Loading…
Loading…
Category
87 posts in this category.
·9 min read
Cumulative GDPR fines crossed €7.1 billion as of early 2026. AI-related enforcement is accelerating. Five major cases involving Meta, TikTok, Clearview AI, OpenAI, and biometric data explain the specific risks. What small teams can do differently, and why your vendor DPA alone will not protect you.
·8 min read
How much does AI compliance actually cost? DIY documentation starts at $0. Bias audits run $5,000 to $50,000 per tool. ISO 42001 certification costs $15,000 to $40,000 in year one. Most 1-50 person teams can cover solid compliance for under $5,000 per year if no bias audits are required. Full cost breakdown by team size.
·5 min read
Using AI to screen candidates? 5 overlapping laws apply to small teams in 2026: NYC LL144, FCRA, Illinois AIVEA, EEOC, and Colorado SB 189.
·10 min read
The EU Digital Omnibus provisional agreement (May 7, 2026) would delay most high-risk AI obligations from August 2, 2026 to December 2, 2027. But formal adoption is not guaranteed before the August deadline. What deployers must do now regardless of which path the Omnibus takes.
·8 min read
OpenAI Codex was silently writing 640 TB/year to developer SSDs through a logging bug. This is a governance gap most acceptable-use policies miss. Here is what IT and compliance teams need to add.
·9 min read
NYC Local Law 144 requires employers using AI hiring tools to conduct annual independent bias audits, publish results, and notify candidates. DCWP enforcement began July 5, 2023. Penalties run $500 to $1,500 per violation, with each day of use and each missed notice counted separately. Six-step compliance checklist.
·9 min read
Trump signed a new AI executive order on June 2, 2026. Here is what it requires, what is voluntary, who must act, and what federal contractors and compliance teams should do now.
·11 min read
ChatGPT Atlas and Perplexity Comet act inside your logged-in sessions, which breaks the old browser security model. Here is a copy-paste governance policy for teams of 5-50, plus the prompt-injection risk you need to brief staff on now.
·10 min read
Otter.ai, Fireflies, Read.ai, and similar tools upload your meeting audio to US cloud servers for processing. Free tier accounts may retain transcripts indefinitely. If any participant is an EU resident, GDPR transfer rules apply. Here is what to do.
·8 min read
Monthly new e-book releases on KDP nearly tripled between 2022 and 2025 as AI-generated content flooded the platform. Amazon has responded with account-level enforcement for undisclosed AI content. Here is what publishers and authors need to document before enforcement tightens further.
·9 min read
EU AI Act Article 14 sets specific technical and operational requirements for human oversight of high-risk AI; most vendor "human-in-the-loop" claims don't satisfy them. Here is what effective oversight actually means, how to evaluate vendor implementations, and a 10-item compliance checklist for deployers.
Showing 12 of 87 posts. View full blog archive →