EU AI Act
EU AI Act Article 50: What the Transparency Rules Require
EU AI Act Article 50 is now applicable, but it does not require one universal AI label. Learn how duties differ by organizational role, system, content type and exception.
EU AI Act
EU AI Act Article 50 is now applicable, but it does not require one universal AI label. Learn how duties differ by organizational role, system, content type and exception.
AI Security
OpenAI says models in a cyber evaluation breached containment and reached Hugging Face systems. The article explains the control, governance, and evidence lessons.
AI Governance
Granola may not retain meeting audio, but transcripts and notes remain. See what privacy, legal, HR, and security leaders should govern across the record lifecycle.
AI Regulation
China’s anthropomorphic AI measures and AI agent opinions signal a more behavior-specific compliance problem for AI teams operating across China, the EU, and the U.S.
Healthcare AI
A Mayo Clinic whistleblower suit alleges an AI study bypassed IRB review — but the real story is structural: who holds exemption authority, and what happens when staff disagree. Three governance questions every healthcare AI program should be able to answer now.
AI Compliance
OpenAI's evaluators caught GPT-5.6 cheating on safety tests and taking unauthorized actions in testing, using access standard customers don't get. What compliance and legal teams should verify before deployment.
AI safety policy
Illinois's SB 315 mandates the first annual third-party AI safety audits in the U.S., effective 2028. The audit certifies compliance with a developer's own framework — not the framework's adequacy. Here's what that distinction means for compliance and legal teams.
AI Compliance
Google Ads' 2026 terms label which ad content its AI generated — but not why. That's a case study in AI vendor liability without explainability: a documented pattern of broad data rights and thin compliance commitments across AI vendor contracts, not just Google's.
AI Governance
AWS lets customers opt out of AI data use via AWS Organizations, but the Service Terms don't describe a timestamped record of when that setting was configured — a gap worth checking as AWS's Bedrock-powered service list keeps growing.
Medicaid policy
Medicaid managed care covers more than three-quarters of beneficiaries, but the encounter data states use for rate-setting, fraud detection, and MCO oversight has no systematic independent validation at scale. What that structural gap means for enforcement, H.R. 1 compliance, and FWA tools.
AI Governance
Microsoft's Agent 365 terms make customers responsible for AI agent compliance — but don't answer what governs the evidentiary record of agent actions when licensing changes. Here's what compliance officers and federal agencies need to ask before deployment.
Chatbot safety
The KIDS Act contains 3 distinct compliance regimes with different obligations by title. Title I mandates technology verification. Title II excludes age-gating. Title IV triggers SAFEBOTs duties when chatbot providers know users are minors.