← All posts

Compliance & Regulation

305 posts on compliance & regulation.

EU AI Act News Today: Live Tracker for Enforcement, Guidelines, and Member-State Implementation

Live tracker for EU AI Act enforcement actions, Commission guidelines, AI Office decisions, member-state designations, Code of Practice updates, and major court rulings. Updated as developments land. Current entries through June 2026 cover the GPAI guidelines, the Article 5 prohibited-practices enforcement, and the August 2 high-risk system deadline countdown.

eu-ai-actregulationcompliancenewstrackerai-governance
Read post →

AI Compliance Jobs: What the Roles Actually Do and the Evidence Auditors Expect

AI compliance roles emerged in 2024 and turned into named job families in 2025. The four common roles are AI Compliance Officer, AI Risk Manager, AI Audit Lead, and AI Governance Engineer. Each operates against a different evidence surface: regulatory mapping, risk register entries, audit trail review, and control implementation. Hiring against the wrong evidence surface is the most expensive mistake compliance leaders make.

ai-governancecompliancecareersauditriskeu-ai-act
Read post →

The Centre for the Governance of AI: What GovAI Research Tells Enterprise CISOs and Where the Gap Sits

The Centre for the Governance of AI (GovAI) is the Oxford-affiliated research organization that publishes some of the most-cited work on AI policy, model evaluations, frontier model governance, and international AI agreements. Enterprise CISOs reading the research will recognize the intellectual scaffolding under EU AI Act and NIST AI RMF text. The gap between research framework and enterprise control sits at the request boundary.

ai-governancegovairesearcheu-ai-actnist-ai-rmfpolicy
Read post →

AI Governance Policy: The Operational Document That Survives a Regulatory Inquiry

Most AI governance policies fail their first regulatory inquiry because they document intent without describing the mechanism that enforces it. The structure that survives names the AI systems in scope, ties each one to a risk tier, attaches identity-bound enforcement at the request layer, and produces a per-decision audit record. This walkthrough covers the seven sections a policy needs to be operational rather than aspirational, the wording auditors expect, and the evidence each section has to point to.

ai-governancepolicycomplianceeu-ai-actauditrisk-management
Read post →

AI Data Residency Controls: Enforcing the Region Boundary at the Gateway

AI data residency requirements show up under GDPR, the EU AI Act, sector regulations like DORA and HIPAA, and national rules such as the Reserve Bank of India circulars. The control that survives audit binds the residency rule to the request at the gateway, routes the call to a region-resident model endpoint, and records the region of decision in the per-decision audit log. This walkthrough covers the three residency conditions, the routing patterns that enforce them, and the audit-record fields that survive a regulator request.

data-residencygdpreu-ai-actcomplianceai-governancecross-border
Read post →

AI Data Lineage for Audit: Tracing a Model Decision Back to Its Inputs

AI data lineage for audit traces a model decision back to the inputs that produced it: the prompt content, the retrieval-augmented documents, the policy in force, the identity of the caller, and the version of the model. Most deployments produce lineage that stops at the prompt and never reaches the retrieval source. The lineage that survives a regulatory inquiry has eight elements, lives outside the application, and is signed at the gateway.

data-lineageauditai-governancecomplianceeu-ai-actrag
Read post →

AI Acceptable Use Policy Template: A Working Baseline for Enterprise AI Governance

An AI acceptable use policy that lists banned tools is already outdated by the time the ink dries. A useful policy describes the categories of allowed use, the data classifications each category may touch, the enforcement mechanism that prevents drift, and the audit posture that makes a breach reconstructable. This template covers the policy structure, the per-role permissions, the enforcement plane that turns the policy from advisory into binding, and the audit record that survives the post-incident review.

acceptable-useai-policygovernanceshadow-aicompliance
Read post →

AI DPIA: How the GDPR Article 35 Assessment Changes When the Processing Runs Through an LLM

GDPR Article 35 has required a DPIA for high-risk personal-data processing since 2018. The EU AI Act adds the Fundamental Rights Impact Assessment for high-risk AI deployers. The two documents overlap in the personal-data section, diverge in the AI-system section, and converge again in the audit and remediation sections. A useful AI DPIA reuses the GDPR template, attaches the AI-specific evidence the regulator now expects, and ties to the per-decision audit log the gateway produces. This walkthrough covers the structural overlap, the new evidence items, and the audit fields the assessment commits to.

gdprdpiaeu-ai-actfriacompliance
Read post →

NYC Local Law 144: What the Bias Audit Requires Three Years In, and Where the AI Gateway Fits

New York City Local Law 144 began enforcement on July 5, 2023. Three years in, the law is the first US statute that requires an independent bias audit before an automated employment decision tool reaches an applicant. The enforcement record now exists: a small but growing set of fines, public disclosures, and audit firms whose methodology has been tested in practice. This walkthrough covers what the bias audit requires, where the per-decision audit log fits, and how the NYC rule lines up with the EU AI Act Article 27 FRIA and the Colorado SB 26-189 deployer obligations.

nyc-local-law-144aedthiring-aibias-auditcompliance
Read post →

California AB 2013: What the Training Data Disclosure Means for Your AI Procurement

California AB 2013 took effect January 1, 2026. The law requires developers of generative AI systems made available to Californians to publish high-level documentation about the data used to train each model, including the source categories, the time period of collection, and whether personal information was included. The procurement team now has a public record to read before signing, and the audit team has a citable artifact for vendor due diligence. This walkthrough covers what the disclosure must contain, what it does not contain, and how the per-decision audit log fits.

california-ab-2013ai-transparencytraining-dataprocurementcompliance
Read post →

EU AI Act Annex III: What the High-Risk Use Case List Actually Covers

Annex III of the EU AI Act enumerates the use cases that trigger high-risk classification under Article 6(2). The list covers biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. Any AI system used in one of those eight areas inherits the full obligation set: Article 9 risk management, Article 12 logging, Article 13 transparency, Article 14 human oversight, and Article 26 deployer responsibilities. The August 2, 2026 deadline applies.

eu-ai-actannex-iiihigh-risk-aicomplianceclassificationregulation
Read post →

EU AI Act Article 19: What the Six-Month Log Retention Rule Requires

Article 19 of the EU AI Act tells deployers of high-risk AI systems what to put in the automatically generated logs Article 12 requires, and how long to keep them. The retention floor is six months. The content has to support traceability for risk monitoring and post-market surveillance. The August 2, 2026 deadline applies. Most application logging stacks miss the identity, classification, and policy-state fields the Article 19 reading actually calls for.

eu-ai-actarticle-19complianceaudithigh-risk-airetention
Read post →