← All posts

Compliance & Regulation

402 posts on compliance & regulation.

California SB 942 AI Risk Assessment: A Scoped Workflow for Content Provenance

California SB 942 creates content-provenance duties rather than a statutory risk-assessment mandate. A useful assessment therefore starts with applicability, identifies each generative system and licensed deployment, tests manifest and latent disclosures, checks the public detection tool, and records ownership for gaps. The workflow stays narrow enough to distinguish provider duties inside the generation pipeline from request-layer evidence an enterprise can produce.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

The EU Action Plan on Cybersecurity and AI: Pre-Market Evaluation, Structured Access, and What Enterprises Must Evidence

On July 7, 2026 the European Commission presented its Action Plan on Cybersecurity and Artificial Intelligence: pre-market evaluation of advanced models, an EU third-party evaluation capacity supporting the AI Office, an ENISA and JRC secure testing platform, a structured-access blueprint for advanced AI capabilities, and tighter alignment with NIS2 and the Cyber Resilience Act. I read the plan as a directional signal about evidence. This walks each pillar and maps it to the authorization and audit records an enterprise has to be able to produce on demand.

eu-ai-actai-governanceai-complianceregulationcybersecurityaudit
Read post →

MITRE ATLAS AI Controls Mapping: Which Tactics Reach an HTTPS Request and Which Never Will

MITRE ATLAS holds 16 tactics and 84 techniques as of version 5.1.0 in November 2025, with agent techniques added in February 2026. Around a dozen of those techniques reach an enterprise consuming hosted models, and the rest target training pipelines and model artifacts. This maps the reachable tactics onto the technical control that addresses each one at the AI request boundary, names the evidence produced, and marks the tactics where a request-path control has nothing to offer.

ai-securityllm-securitypolicy-enforcementprompt-injectionai-governance
Read post →

California SB 942 AI Incident Reporting: The 96-Hour Licensee Clock

The California AI Transparency Act carries a hard internal deadline that reads like an incident procedure: a covered provider must revoke a non-compliant licence within 96 hours of discovering that the licensee no longer maintains the required latent disclosure capability. AB 853 moved the operative date to August 2, 2026 and phased in further obligations for platforms and capture devices.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

Brazil LGPD AI Incident Reporting: Three Business Days and What You Must Name

ANPD Resolution CD/ANPD nº 15 of April 24, 2024 gives Brazilian controllers three business days from confirming an incident to notify the ANPD and affected data subjects. When the incident involves an LLM or an AI agent, the notification still asks which data categories were compromised and what the likely impacts are, and application logs rarely answer either.

ai-complianceai-governancecomplianceregulationauditforensic-audit
Read post →

Brazil LGPD LLM Requirements: The Obligations That Attach to Prompt Traffic

Sending personal data to a large language model is a processing operation under the LGPD, with a purpose, a legal basis, a recipient and a retention position. This sets out which LGPD obligations attach at the moment a prompt leaves the organisation, covering Article 6 principles, Article 20 automated decisions, Article 46 security measures, and the operator relationship.

ai-complianceai-governancecomplianceregulationllmpolicy-enforcement
Read post →

Azure AI Foundry Compliance: RBAC Scope, Key Auth, and the Evidence Gap

Microsoft states that key-based authentication to a Foundry resource grants full access with no role restrictions. That single sentence decides how much an Azure AI Foundry compliance file can rest on RBAC. This covers the built-in roles, the resource, project and agent scopes, the recent role rename, and the request-level evidence RBAC never produces.

ai-complianceai-governanceidentity-and-authorizationcomplianceauditcloud-security
Read post →

AutoGen Compliance: Model Clients, Untested Endpoints, and Event Logging

AutoGen supports OpenAI, Azure OpenAI, Azure AI Foundry, Anthropic, Ollama, Gemini and Llama API clients, several marked experimental, and the documentation notes that OpenAI-compatible endpoints are usable but untested. An AutoGen compliance file records which client each agent holds, which credential it carries, and what the event logger actually preserves.

ai-complianceai-governanceagentic-aicomplianceauditidentity-and-authorization
Read post →

AWS Bedrock Compliance: Building Evidence Around Model Invocation Logging

Amazon Bedrock model invocation logging is disabled by default and captures only calls made through the bedrock-runtime endpoint. An AWS Bedrock compliance file needs the enablement record, the destination configuration, the identity ARN on each invocation, the 100 KB body threshold, and the customer-side policy decision that sits above all of it.

ai-complianceai-governanceauditcompliancecloud-securitypolicy-enforcement
Read post →

Brazil LGPD AI Risk Assessment: What Article 38 Actually Obliges

LGPD Article 38 lets the national authority require a controller to prepare a data protection impact assessment, and sets a minimum content standard: the types of data collected, the methodology for collection and for securing the information, and the controller analysis of measures, safeguards and risk mitigation mechanisms. For an LLM deployment, two of those three are usually undocumented.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

Box AI Compliance: Turning Platform-Neutral Model Routing into Evidence

Box takes a platform-neutral approach to AI models and commits to publishing which models are used, to deleting prompt and answer data at the provider once a response returns, and to not training on customer content without explicit approval. A Box AI compliance file turns those vendor commitments into customer-side records covering permissions, model destination, and the request-level policy decision.

ai-complianceai-governancecomplianceauditpolicy-enforcementidentity-and-authorization
Read post →

Amazon Q Compliance After the Closure to New Customers

AWS has closed Amazon Q Business to new customers and points prospective users to Amazon Quick. For organisations already running it, the compliance file now carries a service lifecycle question alongside the usual shared responsibility work: identity through IAM Identity Center, ACL propagation from connected sources, CloudTrail coverage, and the request-level policy decision AWS does not make.

ai-complianceai-governancecomplianceauditidentity-and-authorizationcloud-security
Read post →