← All posts

Compliance & Regulation

402 posts on compliance & regulation.

FedRAMP AI Risk Assessment: Test the LLM Route Inside the Boundary

A FedRAMP AI risk assessment should treat the LLM workflow as part of a defined cloud-service boundary and test threats, vulnerabilities, likelihood, impact and response against real model routes. NIST SP 800-53 RA-3 supplies the core risk-assessment structure, while current FedRAMP controls and ongoing certification rules keep the result attached to authorization evidence and production change.

ai-complianceai-governancenistauditai-securityarchitecture
Read post →

FedRAMP AI Incident Reporting Starts with the Model Request Record

FedRAMP AI incident reporting should connect the affected federal customer data, model route, request identity and policy decision to the current FedRAMP Incident Evaluation and Communication process. The 2026 rules use FedRAMP Reportable Incident criteria, Potential Agency Impact ratings and class-specific reporting timeframes. This guide shows how to build the incident record and preserve the HTTP AI evidence behind each report.

ai-complianceai-governanceregulationauditai-securitynist
Read post →

Glean Compliance: Join Connector, Identity, AI, and Audit Evidence

Glean compliance requires a joined evidence package across SSO, connector credentials, source permissions, query processing, AI use cases, administration changes, and retention. Glean documents a shared-responsibility model, tenant-specific query endpoints, and separate administrative and customer-event logs. This guide turns those provider facts into a customer control file while keeping native Glean activity separate from enterprise-routed HTTP model traffic.

ai-complianceai-governancecomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

FedRAMP LLM Requirements Follow the Authorized Cloud Service Boundary

FedRAMP LLM requirements come from the authorized cloud service boundary, applicable NIST SP 800-53 controls, agency authorization and current ongoing-certification rules. FedRAMP creates no separate model checklist. Teams should document the model route, propagate identity, control data flow, generate decision records, manage provider changes and prepare incident evidence for every in-scope LLM workflow.

ai-complianceai-governancenistllmauditarchitecture
Read post →

EU Data Governance Act LLM Requirements Follow the Data-Sharing Role

EU Data Governance Act LLM requirements arise when a model workflow participates in protected public-sector data re-use, data intermediation or recognised data altruism. The regulation creates no separate LLM category. Teams should translate the applicable role, purpose, holder rights, security, activity logging and international-access safeguards into controls on each model request.

ai-complianceai-governanceregulationllmauditpolicy-enforcement
Read post →

EU Data Governance Act AI Risk Assessment: Scope the Data Route

An EU Data Governance Act AI risk assessment should start with the organization's statutory role, the data holder, the permitted purpose and the route used for each model request. The DGA supplies role-specific duties for protected public-sector data re-use, data intermediation and data altruism rather than a generic AI assessment form. This guide turns those duties into testable AI traffic scenarios and evidence requirements.

ai-complianceai-governanceregulationauditai-securitypolicy-enforcement
Read post →

AI Governance Deadlines 2026: What Is Live Now

AI governance deadlines in 2026: Article 50 is live, mortgage rules apply, and banks face the ECB October filing. This guide identifies each operative date, the scope test behind it, and the records an organization needs when a regulator or supervisor asks for proof.

ai-governanceeu-ai-actcomplianceregulationauditai-security
Read post →

NIST AI RMF: GOVERN, MAP, MEASURE, MANAGE

NIST AI RMF GOVERN, MAP, MEASURE, MANAGE explained through four artifacts an AI program needs: a charter, inventory, evidence record, and action log. See what each function asks a team to own, how the records connect, and where they support regulatory or audit review.

nistnist-ai-rmfai-governancecomplianceauditai-compliance
Read post →

EU Data Governance Act AI Incident Reporting: The Duties Are Role-Specific

EU Data Governance Act AI incident reporting is narrower than a general cyber-incident regime. Regulation (EU) 2022/868 requires data intermediation services providers and recognised data altruism organisations to inform data holders without delay after unauthorised transfer, access or use of shared non-personal data. This guide scopes the affected role, builds the incident record and separates DGA notifications from GDPR, NIS2 and contractual duties.

ai-complianceai-governanceregulationauditai-securitypolicy-enforcement
Read post →

EU Data Act LLM Requirements for Hosted Inference and AI Platforms

EU Data Act LLM requirements arise when hosted inference, vector storage, fine-tuning or related AI platforms qualify as data processing services. Chapter VI of Regulation (EU) 2023/2854 addresses switching, contract terms, charges and technical portability. Article 32 addresses conflicting third-country governmental access to non-personal data held in the Union. This guide separates those duties from model-safety rules and turns them into provider and customer engineering requirements.

ai-complianceai-governanceeu-data-actregulationllmarchitecture
Read post →

EU Data Act AI Risk Assessment: Test Switching, Export and Transfer Exposure

An EU Data Act AI risk assessment should examine the data processing services around an AI deployment, especially switching, export, contract, interoperability and international access exposure. Regulation (EU) 2023/2854 creates no standalone AI risk-assessment form. This method turns its applicable duties into testable scenarios, assigns each risk to a legal or technical owner, and identifies the evidence needed before a provider switch or transfer question becomes urgent.

ai-complianceai-governanceeu-data-actregulationauditarchitecture
Read post →

EU CRA LLM Requirements: What Applies to Products That Call Models

The EU Cyber Resilience Act regulates products with digital elements rather than LLMs as a technology category. An AI-enabled software product can bring model calls into its cybersecurity design, documentation, vulnerability handling, and reporting work. This article maps the manufacturer baseline for access, confidentiality, integrity, minimisation, monitoring, updates, and evidence, while separating product obligations from standalone cloud services and model APIs.

complianceregulationai-governanceai-securityllm
Read post →