← All posts

Compliance & Regulation

402 posts on compliance & regulation.

Colorado AI Act Compliance: What SB 26-189 Requires of Deployers

On May 14, 2026 Colorado's governor signed SB 26-189, which repeals and replaces the original Colorado AI Act (SB 24-205) and takes effect January 1, 2027. The new law narrows the target to automated decision-making technology that materially influences a consequential decision, and shifts obligations toward adverse-outcome explanations, correction and human-review rights, and a three-year record retention duty. This walks through what deployers must produce and where the evidence comes from.

ai-complianceregulationai-governancecomplianceaudit
Read post →

EU AI Act Compliance Requirements: The 2026 Timeline After the Omnibus

The Digital Omnibus moved the EU AI Act's standalone high-risk obligations to December 2, 2027, but the August 2, 2026 date did not empty out. Article 50 transparency duties still apply then, the penalty framework is live, and the high-risk requirements themselves, risk management and lifetime event logging, still exist on a later clock. This lays out what applies when, by role, and the record-keeping obligation that runs underneath most of it.

eu-ai-actai-complianceregulationcomplianceai-governance
Read post →

GDPR AI Compliance Requirements for LLM Deployments

GDPR predates the LLM era, but its obligations attach the moment personal data reaches a prompt. Lawful basis, purpose limitation, data minimization, special-category handling, automated-decision rights, records of processing, and cross-border transfer rules all apply to AI request traffic. This maps each requirement to the control that satisfies it at the AI request boundary, and shows why prompt content is the layer most GDPR programs currently cannot see.

gdprai-complianceregulationcomplianceai-governance
Read post →

Third-Party AI Risk Management: The Embedded-Model Problem

The hardest third-party AI risk to manage is the AI you did not know a vendor was running. A SaaS tool summarizes your tickets with an LLM, a quality vendor scores your files with a model, and your data leaves for an endpoint you never approved. This walks the third-party AI risk lifecycle, from discovery through offboarding, centered on embedded and subprocessor AI, model-provider concentration, and the due-care obligation a SOC 2 report does not discharge.

ai-governanceai-compliancecomplianceregulationaudit
Read post →

Responsible AI Governance: From Principles to Controls

Responsible AI is usually a list of principles: fairness, accountability, transparency, human oversight. Those principles become governance only when a deterministic policy decision point enforces them and a per-decision record proves it. This walks through how to operationalize responsible AI.

ai-governanceai-compliancecomplianceregulationnist-ai-rmfiso-42001
Read post →

ISO/IEC 23894: What the AI Risk Management Standard Asks You to Produce

ISO/IEC 23894:2023 adapts the ISO 31000 risk management process to AI systems. It is guidance rather than a certifiable standard, which changes how it gets used: teams reach for it to structure risk identification and to feed the risk clauses of ISO/IEC 42001, which is certifiable. This walks the standard structure, the AI-specific risk sources it names, how it relates to 42001 and the NIST AI RMF, and which of its monitoring and record requirements a runtime control produces evidence for.

iso-42001ai-governancecompliancerisk-managementauditregulation
Read post →

AI Governance Standards: Which One Is Certifiable, Which Is Guidance, and What Each Expects in Production

Six documents get called AI governance standards: ISO/IEC 42001, ISO/IEC 23894, the NIST AI RMF, ISO/IEC 27001 with AI extensions, the EU AI Act harmonized standards work, and OWASP AISVS. Only one of them is certifiable, two are law-adjacent, and they differ sharply in how much production evidence they expect. This sorts them by what they are, how they overlap, and which clauses require runtime records rather than documents.

ai-governanceiso-42001nist-ai-rmfcomplianceeu-ai-actaudit
Read post →

UK GDPR and AI: The Six Obligations That Bite When a Prompt Leaves Your Network

The UK has no AI Act. AI use is governed under the UK GDPR and the Data Protection Act 2018, enforced by the ICO, with sector regulators layering their own expectations on top. Six obligations do the work: lawful basis, purpose limitation, data minimisation in the prompt, Article 22 automated decisions, international transfers when a prompt crosses a border, and Article 30 records. This walks each and marks where the evidence has to come from.

complianceai-governanceregulationauditai-securitydata-protection
Read post →

LLM Audit Logging Best Practices: Building Records That Survive a Regulator

A compliant LLM audit log has to reconstruct which model decision touched which record, who initiated it, what was in the prompt, and what policy governed it. Application-written logs fail that test because the system under audit controls its own evidence. This piece lays out the practices that produce records an auditor can actually use: identity binding, per-decision granularity, tamper evidence, and independence from the calling app.

ai-auditllm-loggingcomplianceai-governanceaudit-trail
Read post →

NIS2 and AI Logging: Where the Directive Meets Your Model Traffic

NIS2 requires essential and important entities to run risk-management measures, including access control and logging, and to be able to demonstrate them to a competent authority. AI added a new access surface that most NIS2 programs have not yet mapped: employees and applications sending data to model APIs. This piece covers how the directive applies to AI traffic and the logging that keeps model calls inside your NIS2 evidence.

nis2complianceai-auditaccess-controleu-regulation
Read post →

SOC 2 and AI: Producing Gateway Evidence for the Trust Services Criteria

A SOC 2 audit tests whether your controls operate, and it wants evidence. AI added a category of access to sensitive data that most control narratives do not describe: model calls under a shared key. This piece maps AI gateway records onto the relevant Trust Services Criteria, so logical access and monitoring controls extend to model traffic and produce the artifacts an auditor samples.

soc-2complianceai-auditaccess-controlevidence
Read post →

Claude Text Watermarks Leave a Deployer Evidence Gap

Anthropic says Claude models launched in the EU on or after August 2, 2026 carry machine-readable marks. That provider capability is useful, but a deployer’s evidence needs to show which identity received which model output under which disclosure policy at a specific time.

eu-ai-actai-complianceregulationauditai-governance
Read post →