← All posts

Compliance & Regulation

402 posts on compliance & regulation.

Spain's AEPD Logged the First Breach Notification Where an AI Agent Was the Actor

On September 14, 2026 the Spanish data protection authority received a personal data breach notification in which a third party used an AI agent as the instrument of the attack. The AEPD now tells controllers to write AI-executed and AI-assisted attacks explicitly into their Article 32 risk analyses rather than relying on generic malware language.

gdprai-governancecomplianceagentic-airegulationaudit
Read post →

AI Policy Generator: A Free Tool That Produces a Defensible Internal AI Use Policy in 15 Minutes

A shadow AI policy is the document a regulator reads first when something goes wrong. Most copy-paste templates fail because they list rules without the enforcement architecture behind them. The DeepInspect AI policy generator takes 12 questions about your organization and produces a defensible policy document with the seven sections an EU AI Act reviewer or a HIPAA auditor will recognize. The output is a markdown file your legal team edits and your CISO signs.

ai-policypolicy-generatorcomplianceai-governancefree-toolemployee-policy
Read post →

Australia Privacy LLM Requirements: Inputs, Outputs and Evidence

Australia privacy requirements for LLM deployments follow the existing Privacy Act and Australian Privacy Principles. Organisations need a defined purpose, lawful collection, notice, permitted use or disclosure, cross-border analysis, accurate outputs, security controls, access and correction paths, deletion handling, and evidence for each request route.

ai-complianceai-governancecomplianceregulationllmpolicy-enforcement
Read post →

Australia Privacy AI Risk Assessment: An OAIC-Aligned PIA Workflow

An Australia privacy AI risk assessment should begin before product selection and follow the OAIC privacy impact assessment process through data-flow mapping, APP analysis, mitigation, approval, and review. The assessment becomes operational when each privacy risk maps to an owner, runtime control, test, and retained artifact.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

Claude Connectors Compliance: Build an Evidence Chain Across Remote MCP Calls

Claude connectors compliance depends on evidence across four owners: the calling application, Anthropic API request, remote MCP authorization layer, and destination system. This article defines a control-and-evidence matrix for approved servers, tool permissions, data handling, retention, exceptions, and correlation without repeating a general security or audit-log overview.

ai-complianceai-governanceagentic-aiauditidentity-and-authorizationcompliance
Read post →

Atlassian AI Compliance: Turn Rovo Settings into Reviewable Evidence

Atlassian AI compliance starts with the published Rovo data path, then moves into customer-owned evidence. Review model routing, app-level activation, connector permissions, data contribution settings, residency choices, audit logs, and the policy decision on personal or regulated data before it reaches an LLM.

ai-complianceai-governancecomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

RCW 19.373 AI Controls: Consent, Owners and Evidence

RCW 19.373 requires separate sharing consent before consumer health data reaches an external AI provider. This Washington My Health My Data Act control map assigns each duty to an accountable owner, a runtime or process test, and evidence that can show a regulator what happened.

complianceregulationai-complianceai-governancepolicy-enforcementaudit
Read post →

Utah AI Disclosure Evidence: SB 226 Complaint File

Utah SB 149 created the Artificial Intelligence Policy Act in 2024, and SB 226 moved the consumer-protection rules into Chapter 75 in 2025. This guide builds an audit-evidence package around the current disclosure triggers, high-risk regulated-service rule, safe harbor, consumer-protection liability and Division enforcement. It separates statutory proof from useful HTTP operating evidence and keeps notice delivery with the application.

complianceregulationai-complianceai-governanceauditforensic-audit
Read post →

Korea AI Basic Act AI Controls Mapping: Operator Duties Against One HTTPS Request

South Korea''s AI Basic Act places its obligations on the operator rather than the model, which means most of them resolve to a technical control in the request path. This maps the high-impact duties, the generative AI transparency duties, and the inspection-response duty onto the enforcement point that satisfies each one, names the evidence produced, and marks the two duties that sit outside the AI request boundary and require organisational work instead.

complianceai-governancepolicy-enforcementregulationai-security
Read post →

CCPA CPRA AI Controls Mapping: California ADMT Obligations to Enforcement Points

California finalized its ADMT, risk assessment and cybersecurity audit regulations on 23 September 2025, effective 1 January 2026, with ADMT-specific requirements beginning January 1, 2027. This maps the CCPA and CPRA duties that apply when personal information reaches a model, from pre-use notice through opt-out, access, and appeal, to the control and evidence each requires.

complianceai-governanceregulationpolicy-enforcementai-security
Read post →

SOX AI Controls Mapping for the Authenticated LLM Path

This SOX AI controls mapping assigns each request-layer requirement a control point, accountable owner, repeatable test, retained artifact, and stated boundary. It connects identity, access enforcement, information flow, audit records, integrity, retention, and incident support to authenticated HTTP model traffic without assigning programme-wide obligations to a single gateway.

ai-complianceai-governancesoxfinancial-reportingauditinternal-controls
Read post →

SOX AI Audit Evidence for Model Requests and Decisions

SOX AI audit evidence starts with a complete population of authenticated model requests, then binds reviewer-selected samples to identity, destination, policy, and decision. It also covers response handling, integrity, and retention. This guide separates evidence an HTTP policy gateway can produce from programme and legal records, plus endpoint and operational records that stay outside that boundary.

ai-complianceai-governancesoxfinancial-reportingauditinternal-controls
Read post →