changelog

Directory Changelog

Every change to the directory — additions, removals, ownership corrections, and trending updates — dated and public. Directories rot; this one shows its maintenance.

2026-07-23

  • updated

    Jobs board upgraded to a full ingestion pipeline: daily automated collection from public ATS APIs (Greenhouse, Lever, Ashby) with relevance filtering, deduplication, and a public run log on /jobs for transparency.

  • added

    Launched /jobs — an independent daily aggregation of AI compliance, governance, and security roles. Listings link to employers' own sites; AI Compliance Index is not affiliated with any employer listed.

2026-07-22

  • content

    Published: "An AI Model Just Hacked Hugging Face to Cheat a Test. Here Is What Defenders Do Now" — the Jul 21 agentic sandbox-escape incident and the defensive stack, mapped to the directory.

  • content

    Published: "Hospitals Must Re-ID Every Off-Campus Department by 2028. The AI Doing That Work Is a HIPAA Project." — the CAA 2026 §6225 NPI mandate explained, with the HIPAA-compliant AI stack for the remediation.

  • content

    Published: "The $300M Compliance Startup Accused of Faking Compliance: What Delve Teaches Every Buyer" — verified timeline with confirmed-vs-alleged ledger and a compliance-vendor verification checklist. Editorial note: Delve was evaluated and declined for directory listing.

  • addedCoval

    Added to radar (Model Evaluation & Benchmarking). YC-backed agent simulation/evals; $28M Series A led by Norwest, Jun 2026.

  • addedPromptArmor

    Added to radar (Enterprise Security & Guardrails). YC W24 LLM application security and AI vendor risk.

  • addedLangfuse

    Added to radar (Model Evaluation & Benchmarking). YC W23 open-source LLM evals/observability leader; part of ClickHouse since Jan 2026.

  • addedKeycard

    Added to radar (Enterprise Security & Guardrails). a16z-backed agent IAM; $38M raised, MCP/OAuth 2.1 standards contributor.

  • addedConductorOne

    Added to radar (Enterprise Security & Guardrails). Identity security spanning human and AI-agent identities.

  • content

    Published: "Vanta vs OneTrust for AI Governance: Two Different Machines Wearing One Label" — our first long-form head-to-head comparison, with G2/community sentiment and the Digital Omnibus timeline split.

2026-07-21

  • addedOWASP Agentic AI Security & Governance

    Added to Frameworks & Checklists (verified). v2.0, 2026.

  • addedPrisma AIRS

    Added to radar (Enterprise Security & Guardrails). Palo Alto Networks' AI security platform (v3.0, Mar 2026) — successor home of Protect AI and LLM Guard's technology.

  • content

    Published 10 new answer pages for agent-asked questions, covering all seven categories — from LLM Guard migration to EU AI Act high-risk conformity.

  • addedNIST AI 600-1 (Generative AI Profile)

    Added to Frameworks & Checklists (verified). NIST's GenAI risk profile, Jul 2024.

  • addedEU GPAI Code of Practice

    Added to Frameworks & Checklists (verified). The EU's GPAI compliance code, Jul 2025.

  • addedCSA AI Controls Matrix

    Added to Frameworks & Checklists (verified). 243 controls, 18 domains, Jul 2025.

2026-07-20

  • archivedLLM Guard

    GitHub repository archived by owner on Jul 9, 2026, twelve months after Palo Alto Networks acquired Protect AI. Removed from trending; website repointed to protectai.com/llm-guard; description updated with migration guidance.

  • content

    Published: "Nine AI Security Vendors Sold in Ten Months. Check Who Owns Yours." — the 2025–2026 consolidation tracker.

  • updatedCalypsoAI

    Ownership corrected: part of F5 since Sep 2025.

  • addedAurascape

    Added to radar (Enterprise Security & Guardrails).

  • addedStraiker

    Added to radar (Enterprise Security & Guardrails).

  • addedCisco AI Defense

    Added to radar (Enterprise Security & Guardrails).

  • addedPrompt Security

    Added to radar (Enterprise Security & Guardrails). Part of SentinelOne since Sep 5, 2025.

  • trendingHiddenLayer

    Promoted to trending #3, replacing archived LLM Guard. Verified independent and active: agentic runtime security (Mar 2026), Cohere partnership (Jun 2026).