← All posts

Compliance & Regulation

305 posts on compliance & regulation.

Third-Party AI Risk Management: The Embedded-Model Problem

The hardest third-party AI risk to manage is the AI you did not know a vendor was running. A SaaS tool summarizes your tickets with an LLM, a quality vendor scores your files with a model, and your data leaves for an endpoint you never approved. This walks the third-party AI risk lifecycle, from discovery through offboarding, centered on embedded and subprocessor AI, model-provider concentration, and the due-care obligation a SOC 2 report does not discharge.

ai-governanceai-compliancecomplianceregulationaudit
Read post →

The EU Action Plan on Cybersecurity and AI: Pre-Market Evaluation, Structured Access, and What Enterprises Must Evidence

On July 7, 2026 the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence: pre-market evaluation of advanced models, an EU third-party evaluation capacity supporting the AI Office, an ENISA and JRC secure testing platform, a structured-access blueprint for advanced AI capabilities, and tighter alignment with NIS2 and the Cyber Resilience Act. I read the plan as a directional signal about evidence. This walks each pillar and maps it to the authorization and audit records an enterprise has to be able to produce on demand.

eu-ai-actai-governanceai-complianceregulationcybersecurityaudit
Read post →

Responsible AI Governance: From Principles to Controls

Responsible AI is usually a list of principles: fairness, accountability, transparency, human oversight. Those principles become governance only when a deterministic policy decision point enforces them and a per-decision record proves it. This walks through how to operationalize responsible AI.

ai-governanceai-compliancecomplianceregulationnist-ai-rmfiso-42001
Read post →

The Commission adopted its Article 50 guidelines on July 20: who discloses, who marks, and what you have to be able to prove

The European Commission adopted its final guidelines on the Article 50 transparency obligations on July 20, 2026, thirteen days before those obligations start to apply on August 2. The guidelines set out scope, definitions, and exceptions, and they split the duties actor by actor: providers carry the interaction notice and the machine-readable marking of synthetic content, deployers carry emotion-recognition notice and deepfake disclosure. Generative systems already on the market get until December 2, 2026 for machine-readable marking. This walks the split obligation by obligation and separates the parts an AI policy gateway produces evidence for from the parts it never touches.

eu-ai-actcomplianceregulationai-governanceai-complianceaudit
Read post →

ISO/IEC 23894: What the AI Risk Management Standard Asks You to Produce

ISO/IEC 23894:2023 adapts the ISO 31000 risk management process to AI systems. It is guidance rather than a certifiable standard, which changes how it gets used: teams reach for it to structure risk identification and to feed the risk clauses of ISO/IEC 42001, which is certifiable. This walks the standard structure, the AI-specific risk sources it names, how it relates to 42001 and the NIST AI RMF, and which of its monitoring and record requirements a runtime control produces evidence for.

iso-42001ai-governancecompliancerisk-managementauditregulation
Read post →

AI Governance Standards: Which One Is Certifiable, Which Is Guidance, and What Each Expects in Production

Six documents get called AI governance standards: ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF, ISO/IEC 27001 with AI extensions, the EU AI Act harmonized standards work, and OWASP AISVS. Only one of them is certifiable, two are law-adjacent, and they differ sharply in how much production evidence they expect. This sorts them by what they are, how they overlap, and which clauses require runtime records rather than documents.

ai-governanceiso-42001nist-ai-rmfcomplianceeu-ai-actaudit
Read post →

UK GDPR and AI: The Six Obligations That Bite When a Prompt Leaves Your Network

The UK has no AI Act. AI use is governed under the UK GDPR and the Data Protection Act 2018, enforced by the ICO, with sector regulators layering their own expectations on top. Six obligations do the work: lawful basis, purpose limitation, data minimisation in the prompt, Article 22 automated decisions, international transfers when a prompt crosses a border, and Article 30 records. This walks each and marks where the evidence has to come from.

complianceai-governanceregulationauditai-securitydata-protection
Read post →

AI Governance Regulations in 2026: The Dates That Bind and What Each One Asks You to Show

Eleven binding AI instruments carry 2026 or 2027 dates across the EU, the US states, and financial and healthcare regulators. They differ in scope and penalty, and they converge on three demands: know which AI systems you run, control who may use them and how, and produce records showing both held. This lists the instruments with their operative dates and sorts what each one actually asks you to produce.

ai-governanceeu-ai-actcomplianceregulationauditai-security
Read post →

LLM Audit Logging Best Practices: Building Records That Survive a Regulator

A compliant LLM audit log has to reconstruct which model decision touched which record, who initiated it, what was in the prompt, and what policy governed it. Application-written logs fail that test because the system under audit controls its own evidence. This piece lays out the practices that produce records an auditor can actually use: identity binding, per-decision granularity, tamper evidence, and independence from the calling app.

ai-auditllm-loggingcomplianceai-governanceaudit-trail
Read post →

NIS2 and AI Logging: Where the Directive Meets Your Model Traffic

NIS2 requires essential and important entities to run risk-management measures, including access control and logging, and to be able to demonstrate them to a competent authority. AI added a new access surface that most NIS2 programs have not yet mapped: employees and applications sending data to model APIs. This piece covers how the directive applies to AI traffic and the logging that keeps model calls inside your NIS2 evidence.

nis2complianceai-auditaccess-controleu-regulation
Read post →

SOC 2 and AI: Producing Gateway Evidence for the Trust Services Criteria

A SOC 2 audit tests whether your controls operate, and it wants evidence. AI added a category of access to sensitive data that most control narratives do not describe: model calls under a shared key. This piece maps AI gateway records onto the relevant Trust Services Criteria, so logical access and monitoring controls extend to model traffic and produce the artifacts an auditor samples.

soc-2complianceai-auditaccess-controlevidence
Read post →

AI Accountability Frameworks: What NIST, the EU AI Act, and ISO 42001 Require You to Prove

The NIST AI RMF GOVERN function, EU AI Act Articles 12 and 26, ISO/IEC 42001, and OMB agency guidance all reduce accountability to one operational test: who authorized which AI action, and can you produce the record that proves it. This is a comparison of what each framework demands, and where a policy gateway supplies the evidence layer without standing in for the governance program itself.

ai-governancenist-ai-rmfeu-ai-actiso-42001accountabilitycomplianceaudit
Read post →