Compliance Library Blog Product Sign In

Blog

Practical AI governance intelligence for compliance professionals.

DPIA for AI Systems: When It's Required, What It Must Cover, and How Most Organizations Get It Wrong

March 18, 2026 | 12 min read | ReguLume

78% of organizations now use AI, but most haven't conducted the DPIA that GDPR Article 35 requires. Here's what a compliant assessment actually looks like.

dpia gdpr ai-compliance data-protection eu-ai-act risk-assessment

ISO 42001: The 503 Obligations Your Largest Customer Is About to Require

March 17, 2026 | 11 min read | ReguLume

ISO 42001 certification is showing up in RFPs. Here are the 503 obligations it contains and why voluntary just became mandatory.

iso-42001 ai-standards certification procurement

Your AI System Is Already Regulated — You Just Haven't Mapped the Overlaps

March 16, 2026 | 12 min read | ReguLume

GDPR, EU AI Act, and DORA overlap across 1,570 obligations. Most organizations manage them in separate spreadsheets. That's the gap.

cross-regulation gdpr eu-ai-act eu-dora obligation-mapping

Colorado AI Act: 24 Obligations, 113 Days

March 15, 2026 | 11 min read | ReguLume

Colorado's AI Act enforcement starts June 30, 2026. Here are the 24 specific obligations and why NIST AI RMF compliance just became urgent.

colorado-ai-act us-state-laws compliance-deadline nist-ai-rmf

EU AI Act Article 9: The 23 Obligations Nobody Summarizes

March 14, 2026 | 11 min read | ReguLume

Article 9 says 'implement a risk management system.' It actually contains 23 specific obligations. Here's every one.

eu-ai-act risk-management article-9 obligations

The Auditability Gap — And Why We Built For It From Day One

March 13, 2026 | 9 min read | ReguLume

87.8% of financial institutions lack a defined AI strategy. The Auditability Gap explains why — and what closing it requires.

auditability ai-compliance eu-ai-act governance

78 Bills, 27 States, One Problem: Who's Tracking Your Chatbot Obligations?

March 12, 2026 | 8 min read | ReguLume

Oregon and California passed chatbot safety laws with conflicting obligations. 78 bills across 27 states demand obligation-level tracking, not headline compliance.

chatbot-regulation ai-compliance state-legislation obligation-mapping

Compliant Is Not Defensible — Why Your AI Decisions Need Reasoning Chains

March 11, 2026 | 7 min read | ReguLume

Compliance is a checklist. Defensibility requires structured reasoning chains. Learn why regulators, auditors, and insurers now demand documented AI decision logic.

ai-compliance audit-readiness eu-ai-act defensibility

What AI Compliance Actually Requires — The Definitive List

March 10, 2026 | 12 min read | ReguLume

2,964 obligations across 15 regulations. The complete list of what AI compliance actually requires — obligation by obligation, regulation by regulation.

ai-compliance eu-ai-act obligations regulatory-intelligence

Start your compliance assessment

Map obligations to your AI systems, identify gaps, and generate board-ready reports. Plans start at $149/mo.

Get Started