← All posts

Compliance & Regulation

402 posts on compliance & regulation.

AI Governance Policy: What a Policy Has to Specify to Be Enforceable

Most AI governance policies are written for the auditor but cannot be evaluated at the request layer. A policy that lacks classification rules, identity definitions, and enforcement decision points is prose, not control. Article walks through what the policy has to specify to be enforceable.

ai-governanceai-compliancepolicy-enforcementeu-ai-actcomplianceaudit
Read post →

AI Model Governance: Controls That Operate on the Request Path

AI model governance fails when it sits at the model registry layer alone. Model cards and versioning catalog the asset. Per-request enforcement governs how the model is actually used. Article walks through the runtime layer most model governance programs leave out.

ai-governanceai-complianceauditeu-ai-actarchitecturecompliance
Read post →

AI Data Governance: Classifying What Enters and Leaves the Prompt

AI data governance fails when the classification engine runs on documents and not on prompts. The data lake is sorted, the AI request path is not. Article walks through the prompt-level classification, lineage, and disclosure architecture that satisfies the regulators asking new questions about model inputs.

ai-governanceai-compliancecomplianceeu-ai-actshadow-aiai-security
Read post →

AI Governance Software: What to Look For Beyond the Policy Builder

AI governance software splits into policy-building, inventory, and runtime enforcement. Most products in the category cover policy and inventory and leave runtime evidence to whatever the engineering team builds. Article walks through the architectural layers and what to ask vendors before signing.

ai-governanceai-complianceai-securitycomplianceeu-ai-actpolicy-enforcement
Read post →

AI Governance Training: What to Teach Which Role Inside the Enterprise

AI governance training fails when it gets delivered as a single all-hands course. Each role inside the enterprise needs different content. Article walks through the role-specific training tracks the regulators and auditors expect, and where the curriculum meets the runtime evidence requirement.

ai-governanceai-compliancecomplianceeu-ai-actauditshadow-ai
Read post →

AI Compliance Certification: What Customers Now Ask For in Procurement

AI compliance certification has shifted from a nice-to-have to a procurement gate. Customers ask vendors for ISO 42001 or NIST AI RMF alignment, SOC 2 with AI extensions, and per-decision audit evidence. Article walks through what to prepare, in what order, and where each certification meets the runtime evidence requirement.

ai-complianceai-governancecomplianceiso-42001auditregulation
Read post →

AI Ethics and Governance: Where Principles Meet Per-Decision Records

AI ethics committees set principles. AI governance translates those principles into per-decision enforcement and audit records. Article walks through the seam between the two functions and what each one has to produce so a regulator can trace a principle to the decisions made under it.

ai-governanceai-complianceauditcomplianceeu-ai-actregulation
Read post →

GDPR and AI: Where Article 5, Article 22, and Article 32 Reach Production AI Deployments

GDPR applies to AI deployments wherever the AI system processes personal data of EU residents. The applicable articles overlap with the EU AI Act but predate it and reach a broader surface. Article 5 imposes the lawfulness, purpose limitation, and data minimization principles. Article 22 limits automated individual decision-making. Article 32 imposes the security of processing obligation that the audit log is evidence against. This piece walks through the GDPR articles that reach production AI deployments, the specific obligations each creates, where most AI implementations fail the test, and the inspection-layer architecture that produces the evidence the data protection authority will accept.

gdpreu-ai-actai-compliancedata-protectionaudit-logsinline-enforcement
Read post →

GDPR Article 22 and AI: What Automated Decision-Making Requires of Production Deployments

GDPR Article 22 limits decisions based solely on automated processing that produce legal or similarly significant effects on the data subject. AI deployments that produce loan approvals, credit decisions, hiring decisions, fraud-detection outcomes, or insurance underwriting fall inside the scope. The exemption pathways carry their own obligations: explicit consent, contract necessity, or Union or member state authorization. The Article 22(3) right to obtain human intervention and the transparency obligation require records that demonstrate the meaningful intervention happened and that the data subject received meaningful information. This piece walks through the article, the exemption pathways, the meaningful-intervention test, and the inspection-layer architecture that produces the evidence the supervisor will accept.

gdprarticle-22automated-decisionsai-complianceaudit-logsdata-protection
Read post →

PCI DSS and AI: How v4.0 Reaches Production AI Deployments Touching Cardholder Data

PCI DSS v4.0 took full effect on March 31, 2025. The standard reaches AI deployments wherever cardholder data passes through an AI prompt, a tool result, or a retrieval corpus the AI system queries. The applicable requirements include the data flow documentation under Requirement 1, the cardholder data discovery and scope reduction under Requirement 3, the access control restrictions under Requirement 7, the logging obligations under Requirement 10, and the security testing obligations under Requirement 11. This piece walks through the requirements that reach AI deployments, where most implementations fail the QSA review, and the inspection-layer architecture that produces the audit evidence and the scope reduction the assessor will accept.

pci-dsscardholder-dataai-complianceaudit-logsinline-enforcementpayments
Read post →

EU AI Act for Credit Scoring: Annex III Classification and Article 12 Logging

Annex III, point 5(b) of the EU AI Act classifies AI used to evaluate the creditworthiness of natural persons or establish their credit score as high-risk. The classification can trigger Article 12 logging, Article 13 transparency, Article 14 human oversight, and Article 26 deployer obligations. Regulation (EU) 2026/1744 moved the Annex III application date to 2 December 2027. This piece explains the classification, the evidence a credit-scoring deployment needs, and the limits of an HTTP AI gateway.

eu-ai-actcredit-scoringfintechhigh-risk-aicompliancearticle-12
Read post →

EU AI Act Implementation Timeline: What Triggers When Between February 2025 and August 2028

The EU AI Act entered into force August 1, 2024, but its obligations phase in across multiple dates between February 2025 and August 2028. The prohibited practices under Article 5 became enforceable on February 2, 2025. The general-purpose AI provider obligations under Articles 53 and 55 became enforceable August 2, 2025. The Act itself applies from August 2, 2026, including the Article 50 transparency duties. Regulation (EU) 2026/1744 then deferred the Chapter III high-risk obligations to December 2, 2027 for Annex III systems and August 2, 2028 for Annex I systems embedded in regulated products. This article walks through each phase, the operational consequences for providers and deployers at each date, and the evidence each phase expects to find when a market surveillance authority inspects.

eu-ai-actcompliancetimelineenforcementgpaihigh-risk-ai
Read post →