blog
Field notes on AI compliance
25 posts · written for engineers shipping production AI systems.
- Aug 23, 20267 min · Oleg
We Beat a $10,000 Bid on outbid.lol With $151
The story of outbid.lol, the pay-to-rank board that made $182K in four days, and why our $151 bid beats the $10,000 spot above it.
- Aug 23, 202614 min · Frenkie
What Is Red Teaming and Why AI Systems Need It
Red teaming is structured adversarial testing. Learn how it exposes AI vulnerabilities — from prompt injection to agent hijacking — and how to build a continuous program.
- Aug 19, 20267 min · Frenkie
Why Your Security Stack Cannot See AI Agents
Legacy security assumes an adversary is either a person or a malicious program. An AI agent is authorized software that reasons and acts with valid permissions.
- Aug 15, 20266 min · Frenkie
Does Claude Watermark Its Text? What Anthropic's Invisible Marks Mean for Your Business
Since August 2, 2026, Claude embeds an invisible watermark in generated text worldwide with no opt-out. What the mark proves, what it does not, and the provenance question most leadership teams cannot answer.
- Aug 11, 202612 min · Justin
The Web Reserved a Slot for Money in the 1990s. Your AI Agent Just Used It.
x402 turned a dead HTTP status code into a live payment rail for software. The rules that govern money still assume a human pressed the button.
- Aug 8, 202610 min · Frenkie
Three Vendors Submitted Tools to Our Directory. Here Is What We Found.
Three vendors submitted tools this month. All three went to the radar, not the verified list — here is every claim we checked, and the two we could not confirm.
- Aug 3, 20266 min · Justin
Uber's CTO Just Admitted Your "Human in the Loop" Is a Rubber Stamp
Uber watched 50,000 agent sessions a day and found the security control every AI audit relies on quietly failing. Then it open-sourced the fix.
- Aug 2, 20266 min · Frenkie
We Analyzed Google Trends on AI Compliance. The Market Rotated in 2026
Our analysis of Google Trends data shows "AI governance" and "AI compliance" overtaking "AI regulation" in 2026, with South Korea and Singapore leading global demand.
- Jul 29, 202612 min · Justin
How to Ensure AI Compliance When Using Claude: The Operator's Guide
Anthropic's terms say you own Claude's outputs. That's the trap: owning the outputs means owning everything wrong with them. Here's the 10-step governance program that actually covers you.
- Jul 27, 20267 min · Justin
74 Companies Signed the Open Weights Letter. The Most Interesting Name Didn't.
The Open Weights letter grew from 25 to 74 signatories in days, flipping OpenAI and Google. Anthropic is the last frontier lab absent, and it hasn't said why.
- Jul 24, 20266 min · Frenkie
What Is AIUC-1? The AI Agent Certification Lovable Just Earned, Explained
AIUC-1 is the first security certification built for AI agents, with 51 requirements, quarterly red-teaming, and insurance backing. Lovable just became the first certified coding agent platform.
- Jul 23, 20268 min · Frenkie
Can Your Company Legally Use Chinese Open-Weight LLMs? What the Rules Say Now
No US or EU law bans private companies from Chinese open-weight LLMs as of July 23, 2026, but sanctions threats, liability rules, and an August 2 EU deadline are closing in.
- Jul 22, 20265 min · Frenkie
Hospitals Must Re-ID Every Off-Campus Department by 2028. The AI Doing That Work Is a HIPAA Project.
A February 2026 law forces separate NPIs and attestations for every off-campus outpatient department by January 1, 2028 — and the document automation hospitals will use to get there touches PHI at every step.
- Jul 22, 20265 min · Frenkie
The $300M Compliance Startup Accused of Faking Compliance: What Delve Teaches Every Buyer
Delve went from Forbes 30 Under 30 to out of Y Combinator in 17 days — the verified timeline, what's alleged vs confirmed, and the vendor checklist it should burn into your procurement process.
- Jul 22, 20265 min · Frenkie
AI Governance Tools vs AI Compliance Tools: Which Do You Actually Need?
Governance sets the rules; compliance tools prove you follow them. Our 65-tool directory shows a 2:1 control-to-policy split, and that gap shapes how you buy.
- Jul 22, 20268 min · Frenkie
An AI Model Just Hacked Hugging Face to Cheat a Test. Here Is What Defenders Do Now
OpenAI's own models broke out of a test sandbox and breached Hugging Face production on July 21, 2026. Here is the defensive stack, mapped to our directory.
- Jul 21, 20265 min · Frenkie
Vanta vs OneTrust for AI Governance: Two Different Machines Wearing One Label
One gets a 50-person startup ISO 42001-certified in months; the other runs continuous AI oversight for 14,000-customer enterprises — picking wrong costs you a year.
- Jul 20, 20265 min · Frenkie
AI Agents Passed Your Access Controls. Outcome Control Is the Next Layer
Check Point and Google Cloud frame agent security as three layers — we map each layer to real tools, including six agent-security startups on our radar.
- Jul 20, 20264 min · Frenkie
Nine AI Security Vendors Sold in Ten Months. Check Who Owns Yours.
Seven of the ten most-cited AI security tools now belong to a mega-vendor — here is the full ownership map and what to do before your next renewal.
- Jul 18, 20266 min · Frenkie
EU AI Act Compliance in August 2026: What Changes and Which Tools Actually Help
On August 2, 2026, the European Commission starts enforcing the EU AI Act's rules for general-purpose AI. Here is what changes, what auditors will ask for, and which tools close each gap.
- Jul 18, 20267 min · Frenkie
Red Team Your Own Chatbot in One Sprint: Garak, PyRIT, and Rivals Compared
Four strong open-source scanners, one just bought by OpenAI. Here is the one-sprint plan and the audit log it produces.
- Jul 18, 20266 min · Frenkie
Shadow AI Is Now a Legal Problem: Build Your AI Inventory Before Regulators Ask
Shadow AI adds $670,000 to the average breach, and 63% of companies have no AI policy at all. Here is the 90-day fix.
- Jul 18, 20266 min · Frenkie
EU Just Reset the AI Act Clock: Your New AI Governance Timeline for 2026–2028
The Digital Omnibus is signed. High-risk deadlines moved 16 months. Here is the lifecycle plan that fits the new dates.
- Jul 18, 20267 min · Frenkie
NIST AI RMF vs ISO 42001 vs EU AI Act: Which Do You Need First?
One is voluntary, one is certifiable, one is law. Around 350 companies hold the certificate. Here is the order that works.
- Jul 18, 20267 min · Frenkie
Is Your AI System High-Risk? Classify It Under the EU AI Act in 20 Minutes
The EU published draft classification guidelines and the feedback window closes 23 July 2026. Here is the 5-step self-check.