← All posts

Compliance & Regulation

402 posts on compliance & regulation.

AI Risk Reporting for General Counsel: A Decision-Ready Brief

AI risk reporting for general counsel should connect each deployed AI use to an owner, approved purpose, governing obligation, policy decision, incident record and open legal action. This briefing structure gives legal teams evidence they can test instead of a dashboard of activity counts, while keeping product behavior and public claims tied to operating records.

ai-governanceai-compliancecomplianceauditpolicy-enforcement
Read post →

AI Risk Reporting for ML Engineers Needs Reproducible Evidence

ML engineers need AI risk reporting that binds a production behavior to the exact model, evaluation suite, dataset lineage, release approval, and runtime policy evidence involved. This guide separates model-development evidence from request-layer controls and shows how to build a report that another engineer can reproduce without treating a dashboard score as proof.

ai-governanceai-securitynist-ai-rmfauditdevsecopspolicy-enforcement
Read post →

AI Risk Reporting for the CIO Connects Systems to Decisions

A CIO needs AI risk reporting that joins the application portfolio to model routes, data classes, service owners, control tests and remediation decisions. NIST AI RMF supplies the risk-management functions, and the GAO AI Accountability Framework adds governance, performance and monitoring practices. Request-level records help technology leaders test managed HTTP AI traffic without overstating coverage of local or vendor-native systems.

ai-governanceai-securityai-complianceauditnist-ai-rmfarchitecture
Read post →

Cursor Compliance: Privacy Mode, Data Residency, and SOC 2

Cursor Privacy Mode keeps Customer Data out of training and applies zero-data-retention terms to covered models. This guide shows what to collect for data residency, SOC 2, audit logs, model approvals, and the code paths your team actually permits.

ai-complianceai-governancecomplianceauditllm-securitypolicy-enforcement
Read post →

Utah AI Policy Act Compliance Checklist: 9 Tests for Current Disclosure Rules

Utah SB 226 replaced the original SB 149 consumer-facing provision with Chapter 13-75 in 2025. This nine-test checklist covers legal versioning, supplier and transaction scope, reactive consumer disclosure, high-risk regulated services, safe-harbor presentation, consumer-protection liability, complaint evidence, change control and HTTP operating records. Every item names an owner, evidence artifact and objective completion condition.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

EU AI Act Article 14: 6 Human Oversight Controls

EU AI Act Article 14 lists six human-oversight controls for high-risk AI. See what reviewers must interpret, override, and halt in production, how a stop control must work at the request layer, and which audit evidence connects the reviewer to the decision.

eu-ai-actai-governancecompliancehuman-oversightai-securityregulation
Read post →

Japan APPI AI Controls Mapping for LLM Requests

A Japan APPI AI controls mapping should connect each applicable statutory duty to an owner, an enforcement point, a test, and retained evidence. This mapping covers purpose limitation, special care-required information, security measures, employee and processor supervision, domestic and foreign provision, incident response, and individual rights, with applicability nuances for entrusted LLM providers.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 5338 AI Controls Mapping to Runtime Evidence

ISO/IEC 5338:2023 organizes AI system life cycle work into agreement, organizational project-enabling, technical management, and technical processes. This mapping connects those process families to control objectives, owners, implementations, and evidence, while marking the boundary between model and data lifecycle controls and the HTTP request controls DeepInspect can enforce.

ai-complianceai-governanceauditpolicy-enforcementidentity-and-authorization
Read post →

ISO/IEC 27701 AI Controls Mapping at the HTTP Request Boundary

ISO/IEC 27701:2025 sets requirements for privacy information management by PII controllers and processors. This mapping connects AI inventory, identity, purpose, classification, processor routing, retention, incident response, and control testing to concrete owners and request-level evidence.

ai-complianceai-governancecomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

NIST AI RMF Mapping for AI Gateways: How the Four Functions Land on Request-Layer Controls

The NIST AI Risk Management Framework (AI RMF 1.0, released January 2023) organizes AI risk controls into four functions: Govern, Map, Measure, Manage. The framework is voluntary, but US federal procurement, Fannie Mae LL-2026-04, and the GSA AI Acquisition Resource Guide all reference it directly. This guide walks each of the four functions to the request-layer control on an AI gateway that satisfies it.

nist-ai-rmfcomplianceai-governanceai-gatewayauditcontrols-mapping
Read post →

EU AI Act News Today: Live Tracker for Enforcement, Guidelines, and Member-State Implementation

Live tracker for EU AI Act enforcement actions, Commission guidelines, AI Office decisions, member-state designations, Code of Practice updates, and major court rulings. Updated as developments land. Current entries through June 2026 cover the GPAI guidelines, the Article 5 prohibited-practices enforcement, and the August 2 high-risk system deadline countdown.

eu-ai-actregulationcompliancenewstrackerai-governance
Read post →

AI Vendor Risk Management: The Diligence Questions That Actually Bind Under Audit

AI vendor risk management sits at the intersection of traditional third-party risk and the new AI-specific obligations. The questionnaire that holds up against EU AI Act Article 26, Fannie Mae LL-2026-04, DORA, and sector-specific regimes asks for evidence the vendor can produce on demand. This article walks through the question set, the runtime evidence behind each answer, and the ongoing supervisory obligation that procurement attestations do not discharge.

ai-governanceai-compliancecomplianceeu-ai-actdora
Read post →