Compliance

Examination readiness, audit evidence and the controls that survive a regulator asking for them. See examination readiness and sample examination reports.

FINRA Rule 3110 and AI Agents: A Supervision Guide
Guides

FINRA Rule 3110 and AI Agents: A Supervision Guide

Model risk guidance stepped back from agentic AI. FINRA did not. What Rule 3110 requires of a broker-dealer deploying AI agents, and what the supervisory record has to contain.

Craig Alberino · Sep 19, 2026
The CISO's Guide to Runtime Governance for AI Agents
AI Agents

The CISO's Guide to Runtime Governance for AI Agents

Craig Alberino · May 30, 2026
Runtime Plane vs Workflow Plane: The New AI Governance Split
Runtime Governance

Runtime Plane vs Workflow Plane: The New AI Governance Split

Microsoft and ServiceNow both claimed the workflow plane in five days. The runtime plane is still open. Here is why that matters for enterprise AI procurement.

Craig Alberino · May 10, 2026
Smartflow Sovereign: Built for the EU AI Act
AI Regulation

Smartflow Sovereign: Built for the EU AI Act

The runtime evidence the EU AI Act asks of high-risk systems, due December 2, 2027 for Annex III, and how Smartflow Sovereign records it at the call.

Craig Alberino · Apr 20, 2026
APERION: AI Sovereignty for Regulated Industries
AI Security

APERION: AI Sovereignty for Regulated Industries

Craig Alberino · Apr 1, 2026
What's Missing in Enterprise AI: Governance, Cost Control, and Compliance
AI Governance

What's Missing in Enterprise AI: Governance, Cost Control, and Compliance

APERION CEO Craig Alberino joins Startups Decoded to discuss why enterprise AI has a control plane problem, and what it takes to govern AI at runtime.

Valentina Cruz · Feb 23, 2026
MCP Without Governance Is a Compliance Gap Waiting to Happen
MCP

MCP Without Governance Is a Compliance Gap Waiting to Happen

With 90% enterprise adoption projected and documented security concerns unresolved, MCP governance is no longer optional.

Valentina Cruz · Feb 18, 2026
Every AI Interaction Needs an Audit Trail: The Case for Network-Layer Governance
Compliance

Every AI Interaction Needs an Audit Trail: The Case for Network-Layer Governance

With EU enforcement active and US deadlines approaching, the ability to prove governance is becoming as important as governance itself.

Valentina Cruz · Feb 11, 2026
EU AI Act Year One: Prohibited Practices Review and What's Coming Next
AI Regulation

EU AI Act Year One: Prohibited Practices Review and What's Coming Next

The Commission's mandatory review of prohibited AI practices may expand the ban list. Here's what enterprises should monitor.

Valentina Cruz · Feb 4, 2026
The Colorado AI Act Takes Effect: First Major US State AI Compliance Deadline
AI Regulation

The Colorado AI Act Takes Effect: First Major US State AI Compliance Deadline

Colorado's comprehensive AI legislation becomes enforceable February 1. Here's what enterprises need to know about the most ambitious US state AI law.

Valentina Cruz · Jan 23, 2026
The 2026 AI Compliance Clock: What the EU AI Act's August Deadline Means for US Companies
AI Regulation

The 2026 AI Compliance Clock: What the EU AI Act's August Deadline Means for US Companies

Published January 2026. The EU has since moved Annex III high-risk obligations to December 2, 2027. What changed, and what US companies still face now.

Valentina Cruz · Jan 6, 2026
Trump's AI Executive Order: What Federal Preemption Means for Enterprise Compliance
AI Regulation

Trump's AI Executive Order: What Federal Preemption Means for Enterprise Compliance

The December 11 Executive Order aims to replace 50 state AI frameworks with one federal standard. Here's what that means operationally.

Valentina Cruz · Dec 12, 2025