<?xml version="1.0" encoding="UTF-8"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>The Guardrail</title><description>Independent analysis of AI regulation, assurance and security for teams shipping AI systems.</description><link>https://theguardrailreport.com/</link><language>en</language><lastBuildDate>Sat, 12 Sep 2026 00:00:00 GMT</lastBuildDate><managingEditor>editor@theguardrailreport.com</managingEditor><copyright>© 2026 The Guardrail</copyright><item><title>Article 73 gives you 2, 10 or 15 days. Which clock runs?</title><link>https://theguardrailreport.com/article-73-serious-incident-clocks/</link><guid isPermaLink="true">https://theguardrailreport.com/article-73-serious-incident-clocks/</guid><description>The AI Act sets three serious incident deadlines, not one. Which applies depends on the harm, and the fastest gives a provider two days to notify.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Marta Lindqvist</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Article 73 runs &lt;strong&gt;three&lt;/strong&gt; deadlines, not one: &lt;strong&gt;15 days&lt;/strong&gt; as standard, &lt;strong&gt;10 days&lt;/strong&gt; where a death may be involved, and &lt;strong&gt;2 days&lt;/strong&gt; for widespread infringement or serious disruption of critical infrastructure.&lt;/li&gt;&lt;li&gt;The clock starts when the provider &lt;strong&gt;becomes aware&lt;/strong&gt; of the incident, not when the cause is proven. Article 73(5) expressly allows an incomplete first report.&lt;/li&gt;&lt;li&gt;The duty sits on the &lt;strong&gt;provider&lt;/strong&gt; of a high-risk system. A deployer that puts its own name on a system, or substantially modifies one, can become the provider under Article 25.&lt;/li&gt;&lt;li&gt;Substantive high-risk obligations now begin on &lt;strong&gt;2 December 2027&lt;/strong&gt; for Annex III systems and &lt;strong&gt;2 August 2028&lt;/strong&gt; for Annex I products, after the amendments approved on &lt;strong&gt;16 June 2026&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Article 73 is rarely the first duty to fire. GDPR gives &lt;strong&gt;72 hours&lt;/strong&gt; and NIS2 an early warning inside &lt;strong&gt;24 hours&lt;/strong&gt;, so the AI Act report is often the third notification, not the first.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Regulation</category><category>Action required</category><category>EU</category></item><item><title>Four regimes, four clocks. Which one fires first after an incident?</title><link>https://theguardrailreport.com/which-incident-clock-fires-first/</link><guid isPermaLink="true">https://theguardrailreport.com/which-incident-clock-fires-first/</guid><description>CRA reporting went live on 11 September 2026. With NIS2, GDPR and the AI Act, one event can start four clocks, and the fastest gives you 24 hours.</description><pubDate>Sat, 12 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Owen Castellanos</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Cyber Resilience Act reporting has been mandatory since &lt;strong&gt;11 September 2026&lt;/strong&gt;, on a &lt;strong&gt;24&lt;/strong&gt;, &lt;strong&gt;72&lt;/strong&gt; and &lt;strong&gt;14&lt;/strong&gt; day cadence for actively exploited vulnerabilities.&lt;/li&gt;&lt;li&gt;NIS2 also opens at &lt;strong&gt;24&lt;/strong&gt; hours with an early warning, followed by a fuller notification at &lt;strong&gt;72&lt;/strong&gt; hours.&lt;/li&gt;&lt;li&gt;GDPR gives &lt;strong&gt;72&lt;/strong&gt; hours from awareness of a personal data breach, and the AI Act gives &lt;strong&gt;2&lt;/strong&gt; to &lt;strong&gt;15&lt;/strong&gt; days depending on the harm.&lt;/li&gt;&lt;li&gt;The same event can engage all four. The AI Act clock is almost always the slowest, which is why an AI specific incident process is the wrong place to start.&lt;/li&gt;&lt;li&gt;Four regimes means four recipients: a CSIRT and ENISA, a data protection authority, a market surveillance authority, and in NIS2 cases the national competent authority.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Incidents</category><category>In force</category><category>EU</category></item><item><title>16 more months for high-risk. Which duties still bind you now?</title><link>https://theguardrailreport.com/high-risk-delay-what-still-binds/</link><guid isPermaLink="true">https://theguardrailreport.com/high-risk-delay-what-still-binds/</guid><description>The AI Act amendment moved two dates and left the rest untouched. Prohibitions, GPAI duties and Article 50 transparency all apply today, delay or no delay.</description><pubDate>Fri, 11 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Marta Lindqvist</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;The amendment approved on &lt;strong&gt;16 June 2026&lt;/strong&gt; moved exactly two dates: Annex III high-risk obligations from 2 August 2026 to &lt;strong&gt;2 December 2027&lt;/strong&gt;, and Annex I from 2 August 2027 to &lt;strong&gt;2 August 2028&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;That is a deferral of &lt;strong&gt;16 months&lt;/strong&gt; for standalone high-risk systems and &lt;strong&gt;12 months&lt;/strong&gt; for AI embedded in regulated products. Nothing else in the timetable moved.&lt;/li&gt;&lt;li&gt;Article 50 transparency duties have applied since &lt;strong&gt;2 August 2026&lt;/strong&gt;. Generative systems already on the market got a short extension to &lt;strong&gt;2 December 2026&lt;/strong&gt; for machine-readable marking, and only for that.&lt;/li&gt;&lt;li&gt;A new prohibition covering AI generated intimate imagery and child sexual abuse material carries its own date of &lt;strong&gt;2 December 2026&lt;/strong&gt; and applies whether or not you run anything high risk.&lt;/li&gt;&lt;li&gt;Breaches of the transparency duties can reach &lt;strong&gt;EUR 15 million&lt;/strong&gt; or &lt;strong&gt;3%&lt;/strong&gt; of worldwide annual turnover, so the duties that did not move are not the cheap ones.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Regulation</category><category>Plan now</category><category>EU</category></item><item><title>Article 50 has applied since 2 August. What must you label?</title><link>https://theguardrailreport.com/article-50-transparency-what-to-label/</link><guid isPermaLink="true">https://theguardrailreport.com/article-50-transparency-what-to-label/</guid><description>Four duties, two on providers and two on deployers. Machine-readable marking, deepfake disclosure, and a 2 December 2026 cutoff for legacy systems.</description><pubDate>Thu, 10 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Marta Lindqvist</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Article 50 has applied since &lt;strong&gt;2 August 2026&lt;/strong&gt;. It splits across &lt;strong&gt;4&lt;/strong&gt; substantive paragraphs: two bind providers, two bind deployers.&lt;/li&gt;&lt;li&gt;Article 50(2) requires synthetic audio, image, video and text to be marked in a &lt;strong&gt;machine-readable&lt;/strong&gt; format. Generative systems already on the market before 2 August 2026 have until &lt;strong&gt;2 December 2026&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;That extension covers the marking duty only. The deployer duties in Article 50(3) and 50(4) had no transitional period and applied from day one.&lt;/li&gt;&lt;li&gt;Disclosure must reach the person &lt;strong&gt;at the latest at the time of the first interaction&lt;/strong&gt;, in a clear and distinguishable manner, and must meet accessibility requirements.&lt;/li&gt;&lt;li&gt;Penalties for transparency breaches run to &lt;strong&gt;EUR 15 million&lt;/strong&gt; or &lt;strong&gt;3%&lt;/strong&gt; of worldwide annual turnover, whichever is higher.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Regulation</category><category>In force</category><category>EU</category></item><item><title>AI API keys are production credentials. What does that change?</title><link>https://theguardrailreport.com/ai-api-keys-production-credentials/</link><guid isPermaLink="true">https://theguardrailreport.com/ai-api-keys-production-credentials/</guid><description>Anthropic&apos;s September 2026 report shows stolen AI keys funding attacks and a fake reseller harvesting them. The controls for these keys lag a decade.</description><pubDate>Wed, 09 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Owen Castellanos</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Anthropic&apos;s report covering &lt;strong&gt;December 2025 to August 2026&lt;/strong&gt; documents stolen AI API keys being used to fund further operations, and a fraudulent reseller built specifically to harvest them.&lt;/li&gt;&lt;li&gt;One tracked group dumped &lt;strong&gt;2,100&lt;/strong&gt; cloud token sets across &lt;strong&gt;40&lt;/strong&gt; corporate tenants in &lt;strong&gt;34 hours&lt;/strong&gt;, which is the speed a credential control has to survive.&lt;/li&gt;&lt;li&gt;Another maintained a standing fleet of &lt;strong&gt;13&lt;/strong&gt; collection agents and produced &lt;strong&gt;12&lt;/strong&gt; possible zero-day findings in a single month against roughly &lt;strong&gt;50&lt;/strong&gt; organisations.&lt;/li&gt;&lt;li&gt;The keys are harvested from the places code lives: repositories, container images, mobile app bundles and vendor sandboxes. Only one of those is covered by a typical secret scanning policy.&lt;/li&gt;&lt;li&gt;Anthropic&apos;s own recommendation is the short version of this article: treat AI keys and agent integrations with the same seriousness as production credentials, and buy access only through authorised channels.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Agent security</category><category>Action required</category><category>Global</category></item><item><title>The agent was persuaded. What is it authorised to do next?</title><link>https://theguardrailreport.com/least-privilege-for-autonomous-agents/</link><guid isPermaLink="true">https://theguardrailreport.com/least-privilege-for-autonomous-agents/</guid><description>Prompt injection defences fail sometimes. Scope decides what happens then. Four permission questions that bound the damage when the model is convinced.</description><pubDate>Tue, 08 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Owen Castellanos</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Prompt injection has sat at &lt;strong&gt;LLM01&lt;/strong&gt;, the top entry of the OWASP list for generative AI, since the &lt;strong&gt;2025&lt;/strong&gt; edition. No control removes it, so the design question is what follows a successful one.&lt;/li&gt;&lt;li&gt;Anthropic&apos;s &lt;strong&gt;September 2026&lt;/strong&gt; report describes agents running unattended &lt;strong&gt;for hours or days&lt;/strong&gt;. Any authorisation granted to that agent is exercised at that speed.&lt;/li&gt;&lt;li&gt;Scope, not detection, is the control that degrades gracefully. A detector that is &lt;strong&gt;99%&lt;/strong&gt; effective still fails on the &lt;strong&gt;1%&lt;/strong&gt;, and the blast radius on that attempt is set entirely by permissions.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;14&lt;/strong&gt; of the AI Act requires human oversight for high-risk systems to be effective, which for an autonomous agent means an approval gate on the specific actions that cannot be undone.&lt;/li&gt;&lt;li&gt;Four questions bound the damage: what can it read, what can it write, who can it act as, and what cannot be reversed.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Agent security</category><category>Design control</category><category>EU</category><category>Global</category></item><item><title>Your agent caused the incident. Can you reconstruct what happened?</title><link>https://theguardrailreport.com/agent-incident-what-to-log/</link><guid isPermaLink="true">https://theguardrailreport.com/agent-incident-what-to-log/</guid><description>The AI Act sets a six month floor on log retention and says nothing about content. What you record decides whether an investigation takes hours or weeks.</description><pubDate>Mon, 07 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Owen Castellanos</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Article &lt;strong&gt;12&lt;/strong&gt; requires high-risk systems to allow automatic recording of events across their lifetime. Articles &lt;strong&gt;19&lt;/strong&gt; and &lt;strong&gt;26(6)&lt;/strong&gt; set the retention floor at &lt;strong&gt;at least 6 months&lt;/strong&gt; for providers and deployers.&lt;/li&gt;&lt;li&gt;The Act sets duration, not content. A log that satisfies the &lt;strong&gt;6&lt;/strong&gt; month floor and records nothing about which tool was called cannot answer the first question an investigator asks.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;73&lt;/strong&gt; gives as little as &lt;strong&gt;2 days&lt;/strong&gt; to notify, and Article 73(6) requires an investigation afterwards. Both assume the evidence already exists.&lt;/li&gt;&lt;li&gt;The reconstruction needs &lt;strong&gt;5&lt;/strong&gt; things: the input that arrived, the identity that acted, the tools called, the output returned, and the version of everything involved.&lt;/li&gt;&lt;li&gt;Model version is the field teams forget. Without it, a finding from March cannot be tested against the system running in September.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Incidents</category><category>Evidence gap</category><category>EU</category></item><item><title>ISO 42001 or the NIST AI RMF? Only one gives you a certificate</title><link>https://theguardrailreport.com/iso-42001-or-nist-ai-rmf/</link><guid isPermaLink="true">https://theguardrailreport.com/iso-42001-or-nist-ai-rmf/</guid><description>38 controls in nine areas against four functions and 72 subcategories. One is certifiable, one is not, and procurement asks for the certificate.</description><pubDate>Sun, 06 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Ruth Abiola</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;ISO/IEC 42001 is a certifiable management system standard. Its Annex A lists &lt;strong&gt;38&lt;/strong&gt; reference controls across &lt;strong&gt;9&lt;/strong&gt; control areas.&lt;/li&gt;&lt;li&gt;The NIST AI Risk Management Framework &lt;strong&gt;1.0&lt;/strong&gt; is voluntary guidance built on &lt;strong&gt;4&lt;/strong&gt; functions, Govern, Map, Measure and Manage, elaborated into &lt;strong&gt;72&lt;/strong&gt; subcategories in the companion Playbook.&lt;/li&gt;&lt;li&gt;No body certifies conformance to the NIST framework. If a customer questionnaire asks for a certificate, only one of these two answers it.&lt;/li&gt;&lt;li&gt;The frameworks are complements, not alternatives: the &lt;strong&gt;4&lt;/strong&gt; NIST functions describe how to reason about risk, the &lt;strong&gt;38&lt;/strong&gt; ISO controls describe what to have in place.&lt;/li&gt;&lt;li&gt;Neither one discharges the EU AI Act. Conformity there runs through Chapter III and the technical documentation in Annex &lt;strong&gt;IV&lt;/strong&gt;, whatever certificates sit alongside it.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Assurance</category><category>Reference</category><category>Global</category><category>US</category><category>EU</category></item><item><title>Three ways a deployer becomes the provider under Article 25</title><link>https://theguardrailreport.com/when-a-deployer-becomes-the-provider/</link><guid isPermaLink="true">https://theguardrailreport.com/when-a-deployer-becomes-the-provider/</guid><description>Put your name on it, modify it substantially, or change its purpose so it becomes high risk. Any of the three moves the provider obligations onto you.</description><pubDate>Sat, 05 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Marta Lindqvist</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Article &lt;strong&gt;25&lt;/strong&gt; lists &lt;strong&gt;3&lt;/strong&gt; triggers that turn a deployer, distributor or importer into a provider of a high-risk system.&lt;/li&gt;&lt;li&gt;Putting your own name or trademark on a high-risk system already on the market is trigger &lt;strong&gt;1&lt;/strong&gt;, and it catches white labelled products routinely.&lt;/li&gt;&lt;li&gt;Changing the intended purpose of a system that was not high risk, so that it becomes high risk, is trigger &lt;strong&gt;3&lt;/strong&gt;. It applies to general purpose models too.&lt;/li&gt;&lt;li&gt;The consequence is the full provider set: Annex &lt;strong&gt;IV&lt;/strong&gt; technical documentation, conformity assessment, and the Article &lt;strong&gt;73&lt;/strong&gt; reporting duty with its &lt;strong&gt;2&lt;/strong&gt; to &lt;strong&gt;15&lt;/strong&gt; day clocks.&lt;/li&gt;&lt;li&gt;A contract cannot move a statutory obligation. Article 25(2) requires the original provider to cooperate and hand over information, which is the clause worth negotiating instead.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Regulation</category><category>Check scope</category><category>EU</category></item><item><title>What an AI audit asks to see, and what closes each finding</title><link>https://theguardrailreport.com/what-an-ai-audit-asks-to-see/</link><guid isPermaLink="true">https://theguardrailreport.com/what-an-ai-audit-asks-to-see/</guid><description>Annex IV runs to nine points and point two alone has seven sub-points. The evidence either exists as an artefact or the control exists only in the policy.</description><pubDate>Fri, 04 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Ruth Abiola</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Annex IV of the AI Act lists &lt;strong&gt;9&lt;/strong&gt; numbered points of technical documentation. Point &lt;strong&gt;2&lt;/strong&gt; alone breaks into &lt;strong&gt;7&lt;/strong&gt; sub-points covering development method, architecture, data and validation.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;18&lt;/strong&gt; requires providers to keep that documentation for &lt;strong&gt;10&lt;/strong&gt; years after the system is placed on the market or put into service.&lt;/li&gt;&lt;li&gt;ISO/IEC 42001 adds &lt;strong&gt;38&lt;/strong&gt; reference controls in &lt;strong&gt;9&lt;/strong&gt; areas, each of which an auditor will ask to see evidence for, not a policy describing it.&lt;/li&gt;&lt;li&gt;The recurring finding is not a missing control. It is a control that cannot produce an artefact with a date on it.&lt;/li&gt;&lt;li&gt;Point &lt;strong&gt;4&lt;/strong&gt; of Annex IV asks why your performance metrics are appropriate, which is a question most model cards do not answer.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Assurance</category><category>Evidence</category><category>EU</category><category>Global</category></item><item><title>Prompt injection is not solved. What actually lowers the rate?</title><link>https://theguardrailreport.com/prompt-injection-what-lowers-the-rate/</link><guid isPermaLink="true">https://theguardrailreport.com/prompt-injection-what-lowers-the-rate/</guid><description>Top of the OWASP list since 2025, and used against a vendor sandbox in the September 2026 threat report. Four control classes, honestly rated.</description><pubDate>Thu, 03 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Owen Castellanos</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Prompt injection has been &lt;strong&gt;LLM01&lt;/strong&gt;, the leading entry of the OWASP list for generative AI applications, since the &lt;strong&gt;2025&lt;/strong&gt; edition, and it is still there.&lt;/li&gt;&lt;li&gt;Anthropic&apos;s &lt;strong&gt;September 2026&lt;/strong&gt; report documents an actor injecting instructions into a vendor sandbox and obtaining production API keys from &lt;strong&gt;multiple&lt;/strong&gt; providers at once.&lt;/li&gt;&lt;li&gt;No published control removes the class. Instructions and data arrive on the same channel, so every mitigation lowers a rate rather than closing a hole.&lt;/li&gt;&lt;li&gt;Of &lt;strong&gt;4&lt;/strong&gt; control classes in common use, only &lt;strong&gt;2&lt;/strong&gt; keep working when the model has already been convinced.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;15&lt;/strong&gt; of the AI Act requires high-risk systems to be resilient against attempts to exploit vulnerabilities, which is a legal reason to document what you chose and why.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Agent security</category><category>Open risk</category><category>Global</category><category>EU</category></item><item><title>Who has to run a fundamental rights impact assessment?</title><link>https://theguardrailreport.com/who-must-run-a-fria/</link><guid isPermaLink="true">https://theguardrailreport.com/who-must-run-a-fria/</guid><description>Article 27 binds public bodies, private providers of public services, and two Annex III uses. A DPIA can be reused, but it does not replace the assessment.</description><pubDate>Wed, 02 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Ruth Abiola</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Article &lt;strong&gt;27&lt;/strong&gt; binds three groups: bodies governed by public law, private entities providing public services, and deployers of the Annex III point &lt;strong&gt;5(b)&lt;/strong&gt; and &lt;strong&gt;5(c)&lt;/strong&gt; uses.&lt;/li&gt;&lt;li&gt;Those two points are creditworthiness assessment and risk assessment and pricing in life and health insurance, which puts most of the private sector burden on financial services.&lt;/li&gt;&lt;li&gt;The assessment has &lt;strong&gt;6&lt;/strong&gt; required elements, including the categories of person affected and the specific harms likely to reach them.&lt;/li&gt;&lt;li&gt;Article 27(3) requires the deployer to notify the market surveillance authority of the results, using the template the Article provides for.&lt;/li&gt;&lt;li&gt;Article 27(4) lets you reuse a DPIA where it already covers an element, but a GDPR assessment does not discharge the duty on its own.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Assurance</category><category>Scope check</category><category>EU</category></item><item><title>You only use foundation models. Which GPAI duties reach you?</title><link>https://theguardrailreport.com/gpai-duties-if-you-only-use-models/</link><guid isPermaLink="true">https://theguardrailreport.com/gpai-duties-if-you-only-use-models/</guid><description>Chapter V binds providers of general purpose models, not their users. Fine tuning and rebranding are the two routes by which a user acquires those duties.</description><pubDate>Tue, 01 Sep 2026 00:00:00 GMT</pubDate><dc:creator>Marta Lindqvist</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Chapter V duties have applied since &lt;strong&gt;2 August 2025&lt;/strong&gt;, and the Commission&apos;s enforcement powers over general purpose models since &lt;strong&gt;2 August 2026&lt;/strong&gt;.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;53&lt;/strong&gt; places &lt;strong&gt;4&lt;/strong&gt; duties on model providers: technical documentation, information for downstream providers, a copyright policy, and a public summary of training content.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;51(2)&lt;/strong&gt; presumes systemic risk above &lt;strong&gt;10^25&lt;/strong&gt; floating point operations of training compute, which brings the additional Article &lt;strong&gt;55&lt;/strong&gt; duties.&lt;/li&gt;&lt;li&gt;A company that only calls an API is not a provider of the model. Fine tuning it, or shipping it under its own name, is how that changes.&lt;/li&gt;&lt;li&gt;The duty that matters most to a downstream user is the one owed to them: Article 53(1)(b) requires the model provider to supply the information they need to comply.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Regulation</category><category>Scope check</category><category>EU</category></item><item><title>Twelve questions to ask an AI vendor before the contract</title><link>https://theguardrailreport.com/ai-vendor-due-diligence-questions/</link><guid isPermaLink="true">https://theguardrailreport.com/ai-vendor-due-diligence-questions/</guid><description>Most AI vendor questionnaires test whether a supplier has a policy. These test whether it can hand you the artefacts your own obligations will require.</description><pubDate>Mon, 31 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Ruth Abiola</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;&lt;strong&gt;12&lt;/strong&gt; questions, grouped in &lt;strong&gt;4&lt;/strong&gt; areas: documentation, incident cooperation, credentials, and change notice.&lt;/li&gt;&lt;li&gt;Article 25(2) obliges an original provider to cooperate if you become the provider, which is the hook for asking about the Annex &lt;strong&gt;IV&lt;/strong&gt; pack before signing.&lt;/li&gt;&lt;li&gt;Article &lt;strong&gt;73&lt;/strong&gt; gives as little as &lt;strong&gt;2&lt;/strong&gt; days to notify. A vendor whose support SLA is &lt;strong&gt;5&lt;/strong&gt; business days cannot help you meet it.&lt;/li&gt;&lt;li&gt;The September &lt;strong&gt;2026&lt;/strong&gt; threat report documents production API keys stolen from a vendor sandbox, which makes the credential storage question a security question rather than an administrative one.&lt;/li&gt;&lt;li&gt;NIS2 Article &lt;strong&gt;21&lt;/strong&gt; already requires supply chain security measures of essential and important entities, so for many buyers this is an existing duty rather than a new one.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Assurance</category><category>Procurement</category><category>EU</category><category>Global</category></item><item><title>AI literacy has been mandatory since February 2025. What counts?</title><link>https://theguardrailreport.com/ai-literacy-article-4/</link><guid isPermaLink="true">https://theguardrailreport.com/ai-literacy-article-4/</guid><description>Article 4 binds providers and deployers alike and has no threshold, no exemption for small firms and no template. It also has no penalty of its own.</description><pubDate>Sun, 30 Aug 2026 00:00:00 GMT</pubDate><dc:creator>Marta Lindqvist</dc:creator><content:encoded>&lt;ul&gt;&lt;li&gt;Article &lt;strong&gt;4&lt;/strong&gt; has applied since &lt;strong&gt;2 February 2025&lt;/strong&gt; and binds both providers and deployers, with no size threshold and no sector carve out.&lt;/li&gt;&lt;li&gt;The duty covers staff and &lt;strong&gt;other persons&lt;/strong&gt; operating AI systems on your behalf, which reaches contractors and outsourced teams.&lt;/li&gt;&lt;li&gt;The standard is calibrated: sufficient literacy given technical knowledge, experience, education, training and the context of use. There is no fixed curriculum.&lt;/li&gt;&lt;li&gt;Article 4 carries no penalty of its own in Article 99. Its practical weight is evidential, because a literacy failure is what an oversight failure under Article &lt;strong&gt;14&lt;/strong&gt; looks like from the inside.&lt;/li&gt;&lt;li&gt;A defensible record is &lt;strong&gt;3&lt;/strong&gt; things: who was trained, on what, and when, per role rather than per headcount.&lt;/li&gt;&lt;/ul&gt;</content:encoded><category>Regulation</category><category>In force</category><category>EU</category></item></channel></rss>