← All posts

Compliance & Regulation

305 posts on compliance & regulation.

Texas TRAIGA AI Controls Mapping: Requirement, Owner, Test and Evidence

Texas TRAIGA took effect on 1 January 2026 and combines targeted use prohibitions with complaint-driven Attorney General enforcement. This mapping connects enacted HB 149 requirements to control objectives, accountable owners, implementation points, tests and evidence. It marks HTTP gateway coverage as full, partial or outside scope and keeps legal intent, notices, training data and metrics with their proper owners.

complianceregulationai-complianceai-governancepolicy-enforcementai-security
Read post →

Texas TRAIGA AI Compliance Checklist: 10 Tests for Enacted HB 149

Texas House Bill 149 took effect on 1 January 2026. This ten-item TRAIGA checklist follows the enacted law: scope and role, targeted disclosure, prohibited uses, complaint readiness, the Attorney General’s eight information categories, testing, safeguards and the 60-day cure file. Each item names an owner, evidence artifact and objective completion test without inventing a universal per-decision logging duty.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

TISAX AI Audit Evidence: Build the Sample Around Actual Model Traffic

TISAX AI audit evidence should connect the VDA ISA 6.0.3 requirements for approved external services, risk management, access control, event logging and supplier assurance to the AI requests that actually crossed the assessment scope. This guide builds a sample an assessor can reconstruct while keeping contracts, workforce controls and cloud configuration with their proper owners.

complianceai-complianceai-governanceauditpolicy-enforcementai-security
Read post →

TISAX AI Controls Mapping: Objective, Owner, Test and Evidence

This TISAX AI controls mapping connects verified VDA ISA 6.0.3 control families to an objective, accountable owner, implementation point, test, evidence artifact and coverage verdict. It treats AI as an information-processing service inside the assessment scope and gives Full, Partial or Outside verdicts for an HTTP policy gateway without turning TISAX into a law or inventing AI-specific control numbers.

complianceai-complianceai-governanceauditpolicy-enforcementai-security
Read post →

TISAX AI Compliance Checklist: 12 Owner-Based Completion Tests

This TISAX AI compliance checklist turns VDA ISA 6.0.3 into twelve owner-based tests for AI services in an assessment scope. It covers scope, information assets, external-service approval, risk, identity, model destinations, event logs, suppliers, incidents, continuity and internal review, with evidence fields and explicit limits for controls outside an HTTP policy gateway.

complianceai-complianceai-governanceauditpolicy-enforcementai-security
Read post →

UAE DPL AI Compliance Checklist: 12 Actions With Evidence Tests

This UAE DPL AI compliance checklist turns the federal privacy framework into twelve implementation actions for deployed AI. Every item names an owner, an objective completion test and the evidence to retain, covering scope, purpose, processing basis, security, destinations, transfers, rights, change control and incident response without assigning legal work to an HTTP gateway.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

UAE DPL AI Audit Evidence: Reconstruct the Request and Its Controls

UAE DPL AI audit evidence should connect an approved purpose and processing basis to the personal data, originating identity, model destination, policy decision, transfer record and rights workflow behind a deployed request. This guide builds a reconstructable evidence package while keeping legal decisions and off-path data stores with their accountable owners.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

UAE DPL AI Controls Mapping: Owner, Test, Evidence and Coverage

This UAE DPL AI controls mapping connects the federal privacy framework to control objectives, accountable owners, implementation points, tests, evidence and honest coverage verdicts. It separates legal and organizational decisions from enforceable controls on authenticated HTTP AI traffic, so every Full, Partial and Outside result has a concrete boundary.

complianceregulationai-complianceai-governancepolicy-enforcementaudit
Read post →

UK DPA AI Audit Evidence: Reconstruct Personal Data in Model Traffic

UK data protection law requires accountable processing records, risk assessment, security measures and support for individual rights when AI handles personal data. This guide connects those legal and organisational records to sampled HTTP model traffic, while keeping legal decisions, data stores, processor governance and offline AI controls with their accountable owners.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

UK DPA AI Controls Mapping: Objective, Owner, Test and Evidence

This UK DPA AI controls mapping connects current UK GDPR duties and the Data Protection Act 2018 framework to control objectives, owners, implementation points, tests and evidence. Coverage verdicts distinguish legal and organisational work from the narrower controls available on authenticated HTTP traffic to model providers.

complianceregulationai-governanceai-compliancepolicy-enforcementaudit
Read post →

UK DPA AI Compliance Checklist: 10 Tests for Deployed Model Traffic

This UK DPA AI compliance checklist turns the current UK GDPR and Data Protection Act 2018 framework into ten tests for deployed AI. Each item names an owner, completion condition and retained artifact, while separating legal and organisational duties from controls that can operate on authenticated HTTP model traffic.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

UK ICO AI Audit Evidence: Build a Reconstructable Review Package

This UK ICO AI guidance audit-evidence guide organises an AI review around traceability, sample selection, retrieval, integrity and change history. It uses the ICO guidance as guidance under review, verifies operative duties against current UK legislation, and separates HTTP model-traffic evidence from legal, organisational and offline controls.

complianceregulationai-governanceforensic-auditauditpolicy-enforcement
Read post →