← All posts

Industry Verticals

227 posts on industry verticals.

AI Vendor Risk in Capital Markets Requires Runtime Supervision

FINRA says its rules apply when a member firm uses generative AI directly, through a third party, or through an embedded feature. Regulation S-P adds incident-response and customer-notice duties for covered institutions. A capital-markets vendor assessment therefore needs to connect approved use, customer-information handling, supervision, and model routes to evidence from each authenticated request.

ai-securityai-governanceai-complianceauditregulationpolicy-enforcement
Read post →

AI Vendor Risk in Biotech Extends the Validated System Boundary

A biotech AI vendor can create, modify, or transmit an electronic record used under an FDA predicate rule. When that happens, vendor review has to test validation evidence, access controls, audit trails, record retrieval, and change handling under 21 CFR Part 11. The operational proof lives in the authenticated model request as well as the supplier file.

ai-securityai-governanceai-complianceauditregulationpolicy-enforcement
Read post →

AI Vendor Risk in Behavioral Health Starts With the Treatment Record

A behavioral health AI vendor can receive psychotherapy notes, substance use disorder records, or other ePHI inside an authenticated model request. HIPAA requires written assurances and ongoing activity review, while 42 CFR Part 2 adds protections for substance use disorder records. Vendor review therefore has to connect the contract to real request traffic.

ai-securityai-governanceai-compliancehipaaauditpolicy-enforcement
Read post →

AI Vendor Risk in Automotive Needs a Model-Route Record

NHTSA tells automotive organizations to set clear cybersecurity expectations for suppliers and support verified implementation across the supply chain. Auto-ISAC publishes a dedicated third-party cybersecurity risk management guide. This article turns those supplier expectations into policy and evidence for authenticated AI model traffic.

ai-securityai-governancecybersecurityauditzero-trustpolicy-enforcement
Read post →

AI Vendor Risk for Airlines Lives at the Operational Interface

EU Part-IS requires aviation organizations to identify interfaces with other organizations that can create mutual information-security exposure and to manage risks in contracted activities. NIS2 adds direct supplier and service-provider relationships to required supply-chain security measures. This article applies both duties to authenticated airline model traffic.

ai-securityai-governanceai-complianceregulationauditpolicy-enforcement
Read post →

AI Vendor Risk for Accounting Firms Starts With the Client Record

FTC safeguards requirements make accounting firms responsible for selecting service providers that can protect customer information, putting safeguards in contracts, and overseeing how providers handle the data. This article applies that duty to AI requests carrying tax records, payroll files, client correspondence, and engagement notes.

ai-securityai-governanceai-complianceauditcompliancepolicy-enforcement
Read post →

HIPAA-Compliant AI Agent Platforms: BAAs, Access Control, and Audit Evidence

HIPAA compliance for an AI agent platform starts with a signed Business Associate Agreement, but the Security Rule also demands access control under 45 CFR 164.312(a) and audit controls under 164.312(b). This guide names the model platforms and healthcare tools that sign BAAs in 2026, then explains why a vendor BAA alone does not produce the identity-bound access-control and audit evidence a covered entity needs across its own clinicians and agents.

hipaahealthcareai-complianceai-securityidentity-and-authorizationauditpolicy-enforcement
Read post →

Shadow AI in Mortgage Lending: Borrower Files and Unapproved Model Routes

Shadow AI in mortgage lending can move borrower tax returns, bank statements, credit findings, appraisal notes, and servicing records into model services outside the lender''s approved controls. This article isolates the unauthorized HTTP request path, connects it to Regulation B and the FTC Safeguards Rule, and sets out the identity, content, destination, and evidence controls needed before borrower data reaches an LLM.

shadow-aiai-securityai-governancecompliancedata-loss-preventionaudit
Read post →

FERPA Applies to AI Tools the Moment They Touch a Student Record

FERPA applies to AI tools the moment they touch a student education record, and the "school official" exception only covers your AI vendor when four specific conditions are met. Most edtech AI integrations were built before anyone checked those conditions against the AI step specifically. This piece walks through what FERPA actually requires when AI processes education records, exactly where the school official exception breaks for AI vendors, and the architecture that closes the gap.

ferpaedtechstudent-dataai-complianceauditk12
Read post →

CSBS AI Supervisory Framework: Prepare the Examiner Evidence File

The CSBS Artificial Intelligence Supervisory Framework gives state examiners a Core Examiner Guide, document request list, work program, nonbank supplements, and an optional risk-tiering worksheet. Financial institutions can prepare by connecting each AI use case to its owner, purpose, vendor, risk tier, data controls, change record, and operating evidence. The framework remains discretionary, and each state agency decides how to incorporate it.

ai-complianceai-governancecomplianceregulationauditpolicy-enforcement
Read post →

Singapore MAS Wrote Down Three Runtime Questions for AI Agents in Finance

On 5 August 2026 the Monetary Authority of Singapore answered a parliamentary question on agentic AI in financial services, confirming that its proposed Guidelines on AI Risk Management cover all AI use cases at financial institutions including AI agents. The companion paper published on 3 July 2026, Safeguards for Agentic Finance at Runtime, sets out three questions: what the system is authorised to do, how proposed actions are assessed before execution, and what records are retained. Those three describe a policy decision point.

ai-governanceai-complianceregulationagentic-aipolicy-enforcementaudit
Read post →

AI Governance for Security Architects: Put Policy on the Model-Call Path

A security architect turns AI governance requirements into trust boundaries, identity flows, policy decision points, and evidence paths. This article maps the role to the HTTP model-call boundary, where authenticated users and agents can be evaluated against data classification, model authorization, and policy before a request leaves the enterprise.

ai-governanceai-securityarchitecturezero-trustidentity-and-authorizationpolicy-enforcement
Read post →