AI compliance frameworks
Obligation-by-obligation reference for the frameworks that come up in an LLM security review. Every date is cited to the body that set it, and every page records when that source was last checked. For our own audit and certification status, see the trust page instead.
EU AI Act obligations for LLM applications
What the EU AI Act (Regulation (EU) 2024/1689) requires of teams deploying LLM applications, and the dates that apply after the 2026 AI Omnibus amendment.
· 7 min readEU AI ActcomplianceregulationgovernanceGDPR and LLM data handling
How the GDPR applies when personal data goes into a prompt — lawful basis, transfers, DPIAs, retention and subject rights, for teams deploying LLM applications.
· 5 min readGDPRdata protectionPIIcomplianceISO/IEC 42001 for LLM applications
What ISO/IEC 42001:2023 certifies, how it differs from ISO/IEC 27001, and what an LLM deployment has to produce to survive the audit.
· 4 min readISO 42001certificationgovernancecomplianceNIST AI RMF for LLM applications
What the NIST AI Risk Management Framework (AI 100-1) and its Generative AI Profile (AI 600-1) ask of an LLM deployment, and what a control layer can evidence.
· 4 min readNIST AI RMFgovernancecompliancerisk managementOWASP LLM Top 10 coverage matrix
Which OWASP LLM Top 10 risks SecureAI Guard addresses, how, and which it does not address at all — stated per entry, including the gaps.
· 7 min readOWASP LLM Top 10coverageRFPcontrols