Guides for regulated buyers

What to check before you
buy enterprise AI.

Practical, vendor-neutral guidance on the questions that decide whether an AI deployment clears its first audit. Each guide traces where your data actually flows and what your regulators will expect to see when it does. They are written by the team that builds sovereign AI, and they are meant to be useful whether or not you ever become a customer.

The library

The library is open and free to read.

There is no email gate and no download wall, so every guide is free to read in full. Filter by topic or by the region whose regulators you answer to, and start with the guide that maps to your next audit.

Topic

Region

Compliance

The EU AI Act Article 12 readiness guide

What record-keeping and human-oversight obligations actually require operationally from August 2026 — and the evidence an auditor will ask you to produce.

9 min readDACH
Read
Procurement

The sovereign AI buyer's checklist

Twelve concrete questions that separate verifiable sovereignty from a configuration checkbox — ask them of every vendor, including us.

8 min readGlobal
Read
Risk

Shadow AI: your biggest leak is a paste-⁠box

Why employees pasting contracts into public chatbots is a legal exposure, not an IT nuisance — and why bans fail where better tools succeed.

7 min readGlobal
Read
Compliance

DIFC Regulation 10, explained for platform owners

The Dubai financial centre's AI rules on processing records, human oversight and tamper-resistance — and why deployment architecture decides how hard your audit is.

7 min readGlobal
Read
Economics

Token economics: why your AI bill scales with sloppy context

How RAG and agent context quietly inflate token spend, what compression can and cannot safely remove, and what a 48–79% measured reduction means for a real workload.

8 min readGlobal
Read
Risk

The credentials nobody reviews

Your AI agents hold OAuth tokens, API keys and service accounts that went through no approval process. The agent was reviewed. The studio was reviewed. The identity behind them was not.

5 min readGlobal
Read
Security

When the agents organised themselves: what the Hugging Face swarm means for accountability

Roughly 700 AI agents divided labour, traded favours and compromised production infrastructure across four regions. The uncomfortable part is not that it happened — it is that the account of what happened had to be reconstructed afterwards, by outside parties.

6 min readGlobal
Read
Governance

Apple tightens macOS disk access as AI agents get more capable

Apple is adding friction to macOS Full Disk Access because AI agents are now capable enough to misuse it. The operating system vendor moving first is a signal every enterprise running agents should read carefully.

5 min readGlobal
Read
Security

Why a vendor just built a kill switch for your AI agents

AppViewX expanded its Agent Identity Security platform to discover shadow agents, log what they do and shut them off in real time. The capability it had to add tells you what is already running unseen.

5 min readGlobal
Read
Compliance

AI guardrails in Australia: what the Voluntary AI Safety Standard, Essential Eight and Privacy Act reform mean for enterprise AI

Australia is converging on AI governance from three directions at once — safety guardrails, cyber baselines and privacy reform — and enterprise AI platforms must now prove all three.

6 min readAPAC
Read
Sovereignty

Digital sovereignty, in numbers: what Bitkom's surveys tell every AI buyer

Half of German companies would be paralyzed by a cloud outage — and four in ten already accept trade-offs for sovereign alternatives. The demand is real; the trade-off doesn't have to be.

7 min readDACH
Read
Governance

Evidence before inference: what Cloudflare's new SOC agents get right

Cloudflare has rebuilt its Managed Defense alert triage around a rule most agentic AI projects skip - collect evidence deterministically first, let the model reason second. The architecture is a useful benchmark for any enterprise building agents that touch security decisions.

5 min readGlobal
Read
Governance

When agents build their own networks, who is watching the wiring

doxx.net has opened public beta on a platform that lets AI agents configure their own private networks, and raised 38 million dollars to do it. The architecture solves a real problem. It also creates a new place where enterprise agent traffic can leave without anyone logging it.

5 min readGlobal
Read
Governance

What practitioners actually say about running agents in production

QCon San Francisco 2026 put Airbnb, OpenAI, Netflix and Honeycomb engineers on stage to describe how they operate AI agents at scale. Their lessons point at the same gap a regulated enterprise cannot leave open.

5 min readGlobal
Read
Compliance

Sovereign AI in France: What ANSSI, CNIL and the Cloud de Confiance Doctrine Expect

France has turned trustworthy AI into published doctrine — ANSSI's generative-AI security recommendations, CNIL's GDPR fiches and the SecNumCloud trusted-cloud standard form a concrete requirements list for any enterprise AI platform.

6 min readEurope
Read
Governance

AI is rewriting DevOps faster than most pipelines can review it

DORA's own research body has had to build a new capabilities model because AI changes what "good DevOps" means. For regulated enterprises, the harder question is not whether code ships faster, but whether anyone can still show what shipped and why.

5 min readGlobal
Read
Compliance

India's DPDP Act and Enterprise AI: What MeitY, CERT-⁠In and RBI Expect You to Prove

India's compliance stack for enterprise AI — the DPDP Act 2023 and its 2025 Rules, CERT-In's six-hour incident clock and RBI's FREE-AI framework — rewards platforms that can prove data residency, evidence and oversight by architecture.

6 min readAPAC
Read
Governance

Cloudflare's Clef and the governance gap inside agentic pipelines

Cloudflare has open-sourced Clef and Clef-flash, decision models built for routing and classification inside agentic workflows, plus a reinforcement learning platform to fine-tune them on your own data. Fast, cheap decisions are not the hard part. Knowing which ones were made, and why, is.

5 min readGlobal
Read
Governance

An AI agent wiped an Azure tenant in seven minutes

JadePuffer used a leaked service principal to let an autonomous AI agent map an Azure tenant and destroy it. The attack ran in minutes. The credential had been exposed for longer than anyone checked.

5 min readGlobal
Read
Compliance

Japan AI Governance: What the AI Promotion Act, METI Guidelines and APPI Expect of Enterprises

Japan's AI Promotion Act, the METI/MIC AI Guidelines for Business and a tightening APPI form a soft-law stack that still expects enterprises to prove governance, human oversight and domestic data control.

6 min readAPAC
Read
Governance

A dismissed spyware case and the audit trail nobody could produce

A California judge threw out a Pegasus spyware case brought by El Faro's journalists on jurisdiction, not on the facts. The infections were real; the record of who ordered them was not. That gap is a governance failure any regulated enterprise can inherit.

5 min readGlobal
Read
Governance

Rewinding an AI agent is not the same as governing one

LTM's new AgenTraceIQ promises to monitor AI agents and reverse their unintended actions. The rewind is real and overdue, but it only works if you can already prove what the agent did.

5 min readGlobal
Read
Security

OpenAPPA hit 0% attack success on two benchmarks. Here's what that actually proves

An open source security engine stopped every attack across two independent benchmarks, while an established agent framework let three in ten through. The result says less about one product than about where prompt injection defences now have to sit.

5 min readGlobal
Read
Compliance

NIS2 and your AI stack: who answers when an agent acts?

NIS2 makes management personally accountable for cybersecurity risk — including the AI agents you are about to deploy. Here is the operational checklist.

6 min readDACH
Read
Governance

Pizza Bot and the agents nobody is watching

AWS engineers open-sourced an inbox for background AI agents that work unattended and pause for approval. The design is sound. The reason it matters is how few organisations could say the same about the agents they already run.

5 min readGlobal
Read
Governance

What DoorDash's GenAI platform admits about vendor lock-⁠in

DoorDash told InfoQ it moved 5,000 internal users off a vendor-first model strategy and onto self-hosted open-weight models through a gateway it built itself. The reasons it gave are the reasons any enterprise running agents at scale will eventually hit.

5 min readGlobal
Read
Governance

Why your agent evaluation framework is the control nobody audits

Elastic's own evaluation lead says most agent testing is ad hoc and siloed. A separate survey of 157 enterprises found half have already shipped an agent that passed internal evaluation and then failed a customer anyway.

5 min readGlobal
Read
Compliance

TRACE and the end of "we have a policy for that"

A Linux Foundation standard now lets an AI system prove what it actually did at runtime — hardware-backed, cryptographically verifiable. That changes what an auditor can reasonably ask you for.

5 min readGlobal
Read
Compliance

Singapore AI Governance: What IMDA, PDPC and MAS Expect Enterprises to Prove

Singapore's AI governance stack — IMDA's Model AI Governance Framework, AI Verify testing, PDPC's PDPA guidance and MAS FEAT — rewards enterprises whose AI claims are provable, not merely stated.

6 min readAPAC
Read
Governance

Two zero-⁠days and an AI that explained its own actions

An agentic AI attack chained two unknown flaws against the Dutch institute that exists to find flaws like them, and left behind notes justifying each step. The target was a warning; the method is the one every enterprise now has to plan for.

5 min readGlobal
Read
Compliance

UK AI assurance: what NCSC, ICO, DUAA and SS1/23 now expect from enterprise AI

The UK regulates AI through its existing regulators — and since DUAA took effect, "a human clicked approve" no longer counts as oversight. Here is the evidence they expect.

6 min readUK
Read
Governance

The ungoverned prompt, documented: the incident record every AI policy should cite

The case against ungoverned workplace AI does not rest on hypotheticals. From Samsung's source-code leaks to the breach notifications on a regulator's desk and a €15 million fine, this is the documented record — with dates and sources.

7 min readGlobal
Read
Security

The ungoverned prompt: what your company shares with AI when nobody is looking

Employees adopted AI years before their companies did — through personal accounts and tools IT has never seen. The result is a data flow nobody authorized, nobody logs, and nobody can produce when a regulator asks.

5 min readGlobal
Read
Governance

Who trained the agent you are about to deploy?

A hobbyist posting Reddit updates on a home-trained agentic model is harmless on its own. The pattern behind it, open-weight, agent-capable models with no traceable training record moving into real companies, is not.

5 min readGlobal
Read
Compliance

NIST AI RMF: the playbook US enterprises are measured against — and how to pass it

The NIST AI Risk Management Framework is voluntary on paper and mandatory in practice — here is how US enterprises turn Govern, Map, Measure and Manage into evidence a regulator, court or customer will accept.

6 min readAmericas
Read