<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:dc="http://purl.org/dc/elements/1.1/">
  <channel>
    <title>Warrant · register</title>
    <link>https://www.warrant.build/blog/</link>
    <description>Sub-clause-cited reads on AI agent compliance across nine regulatory regimes and six jurisdictions. Every entry anchored in primary regulator text.</description>
    <language>en</language>
    <copyright>Warrant 2026. On the public record.</copyright>
    <pubDate>Mon, 11 May 2026 21:00:00 +0000</pubDate>
    <lastBuildDate>Mon, 11 May 2026 21:00:00 +0000</lastBuildDate>
    <atom:link href="https://www.warrant.build/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <managingEditor>team@warrant.build (Warrant Editorial)</managingEditor>
    <webMaster>team@warrant.build (Warrant Engineering)</webMaster>
    <image>
      <url>https://www.warrant.build/assets/logo-stamp.svg</url>
      <title>Warrant · register</title>
      <link>https://www.warrant.build/blog/</link>
    </image>



    <item>
      <title>Does the EU AI Act require a separate record for every autonomous agent action?</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-12-agentic-per-action-records</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-12-agentic-per-action-records</guid>
      <pubDate>Mon, 08 Jun 2026 09:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 12 of Regulation (EU) 2024/1689 binds high-risk AI systems to the automatic recording of events over the lifetime of the system.]]></description>
    </item>

    <item>
      <title>CFPB AI guidance, line by line.</title>
      <link>https://www.warrant.build/blog/cfpb-ai-consumer-protection</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/cfpb-ai-consumer-protection</guid>
      <pubDate>Mon, 11 May 2026 20:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>us-federal</category>
      <description><![CDATA[CFPB Circular 2022-03 on ECOA adverse-action notices when AI is used. 2023 chatbot supervisory highlights. 2024 interagency AVM rule. CFPB Circular 2024-06 on algorithmic scores. The US Federal consumer-finance regulator's position on AI explainability and UDAAP exposure.]]></description>
    </item>

    <item>
      <title>PIPL + CAC AI rules, line by line.</title>
      <link>https://www.warrant.build/blog/pipl-china-personal-information-protection-law</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/pipl-china-personal-information-protection-law</guid>
      <pubDate>Mon, 11 May 2026 20:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>china</category>
      <description><![CDATA[China Personal Information Protection Law (PIPL, effective 2021-11-01) + CAC Generative AI Measures (2023-08-15) + Deep Synthesis Provisions (2023-01-10). Article 24 automated decision-making. Articles 38-43 cross-border transfer. Articles 55-56 PIPIA. The APAC privacy stack with extraterritorial reach.]]></description>
    </item>

    <item>
      <title>OWASP LLM Top 10, line by line.</title>
      <link>https://www.warrant.build/blog/owasp-llm-top-10</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/owasp-llm-top-10</guid>
      <pubDate>Mon, 11 May 2026 19:30:00 +0000</pubDate>
      <dc:creator>Warrant Engineering</dc:creator>
      <category>engineering</category>
      <description><![CDATA[The OWASP Top 10 for Large Language Model Applications (2025 edition). Ten applied security categories from prompt injection through unbounded consumption. Cross-references to NIST AI 100-2 attack taxonomy and EU AI Act Article 15(5) cybersecurity obligation.]]></description>
    </item>

    <item>
      <title>NIST AI 100-2, line by line.</title>
      <link>https://www.warrant.build/blog/nist-ai-100-2-adversarial-ml</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/nist-ai-100-2-adversarial-ml</guid>
      <pubDate>Mon, 11 May 2026 19:00:00 +0000</pubDate>
      <dc:creator>Warrant Engineering</dc:creator>
      <category>engineering</category>
      <description><![CDATA[NIST AI 100-2e2025 — Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations. Four top-level attack classes (Evasion, Poisoning, Privacy, Abuse). The engineering taxonomy that translates EU AI Act Article 15(5) cybersecurity into operational categories.]]></description>
    </item>

    <item>
      <title>EU AI Act Article 27, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-27-fundamental-rights-impact-assessment</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-27-fundamental-rights-impact-assessment</guid>
      <pubDate>Mon, 11 May 2026 18:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 27 of Regulation (EU) 2024/1689 sets the fundamental rights impact assessment obligation for high-risk AI deployers. Article 26(9) is the trigger. Six contents elements under 27(1)(a)-(f). The AI Office template under 27(5). Notification to market surveillance authority under 27(3). Sister piece to Article 26 deployer obligations.]]></description>
    </item>

    <item>
      <title>EU AI Act Article 15, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-15-accuracy-robustness-cybersecurity</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-15-accuracy-robustness-cybersecurity</guid>
      <pubDate>Mon, 11 May 2026 17:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 15 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to design and develop the system to achieve an appropriate level of accuracy, robustness, and cybersecurity, and to perform consistently across the lifecycle. Accuracy levels are declared in the Article 13 instructions for use. Resilience covers errors, faults, inconsistencies, fail-safe + redundancy. Cybersecurity covers data poisoning, model poisoning, model evasion, confidentiality attacks. The technical-quality bar of the EU AI Act.]]></description>
    </item>

    <item>
      <title>EU AI Act Article 9, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-9-risk-management</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-9-risk-management</guid>
      <pubDate>Mon, 11 May 2026 16:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 9 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to establish, implement, document, and maintain a risk management system as a continuous iterative process planned and run throughout the entire lifecycle. Ten paragraphs covering the four-step process (identification, estimation, evaluation, adoption of measures), residual-risk acceptability, real-world testing under Article 60, minors and vulnerable groups, and integration with the Article 17 quality management system.]]></description>
    </item>

    <item>
      <title>EU AI Act Article 26, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-26-deployer-obligations</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-26-deployer-obligations</guid>
      <pubDate>Mon, 11 May 2026 12:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 26 of Regulation (EU) 2024/1689 binds deployers of high-risk AI systems. Twelve paragraphs covering use per the provider's instructions for use, competent staff for human oversight, input data relevance, monitoring and serious-incident reporting, log retention floor of six months, workplace-AI worker notification, data-subject notification, public-authority registration under Annex VIII, the DPIA cross-reference, and the Article 27 fundamental-rights impact assessment trigger. Sister piece to the Article 12 / Article 13 / Article 14 reads.]]></description>
    </item>

    <item>
      <title>EU AI Act Article 14, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-14-human-oversight</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-14-human-oversight</guid>
      <pubDate>Mon, 11 May 2026 11:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 14 of Regulation (EU) 2024/1689 binds providers of high-risk AI systems to design and develop the system so it can be effectively overseen by natural persons. The five oversight capabilities the natural person must have are listed verbatim: understanding capacities and limitations, awareness of automation bias, correct interpretation of outputs, the right to disregard or override, the capability to intervene or interrupt. The four-eyes principle in Article 14(5) for biometric identification under Annex III(1).]]></description>
    </item>

    <item>
      <title>EU AI Act, Digital Omnibus, 2026-05-07.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-omnibus-may-7-2026</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-omnibus-may-7-2026</guid>
      <pubDate>Fri, 08 May 2026 12:00:00 +0000</pubDate>
      <dc:creator>Warrant Editorial</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[On 2026-05-07 the Council and European Parliament reached a provisional agreement on the Digital Omnibus on AI deferring the Annex III standalone high-risk application date from 2 August 2026 to 2 December 2027. Annex I embedded high-risk moves to 2 August 2028. Article 50 transparency to 2 December 2026. Provisional, pending Council and Parliament endorsement, legal-linguistic revision, and OJEU publication. Until then the AI Act as enacted continues to govern.]]></description>
    </item>

    <item>
      <title>Colorado AI Act + CCPA ADMT regulations, line by line.</title>
      <link>https://www.warrant.build/blog/colorado-ai-act-ccpa-admt</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/colorado-ai-act-ccpa-admt</guid>
      <pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>us-state-ai</category>
      <description><![CDATA[Colorado AI Act (SB24-205, signed 17 May 2024) and California CCPA ADMT regulations (CPPA, finalised 24 July 2025). Two state-level frameworks for automated decision-making technology in 2026. Reasonable-care duty, consumer notice obligations, opt-out rights, and risk-assessment requirements.]]></description>
    </item>

    <item>
      <title>EU AI Act Annex IV, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-annex-iv-technical-documentation</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-annex-iv-technical-documentation</guid>
      <pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description><![CDATA[Article 11 of Regulation (EU) 2024/1689 obliges every provider of a high-risk AI system to draw up technical documentation before placing the system on the Union market. Annex IV defines, in nine sections, what the documentation must contain. Application 2026-08-02 (subject to provisional deferral to 2027-12-02 under May 2026 Omnibus). The line-by-line reading.]]></description>
    </item>

    <item>
      <title>GDPR Article 22, line by line.</title>
      <link>https://www.warrant.build/blog/gdpr-article-22-automated-decision-making</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/gdpr-article-22-automated-decision-making</guid>
      <pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>gdpr</category>
      <description><![CDATA[Regulation (EU) 2016/679 Article 22 line-by-line. The data subject's right not to be subject to a decision based solely on automated processing, including profiling, which produces legal effects or similarly significantly affects the data subject. Read against AI agents in production.]]></description>
    </item>

    <item>
      <title>HIPAA + healthcare AI, line by line.</title>
      <link>https://www.warrant.build/blog/hipaa-healthcare-ai</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/hipaa-healthcare-ai</guid>
      <pubDate>Sat, 09 May 2026 00:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>hipaa</category>
      <description><![CDATA[HIPAA Privacy Rule (45 CFR Part 164 Subpart E) and Security Rule (Subpart C) read against AI agents handling protected health information. Minimum-necessary, business-associate-agreement, audit-control, and breach-notification obligations applied to the AI deployment perimeter.]]></description>
    </item>

    <item>
      <title>MAS FEAT principles + AIRM, line by line.</title>
      <link>https://www.warrant.build/blog/mas-feat-airm</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/mas-feat-airm</guid>
      <pubDate>Sat, 09 May 2026 14:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>mas-feat</category>
      <description>Singapore MAS FEAT principles (12 Nov 2018) plus the AIRM Information Paper (Dec 2024). The 14 sub-principles + 8 AIRM sections + Veritas Toolkit v2.0. The supervisory expectation tier for Singapore-licensed FIs.</description>
    </item>

    <item>
      <title>India DPDP Act 2023, line by line.</title>
      <link>https://www.warrant.build/blog/india-dpdp-act</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/india-dpdp-act</guid>
      <pubDate>Sat, 09 May 2026 13:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>dpdp</category>
      <description>Digital Personal Data Protection Act 2023 line-by-line. The full Section 8 obligations of a data fiduciary. DPDP Rules 2025 notified 13 Nov 2025; Rule 7 breach notification within 72 hours. DPB constituted under § 18 in Chapter V. Substantive obligations effective 13 May 2027.</description>
    </item>

    <item>
      <title>SEBI Retail Algorithmic Trading Framework, line by line.</title>
      <link>https://www.warrant.build/blog/sebi-retail-algorithmic-trading</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/sebi-retail-algorithmic-trading</guid>
      <pubDate>Sat, 09 May 2026 13:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>sebi</category>
      <description>SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/0000013 (4 Feb 2025) + extension SEBI/HO/MIRSD/MIRSD-PoD/P/CIR/2025/132 (30 Sep 2025). Framework universally applicable to all stock brokers wef 1 April 2026. Glide-path milestones verified verbatim from SEBI PDFs.</description>
    </item>

    <item>
      <title>RBI FREE-AI, line by line.</title>
      <link>https://www.warrant.build/blog/rbi-free-ai</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/rbi-free-ai</guid>
      <pubDate>Sat, 09 May 2026 12:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>rbi-free-ai</category>
      <description>RBI Framework for Responsible and Ethical Enablement of AI report (13 August 2025). Committee chaired by Dr Pushpak Bhattacharyya, IIT Bombay. 7 sutras, 6 pillars (3 innovation enablement + 3 risk mitigation), 26 recommendations.</description>
    </item>

    <item>
      <title>OECD principles, ISO/IEC 24028, and the AIGP body of knowledge.</title>
      <link>https://www.warrant.build/blog/oecd-iso-24028-aigp</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/oecd-iso-24028-aigp</guid>
      <pubDate>Sat, 09 May 2026 11:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>standards</category>
      <description>Three references compliance officers reach for before opening any binding regulator. OECD AI Principles (2019/2024), ISO/IEC 24028:2020 trustworthiness vocabulary, IAPP AIGP body of knowledge (since March 2024).</description>
    </item>

    <item>
      <title>NIST AI RMF 1.0 + Generative AI Profile, line by line.</title>
      <link>https://www.warrant.build/blog/nist-ai-rmf</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/nist-ai-rmf</guid>
      <pubDate>Sat, 09 May 2026 11:15:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>nist-ai-rmf</category>
      <description>Four functions: GOVERN · MAP · MEASURE · MANAGE. NIST AI 100-1 (Jan 2023) + NIST AI 600-1 GenAI Profile (Jul 2024). Cited explicitly in EO 14110 and OMB M-24-10. Crosswalks with ISO/IEC 42001 and the OECD principles.</description>
    </item>

    <item>
      <title>ISO/IEC 42001:2023, line by line.</title>
      <link>https://www.warrant.build/blog/iso-iec-42001-ai-management-system</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/iso-iec-42001-ai-management-system</guid>
      <pubDate>Sat, 09 May 2026 11:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>iso-42001</category>
      <description>The first international management system standard for AI. Published 18 Dec 2023. AIMS analogous to ISO 27001 for infosec. 38 controls in Annex A. Likely backbone of CEN-CENELEC harmonised standards for EU AI Act conformity.</description>
    </item>

    <item>
      <title>EU AI Act Article 13, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-13</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-13</guid>
      <pubDate>Sat, 09 May 2026 11:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description>Article 12 binds the provider to log. Article 13 binds the same provider to give the deployer instructions sufficient to interpret those logs. The paired-obligation reading of Reg (EU) 2024/1689.</description>
    </item>

    <item>
      <title>SR 11-7 + SR 26-2, line by line.</title>
      <link>https://www.warrant.build/blog/sr-11-7-model-risk</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/sr-11-7-model-risk</guid>
      <pubDate>Sat, 09 May 2026 10:30:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>federal-reserve</category>
      <description>Federal Reserve / OCC / FDIC interagency guidance on model risk management. SR 11-7 four pillars carried forward through SR 26-2 with explicit AI/ML scope. The model risk management framework as evidence obligation.</description>
    </item>

    <item>
      <title>FCA Consumer Duty Principle 12, line by line.</title>
      <link>https://www.warrant.build/blog/fca-consumer-duty-principle-12</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/fca-consumer-duty-principle-12</guid>
      <pubDate>Sat, 09 May 2026 10:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>fca</category>
      <description>PRIN 2A line-by-line. The four outcomes (products, value, understanding, support) read against an AI agent making customer-facing decisions. Why the SMF holder's personal liability under SMCR makes Consumer Duty evidence non-optional.</description>
    </item>

    <item>
      <title>the four-layer evidence stack.</title>
      <link>https://www.warrant.build/blog/four-layer-evidence-stack</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/four-layer-evidence-stack</guid>
      <pubDate>Fri, 08 May 2026 10:00:00 +0000</pubDate>
      <dc:creator>Warrant Engineering</dc:creator>
      <category>architecture</category>
      <description>Observability is not the same as runtime. Runtime is not the same as evidence. Evidence is not the same as attestation. Mix them up and you ship a tool the regulator does not accept.</description>
    </item>

    <item>
      <title>evals are the moat. not the model.</title>
      <link>https://www.warrant.build/blog/regulator-grade-evals</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/regulator-grade-evals</guid>
      <pubDate>Fri, 08 May 2026 10:30:00 +0000</pubDate>
      <dc:creator>Warrant Research</dc:creator>
      <category>engineering</category>
      <description>200 traces. 800 stage-evals. Citation precision benchmark cross-checks every sub-clause against canonical regulator text. How three real bugs got caught.</description>
    </item>

    <item>
      <title>one agent. many jurisdictions.</title>
      <link>https://www.warrant.build/blog/one-agent-many-jurisdictions</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/one-agent-many-jurisdictions</guid>
      <pubDate>Fri, 08 May 2026 11:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>compliance</category>
      <description>The same trace evaluated against EU AI Act, FCA Consumer Duty, NYDFS Part 500, SR 11-7, RBI FREE-AI, SEBI, India DPDP, MAS FEAT, simultaneously. Nine frameworks. Six jurisdictions. One evidence package mapped to each obligation, verifiable independently.</description>
    </item>

    <item>
      <title>Standard API call logs do not satisfy 23 NYCRR § 500.6.</title>
      <link>https://www.warrant.build/blog/nydfs-standard-logs</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/nydfs-standard-logs</guid>
      <pubDate>Thu, 07 May 2026 13:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>nydfs</category>
      <description>On 16 October 2024 NYDFS issued an Industry Letter on AI cybersecurity. The letter imposes no new rules. It applies 23 NYCRR Part 500 to AI, including § 500.6(a)(2) audit trails. Read against that rule, standard API call logs and LLM inference logs do not satisfy.</description>
    </item>

    <item>
      <title>The agent perimeter is not a metaphor anymore.</title>
      <link>https://www.warrant.build/blog/agent-perimeter</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/agent-perimeter</guid>
      <pubDate>Thu, 07 May 2026 12:00:00 +0000</pubDate>
      <dc:creator>Warrant Editorial</dc:creator>
      <category>essay</category>
      <description>A piece on Hacker News this week framed AI agents as already-inside-the-perimeter actors. The metaphor is right but understates the structural shift. The perimeter has stopped being a network boundary and started being a logging boundary.</description>
    </item>

    <item>
      <title>EU AI Act Article 12, line by line.</title>
      <link>https://www.warrant.build/blog/eu-ai-act-article-12</link>
      <guid isPermaLink="true">https://www.warrant.build/blog/eu-ai-act-article-12</guid>
      <pubDate>Thu, 07 May 2026 11:00:00 +0000</pubDate>
      <dc:creator>Warrant Compliance</dc:creator>
      <category>eu-ai-act</category>
      <description>Four paragraphs of Regulation (EU) 2024/1689. Verbatim text, the in-scope determination under Annex III, the retention rules, and the penalty exposure under Article 99(4). Enforcement begins 2 August 2026.</description>
    </item>
  </channel>
</rss>
