Resource library
Operational evidence for AI in production.
Start with the rule, the action it governs, and the record someone outside your company can check. These references cover supervision, OVERT, buyer diligence and current regulation, and they don’t mistake a policy document for a record of what ran.
Monthly brief
What changed this month, and what it changes in a review.
One email a month for the person who has to answer the questionnaire: the obligations that moved, the artifact a reviewer will now ask for, and which evidence held up. Colorado’s automated-decision rules take effect on 1 January 2027; the EU AI Act’s high-risk obligations follow. The brief keeps the dates straight.
Double opt-in. One click to join, one click in any issue to leave. Never sold or shared.
The Proof Gap in Healthcare AI
Why intended controls and operational evidence aren’t the same thing.
Open standardOVERT
The open record format. Anyone can check a record in their browser, with no Glacis account.
Current newsGlacis joins PACT AI
Why Glacis joined the coalition building shared foundations for AI assurance.
EU AI Act
Current, role-specific guidance with enacted dates distinguished from historical and proposed timelines.
The EU AI Act guide
Which systems fall under Annex III and Annex I, the enacted dates for each, and the obligations that follow.
Read the guideEU member state implementation guides
Germany
Bundesnetzagentur oversight, KI-VO implementation, works council requirements.
France
CNIL coordination, sectoral regulators, French AI strategy alignment.
Spain
AESIA sandbox, early adopter status, regional considerations.
Italy
AgID coordination, Garante privacy integration, sectoral enforcement.
Netherlands
Autoriteit Persoonsgegevens role, algorithmic impact assessments.
Belgium
EU institution proximity, federal structure, BIPT coordination.
Poland
IT outsourcing hub, cross-border compliance, UODO coordination.
EU AI Act guides by role
CISO guide
Security requirements, Article 12 logging, cybersecurity integration, incident response.
General counsel guide
Legal liability, contract requirements, due diligence, regulatory exposure.
CCO guide
Compliance program design, risk assessment, audit preparation, documentation.
CMIO guide
Clinical AI governance, human oversight, diagnostic AI systems, ambient scribes.
UK AI regulation
The UK’s pro-innovation approach to AI governance, sector-specific oversight, and comparison with EU requirements.
UK AI framework
Pro-innovation principles, sector regulators, AI Security Institute, and upcoming legislation.
UK vs EU AI Act
Regulatory divergence, dual compliance strategies, and cross-border considerations.
UK healthcare AI
MHRA AI-as-medical-device, CQC oversight, NHS AI & Digital Regulations Service, and clinical AI requirements.
UK financial services AI
FCA and PRA AI oversight, Consumer Duty, SM&CR accountability, and model risk.
US state AI laws
What each state has passed, what is in force now, and the effective dates for the rest.
The US state AI laws tracker
Effective dates, a dated change log, and the obligations in force, state by state.
Read the guideCalifornia
AB 2013 training data transparency, employment AI rules, bot disclosure, and political deepfakes.
New York
NYC Local Law 144 hiring audits, RAISE Act frontier safety, LOADinG Act, and NYDFS guidance.
Washington state
Facial recognition regulation, My Health My Data Act, AI Task Force, and pending HB 1168.
Oregon
OCPA profiling opt-out, campaign deepfake disclosure, AG guidance, and 2026 amendments.
Framework crosswalks
Where the AI governance frameworks overlap and where they don’t.
ISO 42001 vs EU AI Act
Control mapping, what certification is worth, and where the management standard and the regulation overlap.
NIST AI RMF vs EU AI Act
US framework alignment with EU regulation, dual compliance strategies for multinational organizations.
EU AI Act vs HIPAA
Healthcare AI compliance across jurisdictions, PHI handling with AI systems, dual compliance requirements.
Operational evidence and AI security research
Explainers on supervision, independent verification, and the signed records behind both: the OVERT series.
AI agent security: an operating boundary for agents
Controls enforced where the agent acts, with a signed record of what was requested and what happened.
Agentic AI security: runtime coverage
Why agent security is a runtime problem, and what coverage means.
AI security controls that leave a record
The difference between claiming a control fired and having a signed record of it.
AI in cyber security: the evidence layer
Detection made the SOC faster. A signed record of each decision is a different artifact, and one an outsider can check.
AI data security: verify the record, not the data
How a record can be checked without disclosing the data it protects.
After a prompt injection attack: reconstruct what happened
When an attack lands, the question is what your controls did, and whether you can show it.
Verifiable AI: when one jailbreak pulls a model
Model-level safety fails open; action-level evidence doesn’t.
What is AI governance?
Beyond policy documents: governance as enforced behavior plus evidence.
AI governance tools: beyond the dashboard
What to demand from governance tooling.
AI governance maturity model
From policy to record: a maturity path measured in evidence someone else can check.
Documentation versus operational evidence
Why artifacts of intent and operational records answer different questions.
The AI governance challenge no one names
The unnamed gap between what governance declares and what systems do.
What makes AI attestation independent?
Independence is a property of who must be trusted to check the claim.
High-risk AI use case guides
Compliance guidance for the AI applications the EU AI Act classifies as high-risk.
Ambient AI scribes
Clinical documentation AI, HIPAA intersection, consent requirements, Sharp lawsuit implications.
Clinical decision support
CDSS compliance, FDA oversight, medical device classification, clinical workflow integration.
AI-assisted diagnosis
Diagnostic AI systems, radiology AI, pathology AI, MDR compliance requirements.
Credit scoring AI
Creditworthiness assessment, ECOA/FCRA compliance, adverse action requirements, model validation.
Insurance underwriting AI
Risk assessment AI, pricing algorithms, claims processing, actuarial model compliance.
Employment AI
Recruitment AI, resume screening, performance evaluation, worker monitoring compliance.
Biometric AI systems
Facial recognition, emotion detection, biometric categorization, prohibited uses.
AI chatbots
Transparency requirements, disclosure obligations, when chatbots become high-risk.
More resources
From actions to evidence
Wherever the AI already acts, we map the rule you intend, the controls you run, and the record a reviewer would need.
Talk to us