← All posts

Compliance & Regulation

402 posts on compliance & regulation.

UK DPA AI Compliance Checklist: 10 Tests for Deployed Model Traffic

This UK DPA AI compliance checklist turns the current UK GDPR and Data Protection Act 2018 framework into ten tests for deployed AI. Each item names an owner, completion condition and retained artifact, while separating legal and organisational duties from controls that can operate on authenticated HTTP model traffic.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

UK ICO AI Audit Evidence: Build a Reconstructable Review Package

This UK ICO AI guidance audit-evidence guide organises an AI review around traceability, sample selection, retrieval, integrity and change history. It uses the ICO guidance as guidance under review, verifies operative duties against current UK legislation, and separates HTTP model-traffic evidence from legal, organisational and offline controls.

complianceregulationai-governanceforensic-auditauditpolicy-enforcement
Read post →

UK ICO AI Controls Mapping: Guidance, Owner, Test and Evidence

The ICO guidance on AI and data protection connects accountability, DPIAs, transparency, lawfulness, fairness, security, minimisation and individual rights. This mapping assigns each objective to an owner, implementation point, test and evidence artifact. It also records the ICO warning that the guidance is under review after the Data (Use and Access) Act and limits gateway coverage to routed HTTP model traffic.

complianceregulationai-complianceai-governancepolicy-enforcementaudit
Read post →

Utah AI Policy Act Controls Mapping: Trigger, Owner, Test and Evidence

Utah SB 226 replaced the original SB 149 consumer-facing AI provision with Chapter 13-75 in 2025. This mapping connects current scope, reactive disclosure, high-risk regulated-service notice, safe harbor, consumer-protection liability and enforcement response to accountable owners, implementation points, tests and evidence. Coverage is graded at the authenticated HTTP model boundary, with presentation and legal classification kept outside it.

complianceregulationai-complianceai-governancepolicy-enforcementaudit
Read post →

Washington My Health My Data AI Compliance Checklist: 10 Production Tests

This Washington My Health My Data AI compliance checklist turns Chapter 19.373 RCW into ten production tests for AI services handling consumer health data. Each item names an owner, retained artifact and completion condition across scope, policy, consent, sharing, rights, processors, security, sale authorization and geofencing.

complianceregulationai-complianceai-governanceauditpolicy-enforcement
Read post →

Washington My Health My Data AI Audit Evidence: Reconstruct Model Disclosures

Washington’s My Health My Data Act covers identifiable health data outside familiar HIPAA assumptions, including some inferences produced with algorithms or machine learning. This guide builds an audit package for scope, privacy notices, consent, sharing, consumer requests, processors and security, then separates statutory proof from HTTP model-traffic evidence.

complianceregulationai-complianceai-governanceauditforensic-audit
Read post →