← All posts

Compliance & Regulation

402 posts on compliance & regulation.

CSA CCM AI Incident Reporting: Build the Timeline Before the Ticket

CSA CCM v4.1 treats incident reporting as an operating chain across Security Incident Management and Logging and Monitoring. Teams need defined event triage, severity levels, escalation paths, tested response plans and a secured incident repository. This guide applies those controls to authenticated HTTP traffic between users or agents and LLM endpoints, with request-level evidence that supports investigation while keeping legal notification and systems outside that traffic path with their proper owners.

ai-complianceai-governancecomplianceauditforensic-auditcloud-security
Read post →

COBIT AI Risk Assessment: Turn Scenarios into Owned Decisions

A COBIT AI risk assessment begins with an enterprise risk profile, then converts a defined AI use case into plausible scenarios, impact and likelihood ratings, and treatment decisions. Each treatment receives an owner, a test, evidence, and a monitoring trigger. This guide maps that workflow to EDM03 and APO12, with DSS05, MEA01, and MEA02 supporting operation and assurance.

ai-governanceai-securitycomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

EU AI Act Article 12 Logging: 6 Record-Keeping Steps

Article 12 logging requires an automatic event record for high-risk AI. Use these six request-layer steps to capture identity, route, data classification, policy, outcome, evidence, and retention, then test the record against the questions a regulator can ask during an audit.

eu-ai-actcomplianceaudit-logsimplementation-guideai-governancearticle-12
Read post →

COBIT AI Incident Reporting: The Operating Chain Behind One Alert

COBIT AI incident reporting is an operating chain, rather than a regulator-facing deadline. This guide applies COBIT 2019 objectives for risk, service requests and incidents, managed security, performance monitoring, and internal control to authenticated HTTP traffic between users or agents and LLM endpoints. It defines the incident record, the evidence handoffs, the closure test, and the limits of an inline gateway.

ai-governanceai-securitycomplianceauditpolicy-enforcement
Read post →

China PIPL LLM Requirements: A Current Enterprise Guide

China's Personal Information Protection Law applies to LLM workflows whenever prompts, retrieved context, outputs, or operating records contain personal information. Enterprises must establish an Article 13 basis, give the required notices, minimize the data, handle sensitive information under stricter rules, and meet automated-decision and cross-border conditions. Provider duties depend on the actual relationship: an entrusted party follows the handler's instructions and assists with compliance, while an independent handler carries its own PIPL obligations.

ai-complianceai-governancecomplianceregulationllmpolicy-enforcement
Read post →

China PIPL AI Risk Assessment: Articles 55 and 56 in Practice

PIPL Article 55 requires a personal information protection impact assessment before sensitive-personal-information processing, automated decision-making, entrusted processing or disclosure, cross-border transfers, and other processing with a major influence on individuals. Article 56 defines the assessment content and requires the report and handling record to be preserved for at least three years. This guide turns those duties into an AI assessment workflow tied to the actual request path.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

China PIPL AI Incident Reporting: Article 57 Notice and Response

PIPL Article 57 requires a personal information handler to act immediately once a personal information leak occurs or might have occurred, and it treats distortion and loss the same way. The handler must take remedial measures and notify the relevant personal information protection authorities and individuals, with a conditional route for withholding individual notice when measures effectively avoid harm. AI incidents need request evidence, while cybersecurity triage remains outside an HTTP policy proxy.

ai-complianceai-governancecomplianceregulationauditforensic-audit
Read post →

CCPA AI Risk Assessment: The CPPA Workflow for ADMT and LLM Processing

The CPPA risk-assessment regulations require covered businesses to assess specified processing before it starts, compare privacy risks with benefits, document operational facts and safeguards, involve relevant employees, and update the assessment after material change. AI teams need to separate the broad risk triggers from the narrower ADMT rules, then connect each approved safeguard to a test and operating record.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

CCPA AI Incident Reporting: California Breach Notice for LLM Events

California breach reporting for an AI incident follows the state data-breach statute and the CCPA private-action provision. The trigger depends on the personal information involved, acquisition or disclosure, encryption status, ownership, and security practices. CPPA automated-decisionmaking rules create a separate compliance track. This guide turns an LLM event into a notice decision, evidence package, and scoped response.

ai-complianceai-governancecomplianceregulationauditforensic-audit
Read post →

Canada AIDA AI Incident Reporting: The PIPEDA Breach Test That Applies

AIDA never became Canadian law. AI incident reporting in the private sector instead turns on PIPEDA: report to the Privacy Commissioner and notify affected individuals when a breach of security safeguards creates a real risk of significant harm, act as soon as feasible, and retain a record of every breach for 24 months. This guide applies that test to prompts, responses, and LLM destinations.

ai-complianceai-governancecomplianceregulationauditforensic-audit
Read post →

Canva AI Compliance: Split Provider Controls from Your AI Request Evidence

Canva AI compliance needs two evidence files. Canva documentation and account settings cover the provider service, privacy choices, team administration, and design sharing. The enterprise file covers the approved use case and acting identity. It also covers data classification and model destination. The file retains the policy decision and evidence for any AI request path the enterprise controls. Keeping the files separate prevents a provider document from being mistaken for proof of a specific prompt decision.

ai-complianceai-governancecomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

California SB 942 LLM Requirements: Duties, Scope, and the Text-Only Boundary

California SB 942 defines generative AI broadly enough to include systems that generate text, images, video, and audio. Its operative detection and disclosure duties focus on image, video, and audio content. This guide separates covered-provider applicability from content-level duties, licensee rules, later AB 853 obligations, enforcement, and the narrow evidence role available at an enterprise HTTP AI request boundary.

ai-complianceai-governancecomplianceregulationllmpolicy-enforcement
Read post →