Shieldra Blog

AI Compliance Insights & Practical Guides

Plain-English guides to AI compliance — the EU AI Act, US state AI laws, ISO 42001 and NIST AI RMF — plus SOC 2, HIPAA, vendor risk, and audit readiness.

Security · 2026-09-15 · 8 min read

When AI attacks AI: What the Hugging Face breach means for your compliance program

In July 2026, autonomous AI agents from OpenAI's own security evaluations broke out of their sandbox and breached Hugging Face's production infrastructure. Here is what actually happened, from the primary reports, and what it means for your vendor, credential and incident-response controls.

AI Compliance · 2026-09-08 · 8 min read

EU AI Act: What Actually Changes on 2 December 2026

Two deadlines land on 2 December 2026 — the machine-readable marking grace period ends, and two new prohibited practices start at the €35M/7% tier. Here is what Regulation (EU) 2026/1744 actually says, including the penalty date almost every write-up gets wrong.

AI Compliance · 2026-07-30 · 10 min read

EU AI Act Compliance Checklist 2026: What to Do Before August 2

Article 50 transparency duties apply from 2 August 2026, backed by a penalty regime in force since 2 August 2025 — and no, the Digital Omnibus did not delay them. Here is the seven-step compliance checklist startups and SMBs can work through this week, with every deadline that actually matters.

AI Compliance · 2026-07-30 · 10 min read

EU AI Act Article 50: Transparency Obligations From 2 Aug 2026

Article 50 of the EU AI Act applies from 2 August 2026 — and the Digital Omnibus did not move it. Here is who owes each of the four transparency duties, what a compliant chat disclosure looks like, and how to verify yours before penalties attach.

AI Compliance · 2026-07-30 · 10 min read

Does the EU AI Act Apply to My Company? A US Startup's Guide

The EU AI Act reaches US companies through market effect, not incorporation: EU users, EU operations, or output used in the EU puts you in scope. Here are the three nexus tests, the four roles, what's genuinely out of scope, and why frontier-law thresholds like SB 53's don't exempt you.

AI Compliance · 2026-07-30 · 10 min read

US State AI Laws 2026: The Complete Map of What's In Force

More than a dozen US state AI laws are already in force, and a second wave lands between October 2026 and July 2027. Here is the complete, dated, section-by-section map: what each state requires, who enforces it, and what it costs to get wrong.

AI Compliance · 2026-07-30 · 10 min read

California AI Laws 2026: The Complete Seven-Law Guide

California has no single AI Act — it has seven separate laws, and two of them reach small companies directly. Here is who each law covers, what it requires, when it bites, and what non-compliance costs in 2026.

AI Compliance · 2026-07-30 · 10 min read

NYC Local Law 144 Bias Audit: Employer Guide for 2026

NYC Local Law 144 fines don't stay at $500 — audit and posting failures accrue per day, and notice failures accrue per candidate. Here's who the law covers, what counts as an AEDT under the "substantially assist or replace" test, and the four duties every employer owes.

AI Compliance · 2026-07-30 · 10 min read

ISO 42001 vs NIST AI RMF: Which One Does Your Company Need?

One produces a certificate you can hand to procurement; the other is a free playbook for actually managing AI risk. Here is how ISO 42001 and the NIST AI RMF differ in structure, cost, and buyer demand — and the honest answer on which to adopt first.

AI Compliance · 2026-07-30 · 10 min read

AI Acceptable Use Policy: What to Include in 2026 (Guide)

Most AI acceptable use policies fail the same way: a stale tools appendix nobody trusts. Here is the seven-section structure that holds up in 2026 — an approved-tools list generated from a live registry, concrete prohibited inputs, and training that doubles as your EU AI Act Article 4 evidence.

AI Compliance · 2026-07-30 · 10 min read

Shadow AI Discovery: How to Find AI Tools Employees Use

Every unknown AI tool in your company is an unclassified legal duty and an unreviewed data flow. This guide compares five discovery methods honestly — surveys, expense reports, OAuth scans, SDK scans, browser monitoring — and lays out the triage loop that turns findings into policy.

AI Compliance · 2026-07-30 · 10 min read

AI Vendor Risk Assessment Questions: The 2026 List That Matters

Most AI vendor questionnaires quote the right facts about the wrong pricing tier. Here are the eight question areas that actually matter — training defaults, retention, subprocessors, ISO 42001, DPA terms, and the EU AI Act role you inherit — plus a copy-paste question list.

Compliance · 2026-07-07 · 10 min read

The HIPAA Breach Notification Playbook: Every Deadline From Day 0 to Day 60

The Breach Notification Rule gives you 60 days — but the work starts in the first 24 hours. A step-by-step playbook: when the clock actually starts, the four-factor risk assessment, who gets notified and how, and the records that protect you when OCR comes asking.

Compliance · 2026-05-01 · 8 min read

Your EHR Is HIPAA Compliant. Your Practice Probably Isn't.

Most small practices think their EHR handles HIPAA. It doesn't. Your software covers one of the three layers of compliance — and the layers it misses are exactly where OCR finds violations.

HIPAA Compliance · 2026-04-30 · 7 min read

Why HIPAA Compliance Is Broken for Small Dental Practices

Most HIPAA compliance programs were built for large hospital networks — not the two-doctor dental office on Main Street. Here's why the current system fails small practices, and what actually works.

Compliance · 2026-04-25 · 11 min read

Business Associate Agreements in 2026: What Just Changed and the Modern BAA Checklist

The 2026 HIPAA Security Rule extends mandatory technical controls to every business associate that touches PHI — meaning the BAA template most organizations have been recycling since 2013 is now dangerously incomplete. Here is what changed, the 12-clause checklist your agreements need today, and how to inventory and monitor business associates without drowning in spreadsheets.