// Topics / Compliance

Compliance

    Compliance Fails at the Vendor Handoff You answer for an AI system you can only partly witness. Build a compliance interface to each vendor, with owners, deadlines, and drills. compliance governance ai Content Marking Is a Pipeline, Not a Policy The EU AI Act marking deadline for existing generative systems is 2 December. Provenance survives only what your pipeline keeps, so test it in CI. compliance ai architecture The EU Gave You a Reprieve, Not a Pardon The Digital Omnibus deferred the AI Act's high-risk duties, not its live ones. Build a deferral ledger: one row per system and obligation. governance compliance ai AI Governance Without Bureaucracy AI governance that works: tighter defaults, named owners, fast escalation, and a small control stack engineers can follow at 2 a.m. No new committees. governance ai security Data Sovereignty by Design: Privacy as Architecture Data privacy and residency are architecture constraints. Four minimum controls, zero-trust data access, and multi-region tradeoffs to build in early. privacy security compliance AI Regulation Is Here: Treat Compliance as Engineering AI regulation already shows up in procurement and security reviews. How to build compliance evidence into the delivery pipeline instead of bolting it on. compliance ai governance AI Data Privacy Is a Plumbing Problem AI privacy fails in the details: what gets logged, who can replay prompts, how long artifacts linger. Treat it as infrastructure, not a checkbox. privacy ai data AI Governance That Works: Risk Tiers and System Cards AI governance that blocks delivery is broken. How to make 'yes' safe and fast instead: risk tiers, one-page system cards, and living evidence. ai governance compliance Enterprise AI Compliance Without the Theater Enterprise AI compliance as architecture: a data inventory, model registry, audit logging, and risk tiers that let low-risk use cases ship in days. ai compliance business GDPR Week One: Lessons From a Fintech Startup GDPR went live on May 25th. The first days inside a fintech startup: last-minute scrambles, consent fatigue, day-one access requests, lagging vendors. compliance privacy business GDPR for Engineers: What We Built at a Fintech Startup Eleven days before the GDPR deadline: data mapping, consent records, export and erasure pipelines, and the backup problem at a fintech startup. compliance privacy business GDPR Is an Engineering Problem: A Technical Checklist GDPR enforcement starts May 2018. The engineering checklist I'm working through at a fintech startup: data inventory, consent, access, deletion, retention. compliance privacy security