← All posts

Compliance & Regulation

402 posts on compliance & regulation.

AI vendor risk assessment: the questions a Head of Security should ask any LLM provider in 2026

An AI vendor risk assessment in 2026 lives at the intersection of EU AI Act Annex IV documentation, DORA Article 28 third-party register requirements, SOC 2 vendor management, and ISO 42001 AIMS controls. The 30 questions cover training-data lineage, sub-processor disclosure, retention policy, deployer audit-log access, fine-tuning isolation, prompt logging consent, incident notification SLA, and exit-strategy artifacts.

ai-vendor-riskthird-party-riskdoraeu-ai-actiso-42001soc-2
Read post →

AI Impact Assessment Template: The Fields a Regulator and an Auditor Both Read

An AI impact assessment template that holds up under EU AI Act Article 27, GDPR Article 35 DPIA, Fannie Mae LL-2026-04, and NIST AI RMF inquiries has to cover the same architectural primitives in the same vocabulary the regulators use. This article walks through the fields the template has to include, the questions each field answers, and the runtime evidence the deployer needs in order to keep the assessment current.

ai-complianceai-governanceeu-ai-actcomplianceaudit
Read post →

AI Governance and Risk Management: How the Two Programs Fit Together

AI governance sets the policies, roles, and accountability for AI use. Risk management identifies, measures, and treats the AI-specific risks the governance framework recognizes. The two programs share inputs (data classification, use case inventory, vendor list) and produce different outputs (policies versus risk treatments). Four frameworks draw the line differently: NIST AI RMF splits GOVERN from MAP/MEASURE/MANAGE, ISO 42001 hands the risk process to ISO 23894, the EU AI Act separates Articles 17 and 26 from Article 9, and SR 26-2 (which superseded SR 11-7 on 17 April 2026) separates board oversight from validation while placing generative and agentic AI outside its scope. This piece covers all four, plus the per-request evidence both programs need to demonstrate operation.

ai-governanceai-risk-managementnist-ai-rmfiso-42001complianceaudit
Read post →

AI Acceptable Use Policy Template: A Working Baseline for Enterprise AI Governance

An AI acceptable use policy that lists banned tools is already outdated by the time the ink dries. A useful policy describes the categories of allowed use, the data classifications each category may touch, the enforcement mechanism that prevents drift, and the audit posture that makes a breach reconstructable. This template covers the policy structure, the per-role permissions, the enforcement plane that turns the policy from advisory into binding, and the audit record that survives the post-incident review.

acceptable-useai-policygovernanceshadow-aicompliance
Read post →

ISO 42001 Annex A Controls: The 38 AI Management Controls and Where Each One Lands in the Deployment

ISO 42001 Annex A lists 38 controls across nine areas (A.2 through A.10) that an organization implementing an AI Management System (AIMS) has to consider. Numbering starts at .2 in every area because the .1 position holds the control objective, and A.6 splits into A.6.1 and A.6.2 for a total of nine lifecycle controls. The auditor's Statement of Applicability records which controls the organization has implemented, which it has excluded (with justification), and which are partially implemented with a target date. This piece gives the full 38-control table with the deployment layer for each, the evidence a certification body accepts per area, what ISO/IEC 42006:2025 changed about who may audit you, and why an ISO 42001 certificate grants no presumption of conformity under EU AI Act Article 17.

iso-42001annex-aaimsai-management-systemai-compliancecertification
Read post →

AI Data Protection for Hospitality: What Twenty Years of FTC Assessments Taught the Hotel Industry

The Third Circuit upheld the FTC authority to treat unreasonable data security as an unfair practice in FTC v. Wyndham Worldwide on August 24, 2015, and the December 2015 stipulated order put the hotel group under annual independent assessments for twenty years. Guest data now reaches commercial models through property teams. This article maps that enforcement theory onto the model request.

ai-compliancehospitalityftcdata-protectionauditgovernance
Read post →

AI Data Protection for Nonprofits: Donor Names Are the One Thing the Code Withholds

Treasury rules at 26 CFR 301.6104(d)-1 require a tax-exempt organisation to make its annual return available for public inspection, and carve out the name and address of any contributor from the copy it must disclose. Development teams now paste donor files into chat products to draft appeals. This article maps the disclosure regime onto the authenticated model request.

ai-compliancenonprofitsirsdata-protectionauditgovernance
Read post →

AI Data Protection for Logistics: Sensitive Security Information and the Need-to-Know Test

TSA rules at 49 CFR 1520.9 let a covered person disclose sensitive security information only to other covered persons with a need to know, and require prompt reporting when SSI reaches anyone unauthorized. Operations teams now paste security programme detail into chat products to draft procedures. This article maps the SSI regime onto the authenticated model request.

ai-compliancelogisticstsadata-protectionaudittransportation
Read post →

AI Data Protection for Staffing and HR: The Disposal Rule Meets a Prompt You Cannot Recall

The FTC Disposal Rule at 16 CFR 682.3 obliges anyone holding consumer information for a business purpose to take reasonable measures against unauthorized access in connection with its disposal, including erasure so the data cannot practicably be reconstructed. A recruiter pasting a background check summary into a chat product creates a copy nobody can dispose of. This article maps the duty onto the model request.

ai-compliancestaffingftcfcradata-protectionaudit
Read post →

AI Data Protection for Construction: OSHA Medical Records and the Thirty-Year Horizon

OSHA requires employee medical records to be kept for the duration of employment plus thirty years, and 29 CFR 1904.29 bars the employee name from the OSHA 300 Log for privacy concern cases. Safety teams now paste incident narratives into chat products to draft reports. This article maps the OSHA recordkeeping and confidentiality duties onto the authenticated model request.

ai-complianceconstructionoshadata-protectionauditrecordkeeping
Read post →

AI Data Protection for Manufacturing: The Deemed Export Rule and Third-Party Models

ITAR treats releasing technical data to a foreign person inside the United States as an export, and its encryption carve-out at 22 CFR 120.54 only holds when the means of decryption are withheld from every third party. A model provider decrypts what it processes. This article maps the deemed export rules onto the authenticated model request a manufacturing engineer makes.

ai-compliancemanufacturingitarexport-controlsdata-protectionaudit
Read post →

AI Data Protection for Telecom: CPNI Rules When Call Detail Reaches a Model

FCC rules at 47 CFR 64.2005 restrict how a carrier may use customer proprietary network information, and 47 CFR 64.2011 sets a seven-business-day notification duty to the Secret Service and FBI after a CPNI breach. Care and network teams now paste that same call detail into commercial chat products. This article maps the CPNI regime onto the authenticated model request.

ai-compliancetelecomfcccpniauditdata-protection
Read post →