← All posts

Compliance & Regulation

305 posts on compliance & regulation.

EU AI Act Deployer vs Provider: Who Owns Which Obligation in a High-Risk Deployment

The EU AI Act splits obligations between the provider that places an AI system on the market and the deployer that puts it into use. The split matters because deployers regularly assume they only have to consume the provider''s documentation, while providers regularly assume the deployer carries the runtime-evidence burden. Both assumptions leave gaps the regulator will surface. This article walks through the provider obligations under Articles 16, 17, and 43, the deployer obligations under Article 26, the shared traceability obligation under Article 12, and the operational division most enterprise deployments need to land before the August 2, 2026 enforcement date for high-risk systems.

eu-ai-actcompliancedeployer-obligationsprovider-obligationshigh-risk-aiarticle-26
Read post →

EU AI Act Deployer Checklist: 22 Items Every Enterprise Deployer Needs Before August 2, 2026

August 2, 2026 is the enforcement date for the high-risk system obligations under Chapter III, Section 2 of the EU AI Act. Most enterprise compliance teams have a checklist for the provider-side obligations. Fewer have a structured checklist for the deployer side, where the runtime-evidence obligation lands. This article walks through 22 specific items a deployer of a high-risk AI system needs to have in place before August 2, organized into pre-deployment artifacts, runtime-evidence infrastructure, human oversight workflow, notification mechanisms, and ongoing operational requirements. Each item references the specific article of the act it satisfies.

eu-ai-actdeployer-obligationscompliance-checklistarticle-26enforcementaugust-2026
Read post →

EU AI Act Implementation Timeline: What Triggers When Between February 2025 and August 2027

The EU AI Act entered into force August 1, 2024, but its obligations phase in across multiple dates between February 2025 and August 2027. The prohibited practices under Article 5 became enforceable on February 2, 2025. The general-purpose AI provider obligations under Articles 53 and 55 became enforceable August 2, 2025. The high-risk system obligations under Chapter III, Section 2 become enforceable August 2, 2026. The remaining obligations for high-risk systems already on the market follow on August 2, 2027. This article walks through each phase, the operational consequences for providers and deployers at each date, and the evidence each phase expects to find when a market surveillance authority inspects.

eu-ai-actcompliancetimelineenforcementgpaihigh-risk-ai
Read post →

Enterprise AI Governance: What the Operational Layer Actually Has to Produce

Enterprise AI governance gets framed as a policy program. The policies are necessary, but they sit on top of an operational layer that produces evidence, enforces controls, and tracks decisions in real time. This article walks through the four artifacts a real enterprise AI governance program needs at the operational layer: the AI system inventory, the per-decision audit record, the policy enforcement record, and the incident reconstruction artifact. Each is mapped to specific regulatory regimes and to the questions a board will ask.

ai-governanceenterprisecomplianceauditregulationai-security
Read post →

AI Bill of Materials (AIBOM): The Inventory Layer Compliance Teams Keep Skipping

Search interest in "AIBOM" and "AI bill of materials" is climbing fast, but the SERP is owned by vendors selling tooling rather than explainer content. This article defines AIBOM in concrete terms, compares it to the Software Bill of Materials (SBOM), maps the artifact to NIST AI RMF and EU AI Act Article 11 documentation requirements, and walks through what an AIBOM actually contains: model card references, training data lineage, inference dependencies, and gateway policy version. The per-decision audit log of LLM traffic is the inference-layer AIBOM artifact most programs are missing.

ai-governancecomplianceai-complianceauditeu-ai-actnist-ai-rmf
Read post →

GOVERN, MAP, MEASURE, MANAGE: The NIST AI RMF Functions in Plain English with Concrete Artifacts

NIST AI RMF organizes around four functions: GOVERN, MAP, MEASURE, MANAGE. Most teams encounter them as four-letter acronyms in vendor pitches and lose the thread. This article walks through each function in plain English, the concrete artifact a real organization produces under each, and where the four interlock with EU AI Act, ISO 42001, and federal procurement reviews. The artifact-first framing matters because GOVERN without artifacts is policy theater and MEASURE without artifacts is an audit gap.

nistnist-ai-rmfai-governancecomplianceauditai-compliance
Read post →

AI vendor liability: you own it, the vendor will not

Microsoft, SAP, Oracle, Salesforce, ServiceNow, and Workday all sell AI agents under enterprise contracts. When The Register asked who is liable for the decisions those agents make, Microsoft and SAP declined to comment and the other four did not respond. The contract language already places the risk on the deployer. This piece walks through what the regulators say, what the contracts say, and what a deployer must produce on its own to discharge the obligation.

ai-vendor-liabilityeu-ai-actcomplianceauditai-governance
Read post →

Fannie Mae LL-2026-04: the first sector-specific AI governance mandate for lenders

Fannie Mae Lender Letter LL-2026-04 was issued April 8, 2026 and takes effect August 8, 2026. It is the first sector-specific AI governance mandate in US mortgage lending. The Letter requires lenders to inventory AI usage, document data classification, attach identity context, and produce audit records for AI-influenced credit decisions. Freddie Mac Section 1302.8 has been enforced since March 3, 2026. This piece walks through the requirements, what they mean for the lender stack, and the architecture that satisfies them.

fannie-maemortgageai-governancelendingcomplianceaudit
Read post →

DORA and AI: what EU financial entities have to map by January 2027

The EU Digital Operational Resilience Act took effect January 17, 2025 and treats LLM vendors as critical ICT third parties at scale. By January 2027, EU financial entities have to maintain a Register of Information covering ICT third-party arrangements, run exit-strategy testing for material providers, manage concentration risk, and produce per-decision audit trails for AI-influenced decisions. This piece walks through what DORA actually requires from an AI program and the architecture that satisfies it.

dorafinancial-servicesai-governanceeu-regulationauditbanking
Read post →

HIPAA-compliant LLMs: what the deployer has to produce when OCR shows up

HIPAA does not approve LLMs. HIPAA places obligations on covered entities and business associates around how PHI gets used, accessed, and audited. When OCR opens a complaint review of a clinical AI deployment, the questions are specific: who accessed PHI in what context, with what authorization, with what evidence. This piece walks through what HIPAA actually requires from an AI deployment, what a Business Associate Agreement does and does not cover, and the architecture that produces the audit artifact OCR will ask for.

hipaahealthcarephicomplianceauditclinical-ai
Read post →

EU AI Act Compliance: What the Regulation Requires from Enterprise AI Architecture

The EU AI Act enters force in stages from February 2025 through August 2027. The August 2, 2026 deadline brings high-risk system obligations into effect for most enterprise AI deployments in the EU market. Penalties under Article 99 reach €35 million or 7% of global annual turnover. This pillar walks through what the Act actually mandates, where most architectures fall short, and the infrastructure pattern that satisfies the obligations at scale.

eu-ai-actcomplianceai-governanceauditregulationhigh-risk-ai
Read post →