Blog

Regulation

19 articles on AI security regulation.

Regulation7 min

EU AI Act Digital Omnibus 2026 — the operational changes

A source-linked briefing on the dates, Article 5 additions, provider/deployer boundaries, and classification changes introduced by Regulation (EU) 2026/1744.

Regulation11 min

Prohibited AI practices under the EU AI Act — what Article 5 actually bans

Article 5 now bans ten AI practices outright, including two additions from the 2026 AI Omnibus. What falls inside the line and how reviews distinguish.

Regulation13 min

ISO 42001 audit readiness — the controls that fail most often

ISO 42001 audits surface the same gaps: incomplete risk registers, missing triggers, intent-not-practice evidence. Close them first.

Regulation11 min

DPAs and AI systems — what DPOs actually need to document

Data Protection Authorities are asking about AI in DPA reviews. What DPOs must document and the gaps regulators find first.

Regulation8 min

Is your AI system high-risk under the EU AI Act? How to find out

Determine whether your AI system is high-risk under the EU AI Act's Annex III categories and what that classification requires.

Regulation10 min

An AI Risk Disposition that holds up in regulator review

Most risk dispositions are written for internal approval. What must change so they survive external regulator scrutiny.

Regulation13 min

EU AI Act Article 9 risk management — what evidence is required

Article 9 requires a risk management system for high-risk AI. Six requirements translated into evidence artefacts auditors will request.

Regulation10 min

The EU AI Act timeline and what to prepare first

EU AI Act provisions apply in phases. Which obligations hit when, and the preparation steps that deliver value first.

Regulation12 min

Running RAG over regulated data — the review checklist

RAG over GDPR, HIPAA, or financial data needs controls at data, retrieval, and output layers. Checklist mapped by data class with evidence requirements.

Regulation10 min

Reviewing how an AI vendor handles your data

Is your data used for training? Who accesses it? Where is it stored? The DPA rarely answers these. The data-handling review for AI vendors.

Regulation11 min

General-purpose AI obligations under the EU AI Act

GPAI provisions create obligations for foundation model providers. What they mean and what deployers of GPAI-powered systems need to know.

Regulation11 min

EU AI Act obligations for deployers (not just providers)

Deployers -- not just providers -- carry significant EU AI Act obligations. What organisations using AI systems for their own purposes must do.

Regulation10 min

RAG PII Leakage — 3 Retrieval Paths That Expose Data

RAG over internal corpora frequently exposes personal data never intended to be queryable. The most common data-protection finding in RAG security reviews.

Regulation11 min

EU AI Act vs GDPR — where they overlap for AI systems

GDPR and the EU AI Act overlap heavily for AI processing personal data. Where obligations are additive, and which review artefacts satisfy both.

Regulation10 min

AI subprocessor risk in your vendor chain

When a vendor's AI runs on a third-party model provider, that provider is a subprocessor. Retention, training, and transfer risks your DPA missed.

Regulation12 min

The technical documentation the EU AI Act expects

Annex IV defines what technical documentation high-risk AI needs before market placement. What it requires, what it means, and the common gaps.

Regulation12 min

High-risk AI obligations under the EU AI Act

Six obligations apply to high-risk AI: risk management, documentation, data governance, transparency, oversight, accuracy. Each mapped to evidence.

Regulation10 min

Building an EU AI Act system inventory

The EU AI Act requires knowing every AI system you deploy and its tier. Here's how to build that inventory when AI hides in SaaS and vendor products.

Regulation11 min

EU AI Act risk tiers, explained for engineers

Four risk tiers determine your EU AI Act obligations. How to classify your system and what each tier demands.