each for AI traffic, with the owner named and an honest coverage verdict.

Compliance & Regulationcomplianceregulationai-governanceai-compliancedata-privacypolicy-enforcement
Read post →

Saudi PDPL AI Compliance Checklist: 12 Items With an Objective Completion Test

SDAIA has issued 48 enforcement decisions since the PDPL transition period closed on 14 September 2024, concentrated on legal basis, unauthorised disclosure, absent safeguards and marketing consent. This is a twelve-item checklist for an organisation running AI on personal data in the Kingdom, ordered by dependency rather than by statutory sequence, each item carrying a test somebody outside the privacy team could run, and honest about the five items no architecture closes.

Compliance & Regulationcomplianceregulationai-complianceai-governancedata-privacyaudit
Read post →

Singapore PDPA AI Audit Evidence: The Records Behind a Defensible AI Deployment

Singapore PDPA AI audit evidence starts with the records behind each deployed request: purpose, notice, consent or exception, originating identity, data class, destination, policy outcome, retention and breach assessment. This guide builds the evidence package around the PDPC obligations and its 1 March 2024 AI guidance, then separates runtime proof from privacy work that stays off the request path.

Compliance & Regulationcomplianceregulationai-governanceai-complianceauditpolicy-enforcement
Read post →

Singapore PDPA AI Compliance Checklist: 12 Items With a Completion Test

This Singapore PDPA AI compliance checklist turns the PDPC obligations into twelve dependency-ordered actions for an organisation deploying AI. Each item names an owner, an objective completion test and the evidence to retain, covering scope, purpose, notification, accountability, protection, overseas transfers, retention, access and breach response without assigning legal work to an HTTP gateway.

Compliance & Regulationcomplianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

Singapore PDPA AI Controls Mapping: Obligation, Owner, Test and Evidence

This Singapore PDPA AI controls mapping connects the Commission’s obligations to a control objective, accountable owner, implementation point, test and evidence artifact. It covers purpose, notification, consent, accountability, protection, accuracy, retention, overseas transfers, access, correction and breach notification, with Full, Partial and Outside verdicts that keep a request gateway inside its real boundary.

Compliance & Regulationcomplianceregulationai-governanceai-compliancepolicy-enforcementaudit
Read post →

StateRAMP AI Audit Evidence: Build a Package an Assessor Can Replay

StateRAMP AI audit evidence has to connect the authorization boundary, NIST SP 800-53 Revision 5 control narrative, tested AI request, and retained decision record. This guide organizes the package around sampling, replay, custody, integrity, and retrieval so a 3PAO can trace one authenticated caller through an LLM transaction without reconstructing the event from unrelated logs.

Compliance & Regulationai-complianceai-governanceauditforensic-auditnistzero-trust
Read post →

StateRAMP AI Compliance Checklist: 10 Tests for the Revision 5 Package

This StateRAMP AI compliance checklist turns the current GovRAMP Revision 5 package into 10 gradable actions for AI-enabled cloud services. Each item names an owner, required evidence, and a pass condition covering the assessed boundary, AI disclosures, identity, model routes, prompt protection, audit records, continuous monitoring, incident drills, and responsibility gaps.

Compliance & Regulationai-complianceai-governancecomplianceauditnistzero-trust
Read post →