Compliance and regulation
4 articles on compliance and regulation from the Penaxtra engineering, security research, and compliance teams.
4 articles, newest first. Click a category in the left sidebar to narrow the list; the column headers below are static labels.
| Article | Category | Read | Published |
|---|---|---|---|
| The High-Risk Deferral Is Law. The August Date Landed Anyway. The Digital Omnibus on AI entered into force on 27 July 2026, moving the EU AI Act high-risk deadline to December 2027. What most summaries miss is that 2 August 2026 still arrived for everything the deferral did not touch, and that a longer runway does not extend the record you have to show at the end of it. | Compliance and regulation | 6 min | |
| The EU AI Act High-Risk Deadline Is Moving to 2027. The Work Did Not. The Digital Omnibus is set to push the EU AI Act high-risk deadline from August 2026 to December 2027 - politically agreed, not yet law. The obligations did not change, only the clock. What a security team still has to build. | Compliance and regulation | 9 min | |
| EU AI Act Cybersecurity Requirements for High-Risk AI Systems A practitioner's guide to Article 15 cybersecurity, Article 9 risk management, and Article 17 quality management for high-risk AI providers. What auditors will actually ask in 2026. | Compliance and regulation | 8 min | |
| NIST AI 600-1 Profile in 20 Minutes - What Auditors Care About A practitioner's reading of NIST AI 600-1, the Generative AI Profile under the NIST AI RMF. Which functions matter most, the three controls auditors ask about every time, and how to map them to live evidence. | Compliance and regulation | 6 min |