← All posts

Industry Verticals

237 posts on industry verticals.

CMMC AI Controls Mapping for CUI Flowing to a Model Endpoint

This CMMC AI controls mapping connects Level 2 security requirements drawn from NIST SP 800-171 Revision 2 to the authenticated HTTP path between a defense contractor user or agent and an LLM. Each entry names the control point, owner, assessment objective test, retained artifact, and the boundary where an AI gateway stops contributing and IAM, endpoint, media protection and incident teams take over.

ai-complianceai-governancecmmcpublic-sectorarchitecturepolicy-enforcement
Read post →

GLBA AI Controls Mapping Against the Safeguards Rule Elements

This GLBA AI controls mapping takes the elements of 16 CFR 314.4 and assigns each one a control point, an owner, a repeatable test, a retained artifact, and a boundary on the authenticated path from a user or agent to an LLM. It shows where an HTTP enforcement point gives direct coverage for access limits and monitoring, and where the qualified individual, IAM, cryptography, procurement and incident response teams stay accountable.

ai-complianceai-governanceglbafinancial-servicesarchitecturepolicy-enforcement
Read post →

GLBA AI Audit Evidence for the Safeguards Rule Monitoring Element

GLBA AI audit evidence has to show that a financial institution monitored and logged what authorized users did with customer information when they sent it to a model endpoint. This guide builds the package around 16 CFR 314.4(c)(8), the written risk assessment at 314.4(b), the access limits at 314.4(c)(1), the 30 day FTC notice at 314.4(j), and the annual report at 314.4(i).

ai-complianceauditglbafinancial-servicesai-governancezero-trust
Read post →

GLBA AI Compliance Checklist Built on the Safeguards Rule Elements

A GLBA AI compliance checklist runs against the elements in 16 CFR 314.4, not against a generic security questionnaire. This guide grades LLM traffic on the qualified individual, the written risk assessment, access controls, encryption, monitoring and logging of authorized user activity, service provider oversight, the incident response plan, and the annual board report, with an evidence field and a boundary line for each.

ai-complianceai-governanceglbafinancial-servicespolicy-enforcementaudit
Read post →

ECB Operational Resilience and AI: What Bank Supervisors May Inspect

The ECB has identified frontier AI as a structural cyber-resilience challenge for banks. This guide separates the operational-resilience controls a policy gateway can evidence from the patching, legacy-modernisation, and crisis-management controls it cannot replace.

ai-securityai-compliancedoraregulationai-governanceaudit
Read post →

AI Compliance in Banking: The Regulatory Map for a Bank Running LLMs

A bank running LLMs answers to model risk guidance, operational-resilience rules, fair-lending law, and data-protection statutes at the same time. This article maps SR 11-7, DORA, ECB supervisory signals, ECOA, and the EU AI Act, then shows the operational thread that joins them at the AI request layer.

bankingfinanceai-compliancemodel-riskaudit-trailregulatory-compliance
Read post →

DORA + AI: What EU Banks Need to Map Before the January 2027 ICT Third-Party Register Deadline

The Digital Operational Resilience Act (DORA) treats LLM providers as critical ICT third parties when usage reaches scale. EU banks have to register, monitor, and document exit strategies for these dependencies. The deadline for the consolidated ICT third-party register goes live in January 2027. This article walks through the register requirements, the exit-strategy mandate, the concentration-risk test, and what changes when bank inference runs through OpenAI, Anthropic, and AWS Bedrock simultaneously. Gateway-level audit logs satisfy the per-decision evidence requirement DORA assumes.

doracomplianceregulationai-complianceai-governanceaudit
Read post →

Insurance AI Pricing Under the EU AI Act and NAIC Bulletin: The High-Risk Architecture

Life and health insurance pricing using AI is classified as high-risk under EU AI Act Annex III point 5(c). The NAIC Model Bulletin on the Use of AI Systems by Insurers adopted in December 2023 has been incorporated by twenty-five US state insurance regulators as of 2025. Colorado SB21-169 sets concrete obligations for life insurers using external consumer data. The combined regime requires per-decision audit records, governance documentation, third-party risk management, and demonstrable testing for unfair discrimination across protected classes.

insuranceai-complianceeu-ai-actnaicaudithigh-risk-ai
Read post →

HIPAA AI Compliance in Healthcare: The Architecture for PHI in Prompts

Cloud Radix reports that 57% of healthcare professionals use unauthorized AI to process PHI without a Business Associate Agreement. The HHS Office for Civil Rights treats unauthorized PHI disclosure as a breach regardless of intent. This piece walks through what HIPAA actually requires for AI processing of PHI, where most healthcare AI deployments are exposed, and the inspection architecture that produces the access logs and access controls HIPAA expects.

hipaahealthcareai-compliancephiauditai-governance
Read post →

DORA AI Compliance for Banking: What the Operational Resilience Regime Requires from AI Systems

DORA took effect January 2025 across the EU financial sector and overlaps with the EU AI Act on the high-risk AI systems banks operate. The combined obligation includes operational resilience, third-party risk management, incident reporting, and per-decision audit records for AI-assisted financial decisions. This piece walks through what DORA actually requires of AI systems, how Article 6 and Annex III of the EU AI Act layer on top, and the architecture that satisfies both.

dorabankingai-complianceeu-ai-actauditfinancial-services
Read post →

EU AI Act for Healthcare: What Articles 6, 12, and Annex III Require of Hospital AI Deployments

EU AI Act high-risk classification applies to several healthcare AI use cases including AI as a safety component of medical devices under Article 6(1) and the Annex III categories covering access to essential services, biometric categorization, and emergency triage. From August 2, 2026, hospitals deploying these AI systems take on deployer obligations under Article 26 and have to support providers in meeting Articles 8 through 17. The Medical Device Regulation and the EU AI Act layer for software-as-a-medical-device. The architecture that satisfies the high-risk regime is per-decision audit records that capture identity, data class, policy state, and decision outcome on the hospital side.

healthcareeu-ai-actmedical-devicesmdrai-compliancehospital-ai
Read post →

Tennessee's AI therapist-impersonation ban is now in force: the enforcement problem for healthcare chatbot deployers

Tennessee SB 1580 took effect July 1, 2026 and prohibits AI systems from presenting themselves as licensed mental-health professionals. Digital-health, EAP, and payer platforms running patient-facing conversational AI now face a concrete evidence problem: proving the model never claimed licensure across millions of conversation turns. Tennessee Attorney General enforcement applies. This piece walks through the statute, the enforcement architecture (response-side policy plus per-decision audit logs), and how the same controls extend to the 2026 state chatbot wave landing in Utah, California, and New York.

healthcare-aicomplianceregulationchatbotauditstate-ai-laws
Read post →