← All posts

Compliance & Regulation

402 posts on compliance & regulation.

EU AI Act Fines vs GDPR Fines: How the Two Penalty Regimes Compare

The EU AI Act and GDPR operate parallel penalty regimes. GDPR caps the highest tier at 20 million EUR or 4% of global annual turnover. The AI Act caps its highest tier at 35 million EUR or 7% for prohibited AI practices, with 15 million EUR or 3% for high-risk non-compliance and 7.5 million EUR or 1% for misleading information. The two regimes can apply concurrently. This piece walks through the tiers, the trigger conditions, the enforcement bodies, and where the obligations actually overlap.

eu-ai-actgdprcompliancepenaltiesregulationfines
Read post →

EU AI Act Deployer vs Provider: Who Owns Which Obligation in a High-Risk Deployment

The EU AI Act splits obligations between the provider that places an AI system on the market and the deployer that puts it into use. The split matters because deployers regularly assume they only have to consume the provider''s documentation, while providers regularly assume the deployer carries the runtime-evidence burden. Both assumptions leave gaps the regulator will surface. This article walks through the provider obligations under Articles 16, 17, and 43, the deployer obligations under Article 26, the shared traceability obligation under Article 12, and the operational division most enterprise deployments need to land before the August 2, 2026 enforcement date for high-risk systems.

eu-ai-actcompliancedeployer-obligationsprovider-obligationshigh-risk-aiarticle-26
Read post →

EU AI Act Deployer Checklist: 22 Items Every Enterprise Deployer Needs Before August 2, 2026

August 2, 2026 is the enforcement date for the high-risk system obligations under Chapter III, Section 2 of the EU AI Act. Most enterprise compliance teams have a checklist for the provider-side obligations. Fewer have a structured checklist for the deployer side, where the runtime-evidence obligation lands. This article walks through 22 specific items a deployer of a high-risk AI system needs to have in place before August 2, organized into pre-deployment artifacts, runtime-evidence infrastructure, human oversight workflow, notification mechanisms, and ongoing operational requirements. Each item references the specific article of the act it satisfies.

eu-ai-actdeployer-obligationscompliance-checklistarticle-26enforcementaugust-2026
Read post →

EU AI Act Article 72: Post-Market Monitoring as a Runtime Architecture Requirement

Article 72 of the EU AI Act requires providers of high-risk AI systems to set up and document a post-market monitoring system that actively and systematically collects data on the performance of the AI throughout its lifetime. The monitoring has to feed back into the risk management process under Article 9 and into the technical documentation under Article 11. The architectural requirement is for a runtime evidence pipeline, not for periodic reporting. Most providers run product analytics and call it post-market monitoring, and the regulator will not accept that under inspection.

eu-ai-actai-governancecompliancemonitoringauditregulation
Read post →

EU AI Act Article 50: Transparency Obligations for AI Systems Interacting with People

Article 50 of the EU AI Act applies to AI systems that interact directly with people, generate synthetic content, or perform emotion recognition or biometric categorization. The obligation is to inform the affected person that they are interacting with an AI system or that the content they are seeing is AI-generated. The disclosure has to be clear, in time, and recorded as evidence. The architectural requirement runs to the AI request boundary and to the audit trail. Most production deployments handle disclosure as a UX choice and never wire it into an evidence layer.

eu-ai-actai-governancecompliancetransparencyai-securityregulation
Read post →

California SB 942 AI Controls Mapping: Obligations to What a Proxy Can and Cannot Enforce

The California AI Transparency Act (SB 942) takes effect 2 August 2026 after AB 853 delayed it. Its obligations split cleanly into two groups: content-provenance duties that live at the model and generation layer, and deployer-side evidence duties that live in the traffic. This maps each SB 942 obligation to the control that satisfies it, and marks honestly which ones an HTTP enforcement point can produce evidence for and which belong to the covered provider. Precision on that boundary is the point.

complianceai-governanceregulationpolicy-enforcementai-security
Read post →

California SB 942 AI Compliance Checklist: Ten Items Split by Who Actually Owns Each One

A working checklist for the California AI Transparency Act (SB 942), operative 2 August 2026 after AB 853 delayed it. The list is split deliberately: the provenance and detection items a covered provider owns at the generation layer, and the evidence and verification items a deployer or licensee owns in the traffic. Each item names the action, who owns it, and the evidence to produce, so nobody assumes the vendor covered their side.

complianceai-governanceregulationauditai-security
Read post →

California SB 942 AI Audit Evidence: What a Deployer of Covered Generative Systems Has to Show

The California AI Transparency Act (SB 942) takes effect 2 August 2026 after AB 853 delayed it from January, and it puts content-provenance obligations on covered providers of generative image, video, and audio systems with more than one million monthly users. Watermark generation sits at the model layer, outside an HTTP proxy. The evidence an enterprise deploying or licensing those systems has to produce sits in the traffic. This walks the audit artifacts that are actually visible at the request boundary and names what is not.

complianceai-governanceregulationauditai-security
Read post →

AI Governance Audit Framework: What Auditors Actually Test

An AI governance audit framework tests three layers: policy artifacts, control operation, and per-request evidence. The auditor reads the policy, samples requests, and traces each sampled request through the control to the evidence record. Programs that pass tend to share six properties. Programs that fail typically fail at the evidence layer because the audit record does not exist or is under the same control as the application generating the request. This piece walks through the framework, the six properties, and the architecture the framework depends on.

ai-governanceauditcomplianceeu-ai-actsoc-2iso-42001
Read post →

What to Log for AI Compliance: The Eight Fields Every Per-Decision Record Needs

EU AI Act Article 19, Fannie Mae LL-2026-04, HIPAA, and SOC 2 with AI all converge on a per-decision record. The vocabulary differs across regimes. The fields do not. This piece walks through the eight fields every per-decision record needs to satisfy the converged requirement: identity of the natural person, identity of the agent, role and scopes, data classification, policy version, model and route, decision outcome, and a tamper-evident timestamp.

ai-audit-logscomplianceeu-ai-actauditregulation
Read post →

State of AI Compliance Q2 2026: The Regulations That Took Effect, the Enforcement Actions That Landed, and the Evidence Gaps Auditors Cited

Q2 2026 closed with the EU AI Act high-risk system requirements 60 days from effect, the Fannie Mae and Freddie Mac AI governance frameworks already in force, and the first major enforcement actions under the EU AI Act risk-management obligations on the docket. This quarterly mini-report walks through the regulations that took effect or shifted in Q2 2026, the enforcement and litigation actions that landed, the recurring evidence gaps auditors cited, and the architectural patterns enterprises adopted to close them.

ai-complianceeu-ai-actfannie-maehipaaquarterly-reportai-governance
Read post →

Fundamental Rights Impact Assessment (FRIA): The Article 27 Document Most Deployers Are Missing

Article 27 of the EU AI Act requires public bodies and private deployers of certain high-risk AI systems to perform a Fundamental Rights Impact Assessment before first use. The FRIA is a documented process covering intended purpose, persons affected, specific risks of harm, and human-oversight arrangements. It is distinct from a GDPR DPIA. This piece walks through what the FRIA includes, who has to perform one, the August 2026 trigger, and how per-decision records at the AI request boundary feed the FRIA evidence base.

eu-ai-actfriacompliancefundamental-rightsauditregulation
Read post →