Skip to main content

AI compliance frameworks

Obligation-by-obligation reference for the frameworks that come up in an LLM security review. Every date is cited to the body that set it, and every page records when that source was last checked. For our own audit and certification status, see the trust page instead.


  • EU AI Act obligations for LLM applications

    What the EU AI Act (Regulation (EU) 2024/1689) requires of teams deploying LLM applications, and the dates that apply after the 2026 AI Omnibus amendment.

    · 7 min read
    EU AI Act
    compliance
    regulation
    governance
  • GDPR and LLM data handling

    How the GDPR applies when personal data goes into a prompt — lawful basis, transfers, DPIAs, retention and subject rights, for teams deploying LLM applications.

    · 5 min read
    GDPR
    data protection
    PII
    compliance
  • ISO/IEC 42001 for LLM applications

    What ISO/IEC 42001:2023 certifies, how it differs from ISO/IEC 27001, and what an LLM deployment has to produce to survive the audit.

    · 4 min read
    ISO 42001
    certification
    governance
    compliance
  • NIST AI RMF for LLM applications

    What the NIST AI Risk Management Framework (AI 100-1) and its Generative AI Profile (AI 600-1) ask of an LLM deployment, and what a control layer can evidence.

    · 4 min read
    NIST AI RMF
    governance
    compliance
    risk management
  • OWASP LLM Top 10 coverage matrix

    Which OWASP LLM Top 10 risks SecureAI Guard addresses, how, and which it does not address at all — stated per entry, including the gaps.

    · 7 min read
    OWASP LLM Top 10
    coverage
    RFP
    controls