← All posts

Compliance & Regulation

402 posts on compliance & regulation.

AI Regulatory Compliance: Controls and Evidence That Hold Up

AI regulatory compliance needs evidence that a named person or agent reached an approved model, a policy decided the request, and a review can reconstruct that decision. This guide maps EU AI Act, US state, and sector rules to those runtime controls.

ai-governanceregulatory-complianceeu-ai-actregulationai-security
Read post →

EU AI Act Incident Reporting: Article 73 Serious-Incident Duties

EU AI Act Article 73 requires providers of high-risk AI systems to report serious incidents to the relevant market-surveillance authority. This guide explains the Article 3(49) trigger, the 15-day outer limit, the two-day widespread-infringement timeline, the 10-day death timeline, and the evidence a provider needs to investigate and report.

eu-ai-actcomplianceincident-responsehigh-risk-airegulationarticle-73
Read post →

EU AI Act Providers vs Deployers: Who Owns Article 16 vs Article 26 Obligations

The EU AI Act assigns different obligations to providers and deployers of high-risk AI systems. Article 16 covers provider obligations; Article 26 covers deployer obligations. The split matters because most enterprises operating AI in the EU are deployers, not providers, and the deployer obligations are routinely underestimated. The Digital Omnibus on AI (Regulation (EU) 2026/1744) deferred standalone Annex III high-risk obligations from August 2, 2026 to December 2, 2027, and embedded Annex I systems to August 2, 2028, but the provider-deployer split itself did not change. This article walks the provider-deployer split, the cases that change the assignment, and the architectural artifacts each side needs.

eu-ai-actcomplianceai-governanceregulationhigh-risk-aideployer-obligations
Read post →

EU AI Act Article 13: The Transparency Mandate for High-Risk Systems

Article 13 of the EU AI Act requires providers of high-risk AI systems to design them so deployers can interpret outputs, understand limitations, and exercise human oversight. The mandate takes effect August 2, 2026. Generic model cards fail the test.

eu-ai-actai-governancecompliancetransparencyai-securityregulation
Read post →

EU AI Act Article 26: The Deployer Obligations Most Teams Miss

Article 26 of the EU AI Act puts operational obligations on the deployer of a high-risk AI system. The deployer must monitor operation, suspend use under specific risk conditions, keep automatically generated logs, and inform the provider and authorities. The mandate takes effect August 2, 2026.

eu-ai-actai-governancecompliancedeployer-obligationsauditregulation
Read post →

EU AI Act Annex III: The Eight Categories That Define High-Risk AI

Annex III of the EU AI Act lists the eight categories of AI systems classified as high-risk. Inclusion in Annex III triggers the full obligations of Articles 8 to 27 from August 2, 2026. Most enterprise teams are inside the scope without realizing it.

eu-ai-actai-governancecompliancehigh-riskclassificationregulation
Read post →

EU AI Act High-Risk Classification: The Article 6 Two-Branch Test

Article 6 of the EU AI Act establishes a two-branch test for classifying an AI system as high-risk. Branch one covers safety components of regulated products. Branch two covers the Annex III use cases. The classification triggers the full operational regime from August 2, 2026.

eu-ai-actai-governancecompliancehigh-riskclassificationregulation
Read post →

How to Comply with the EU AI Act: The Six-Workstream Operating Plan

EU AI Act compliance breaks into six operational workstreams: scope classification, technical documentation, conformity assessment, runtime evidence, deployer monitoring, and incident reporting. The mandate takes effect August 2, 2026. Most organizations are running three of the six and missing the rest.

eu-ai-actai-governancecomplianceimplementationauditregulation
Read post →