← All posts

Compliance & Regulation

305 posts on compliance & regulation.

AI Governance Operating Model: Decision Rights That Reach the Enforcement Point

An AI governance operating model assigns decision rights, ownership, and escalation paths for AI systems. Most models allocate authority over controls that never run at the request layer. This piece covers the centralized, federated, and hub-and-spoke archetypes, the RACI split across security, legal, data, and product, and why decision rights only govern anything when they bind to a runtime enforcement point.

ai-governanceoperating-modelcompliancegovernance-structureai-security
Read post →

AI Governance Oversight: The Evidence a Board Can Actually Verify

AI governance oversight fails when boards and committees review attestations instead of evidence. This piece covers what an oversight body is accountable for, the quarterly evidence package it should demand, and why per-decision audit records from the AI request layer are the only oversight substrate that survives a regulator or a lawsuit.

ai-governanceoversightboardcomplianceai-security
Read post →

AI Governance Strategy: Principles That Terminate in Enforceable Controls

An AI governance strategy sets the principles, scope, and target state for how an organization controls AI. Most strategies stop at principles and never specify the enforcement point that makes them real. This piece covers the components of a governance strategy and the test every principle has to pass: can it be enforced on AI traffic at runtime.

ai-governancestrategycompliancegovernance-frameworkai-security
Read post →

AI Governance vs AI Compliance: The Control System and the Evidence It Produces

AI governance and AI compliance get used interchangeably and are not the same work. Governance is the running control system over AI. Compliance is the evidence that system produces for a specific regulation. This piece draws the distinction precisely and shows why both draw on the same runtime substrate at the AI request layer.

ai-governanceai-compliancecomparisonregulationai-security
Read post →

AI Incident Response Plan for LLM Deployments: You Cannot Investigate What You Did Not Log

An AI incident response plan for LLM deployments has to answer questions endpoint forensics cannot: which identity made which AI request, under which policy, with what data. This piece maps the incident response lifecycle to LLM-specific incidents and shows why per-decision audit records at the AI request layer are the forensic substrate the plan depends on.

ai-governanceincident-responsellm-securityaudit-logai-security
Read post →

AI Model Inventory Management: Why the Request Layer Is the Only Accurate Source

An AI model inventory built from surveys is stale the day it ships, because most AI usage is unsanctioned and invisible to the teams filling in the form. This piece covers the fields a usable AI model inventory needs and why the AI request layer, which observes every call to a model, is the only source that keeps the inventory current.

ai-governancemodel-inventorycomplianceshadow-aiai-security
Read post →

AI Operational Governance: The Day-Two Control Loop That Runs on Every Request

AI operational governance is the running control loop over AI, distinct from the design-time work of strategy and operating models. It is what evaluates, decides, records, and reviews every AI request in production. This piece covers the day-two mechanics, policy versioning, exception expiry, drift detection, and on-call for AI policy, and why the loop has to live at the AI request layer.

ai-governanceoperational-governancecomplianceruntime-securityai-security
Read post →

AI Regulatory Compliance: Different Laws, One Set of Runtime Controls

The EU AI Act, US state laws, and sector rules use different vocabulary and converge on the same three runtime controls: identity-bound access to AI, policy evaluation on every request, and records detailed enough to reconstruct decisions. This piece maps the major regulations to that shared control set and shows why building the control once satisfies most of the map.

ai-governanceregulatory-complianceeu-ai-actregulationai-security
Read post →

An AI Risk Assessment Template That Survives a Regulatory Review

Most AI risk assessment templates are a spreadsheet of likelihood-times-impact scores that no regulator would accept as evidence. This walks through the fields an assessment actually needs, mapped to NIST AI RMF MAP and MEASURE and to EU AI Act obligations, and shows why the row a template skips most often is where the AI request produces an identity-bound record of what happened at inference.

ai-governanceai-compliancenist-ai-rmfeu-ai-actcompliance
Read post →

Colorado AI Act Compliance: What SB 26-189 Requires of Deployers

On May 14, 2026 Colorado's governor signed SB 26-189, which repeals and replaces the original Colorado AI Act (SB 24-205) and takes effect January 1, 2027. The new law narrows the target to automated decision-making technology that materially influences a consequential decision, and shifts obligations toward adverse-outcome explanations, correction and human-review rights, and a three-year record retention duty. This walks through what deployers must produce and where the evidence comes from.

ai-complianceregulationai-governancecomplianceaudit
Read post →

EU AI Act Compliance Requirements: The 2026 Timeline After the Omnibus

The Digital Omnibus moved the EU AI Act's standalone high-risk obligations to December 2, 2027, but the August 2, 2026 date did not empty out. Article 50 transparency duties still apply then, the penalty framework is live, and the high-risk requirements themselves, risk management and lifetime event logging, still exist on a later clock. This lays out what applies when, by role, and the record-keeping obligation that runs underneath most of it.

eu-ai-actai-complianceregulationcomplianceai-governance
Read post →

GDPR AI Compliance Requirements for LLM Deployments

GDPR predates the LLM era, but its obligations attach the moment personal data reaches a prompt. Lawful basis, purpose limitation, data minimization, special-category handling, automated-decision rights, records of processing, and cross-border transfer rules all apply to AI request traffic. This maps each requirement to the control that satisfies it at the AI request boundary, and shows why prompt content is the layer most GDPR programs currently cannot see.

gdprai-complianceregulationcomplianceai-governance
Read post →