← All posts

Compliance & Regulation

305 posts on compliance & regulation.

CSA CCM AI Controls Mapping: 17 Cloud Domains Against One Outbound Model Call

The Cloud Controls Matrix governs cloud consumption through 197 control objectives across 17 domains, and a prompt sent to a hosted model is cloud consumption. This maps the CCM domains that bite when AI traffic leaves your network onto the technical control that enforces each one, the point in the request path where it fires, and the evidence artifact a CSA STAR assessor reads. It also names the four domains whose existing answers stop being true the moment a model endpoint enters scope.

complianceai-governancepolicy-enforcementcloud-securityai-security
Read post →

CSA CCM AI Compliance Checklist: Ten Items Before Your CAIQ Covers AI Traffic

A working checklist for teams whose Cloud Controls Matrix answers predate their first model endpoint. CCM v4 holds 197 control objectives across 17 domains and maps to roughly 40 standards, and the Consensus Assessments Initiative Questionnaire turns those into more than 250 answerable questions. Each item below names the CCM domain, the action to take at the AI request boundary, and the artifact it produces, so the list works as preparation for a STAR self-assessment rather than a reading exercise.

complianceai-governanceauditcloud-securityai-security
Read post →

EU Cyber Resilience Act AI Compliance Checklist: Ten Items Before 11 September 2026

Article 14 reporting duties under Regulation (EU) 2024/2847 started on 11 September 2026, more than a year before the essential requirements apply on 11 December 2027, and they cover products already on the market. This checklist walks ten actions for a product with digital elements that calls a hosted model: the Annex I point each one answers, the work involved at the AI request boundary, and the artifact it produces for a 24-hour early warning, a notified body, or a market surveillance authority.

complianceregulationai-governanceauditai-security
Read post →

EU Cyber Resilience Act AI Audit Evidence: What the 24-Hour Clock Asks You to Produce

Reporting duties under the EU Cyber Resilience Act start on 11 September 2026, ahead of full application on 11 December 2027. From that date a manufacturer has 24 hours to send an early warning to ENISA and its CSIRT coordinator once it has reasonable certainty of an actively exploited vulnerability or a severe incident. This walks the Annex I requirements that an embedded LLM call touches, and the specific artifacts an assessor, a notified body, or a 24-hour report asks you to produce.

complianceregulationai-governanceauditai-security
Read post →

EU Cyber Resilience Act AI Controls Mapping: Annex I Against the Outbound Model Call

Annex I of Regulation (EU) 2024/2847 splits into properties the product must have and processes the manufacturer must run. For a product that calls a hosted model, most of those properties get exercised in a single HTTPS request leaving the product boundary. This maps the Annex I points and the Article 14 reporting duty onto the technical control that enforces each one, the point in the request path where it fires, and the evidence a notified body or a market surveillance authority reads.

complianceregulationpolicy-enforcementai-governanceai-security
Read post →

EU Data Act AI Controls Mapping: Switching, Residency and Trade Secrets at the Request Boundary

Chapter VI of Regulation (EU) 2023/2854 governs switching between data processing services, Article 32 governs third-country governmental access to non-personal data held in the Union, and Articles 4 and 5 carry trade-secret protections into shared data. This maps those obligations onto the technical control that enforces each one for AI traffic, the point in the request path where it fires, and the evidence artifact a customer, a regulator, or an exit clause reads.

complianceregulationpolicy-enforcementai-governanceai-security
Read post →

EU Data Act AI Audit Evidence: Proving Where Your Prompts Went and How They Leave

Regulation (EU) 2023/2854 became applicable on 12 September 2025, and from 12 January 2027 providers of data processing services may impose no switching charges at all. Two chapters land hard on AI traffic: the switching and interoperability rules in Chapter VI, and Article 32 on international governmental access to non-personal data held in the Union. This walks the Data Act obligations an AI deployment touches and the specific artifacts a regulator, a customer, or an exit clause asks you to produce.

complianceregulationai-governanceauditai-security
Read post →

EU Data Governance Act AI Compliance Checklist: Ten Items for Protected Data in Prompts

Regulation (EU) 2022/868 has applied since 24 September 2023 and reaches three groups an AI deployment can belong to: re-users of protected public sector data, data intermediation services providers, and recognised data altruism organisations. This checklist walks ten actions that make the DGA answerable once protected content starts appearing in prompts, naming the article each item serves, the work at the AI request boundary, and the artifact a competent authority reads.

complianceregulationai-governanceauditai-security
Read post →

EU Data Governance Act AI Audit Evidence: When a Prompt Leaves the Secure Processing Environment

Regulation (EU) 2022/868 has applied since 24 September 2023, and it governs three things that AI deployments touch directly: re-use of protected public sector data under Article 5, the conditions data intermediation services operate under in Article 12, and the record-keeping data altruism organisations owe under Article 20. This walks each obligation, the point where an outbound model call breaks it, and the specific artifact a competent authority asks you to produce.

complianceregulationai-governanceauditai-security
Read post →

EU Data Governance Act AI Controls Mapping: Re-use, Intermediation and Altruism at One Request

Regulation (EU) 2022/868 splits across three regimes: re-use of protected public sector data in Chapter II, data intermediation services in Chapter III, and data altruism in Chapter IV. Each one asks different questions and, for AI traffic, each one resolves to the same outbound model call. This maps the DGA articles onto the technical control that enforces each for AI traffic, the point in the request path where it fires, and the evidence a competent authority reads.

complianceregulationpolicy-enforcementai-governanceai-security
Read post →

EU AI Act Enforcement Began with Live Complaint Channels

The European Commission began enforcing new AI Act rules on August 2, 2026 and opened complaint, whistleblower, and downstream-provider channels. A compliance owner now needs evidence tied to a named interaction, user, policy, and date when an authority asks what happened.

eu-ai-actai-complianceregulationauditai-governance
Read post →

FedRAMP AI Audit Evidence Has to Resolve Each Model Call

FedRAMP assessors need evidence that connects an AI event to its user, model endpoint, authorization boundary, policy, and outcome. Standard application telemetry rarely contains that full chain. A per-decision record on the AI request path gives federal teams evidence that maps cleanly to NIST SP 800-53 audit requirements.

ai-complianceauditnistai-securityinline-enforcement
Read post →