← All posts

Compliance & Regulation

402 posts on compliance & regulation.

EU AI Act Annex III: 8 High-Risk Use Cases, Explained

EU AI Act Annex III lists eight high-risk AI use-case categories, including biometrics, education, employment, credit scoring, law enforcement, and justice. See the covered systems, Article 6(3) exception, and the provider and deployer obligations that follow.

eu-ai-actannex-iiihigh-risk-aicomplianceclassificationregulation
Read post →

EU Data Act AI Compliance Checklist for Cloud and Model Switching

An EU Data Act AI compliance checklist covers the parts of Regulation (EU) 2023/2854 that reach an AI deployment: the switching obligations in Chapter VI, the international governmental access safeguards in Article 32, the contractual transparency duty in Article 28, and the connected-product data rules in Chapter II. Each check has an owner, a pass condition, evidence fields, and a boundary line.

ai-complianceai-governanceeu-data-actregulationpolicy-enforcementarchitecture
Read post →

NIS2 AI Controls Mapping for the Authenticated LLM Request Path

This NIS2 AI controls mapping takes the ten measures in Article 21(2) of Directive (EU) 2022/2555 and assigns each one a control point, an owner, a repeatable test, a retained artifact, and a stated boundary on the authenticated path from a user or agent to an LLM. It marks where an HTTP enforcement point contributes directly and where identity, endpoint, continuity and reporting teams stay accountable.

ai-complianceai-governancenis2architecturepolicy-enforcementregulation
Read post →

NIS2 AI Audit Evidence That Survives a 72 Hour Notification

NIS2 AI audit evidence has two customers: a competent authority testing Article 21 measures, and a CSIRT reading an incident notification written against the clocks in Article 23(4). This guide builds one evidence package that serves both, covering population definition, sample binding, integrity, retention, and the boundary where an AI gateway stops contributing.

ai-complianceauditnis2regulationai-governancezero-trust
Read post →

NIS2 AI Compliance Checklist for Authenticated LLM Traffic

A NIS2 AI compliance checklist has to grade the ten measures in Article 21(2) against the AI request path, not against a generic security policy. This guide gives each check an owner, a pass condition, an evidence field, and a boundary line, then keeps the 24 hour, 72 hour, and one month reporting clocks from Article 23 attached to the systems that can actually meet them.

ai-complianceai-governancenis2regulationpolicy-enforcementaudit
Read post →

CCPA CPRA AI Compliance Checklist: Ten ADMT Controls Before January 2027

A working checklist for businesses running AI over California consumer data before ADMT-specific requirements begin January 1, 2027. Each item names the duty, the concrete action, and the evidence it produces, so the list functions as an audit-readiness pass rather than a statement of intent. Ordered the way a CPPA review moves: scope and identity first, then notice and opt-out, then access, appeal and security.

complianceai-governanceregulationauditai-security
Read post →

CCPA CPRA AI Audit Evidence: What the CPPA Expects Once the ADMT Rules Bite

California finalized its automated decisionmaking technology rules on 23 September 2025. The regulations took effect on 1 January 2026, ADMT obligations attach from 1 April 2027, and the first risk assessments go to the California Privacy Protection Agency by 1 April 2028. This walks the specific evidence a CCPA review asks for when a prompt carrying personal information reaches a model, from pre-use notice through opt-out and appeal, and names which system each artifact has to come from.

complianceai-governanceregulationauditai-security
Read post →

California AI Law in 2026: Which Statutes Bind an Enterprise Deployer, and When

A compliance owner tracking California AI law in 2026 has five statutes to sort: SB 1001 bot disclosure, AB 2013 training-data transparency, SB 942 (delayed to August 2, 2026 by AB 853), the CPPA automated-decisionmaking rules under the CCPA, and SB 53 frontier-model safety. This piece separates the obligations that bind you as a deployer from the ones that bind model developers, with effective dates and the primary sources for each.

compliancecalifornia-ai-lawregulationautomated-decision-makingaudit-trail
Read post →

EU AI Act vs GDPR: How the Two Regimes Diverge on Record-Keeping, Identity, and the Per-Decision Trace

Compliance teams reach for the GDPR record-keeping playbook when the EU AI Act lands on the legal calendar. The two regimes overlap on data subject rights and personal-data scope. They diverge on the cadence of evidence, the identity of the actor the record describes, and the per-decision trace the AI Act requires. This piece walks through the five axes where the regimes diverge, the record formats each regulator reads, and the architectural changes the AI request path needs before August 2, 2026.

eu-ai-actgdprcompliancearticle-12audit-logsgovernance
Read post →

EU AI Act Article 9: What the Risk Management System Obligation Requires

Article 9 of the EU AI Act requires a risk management system for every high-risk AI system, running as a continuous iterative process across the lifecycle. The obligations include risk identification, risk estimation, risk evaluation, and the adoption of risk management measures. The August 2, 2026 deadline applies. Most enterprise AI deployments treat risk management as a documentation exercise that ends at conformity assessment. The Article 9 reading expects an operating system that produces evidence at every decision point.

eu-ai-actarticle-9risk-managementcompliancehigh-risk-aigovernance
Read post →

EU AI Act Importers and Distributors: The Lesser-Known Article 23 and Article 24 Obligations

Article 23 covers importer obligations and Article 24 covers distributor obligations for high-risk AI systems in the EU. The roles get conflated with provider and deployer roles in practice. An importer is the operator that places a high-risk AI system from outside the EU onto the EU market. A distributor is the operator that makes a high-risk AI system available in the EU market without being the importer or the provider. Both have specific verification obligations before the system reaches the deployer. With the August 2, 2026 enforcement date approaching, EU resellers and EU branches of non-EU vendors need to understand which obligations belong to them.

eu-ai-actcomplianceai-governanceregulationhigh-risk-aiimporter-distributor
Read post →

What the EU Commission''s May 2026 High-Risk Classification Guidelines Change About Your AI Scope Assessment

On May 19, 2026, the European Commission published its draft guidelines clarifying which AI systems fall within the high-risk classification under Annex III of the EU AI Act. The guidelines arrive 75 days before the August 2 enforcement date for high-risk obligations. They tighten the criteria for "intended purpose," reshape how deployers and providers classify HR screening, clinical decision support, and fraud detection systems, and accelerate the scope assessment timeline. This article walks through the new criteria, applies them to three concrete enterprise deployments, and identifies the per-decision evidence each will need to produce on demand from August 2 onward.

eu-ai-acthigh-risk-aicomplianceannex-iiiclassificationenforcement
Read post →