Resource Library
The AI Runtime Assurance Library
Practical references for the teams turning AI governance from policy language into runtime controls, signed evidence, and review-ready artifacts.
EU AI Act Compliance
The world’s first comprehensive AI regulation. Master the requirements with our detailed guides.
The Complete EU AI Act Guide
Everything you need to know about the EU AI Act: risk classifications, compliance timelines, penalties, and implementation strategies.
Read the GuideEU Member State Implementation Guides
Germany
Bundesnetzagentur oversight, KI-VO implementation, works council requirements.
France
CNIL coordination, sectoral regulators, French AI strategy alignment.
Spain
AESIA sandbox, early adopter status, regional considerations.
Italy
AgID coordination, Garante privacy integration, sectoral enforcement.
Netherlands
Autoriteit Persoonsgegevens role, algorithmic impact assessments.
Belgium
EU institution proximity, federal structure, BIPT coordination.
Poland
IT outsourcing hub, cross-border compliance, UODO coordination.
Role-Specific EU AI Act Guides
CISO guide
Security requirements, Article 12 logging, cybersecurity integration, incident response.
General Counsel guide
Legal liability, contract requirements, due diligence, regulatory exposure.
CCO guide
Compliance program design, risk assessment, audit preparation, documentation.
CMIO guide
Clinical AI governance, human oversight, diagnostic AI systems, ambient scribes.
UK AI Regulation
The UK’s pro-innovation approach to AI governance, sector-specific oversight, and comparison with EU requirements.
UK AI framework
Pro-innovation principles, sector regulators, AI Security Institute, and upcoming legislation.
UK vs EU AI Act
Regulatory divergence, dual compliance strategies, and cross-border considerations.
UK healthcare AI
MHRA AI-as-medical-device, CQC oversight, NHS AI Lab, and clinical AI requirements.
UK financial services AI
FCA and PRA AI oversight, Consumer Duty, SM&CR accountability, and model risk.
US State AI Laws
State-level AI regulation is expanding rapidly. Navigate the evolving patchwork of US AI laws.
US State AI Laws Overview
Comprehensive survey of state-level AI regulation across the US, from Colorado to California and beyond.
Read the GuideCalifornia
AB 2013 training data transparency, employment AI rules, bot disclosure, and political deepfakes.
New York
NYC Local Law 144 hiring audits, RAISE Act frontier safety, LOADinG Act, and NYDFS guidance.
Washington state
Facial recognition regulation, My Health My Data Act, AI Task Force, and pending HB 1168.
Oregon
OCPA profiling opt-out, campaign deepfake disclosure, AG guidance, and 2026 amendments.
Framework Crosswalks
Understand how different AI governance frameworks align, overlap, and complement each other.
ISO 42001 vs EU AI Act
Control mapping, certification value, implementation synergies between the AI management standard and regulation.
NIST AI RMF vs EU AI Act
US framework alignment with EU regulation, dual compliance strategies for multinational organizations.
EU AI Act vs HIPAA
Healthcare AI compliance across jurisdictions, PHI handling with AI systems, dual compliance requirements.
Runtime Evidence & AI Security Research
Evidence-grade explainers on verifiable AI, runtime attestation, and proving what your controls actually did — the OVERT series.
AI Agent Security: Prove What the Agent Did
Enforcing controls at the action boundary, with signed receipts for what the agent actually did.
Agentic AI Security: Runtime Coverage
Why agent security is a runtime problem, and what coverage actually means.
AI Security Solutions That Leave a Receipt
The difference between claiming a control fired and proving it.
AI in Cyber Security: The Evidence Layer
Detection made the SOC faster; neither detection nor response proves a control held.
AI Data Security: Verify a Receipt, Not the Data
Proof without exposure: only hashes and signatures cross the line.
After a Prompt Injection Attack: Prove What Held
When an attack lands, the question is what your controls did — and whether you can show it.
Verifiable AI: When One Jailbreak Pulls a Model
Model-level safety fails open; action-level evidence doesn't.
What Is AI Governance?
Beyond policy documents: governance as enforced behavior plus evidence.
AI Governance Tools: A System of Proof
What to demand from governance tooling beyond dashboards.
AI Governance Solutions: From Policy to Proof
Evaluating solution categories by what they can prove, not what they promise.
AI Governance Maturity Model
From policy to proof: a maturity path measured in verifiable evidence.
Documentation Is Not Evidence
Why artifacts of intent can't stand in for artifacts of behavior.
The AI Governance Challenge No One Names
The unnamed gap between what governance declares and what systems do.
What Makes AI Attestation Independent?
Independence is a property of who must be trusted to check the claim.
High-Risk AI Use Case Guides
Detailed compliance guidance for specific AI applications classified as high-risk under the EU AI Act.
Ambient AI scribes
Clinical documentation AI, HIPAA intersection, consent requirements, Sharp lawsuit implications.
Clinical decision support
CDSS compliance, FDA oversight, medical device classification, clinical workflow integration.
AI-assisted diagnosis
Diagnostic AI systems, radiology AI, pathology AI, MDR compliance requirements.
Credit scoring AI
Creditworthiness assessment, ECOA/FCRA compliance, adverse action requirements, model validation.
Insurance underwriting AI
Risk assessment AI, pricing algorithms, claims processing, actuarial model compliance.
Employment AI
Recruitment AI, resume screening, performance evaluation, worker monitoring compliance.
Biometric AI systems
Facial recognition, emotion detection, biometric categorization, prohibited uses.
AI chatbots
Transparency requirements, disclosure obligations, when chatbots become high-risk.
More Resources
Turn one workflow into evidence
Get runtime coverage. We map one high-risk AI workflow, place local controls, instrument signed receipts, and assemble the evidence pack reviewers can use.
Get runtime coverage