JOURNALLong-form · compliance · CISO · engineering

Notes on AI agent compliance.

Long-form writing for compliance officers, CISOs and engineers who need to understand the regulatory shape of AI agents in production.

Ops Playbook

Fleet-deploying AI audit — the ops-team playbook

One developer's pip install to an entire enterprise estate without manual touch. SCCM, Intune, Ansible, Kubernetes — the patterns that actually work at fleet scale.

Architecture

Retention vs notarisation — why both, not either

Retention is how long you keep evidence. Notarisation is whether the evidence is provable. They solve different problems and you need both — here's the framework.

Procurement

The SCIM + SSO procurement checklist for AI vendors

Which SCIM operations matter, what SSO modes to require, and which "we support SSO" claims are actually thin wrappers. Put this on every vendor evaluation.

Explainer

How to prove what an AI agent did — a practical guide

Proving what an AI agent did needs a contemporaneous record, a tamper-evident mechanism, and a regulator-acceptable format. The five-step pattern every defensible audit trail uses.

RFC 3161

RFC 3161 timestamping for AI audit logs — why it matters

A hash chain proves internal consistency. RFC 3161 proves the records existed at a specific moment in time. How a TSA round-trip works and why your AI logs need one.

SOC 2 vs AI Act

Article 12 vs SOC 2 — what each one actually covers

Compliance officers keep asking: we have SOC 2 — does that cover the AI Act? No. They audit different layers. The side-by-side so you can stop re-explaining it in procurement reviews.

EU AI Act

EU AI Act Article 12 explained — what record-keeping actually means

The clearest plain-English breakdown of what high-risk AI systems must log under Article 12, what the AI Office has signalled as adequate, and how to operationalise it before August 2026.

Insurance

Cyber insurance is repricing AI risk — here's what underwriters want to see

Specialty brokers and Lloyd's syndicate underwriters increasingly require AI logging evidence at renewal. What the submissions actually ask for, and how to answer.

Engineering

Why Datadog and Splunk can't produce an Article 12 pack

An engineer's-eye view: the structural reasons general-purpose observability and SIEM tooling don't capture the right shape of evidence for AI agent compliance.

Our blog is where the long-form thinking lives. We write for the people who actually have to make AI agent compliance work — CISOs preparing for the EU AI Act, compliance officers translating Article 12 into engineering tickets, and engineers shipping evidence packs to auditors. No gated PDFs and no email-walled webinars. Everything is published openly, indexed properly, and built to be cited.

Cadence is roughly weekly. We publish when we have something specific to say — a regulatory interpretation that's load-bearing in our discovery conversations, a piece of engineering nuance we keep explaining, or a comparison with another tool we've evaluated and want to be straight about. If you're researching for a procurement review, you'll find more substance here than in the marketing pages. If you're researching for an essay, every claim is sourced.

Follow long-form on LinkedIn; RSS at /blog/feed.xml ships alongside the next docs cut. Pull-requests on factual errors welcome — the repository will be public when the SDK launches on PyPI.