Resource library

Operational evidence for AI in production.

Start with the rule, the action it governs, and the record someone outside your company can check. These references cover supervision, OVERT, buyer diligence and current regulation, and they don’t mistake a policy document for a record of what ran.

Monthly brief

What changed this month, and what it changes in a review.

One email a month for the person who has to answer the questionnaire: the obligations that moved, the artifact a reviewer will now ask for, and which evidence held up. Colorado’s automated-decision rules take effect on 1 January 2027; the EU AI Act’s high-risk obligations follow. The brief keeps the dates straight.

Regulation deep dive

EU AI Act

Current, role-specific guidance with enacted dates distinguished from historical and proposed timelines.

Pillar guide

The EU AI Act guide

Which systems fall under Annex III and Annex I, the enacted dates for each, and the obligations that follow.

Read the guide

EU member state implementation guides

EU AI Act guides by role

Research

Operational evidence and AI security research

Explainers on supervision, independent verification, and the signed records behind both: the OVERT series.

AI agent security: an operating boundary for agents

Controls enforced where the agent acts, with a signed record of what was requested and what happened.

Agentic AI security: runtime coverage

Why agent security is a runtime problem, and what coverage means.

AI security controls that leave a record

The difference between claiming a control fired and having a signed record of it.

AI in cyber security: the evidence layer

Detection made the SOC faster. A signed record of each decision is a different artifact, and one an outsider can check.

AI data security: verify the record, not the data

How a record can be checked without disclosing the data it protects.

After a prompt injection attack: reconstruct what happened

When an attack lands, the question is what your controls did, and whether you can show it.

Verifiable AI: when one jailbreak pulls a model

Model-level safety fails open; action-level evidence doesn’t.

What is AI governance?

Beyond policy documents: governance as enforced behavior plus evidence.

AI governance tools: beyond the dashboard

What to demand from governance tooling.

AI governance maturity model

From policy to record: a maturity path measured in evidence someone else can check.

Documentation versus operational evidence

Why artifacts of intent and operational records answer different questions.

The AI governance challenge no one names

The unnamed gap between what governance declares and what systems do.

What makes AI attestation independent?

Independence is a property of who must be trusted to check the claim.

From actions to evidence

Wherever the AI already acts, we map the rule you intend, the controls you run, and the record a reviewer would need.

Talk to us