# Areebi - Full Documentation > The secure control plane for enterprise AI. Deploy privately, control access, protect data, and stay compliant. Areebi is an AI governance platform that provides enterprise-grade security, data loss prevention, policy enforcement, audit logging, and compliance automation for organizations using AI. Built for mid-market and enterprise organizations that need to adopt AI safely, Areebi delivers a centralized control plane that sits between users and AI models, enforcing security policies and maintaining compliance evidence automatically. Areebi supports private deployment via Docker, Kubernetes, on-premises infrastructure, and private cloud environments - ensuring that sensitive data never leaves the organization's control. With native support for 30+ LLM providers, Areebi is fully model-agnostic and works with any AI workflow. ## Platform ### What Is an AI Control Plane? An AI control plane is a centralized management layer that sits between an organization's users and the AI models they interact with. It provides visibility, policy enforcement, and security controls across every AI interaction - regardless of which models, applications, or teams are involved. Unlike point solutions that address only one aspect of AI governance (such as prompt filtering or access control alone), a control plane provides unified oversight. It captures all AI activity in a single audit trail, applies consistent security and compliance policies, and gives administrators real-time visibility into how AI is being used across the organization. Areebi's AI control plane is purpose-built for enterprise environments. It integrates with existing identity providers (Okta, Azure AD), supports granular role-based access control, and provides compliance templates for more than 20 regulatory frameworks. Organizations can enforce data loss prevention rules, detect shadow AI usage, and generate audit-ready compliance evidence - all from a single platform. ### Core Capabilities #### Data Loss Prevention (DLP) and PII Masking Areebi scans every prompt and response in real time, detecting and masking personally identifiable information (PII), financial data, health records, and other sensitive content before it reaches any AI model. Organizations can define custom data patterns specific to their industry and configure actions ranging from automatic redaction to user warnings to outright blocking. #### Visual Policy Builder The no-code policy engine lets compliance teams and administrators define governance rules without writing code. Policies can target specific user groups, models, content categories, or interaction types. Conditions can be combined with AND/OR logic, and policies can be tested in simulation mode before enforcement. Changes are versioned and auditable. #### Immutable Audit Logging Every AI interaction is captured in a tamper-proof audit log that includes the user identity, timestamp, model used, prompt content, response content, and any policy actions applied. Logs can be exported in standard formats for compliance review, and retention policies can be configured to meet regulatory requirements. This creates the compliance evidence trail that auditors require. #### Shadow AI Detection and Prevention Areebi identifies unauthorized AI usage across the organization by monitoring network traffic patterns and integrating with CASB solutions. When shadow AI is detected, administrators can block access, redirect users to governed AI channels, or alert security teams. Usage analytics show trends over time, helping organizations understand and address the root causes of shadow AI adoption. #### Private Deployment Options Areebi deploys in the customer's own environment - never in a shared multi-tenant cloud. Supported deployment models include Docker containers, Kubernetes clusters, on-premises servers, and private cloud instances on AWS, Azure, or GCP. This ensures that prompts, responses, and organizational data never leave the customer's security boundary. ## Compliance Frameworks ### NIST AI Risk Management Framework (AI RMF 1.0) Compliance How to comply with the NIST AI Risk Management Framework. Map AI RMF core functions - Govern, Map, Measure, Manage - to enterprise controls with Areebi. URL: https://www.areebi.com/compliance/nist-ai-rmf ### ISO/IEC 42001 AI Management Systems Compliance Complete guide to ISO/IEC 42001 AI management system certification. Learn requirements, implementation steps, and how Areebi maps to ISO 42001 clauses. URL: https://www.areebi.com/compliance/iso-42001 ### UK AI Governance & Regulation Compliance Guide Navigate UK AI regulation with Areebi. Understand the 5 core principles, sector regulators (ICO, FCA, Ofcom), AI Security Institute, and upcoming AI bill. URL: https://www.areebi.com/compliance/uk-ai-governance ### Colorado AI Act (SB 24-205) Compliance Guide Complete guide to the Colorado AI Act (SB 24-205). Understand algorithmic discrimination rules, developer and deployer duties, and enforcement timeline. URL: https://www.areebi.com/compliance/colorado-ai-act ### California AI Transparency Act (SB 942) Compliance Guide Guide to California's AI Transparency Act (SB 942). Understand AI content detection, watermarking requirements, and compliance obligations for AI platforms. URL: https://www.areebi.com/compliance/california-ai-transparency ### Australia AI Governance & Privacy Act Compliance Guide Navigate Australian AI regulation including Privacy Act amendments, OAIC guidance, AI Safety Institute, and sector-specific obligations for APRA and ASIC. URL: https://www.areebi.com/compliance/australia-ai-governance ### Canada AI Governance & Post-AIDA Compliance Guide Navigate Canadian AI regulation after AIDA's collapse. Understand PIPEDA obligations, Quebec Law 25, and the emerging federal AI framework for enterprises. URL: https://www.areebi.com/compliance/canada-ai-governance ### Singapore Model AI Governance Framework Compliance Guide Guide to Singapore's AI governance framework, Agentic AI Framework, PDPA requirements, and National AI Council. Build compliant AI systems with Areebi. URL: https://www.areebi.com/compliance/singapore-ai-governance ### NYC Local Law 144 - AI Hiring Bias Audit Compliance Complete guide to NYC Local Law 144 compliance. Understand AEDT bias audit requirements, public posting rules, and how Areebi supports HR AI governance. URL: https://www.areebi.com/compliance/nyc-local-law-144 ### PCI-DSS 4.0 Compliance for AI Systems How PCI-DSS 4.0 applies to AI systems processing payment card data. Map 12 requirements to AI governance controls with Areebi's enterprise platform. URL: https://www.areebi.com/compliance/pci-dss-4 ### FedRAMP for AI Platforms - Authorization Guide Guide to FedRAMP authorization for AI platforms. Understand Rev 5 security controls, authorization process, and how to sell AI solutions to the US government. URL: https://www.areebi.com/compliance/fedramp-ai ### New Zealand AI Governance & Compliance Guide Guide to New Zealand AI governance. Understand the light-touch regulatory approach, Privacy Act 2020, National AI Strategy, and OECD alignment for AI. URL: https://www.areebi.com/compliance/new-zealand-ai-governance ### OECD AI Principles - International AI Governance Framework Guide to the OECD AI Principles (2019, updated 2024). Understand the 5 principles, 5 recommendations, and how they influence global AI regulation. URL: https://www.areebi.com/compliance/oecd-ai-principles ### Illinois AI Video Interview Act Compliance Guide Guide to the Illinois Artificial Intelligence Video Interview Act. Understand consent requirements, AI analysis restrictions, and candidate rights for compliance. URL: https://www.areebi.com/compliance/illinois-ai-video-interview ### FTC AI Enforcement Actions & Compliance Guide Guide to FTC enforcement of AI under Section 5. Understand AI washing, deceptive AI claims, and how to avoid FTC enforcement with proper AI governance. URL: https://www.areebi.com/compliance/ftc-ai-enforcement ### SEC AI Disclosure Guidance & Compliance Guide to SEC AI disclosure requirements. Understand AI risk disclosure obligations, AI washing enforcement, and AI in investment advice examinations. URL: https://www.areebi.com/compliance/sec-ai-disclosure ### UK Online Safety Act & AI Compliance Guide Guide to the UK Online Safety Act's implications for AI. Understand duties for AI-generated content, deepfakes, and online safety obligations for AI platforms. URL: https://www.areebi.com/compliance/uk-online-safety-act ### CCPA and AI: California Consumer Privacy Act Compliance How the California Consumer Privacy Act (CCPA) and CPRA amendments apply to AI systems processing consumer data. Implement automated decision-making rights, data deletion, and opt-out controls with Areebi. URL: https://www.areebi.com/compliance/ccpa ### FERPA and AI: Educational Data Privacy Compliance How FERPA applies to AI systems processing student education records. Implement consent controls, school official exceptions, and directory information governance with Areebi. URL: https://www.areebi.com/compliance/ferpa ### SOX and AI: Sarbanes-Oxley Compliance for AI-Driven Financial Reporting How Sarbanes-Oxley applies to AI systems in financial reporting. Implement Section 302/404 controls, audit trail requirements, and internal controls over AI-generated financial estimates with Areebi. URL: https://www.areebi.com/compliance/sox-ai ### GLBA and AI: Gramm-Leach-Bliley Act Compliance for AI Systems How the Gramm-Leach-Bliley Act applies to AI systems processing nonpublic personal information. Implement Safeguards Rule controls, privacy notice compliance, and NPI protection with Areebi. URL: https://www.areebi.com/compliance/glba ### Texas AI Laws: TRAIGA (HB 149) and HB 2060 Compliance Guide How to comply with the Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149), effective January 1, 2026, and HB 2060's state-agency AI requirements. Penalties, scope, deployer and developer obligations, NIST AI RMF safe harbor, and an implementation roadmap. URL: https://www.areebi.com/compliance/texas-ai-laws ### Japan AI Guidelines for Business: METI/MIC, Hiroshima Process, and the AI Promotion Act How to comply with Japan's AI Guidelines for Business (METI/MIC, version 1.0 April 2024, originally October 2023 draft), the Hiroshima AI Process and G7 Code of Conduct (October 2023), and the proposed Japanese AI Promotion Act under deliberation in the 2024-2025 Diet session. Developer, Provider, and Business User tiers, soft-law enforcement, and how Japan's voluntary approach diverges from the EU AI Act. URL: https://www.areebi.com/compliance/japan-ai-guidelines ### South Korea AI Basic Act (AI Framework Act): 2026 Compliance Guide How to comply with South Korea's Act on Promotion of AI Development and Establishment of a Foundation for Trust (AI Basic Act / AI Framework Act), passed by the National Assembly on December 26, 2024 and effective January 22, 2026. Scope, high-impact AI obligations, transparency duties, generative AI marking, foreign business representatives, MSIT enforcement, and penalties up to KRW 30 million. URL: https://www.areebi.com/compliance/south-korea-ai-act ### India AI Regulation: DPDPA 2023 and the Proposed Digital India Act How to comply with India's evolving AI and data governance framework: the Digital Personal Data Protection Act 2023 (DPDPA, in force), MeitY advisories on AI labelling (2023 - 2024), the Data Protection Board, Significant Data Fiduciary (SDF) obligations, and the proposed Digital India Act (DIA, draft principles). Penalties up to INR 250 crore. URL: https://www.areebi.com/compliance/india-digital-india-act-ai ### Brazil AI Regulation: LGPD and the Proposed Marco Legal da IA (PL 2338/2023) How to comply with Brazil's AI framework: LGPD (in force), PL 2338/2023 Marco Legal da IA (proposed), ANPD oversight. Penalties up to BRL 50M per violation. URL: https://www.areebi.com/compliance/brazil-lgpd-ai ### UAE AI Compliance: PDPL (Federal Decree-Law 45/2021) + DIFC + ADGM data laws UAE AI compliance: PDPL (in force since Jan 2022), DIFC DP Law 5/2020, ADGM DP Reg 2021. UAE Data Office oversight. Penalties up to AED 5M. URL: https://www.areebi.com/compliance/uae-pdpl ### NIS2 Directive + AI: cybersecurity obligations for AI-enabled essential entities (EU 2022/2555) NIS2 Directive (EU 2022/2555) cybersecurity rules for essential + important entities. AI risk management overlay. Penalties up to 2% global turnover. URL: https://www.areebi.com/compliance/nis2-directive-ai ### APRA CPS 230 and AI: Operational Risk for Australian Financial Services How APRA Prudential Standard CPS 230 (effective 1 July 2025) governs AI systems and AI vendors as material service providers for Australian banks, insurers and super funds - and how to manage AI operational risk, concentration and resilience. URL: https://www.areebi.com/compliance/apra-cps-230-ai ### APRA CPS 234 & AI: Securing AI Models, Pipelines and Inference APIs How APRA CPS 234 applies to AI in Australian banks, insurers and super funds. Treat AI models, training data, fine-tuning pipelines, vector stores and inference APIs as in-scope information assets - and map each obligation to Areebi's secure AI control plane. URL: https://www.areebi.com/compliance/apra-cps-234-ai ### Privacy Act Automated Decision-Making (ADM) Transparency: The 10 December 2026 Deadline An operational guide to the new Privacy Act automated decision-making transparency obligation (APP 1.7-1.9) commencing 10 December 2026: what your privacy policy must disclose, what counts as a "computer program", how it is enforced, and how Australian regulated enterprises prepare. URL: https://www.areebi.com/compliance/privacy-act-adm-transparency ### Australia's AI Rules in 2026: No AI Act, the National AI Plan and the 6 Essential Practices What Australian enterprises must actually do for AI in 2026: no AI Act, no mandatory guardrails - existing laws, sector regulators, the National AI Plan, an advisory AI Safety Institute, and the 6 Essential Practices in the Guidance for AI Adoption. URL: https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard ### Sovereign and Self-Hosted AI in Australia: Data Residency, Sovereignty and Compliance How Australian regulated enterprises run enterprise AI while keeping data onshore and under Australian jurisdiction. The 2026 operational guide to data residency vs data sovereignty, APP 8 cross-border exposure, the US CLOUD Act, ISM/PSPF and IRAP data-residency expectations, and the deployment spectrum from public SaaS to air-gapped - mapped to Areebi's privately-deployable secure AI control plane. URL: https://www.areebi.com/compliance/sovereign-ai-australia ### DTA Policy for the Responsible Use of AI in Government: 2026 Mandatory Requirements An operational guide to the DTA Policy for the responsible use of AI in government (Version 2.0, effective 15 December 2025). Covers the mandatory requirements for non-corporate Commonwealth entities - accountable officials, AI use case registers, AI impact assessments and public transparency statements - their 2026 phasing dates, the new AI procurement guidance, and how Australian agencies and their vendors operationalise the controls. URL: https://www.areebi.com/compliance/dta-ai-policy ### ASD Essential Eight and AI: Securing AI Systems to the Australian Cyber Baseline How to bring AI systems - models, pipelines, inference endpoints and AI-enabled SaaS - inside the ASD Essential Eight. A CISO and government security lead guide to the eight mitigation strategies, the Maturity Model (ML0 to ML3), shadow AI, and what changes when AI enters scope. URL: https://www.areebi.com/compliance/essential-eight-ai ### IRAP, the ISM and PSPF for AI: Running AI Workloads in Australian Government Environments An operational guide to running AI workloads in Australian Government environments under the ISM, PSPF 2025 and IRAP. Covers the December 2025 ISM AI controls, the April 2025 IRAP Common Assessment Framework, data sovereignty gates, and how a Secure AI Control Plane maps to the controls baseline. URL: https://www.areebi.com/compliance/irap-ism-ai ### ASIC REP 798 and Directors' AI Duties: Closing the Financial Services Governance Gap How ASIC Report 798 "Beware the gap" (29 October 2024) applies existing technology-neutral obligations and directors' duties to AI in Australian financial services - and how AFS and credit licensee boards, GCs, CROs and CISOs close the governance gap ASIC identified across 23 licensees and 624 AI use cases. URL: https://www.areebi.com/compliance/asic-rep-798-ai ### The SOCI Act and AI: Critical Infrastructure Risk Management for AI Systems and Data Stores How the Security of Critical Infrastructure (SOCI) Act 2018 - materially expanded by the Enhanced Response and Prevention Act 2024 - captures AI systems and AI data stores in Australian critical-infrastructure sectors, and how to bring AI inside an all-hazards Critical Infrastructure Risk Management Program (CIRMP). URL: https://www.areebi.com/compliance/soci-act-ai ## Learn - AI Governance Glossary ### What is AI Governance? AI governance is the framework of policies, processes, and controls that organizations use to ensure artificial intelligence is deployed responsibly, securely, and in compliance with regulations. URL: https://www.areebi.com/learn/what-is-ai-governance ### What is Shadow AI? Shadow AI refers to the use of artificial intelligence tools and services by employees without the knowledge, approval, or oversight of an organization's IT or security teams. URL: https://www.areebi.com/learn/what-is-shadow-ai ### What is AI DLP? AI DLP (Data Loss Prevention for AI) is a security control that monitors, detects, and prevents sensitive data - including PII, PHI, financial data, and intellectual property - from being exposed through AI tools and large language model interactions. URL: https://www.areebi.com/learn/what-is-ai-dlp ### What is Prompt Injection? Prompt injection is a security attack where malicious instructions are embedded in user inputs to manipulate a large language model into ignoring its original instructions, bypassing safety controls, or producing unauthorized outputs. URL: https://www.areebi.com/learn/what-is-prompt-injection ### What is an AI Firewall? An AI firewall is a security layer that sits between users and AI models, inspecting and filtering prompts and responses in real-time to enforce security policies, prevent data leakage, and block prompt injection attacks. URL: https://www.areebi.com/learn/what-is-ai-firewall ### What is AI Compliance? AI compliance is the practice of ensuring that artificial intelligence systems meet the legal, regulatory, and ethical requirements set by applicable laws and industry standards across all jurisdictions where an organization operates. URL: https://www.areebi.com/learn/what-is-ai-compliance ### What is Algorithmic Discrimination? Algorithmic discrimination occurs when an AI system produces outputs that unfairly disadvantage individuals or groups based on protected characteristics such as race, gender, age, or disability, often due to biased training data or flawed model design. URL: https://www.areebi.com/learn/what-is-algorithmic-discrimination ### What is AI Risk Management? AI risk management is the systematic process of identifying, assessing, mitigating, and monitoring risks associated with the development, deployment, and use of artificial intelligence systems throughout their lifecycle. URL: https://www.areebi.com/learn/what-is-ai-risk-management ### What is AI Transparency? AI transparency is the principle that organizations deploying AI systems must be open about how those systems work, what data they use, how decisions are made, and when users are interacting with AI rather than a human. URL: https://www.areebi.com/learn/what-is-ai-transparency ### What is Automated Decision-Making? Automated decision-making (ADM) is the process of making decisions about individuals using algorithms or AI systems with limited or no human involvement, particularly decisions that significantly affect rights, opportunities, or access to services. URL: https://www.areebi.com/learn/what-is-automated-decision-making ### What is an AI Audit? An AI audit is a structured evaluation of an AI system's compliance with regulatory requirements, organizational policies, ethical standards, and technical performance benchmarks, typically conducted by independent assessors. URL: https://www.areebi.com/learn/what-is-ai-audit ### What is Responsible AI? Responsible AI is an approach to developing, deploying, and operating artificial intelligence systems that prioritizes fairness, transparency, accountability, privacy, safety, and human oversight throughout the AI lifecycle. URL: https://www.areebi.com/learn/what-is-responsible-ai ### What is AI Bias Testing? AI bias testing is the process of systematically evaluating AI systems for discriminatory patterns in their outputs, using statistical methods to detect disparate impact across protected groups before and after deployment. URL: https://www.areebi.com/learn/what-is-ai-bias-testing ### What is AI Observability? AI observability is the practice of gaining comprehensive visibility into how AI systems are being used across an organization, what data flows through them, and whether they are performing as expected - enabling governance, cost control, and risk management at scale. URL: https://www.areebi.com/learn/what-is-ai-observability ### What is AI Compliance Automation? AI compliance automation is the use of technology to continuously and automatically enforce, monitor, and evidence an organization's adherence to AI-related laws, regulations, and standards, replacing manual checklists and periodic audits with real-time, machine-driven compliance controls. URL: https://www.areebi.com/learn/what-is-ai-compliance-automation ### What is an AI Policy Engine? An AI policy engine is an automated system that defines, enforces, and monitors organizational rules governing how AI tools are used, what data can be processed, which models are accessible, and what outputs are permitted - replacing manual policy enforcement with real-time, programmatic controls. URL: https://www.areebi.com/learn/what-is-ai-policy-engine ### What is an AI Control Plane? An AI control plane is the centralized management layer that governs policies, access, data protection, compliance, and observability across all AI usage in an organization - separating the management of AI from the execution of AI interactions. URL: https://www.areebi.com/learn/what-is-ai-control-plane ### What is Adversarial Robustness? Adversarial robustness is the ability of an AI system to maintain correct, safe, and predictable behavior when subjected to deliberately crafted adversarial inputs designed to cause misclassification, policy bypass, data leakage, or other unintended outcomes. URL: https://www.areebi.com/learn/what-is-adversarial-robustness ### What is Model Drift? Model drift is the degradation of an AI model's performance over time as the statistical properties of real-world data diverge from the data the model was trained on, causing predictions and outputs to become less accurate, less relevant, or potentially unsafe. URL: https://www.areebi.com/learn/what-is-model-drift ### What is Data Poisoning? Data poisoning is an adversarial attack in which an attacker deliberately corrupts the training, fine-tuning, or retrieval data used by an AI system, embedding malicious patterns that cause the model to produce incorrect, biased, or harmful outputs when triggered by specific inputs. URL: https://www.areebi.com/learn/what-is-data-poisoning ### What is Differential Privacy? Differential privacy is a mathematical framework that provides provable guarantees about the privacy of individuals in a dataset by adding carefully calibrated noise to data queries, model training, or outputs - ensuring that no single individual's data can be identified or reconstructed from the results. URL: https://www.areebi.com/learn/what-is-differential-privacy ### What is AI Red Teaming? AI red teaming is the practice of systematically probing AI systems through adversarial testing - simulating real-world attacks, misuse scenarios, and edge cases - to identify vulnerabilities, safety failures, and governance gaps before they can be exploited in production. URL: https://www.areebi.com/learn/what-is-ai-red-teaming ### What are Model Cards? Model cards are standardized documentation artifacts that describe an AI model's intended use, performance characteristics, training data, limitations, ethical considerations, and evaluation results - providing transparency and accountability for anyone who develops, deploys, or is affected by the model. URL: https://www.areebi.com/learn/what-is-model-cards ### What is Federated Learning Security? Federated learning security encompasses the techniques, protocols, and governance practices that protect distributed machine learning systems - where models are trained across multiple decentralized devices or organizations without centralizing raw data - from adversarial attacks, privacy leakage, model poisoning, and inference threats. URL: https://www.areebi.com/learn/what-is-federated-learning-security ### What is AI Supply Chain Security? AI supply chain security is the practice of identifying, assessing, and mitigating risks across the entire chain of third-party dependencies that enterprise AI systems rely on - including pre-trained models, training datasets, open-source libraries, model hosting providers, data annotation services, and plugin ecosystems. URL: https://www.areebi.com/learn/what-is-ai-supply-chain-security ### What is AI Incident Response? AI incident response is the structured process organizations use to detect, triage, contain, eradicate, recover from, and learn from incidents involving AI systems - including prompt injection attacks, data leakage through prompts, model behavior failures, data poisoning, and emergent harmful outputs from generative models. URL: https://www.areebi.com/learn/what-is-ai-incident-response ### What is AI Vendor Risk? AI vendor risk is the set of confidentiality, integrity, availability, compliance, and operational risks an organization inherits when it relies on third-party AI providers, sub-processors, and model-as-a-service supply chains - including foundation model vendors, fine-tuning data providers, hosted inference platforms, AI plugin marketplaces, and downstream SaaS products that embed third-party AI. URL: https://www.areebi.com/learn/what-is-ai-vendor-risk ### What is Data Residency for AI? Data residency for AI is the discipline of controlling where AI prompts, responses, embeddings, fine-tuning corpora, and training data are stored and processed. It extends classical cloud data residency to the new surfaces introduced by AI: ephemeral prompt and response streams, vector stores, RAG document caches, model weights, and the metadata that AI providers collect for abuse monitoring and product improvement. URL: https://www.areebi.com/learn/what-is-data-residency-for-ai ### What is AI Runtime Policy? AI runtime policy is the set of identity-aware, content-aware, and context-aware rules enforced at the prompt and response boundary of an AI system - in real time, on every interaction. It is the operational counterpart to static AI governance policy documents: where policy documents describe what the organisation says it will do, runtime policy is what the system actually allows, blocks, redacts, escalates, or audits when an employee, agent, or downstream service sends a prompt to a model. URL: https://www.areebi.com/learn/what-is-ai-runtime-policy ### What is Prompt Engineering Security? Prompt engineering security is the discipline of designing prompts, prompt templates, and the surrounding system architecture so that the resulting AI behaviour is resistant to prompt injection, jailbreak, role confusion, instruction override, and unintended tool invocation. It treats prompts as a security artefact - subject to the same review, versioning, testing, and runtime defence as any other piece of trusted software - rather than as throwaway natural-language strings. URL: https://www.areebi.com/learn/what-is-prompt-engineering-security ### What is AI Rate Limiting? AI rate limiting is the discipline of controlling the rate, volume, and cost of requests against AI systems - across users, tenants, agents, and downstream services - to prevent abuse, denial of service, data-exfiltration via excessive querying, runaway model spend, and breach of regulatory or contractual usage limits. It generalises classical API rate limiting with concepts that only make sense for AI: per-token budgets, model-cost-aware quotas, semantic-similarity throttling, and tenant-fair queueing across requests of wildly differing computational cost. URL: https://www.areebi.com/learn/what-is-ai-rate-limiting ### What is Agent Governance? Agent governance is the discipline of governing autonomous AI agents - systems that take multi-step actions on behalf of users or organisations - across their full lifecycle. It extends beyond prompt governance to cover tool-call authorisation, action audit and replay, multi-agent coordination, drift detection, and decision-authority boundaries between AI assistance and AI action. Agent governance is what stops an agent's expanding autonomy from outrunning the organisation's controls. URL: https://www.areebi.com/learn/what-is-agent-governance ### What is AI Attribution? AI attribution is the practice of tracing AI-system outputs back to their inputs, prompts, retrieved sources, training data lineage, and the user or tenant context that produced them. It is the operational foundation for audit, accountability, transparency, and copyright defence in AI systems. Without attribution, an AI output is a black-box artefact; with attribution, it is an auditable record that can be inspected, contested, and reconstructed. URL: https://www.areebi.com/learn/what-is-ai-attribution ### What is Retrieval-Augmented Generation (RAG)? Retrieval-Augmented Generation (RAG) is an AI architecture that combines a large language model with an external knowledge source - usually a vector database of an organization's own documents - so that the model retrieves relevant context at query time and grounds its generated responses in that retrieved evidence rather than relying solely on parametric memory from training. URL: https://www.areebi.com/learn/what-is-rag ### What is LLM Fine-Tuning? LLM fine-tuning is the process of continuing the training of a pretrained large language model on a smaller, task-specific or domain-specific dataset so that the model's weights shift to better reflect the desired behavior, style, or knowledge - producing a derived model that retains the base model's general capabilities while specializing in the customer's task. URL: https://www.areebi.com/learn/what-is-fine-tuning ### What is Agentic AI? Agentic AI is the class of AI systems that go beyond responding to a single prompt - they plan multi-step actions, call external tools, write to systems of record, and pursue a goal across multiple turns - making their behavior more powerful than a chat model but also far harder to govern, because the system is taking actions in the world rather than merely producing text. URL: https://www.areebi.com/learn/what-is-agentic-ai ### What is a Private LLM? A private LLM is a large language model deployed so that prompts, responses, and any documents it processes remain inside infrastructure the organisation controls - on-premise servers, a private cloud tenancy, an air-gapped environment, or a local machine - rather than being sent to a shared public AI service. URL: https://www.areebi.com/learn/what-is-a-private-llm ### What is an LLM Gateway? An LLM gateway is a single API endpoint that sits between your applications and one or more large language model providers, centralising routing, authentication, rate limiting, cost tracking, caching, data loss prevention, and audit logging so that every AI request passes through one governed control point rather than each application calling each model directly. URL: https://www.areebi.com/learn/what-is-an-llm-gateway ### What is LLM Security? LLM security is the discipline of protecting large language model applications across their full lifecycle - the prompts and data flowing in, the model and its supply chain, the runtime that serves it, and the outputs and actions it produces - against threats such as prompt injection, sensitive-data disclosure, insecure output handling, and supply-chain compromise, using a combination of inline runtime controls, governance, and monitoring. URL: https://www.areebi.com/learn/what-is-llm-security ### What is RAG Security? RAG security is the practice of protecting retrieval-augmented generation systems against the risks unique to coupling a large language model with an external knowledge base - poisoned or malicious documents, access-control bypass where the retriever surfaces data a user is not entitled to, embedding inversion and leakage, and indirect prompt injection through retrieved content - by enforcing access control at retrieval time, sanitising ingested and retrieved content, and treating the vector store as a regulated data asset. URL: https://www.areebi.com/learn/what-is-rag-security ### What is AI TRiSM? AI TRiSM (AI Trust, Risk and Security Management) is a framework defined by Gartner for governing artificial intelligence across four pillars - explainability and model monitoring, AI application security, data and content anomaly detection, and AI governance - so that organisations can ensure their AI models and applications are trustworthy, fair, reliable, robust, and protect data privacy. URL: https://www.areebi.com/learn/what-is-ai-trism ### What is an Enterprise LLM? An enterprise LLM is a large language model deployment that adds the controls an organisation requires to use AI at scale safely - single sign-on and role-based access control, immutable audit logging, real-time data loss prevention, data residency control, and a policy engine - on top of the raw model, so that the deployment is governed, attributable, compliant, and integrated with enterprise identity rather than being a bare model endpoint. URL: https://www.areebi.com/learn/what-is-an-enterprise-llm ## Integrations ### OpenAI / GPT Connect OpenAI GPT models to Areebi for enterprise-grade governance - DLP, audit logging, policy enforcement, and compliance controls on every prompt and response. URL: https://www.areebi.com/integrations/openai ### Anthropic / Claude Use Anthropic's Claude models with full enterprise governance - DLP, audit logging, policy enforcement, and compliance controls through Areebi's secure AI platform. URL: https://www.areebi.com/integrations/anthropic ### Azure OpenAI Service Deploy Azure OpenAI Service with Areebi's governance layer for double-layered enterprise security - DLP, audit logging, policy enforcement, and compliance controls within your Azure environment. URL: https://www.areebi.com/integrations/azure-openai ### Google Vertex AI Connect Google Vertex AI and Gemini models to Areebi for enterprise governance - DLP, audit logging, policy enforcement, and compliance controls across your GCP AI workloads. URL: https://www.areebi.com/integrations/google-vertex ### Ollama (Local LLMs) Run local LLMs with Ollama through Areebi's governance layer - DLP, audit logging, policy enforcement, and compliance controls for air-gapped and data-sovereign AI deployments. URL: https://www.areebi.com/integrations/ollama ### AWS Bedrock Connect AWS Bedrock to Areebi for enterprise governance - DLP, audit logging, policy enforcement, and compliance controls across Claude, Llama, Titan, and all Bedrock foundation models. URL: https://www.areebi.com/integrations/aws-bedrock ### Okta Integrate Okta SSO with Areebi for identity-aware AI governance - SAML authentication, group-based access control, automated provisioning, and user-level audit trails across all AI interactions. URL: https://www.areebi.com/integrations/okta ### Microsoft Entra ID Connect Microsoft Entra ID (Azure AD) to Areebi for identity-aware AI governance - SSO, conditional access, group sync, and user-level audit trails across your Microsoft ecosystem. URL: https://www.areebi.com/integrations/azure-ad ### Hugging Face Govern Hugging Face model usage across your organisation with Areebi - apply DLP, audit logging, and policy controls to any of the 200,000+ models available on the Hugging Face Hub. URL: https://www.areebi.com/integrations/hugging-face ### OpenRouter Apply consistent governance across every model OpenRouter routes to - DLP, audit logging, cost controls, and compliance policies that follow your prompts regardless of which downstream provider is selected. URL: https://www.areebi.com/integrations/openrouter ### Together AI Govern Together AI's open-source model hosting and fine-tuning with Areebi - enforce DLP, audit every inference and training job, and apply compliance controls across Llama, Mixtral, and custom model deployments. URL: https://www.areebi.com/integrations/together-ai ### LM Studio Govern LM Studio desktop LLM usage with Areebi - eliminate shadow AI risk from employees running local models on work machines with DLP, audit logging, and policy enforcement. URL: https://www.areebi.com/integrations/lm-studio ### LocalAI Govern self-hosted LocalAI deployments with Areebi - full DLP, audit logging, and compliance controls for your OpenAI-compatible on-premise AI infrastructure. URL: https://www.areebi.com/integrations/localai ### KoboldCPP Govern KoboldCPP deployments with Areebi - enterprise DLP, audit logging, and compliance controls for lightweight CPU-only inference in air-gapped and resource-constrained environments. URL: https://www.areebi.com/integrations/koboldcpp ### Google Gemini Connect Google Gemini models via the developer API (ai.google.dev) to Areebi for enterprise governance - DLP scanning, audit trails, and policy enforcement across Gemini Pro, Flash, and Ultra. URL: https://www.areebi.com/integrations/google-gemini ### Cohere Connect Cohere's Command, Embed, and Rerank models to Areebi for governed RAG pipelines - DLP on retrieval workflows, audit logging across the full search-generate cycle, and policy enforcement for enterprise embeddings. URL: https://www.areebi.com/integrations/cohere ### Mistral AI Connect Mistral AI models to Areebi for EU-aligned governance - GDPR-aware DLP, EU AI Act compliance support, audit logging, and data sovereignty controls for European AI deployments. URL: https://www.areebi.com/integrations/mistral-ai ### Groq Connect Groq's LPU-powered inference to Areebi for speed-preserving governance - sub-50ms DLP overhead on the fastest inference platform, real-time audit logging, and policy enforcement without sacrificing Groq's latency advantage. URL: https://www.areebi.com/integrations/groq ### DeepSeek Connect DeepSeek models to Areebi for governance with data sovereignty controls - DLP enforcement, geopolitical risk mitigation, audit logging, and compliance policies for organisations using PRC-origin AI infrastructure. URL: https://www.areebi.com/integrations/deepseek ### NVIDIA NIM Govern NVIDIA NIM inference microservices through Areebi - enforce DLP, audit every GPU-accelerated inference call, and apply compliance controls across your NVIDIA AI Enterprise deployment. URL: https://www.areebi.com/integrations/nvidia-nim ### Fireworks AI Govern Fireworks AI inference through Areebi - apply DLP to function calls and structured outputs, audit every interaction, and enforce compliance policies on one of the fastest inference platforms available. URL: https://www.areebi.com/integrations/fireworks-ai ### Perplexity AI Govern Perplexity AI's search-augmented generation through Areebi - apply DLP to prompts containing web-sourced content, audit search-enriched responses, and mitigate the unique risks of real-time web data entering your AI workflows. URL: https://www.areebi.com/integrations/perplexity-ai ### TrueFoundry Govern the full ML lifecycle on TrueFoundry through Areebi - enforce DLP across model deployment pipelines, audit inference calls from Kubernetes-native workloads, and apply compliance controls from fine-tuning through production serving. URL: https://www.areebi.com/integrations/truefoundry ## Use Cases ### AI Governance for Code Generation Protect intellectual property, enforce license compliance, and maintain code quality standards when developers use AI code generation tools like GitHub Copilot, Cursor, and other AI coding assistants. URL: https://www.areebi.com/use-cases/code-generation ### AI Governance for Customer Support Automation Protect customer PII, ensure response quality, and enforce escalation policies when deploying AI-powered chatbots, ticket classification, and support automation tools. URL: https://www.areebi.com/use-cases/customer-support ### AI Governance for Document Analysis Protect privileged information, enforce data classification, and maintain audit trails when using AI for contract review, regulatory analysis, and document processing. URL: https://www.areebi.com/use-cases/document-analysis ### AI Governance for Research & Development Protect intellectual property, ensure reproducibility, and validate AI model outputs when research and development teams use AI for scientific research, data analysis, and innovation workflows. URL: https://www.areebi.com/use-cases/research-development ### AI Governance for Compliance Automation Automate AI compliance evidence generation, continuous control monitoring, and audit preparation across HIPAA, SOC 2, EU AI Act, NIST, and other regulatory frameworks with Areebi's AI governance platform. URL: https://www.areebi.com/use-cases/compliance-automation ### AI Governance for Internal Knowledge Management Govern AI-powered knowledge bases, RAG systems, and internal document Q&A tools to prevent data leakage, enforce access controls, and maintain security over your organization's most sensitive information. URL: https://www.areebi.com/use-cases/internal-knowledge-management ### AI Governance for HR & Recruiting Govern AI use in hiring, screening, interviews, and employee management to prevent bias, protect candidate PII, and comply with AI hiring regulations including Illinois AI Video Interview Act and NYC Local Law 144. URL: https://www.areebi.com/use-cases/hr-recruiting ### AI Governance for Marketing Teams Govern AI-powered content generation, ensure personalization algorithm fairness, enforce brand safety standards, and maintain GDPR consent compliance across marketing AI tools. URL: https://www.areebi.com/use-cases/marketing ### AI Governance for Sales Teams Govern CRM AI tools, ensure deal scoring fairness, protect intellectual property in proposal generation, and prevent competitive intelligence leakage across your sales organization. URL: https://www.areebi.com/use-cases/sales ### AI Governance for Financial Analysis Ensure SEC disclosure compliance, govern trading algorithms, enforce financial data DLP, satisfy SR 11-7 model risk requirements, and maintain complete audit trails for AI-assisted financial analysis. URL: https://www.areebi.com/use-cases/financial-analysis ### AI Governance for Data Analytics & Business Intelligence Protect proprietary data, financial metrics, and customer information when BI teams use AI for data analysis, report generation, and natural language queries over databases. Areebi's DLP ensures sensitive analytics data never leaves your control. URL: https://www.areebi.com/use-cases/data-analytics ### AI Governance for Finance & Accounting Teams Protect revenue data, M&A information, payroll details, and other sensitive financial information when finance and accounting teams use AI for forecasting, expense analysis, and audit preparation. Maintain SOC 2 and PCI-DSS compliance with Areebi's AI governance platform. URL: https://www.areebi.com/use-cases/finance-accounting ### AI Governance for Executive Communications Protect material non-public information, strategic plans, and confidential business data when executives use AI for board presentations, investor updates, and strategic memos. Areebi's DLP catches sensitive executive content before it reaches external AI providers. URL: https://www.areebi.com/use-cases/executive-communications ### AI Governance for Supply Chain & Procurement Protect pricing data, vendor terms, and supply chain intelligence when procurement teams use AI for vendor analysis, contract review, and RFP responses. Areebi provides controlled AI access that prevents sensitive procurement data from reaching external providers. URL: https://www.areebi.com/use-cases/supply-chain ### AI Governance for IT Operations & DevOps Protect API keys, infrastructure configurations, and security vulnerabilities when IT and DevOps teams use AI for infrastructure troubleshooting, code review, and incident response. Areebi's DLP detects secrets and sensitive infrastructure data before they reach external AI providers. URL: https://www.areebi.com/use-cases/it-operations ## Comparisons ### Manual AI Governance vs Automation: True Cost Manual AI governance vs automated enforcement, compared line by line: where spreadsheets, ad-hoc policies, and reactive monitoring fail at scale, what each approach really costs, and when to switch. URL: https://www.areebi.com/compare/manual-ai-governance ### Areebi vs Point Solutions (DLP-Only Tools) Compare Areebi's complete AI governance platform against DLP-only point solutions like Nightfall AI and Protect AI. Discover why data-loss prevention alone leaves critical governance gaps. URL: https://www.areebi.com/compare/point-solutions ### Areebi vs Platform Bundles (Cisco, Palo Alto) Compare Areebi's purpose-built AI governance platform against Cisco and Palo Alto Networks AI governance bundles. Learn why buying AI governance as part of a mega-platform costs 3-5x more and delivers less. URL: https://www.areebi.com/compare/platform-bundles ### Areebi vs DIY / Open Source AI Governance Compare Areebi's enterprise AI governance platform against building your own solution with AnythingLLM, LangChain, or other open-source tools. Understand the true cost of build-vs-buy for AI governance. URL: https://www.areebi.com/compare/diy-open-source ### Best AI Governance Tools & Platforms for 2026 The definitive guide to AI governance tools and platforms in 2026. Compare Areebi, Wald.ai, Nightfall AI, Lakera, Robust Intelligence, Cisco, Palo Alto, and DIY approaches across capabilities, pricing, and deployment models. URL: https://www.areebi.com/compare/best-ai-governance-tools-2026 ### Areebi vs Lakera (Now Check Point AI Security) Compare Areebi's complete AI governance platform against Lakera's LLM security focus. Lakera was acquired by Check Point in 2025 - learn what that means for your AI governance strategy and why an AI control plane beats a prompt firewall. URL: https://www.areebi.com/compare/lakera ### Areebi vs Protecto.ai Compare Areebi's complete AI governance platform against Protecto.ai's AI data privacy focus. Discover why data masking alone is not AI governance and why organisations need a full control plane, not a single-purpose privacy tool. URL: https://www.areebi.com/compare/protecto-ai ### Areebi vs Prompt Security (Now SentinelOne Singularity) Compare Areebi's complete AI governance platform against Prompt Security's browser-based GenAI security. Prompt Security was acquired by SentinelOne for $250-300M in 2025 - learn what changed and why a purpose-built AI control plane outperforms a bundled security module. URL: https://www.areebi.com/compare/prompt-security ### Areebi vs Wald.ai Compare Areebi's complete AI governance platform against Wald.ai's SaaS-only AI workspace. Wald.ai offers DLP and policy controls but lacks private deployment, compliance automation, incident replay, and the governance depth enterprises require. See how a full AI control plane compares to a SaaS workspace with guardrails. URL: https://www.areebi.com/compare/wald-ai ### Areebi vs Nightfall AI Compare Areebi's complete AI governance platform against Nightfall AI's DLP-focused approach. Nightfall detects sensitive data in SaaS apps - Areebi governs the entire AI lifecycle with DLP as one of 14 capabilities including policy engine, audit trails, shadow AI detection, and compliance automation. URL: https://www.areebi.com/compare/nightfall-ai ### Areebi vs Microsoft Purview AI Hub Compare Areebi's provider-agnostic AI governance platform against Microsoft Purview AI Hub. Purview is locked to the Microsoft ecosystem - Areebi works with any LLM, any cloud, any deployment model, and delivers full governance beyond data classification. URL: https://www.areebi.com/compare/microsoft-purview-ai ### Areebi vs Robust Intelligence Compare Areebi's operational AI governance platform against Robust Intelligence (now Cisco AI Defense). Robust Intelligence focuses on pre-deployment model validation and AI red teaming - Areebi governs day-to-day AI usage with DLP, policy engine, audit trails, shadow AI detection, and compliance automation. URL: https://www.areebi.com/compare/robust-intelligence ### Areebi vs Cisco AI Defense: Complete Comparison for 2026 Compare Areebi's standalone AI governance platform against Cisco AI Defense. Cisco requires buying into the Cisco Security Cloud ecosystem. Areebi deploys independently in under 2 weeks at a fraction of the cost. URL: https://www.areebi.com/compare/cisco-ai-defense ### Areebi vs Palo Alto AI Security: Which Is Right for Your Organization? Compare Areebi's purpose-built AI governance platform against Palo Alto Networks AI Security. Palo Alto bundles AI capabilities with Prisma Cloud and NGFW at enterprise-only pricing. Areebi delivers standalone AI governance accessible to mid-market organisations. URL: https://www.areebi.com/compare/palo-alto-ai-security ### Areebi vs Netskope for AI Governance: A Detailed Comparison Compare Areebi's complete AI control plane against Netskope's AI visibility capabilities. Netskope provides network-level observation of AI usage through its CASB/SSE platform but lacks DLP on prompts, policy engine, workspace, and compliance templates. Areebi delivers active AI governance. URL: https://www.areebi.com/compare/netskope-ai-governance ### NIST AI RMF vs ISO/IEC 42001: Which AI Framework Should You Adopt? A detailed comparison of the NIST AI Risk Management Framework and ISO/IEC 42001. Scope, certifiability, audit model, structure, governance coverage, technical lifecycle coverage, when to use one vs the other vs both, and how Areebi maps to each. URL: https://www.areebi.com/compare/nist-ai-rmf-vs-iso-42001 ### Areebi vs Fairly AI: AI Control Plane vs Model Risk Management Compare Areebi's broad AI control plane (workspace, DLP, runtime policy, audit, multi-framework compliance) against Fairly AI's focused model risk management depth (per Fairly AI's public materials as of 2026-05). When to pick each, where they overlap, and where they are genuinely complementary. URL: https://www.areebi.com/compare/areebi-vs-fairly-ai ### Areebi vs Monitaur: AI Control Plane vs Model Governance and Assurance Compare Areebi's broad AI control plane (workspace, DLP, runtime policy, audit, multi-framework compliance) against Monitaur's model governance and assurance depth (model documentation, lineage, regulator-ready evidence) per Monitaur's public materials as of 2026-05. When to pick each, where they overlap, where they are genuinely complementary, and a fair evaluation checklist for prospects. URL: https://www.areebi.com/compare/areebi-vs-monitaur ### Build vs Buy AI Governance: Honest TCO and Decision Framework An honest comparison of building an AI governance programme in-house versus buying a vendor platform. Full TCO model (2 - 3 FTE × $250k loaded × 18 months ~ $750k - 1.2M + tooling vs $30k - 300k/year vendor license), framework for when each path wins, the hybrid open-source pattern, and a comparison table covering time-to-compliance, audit-readiness, framework coverage, and vendor risk. URL: https://www.areebi.com/compare/build-vs-buy-ai-governance ### Areebi vs Credal: 2026 AI Security Platform Comparison Compare Areebi's full AI control plane against Credal.ai's enterprise AI security platform. Credal focuses on approved prompts, DLP, and a hosted AI hub. Areebi adds deployment flexibility, governance depth, and compliance automation. An honest 2026 head-to-head. URL: https://www.areebi.com/compare/credal ### Areebi vs Wiz AI Security Posture Management (AI-SPM): 2026 Comparison Compare Areebi's Secure AI Control Plane against Wiz AI-SPM. Wiz AI-SPM is an extension of Wiz's CNAPP for AI workload discovery and model inventory. Areebi is a governance-first AI control plane. Different categories, sometimes both fit. An honest 2026 comparison. URL: https://www.areebi.com/compare/wiz-ai-spm ### Areebi vs 6clicks: Runtime AI Control Plane vs GRC Platform (Australia) An honest, architecture-first comparison of Areebi (a runtime secure AI control plane that enforces DLP, policy and guardrails on live AI traffic) and 6clicks (an established, Australian-founded GRC platform with its Hailey AI engine). Different layers, often complementary - here is how to choose, for Australian regulated enterprises. URL: https://www.areebi.com/compare/areebi-vs-6clicks ### Areebi vs Redactive: Secure AI Control Plane vs Permissions-Aware AI Data Layer (Australia) An honest, architecture-first comparison of Areebi and Redactive for Australian regulated enterprises. Redactive (now part of RecordPoint) publicly positions itself as a permissions-aware AI data layer with named Australian deployments; Areebi is a privately deployable runtime control plane spanning DLP, policy, audit, guardrails and shadow-AI discovery. We explain where each fits and where they are complementary. URL: https://www.areebi.com/compare/areebi-vs-redactive ### Best AI Governance and Security Platforms for Australian Regulated Enterprises (2026) An honest, Australian-market landscape of AI governance and security platforms for regulated buyers in 2026. Compare runtime AI control planes (Areebi, Microsoft Purview), permissions-aware AI data layers (Redactive, now RecordPoint) and GRC/AI-governance platforms (6clicks, OneTrust, ServiceNow) against the Privacy Act ADM transparency obligation, APRA CPS 230 and CPS 234, IRAP and data sovereignty, and the voluntary AI safety guidance. Includes a category fit table and a how-to-choose framework. URL: https://www.areebi.com/compare/best-ai-governance-platform-australia-2026 ### AnythingLLM vs LibreChat: Honest Technical Comparison (2026) A deep, vendor-neutral comparison of AnythingLLM and LibreChat - architecture, RAG, multi-user and SSO, deployment, MCP extensibility, and licences. Both are MIT-licensed and excellent. We explain who should pick which, with real feature names verified as of June 2026. URL: https://www.areebi.com/compare/anythingllm-vs-librechat ### AnythingLLM vs Open WebUI: Honest Comparison + Licence Facts (2026) A vendor-neutral comparison of AnythingLLM and Open WebUI - architecture, RAG, multi-user and SSO, deployment, MCP, and the licences. We explain Open WebUI's modified BSD-3-Clause branding clause (the 50-user threshold) in plain terms, and who should pick which. Verified June 2026. URL: https://www.areebi.com/compare/anythingllm-vs-open-webui ### Areebi vs AnythingLLM: The Engine and the Governed Platform (2026) Areebi is built on AnythingLLM. This is an honest comparison of the raw open-source AnythingLLM engine against Areebi, the hardened, governed enterprise platform built on it - DLP, immutable audit, policy engine, enforced SSO/MFA, compliance templates, and support SLAs. When raw AnythingLLM alone is the right call, we say so. Verified June 2026. URL: https://www.areebi.com/compare/areebi-vs-anythingllm ### ChatGPT Enterprise Alternatives: 9 Real Options for 2026 Nine honest ChatGPT Enterprise alternatives for business in 2026, assessed across data privacy posture, deployment model, governance controls, price band, and best-fit use case. Microsoft 365 Copilot, Claude Enterprise, Google Gemini for Workspace, Glean, Writer, AnythingLLM, LibreChat, Areebi, and building your own - with a selection-criteria framework and a comparison table. Pricing cited. URL: https://www.areebi.com/compare/chatgpt-enterprise-alternatives ### EU AI Act vs NIST AI RMF: Clause-by-Clause Comparison How EU AI Act (Regulation 2024/1689) and NIST AI Risk Management Framework 1.0 differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/eu-ai-act-vs-nist-ai-rmf ### EU AI Act vs GDPR: Clause-by-Clause Comparison How EU AI Act (Regulation 2024/1689) and GDPR (Regulation 2016/679, Articles 22, 25, 35) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/eu-ai-act-vs-gdpr ### ISO 42001 vs SOC 2: Clause-by-Clause Comparison How ISO/IEC 42001:2023 AI Management System and SOC 2 Trust Services Criteria differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/iso-42001-vs-soc-2 ### ISO 42001 vs EU AI Act: Clause-by-Clause Comparison How ISO/IEC 42001:2023 AI Management System and EU AI Act (Regulation 2024/1689) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/iso-42001-vs-eu-ai-act ### EU AI Act vs Colorado AI Act: Clause-by-Clause Comparison How EU AI Act (Regulation 2024/1689) and Colorado AI Act (SB 24-205) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/eu-ai-act-vs-colorado-ai-act ### Colorado AI Act vs NYC LL144: Clause-by-Clause Comparison How Colorado AI Act (SB 24-205) and NYC Local Law 144 (Automated Employment Decision Tools) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/colorado-ai-act-vs-nyc-local-law-144 ### NIST AI RMF vs NIST GenAI Profile: Clause-by-Clause Comparison How NIST AI Risk Management Framework 1.0 and NIST AI 600-1 Generative AI Profile differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/nist-ai-rmf-vs-generative-ai-profile ### HIPAA vs GDPR: Clause-by-Clause Comparison How HIPAA Privacy + Security Rules and GDPR (Regulation 2016/679, Articles 22, 25, 35) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/hipaa-vs-gdpr-for-ai ### SOC 2 vs FedRAMP: Clause-by-Clause Comparison How SOC 2 Trust Services Criteria and FedRAMP Moderate / High (Rev. 5) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/soc-2-vs-fedramp-for-ai ### ISO 42001 vs GDPR: Clause-by-Clause Comparison How ISO/IEC 42001:2023 AI Management System and GDPR (Regulation 2016/679, Articles 22, 25, 35) differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/iso-42001-vs-gdpr ### NIST AI RMF vs Singapore MGF: Clause-by-Clause Comparison How NIST AI Risk Management Framework 1.0 and Singapore Model AI Governance Framework + AI Verify differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/nist-ai-rmf-vs-singapore-model-ai-governance ### SOC 2 vs HIPAA: Clause-by-Clause Comparison How SOC 2 Trust Services Criteria and HIPAA Privacy + Security Rules differ across 15 governance dimensions, every cell clause-cited. Overlap, gaps, penalties and which to implement first. URL: https://www.areebi.com/compare/soc-2-vs-hipaa-for-ai ## Blog ### Shadow AI Detection: How to Detect Unsanctioned AI (2026 Guide) A practical guide to shadow AI detection: the five detection-signal families (network and DNS, SaaS billing, identity and OAuth, endpoint and browser, collaboration apps), the detection tooling landscape (CASB, DLP, SSPM, browser governance, purpose-built AI security), how to build a continuous detection programme, the metrics to track, and the block-versus-govern decision. Cited primary sources: IBM Cost of a Data Breach 2025, Cyberhaven, Harmonic Security, Varonis, Gartner. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/shadow-ai-detection-guide ### ChatGPT Enterprise Pricing in 2026: The Complete Cost Breakdown The definitive 2026 breakdown of ChatGPT Enterprise pricing: reported per-seat costs ($45-$75/user/month), the 150-seat minimum, the new credits-based flexible pricing model, hidden costs, and a sourced TCO comparison against Microsoft 365 Copilot, Claude Enterprise, and private deployment at 100, 250, and 500 seats. Every number cited. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/chatgpt-enterprise-pricing-breakdown ### Self-Hosted LLM for Business: The Realistic 2026 Guide A practical, opinionated guide to self-hosting a large language model for business in 2026 - why businesses self-host (data control, residency, cost at scale), the realistic stack options (Ollama, vLLM, AnythingLLM, LibreChat, Open WebUI) in one comparison table, hardware sizing, the hidden operational costs DIY estimates omit, and when a managed private deployment beats building it yourself. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/self-hosted-llm-for-business ### On-Premise AI Chatbot Buyer's Guide (2026) A buyer's guide for selecting an on-premise or private AI chatbot for business in 2026 - a requirements checklist, an evaluation criteria table across security, deployment, model support, and governance, the questions to ask every vendor, the red flags that should end an evaluation, and a TCO worksheet that captures the costs vendors leave out. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/on-premise-ai-chatbot-buyers-guide ### AnythingLLM Enterprise Guide: Deployment, Hosting, and Hardening (2026) A definitive guide to running AnythingLLM in an enterprise: Docker, Kubernetes and desktop deployment, multi-user setup, the real enterprise-readiness gaps in the raw open-source build (audit depth, DLP, policy enforcement, SSO enforcement), the hosting landscape, a hardening checklist, and where a governed platform fits. Facts verified June 2026. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/anythingllm-enterprise-guide ### Open WebUI Enterprise License Explained: The 50-User Branding Clause (2026) A factual, neutral explanation of the Open WebUI licence: what changed and when, the exact branding-protection clause, the 50-user / 30-day threshold that triggers the enterprise requirement, what the enterprise licence provides, and the realistic options for organisations - comply, license, or move to an alternative. Verified against the official LICENSE and docs, June 2026. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/open-webui-enterprise-license-explained ### LibreChat for Business: What It Does Well and the Governance Gaps (2026) A practical guide to deploying LibreChat in a business: what it genuinely does well (multi-provider chat, strong enterprise auth, spend controls, agents and MCP), the requirements for a production business deployment, the governance gaps you must plan around (DLP, immutable audit, policy enforcement, compliance evidence), and how it compares to other open-source options. Facts verified June 2026. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/librechat-for-business ### Is ChatGPT Safe for Business? An Evidence-Led 2026 Review A balanced, evidence-led answer to whether ChatGPT is safe for business in 2026. What OpenAI does with consumer versus Team/Business and Enterprise data, the real incidents (Samsung, the March 2023 chat-history bug), the leakage statistics (Cyberhaven, Harmonic), a risk-by-tier table, a controls checklist for safe use, and when a private deployment is the right answer. Verdict: yes, with conditions. Every statistic cited. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/is-chatgpt-safe-for-business ### The Complete AI Acceptable Use Policy Guide (2026) The most complete free guide to writing an AI acceptable use policy in 2026. Why every company needs one now, the 12 sections every AI AUP must contain - each with real, copy-ready example policy language - industry variations for healthcare and financial services, a rollout playbook, and the common failure modes. Includes a free downloadable template and a policy generator. Sources cited. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/ai-acceptable-use-policy-guide ### AI Data Sovereignty in Australia: The 2026 Practical Guide A practical 2026 guide to AI data sovereignty in Australia: what sovereignty means for AI workloads under Australian law, the 2025-2026 trigger events (the DeepSeek government-device ban, APRA's April 2026 AI letter, GovAI Chat on IRAP-assessed infrastructure, ACSC guidance), where popular AI tools actually process Australian data, the sovereignty options ladder, and a compliance mapping. Sources cited. Published: 2026-06-10 URL: https://www.areebi.com/resources/blog/ai-data-sovereignty-australia ### NIST AI RMF MAP Function: Deep Dive for CISOs (2026) A CISO-focused deep dive into the NIST AI RMF MAP function and its five subcategories (MAP 1-5). Concrete context-setting, risk categorization, capability documentation, impact mapping, and risk tolerance workflows, mapped to Areebi platform capabilities and authoritative source documents (NIST AI 100-1, AI 600-1, OMB M-24-10, EO 14110, ISO/IEC 42001). Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/nist-ai-rmf-map-function-deep-dive ### NIST AI RMF MANAGE Function: Deep Dive for CISOs (2026) A CISO-focused deep dive into the NIST AI RMF MANAGE function and its four subcategories (MANAGE 1-4). Concrete risk prioritization and response, resource allocation, risk communication, and continuous improvement workflows, mapped to Areebi platform capabilities and authoritative source documents (NIST AI 100-1, AI 600-1, OMB M-24-10, EO 14110, ISO/IEC 42001). Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/nist-ai-rmf-manage-function-deep-dive ### Solving Brand Confusion in AI Security: Lessons from Search Misspellings How new AI security vendors handle brand-misspell search queries: alternateName JSON-LD schema, redirected misspell domains, branded content clusters, and Search Console attribution. Practical SEO playbook with examples and citations to Google Search Central, Schema.org, and John Mueller statements. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/solving-brand-confusion-ai-security-misspellings ### The Real Cost of One Shadow-AI Data Breach (2026 Models) Worked cost model for a single shadow-AI data breach in a mid-market regulated US organisation. Starts from the IBM Cost of a Data Breach Report 2025 baseline ($4.88M US average), then layers AI-specific cost factors: longer dwell time, EU AI Act and GDPR penalty exposure, HIPAA Tier 4 fines, and reputation harm. Sources: IBM, Ponemon, EU AI Act, HHS, NIST AI RMF. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/cost-of-one-shadow-ai-breach-2026 ### Governing GenAI in Healthcare Operations: A Compliance-First Playbook Practical playbook for governing generative AI across clinical and operational workflows in US healthcare: ambient clinical documentation, claims and coding, patient communication, research, and administrative ops. Covers HIPAA Privacy Rule, Security Rule, BAA expectations, HHS guidance, ONC interoperability obligations, and per-workflow control patterns. 45 CFR 164 referenced throughout. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/governing-genai-healthcare-operations-2026 ### The Real Cost of a Toxic AI Vendor Backlink Profile (2026 Case Notes) Defensive-SEO field notes for AI security and governance vendors. PBN patterns targeting the AI-security category (rank-your.*, buybacklinks.*, link-farm clusters), what a disavow operation actually involves, and the SEO and brand-trust cost of doing nothing. Cites John Mueller statements on the disavow tool, Ahrefs DR documentation, and Bing Webmaster Tools. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/toxic-ai-vendor-backlink-profile-2026 ### State of AI Governance: May 2026 Roundup A monthly roundup of AI governance developments as of May 2026: EU AI Act enforcement nine months after high-risk obligations landed, the Colorado AI Act's February 2026 effective date in operation, California SB-942 disclosures, Singapore AI Verify adoption, and the one-year mark of NIST AI 600-1. Cites the EU AI Act Service, NIST, IAPP, and the OECD AI Policy Observatory. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/state-of-ai-governance-may-2026 ### The CISO's AI Governance Playbook: 30/60/90 Day Plan A practical 30/60/90 day playbook for CISOs standing up AI governance: 30 days of discovery and shadow AI audit, 60 days of policy, DLP, and audit baseline, 90 days of compliance mapping and tabletop. Includes checklists by phase and references to NIST AI RMF, ISACA's AI Audit Toolkit, CSA's MLSecOps work, and IAPP. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ciso-ai-governance-playbook-30-60-90 ### Prompt Injection 2026: A Defender's Deep Dive A defender-focused deep dive into prompt injection as of 2026. Real attack patterns (direct, indirect via retrieval, multi-turn, payload smuggling), concrete defences (input sanitisation, output validation, structured prompting, policy enforcement at the boundary), and authoritative source mapping to OWASP Top 10 for LLM Applications (LLM01), NIST AI 600-1, MITRE ATLAS, and the work of Simon Willison. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/prompt-injection-deep-dive-2026 ### The AI Red Team You Don't Have Yet (And How To Start) A practical guide to building the AI red team capability most enterprises are missing in 2026. What an AI red team is, how it differs from a traditional red team, the hiring versus outsourcing decision, a 90-day starter plan, the exercises to run first, and how it all maps to NIST AI 100-1, NIST AI 600-1, the AI Village at DEF CON, and the MLCommons AI Safety community. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-red-team-you-dont-have-2026 ### FedRAMP 20x and What It Means for AI Vendors in 2026 A practitioner-focused brief on the FedRAMP 20x modernisation programme and what it changes for AI vendors selling to the US federal government in 2026. How 20x differs from legacy FedRAMP Moderate / High authorisations, where it intersects with OMB M-24-10 and M-24-18, what the new continuous-monitoring expectations look like, and what AI vendors need to start doing now. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/fedramp-20x-impact-ai-vendors-2026 ### ISO/IEC 42001 Certification: A 12-Month Roadmap A detailed 12-month roadmap to ISO/IEC 42001:2023 certification for AI Management Systems (AIMS). Four phases mapped to months 1-12 covering scope and gap analysis, policy and risk management, operations and monitoring, and audit preparation through Stage 1 and Stage 2. Comparison to ISO/IEC 27001 (overlap and differences), NIST AI RMF crosswalk, and a practical accreditation-body shortlist (ANSI/UL, BSI, DNV, SGS). Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/iso-42001-certification-12-month-roadmap ### DORA + AI: What Financial Institutions Need to Know by 2026 The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has been in application since 17 January 2025. For financial entities now running generative AI in production, DORA quietly added a new set of obligations - around ICT third-party risk, incident reporting, resilience testing, and information sharing - that apply to every AI workload connected to a covered function. This deep dive maps how AI workloads sit inside DORA's five pillars, where the audit gaps emerge in practice, and how Areebi's audit trail and policy engine reduce the evidence burden. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/dora-ai-financial-institutions-2026 ### Build vs Buy: The AI Governance Platform Decision (2026) The honest math on building an AI governance platform in-house versus buying one, and the realistic open-source middle path. Twelve-month total cost of ownership comparison for a 500-employee company, the criteria that make build the correct answer, the criteria that make buy the correct answer, and a decision framework you can hand to a CFO without losing the room. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/build-vs-buy-ai-governance-platform-2026 ### AI Agent Monitoring 101: Observability Beyond Prompts Monitoring an agentic AI system is a different discipline from monitoring a single-turn LLM prompt. Tool-call traces, action authorization audit, retrieval provenance, multi-step replay, and drift detection all matter. This guide explains the new agent observability stack, maps it to OWASP LLM06 Excessive Agency and LLM07 Insecure Plugin Design, and shows how to wire it to NIST AI 600-1's agent-specific guidance. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-agent-monitoring-observability-2026 ### Australian Privacy Act 2026: A CISO's Checklist The Privacy and Other Legislation Amendment Act 2024 passed Australian Parliament on 29 November 2024 and received Royal Assent on 10 December 2024. It is the largest revision of the Privacy Act 1988 in a decade. The children's privacy reforms commence 10 December 2026, the statutory tort of serious invasions of privacy was active from 10 June 2025, and the OAIC's 2026 enforcement priorities lean heavily on AI and automated decision-making. This is the CISO-facing 12-month compliance checklist. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/australian-privacy-act-2026-ciso-checklist ### The 90-Minute Shadow AI Hunt Playbook (2026) A practical 90-minute playbook to discover shadow AI in your organisation. Six parallel workstreams - SaaS billing audit, DNS log scan, browser extension survey, finance card scan, Slack/Teams app inventory, and SSO/IDP scan - with concrete commands, worksheets, and a unified inventory output. Sources: CSA Top Threats to Cloud Computing 2024, NIST SP 800-115, IDC SaaS management research, IAPP shadow IT studies. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/90-minute-shadow-ai-hunt-playbook ### OMB M-24-18 Federal Contractor AI Compliance Checklist (2026) A working compliance checklist for federal AI contractors under OMB Memorandum M-24-18 (October 2024). Covers scope, pre-award diligence, in-life monitoring, rights-impacting versus safety-impacting AI, the AI Use Case Inventory requirement, and cross-references to NIST AI RMF and Executive Order 14110. Authoritative sources: OMB M-24-18, OMB M-24-10, EO 14110, AI.gov, GSA AI guidance. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/omb-m-24-18-federal-contractor-checklist ### OpenAI Enterprise + AI Governance: A CISO's Guide (2026) A CISO-grade review of OpenAI ChatGPT Enterprise: BAA availability, SOC 2 status, EU data residency, retention controls, fine-tuning isolation, and the audit log and identity gaps where an external control plane is required. Authoritative sources: OpenAI Trust portal, OpenAI Enterprise privacy documentation, NIST AI 600-1, EU AI Act Article 50. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/openai-enterprise-ai-governance-ciso-guide ### Anthropic Claude + Areebi: An Architecture Walkthrough (2026) An honest architecture walkthrough for deploying Anthropic Claude in an enterprise with the Areebi control plane. Covers Claude API access, Claude Enterprise, model versioning, prompt caching, Constitutional AI safety controls, and where Areebi adds workspace, DLP, and audit at the boundary. Sources: Anthropic Trust portal, Claude API documentation, Constitutional AI paper, NIST AI 600-1. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/anthropic-claude-areebi-architecture-walkthrough ### The AI Vendor List Your CFO Asked For (And How to Build It) - 2026 The practical playbook for building the AI vendor inventory CFOs now demand. Scope, classification, risk tiering, spend visibility, exit clauses, BAA and DPA matrices, with citations to NIST SP 800-161, IDC AI vendor surveys, IAPP vendor risk guidance, and Gartner AI vendor frameworks. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-vendor-list-cfo-2026 ### Singapore AI Verify in 2026: Implementation Notes for ASEAN Buyers A practical implementation guide to Singapore's AI Verify framework, the AI Verify Foundation toolkit, and the Model AI Governance Framework. Crosswalks to NIST AI RMF, ISO/IEC 42001, the EU AI Act, and OECD AI Principles, with citations to IMDA, AI Verify Foundation, PDPC, and OECD AI Policy Observatory. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/singapore-ai-verify-implementation-2026 ### Manufacturing AI Operations: Trade Secret Protection in 2026 How manufacturers protect CAD/CAM, process IP, and supply-chain optimisation models when production teams use AI. Air-gapped deployment, customer-managed encryption, redaction, output watermarking, and contract patterns aligned with the US Defend Trade Secrets Act, EU Trade Secrets Directive, NIST SP 800-218, and ISO/IEC 27002 Annex. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/manufacturing-ai-trade-secret-protection-2026 ### Insurance Underwriting AI: A Governance Framework for Actuaries (2026) An actuarial-grade governance framework for AI in insurance underwriting and pricing. Covers the NAIC AI Model Bulletin, state DOI examinations, model risk overlap with Federal Reserve SR 11-7 and OCC 2011-12, plus Colorado DOI and NY DFS bulletins. Practical pattern for documentation, fairness testing, drift monitoring, and examiner audit trails. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/insurance-underwriting-ai-actuarial-governance-2026 ### GDPR + Generative AI: The EDPB Opinion 28/2024 Implementation Playbook for CISOs A CISO-grade implementation playbook for EDPB Opinion 28/2024. Covers anonymity tests, legitimate interest assessments, Article 6 lawful bases, DPIAs, and the model-training vs deployment split for LLM systems. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/gdpr-generative-ai-edpb-opinion-28-2024-playbook ### AI Bill of Materials (AIBOM): What NTIA, NIST, and EO 14110 Require - and What to Ship Now An engineering-grade AIBOM playbook covering NTIA SBOM minimum elements adapted for AI, SPDX 3.0 AI profile fields, CycloneDX 1.6 ML-BOM components, EO 14110 reporting obligations, and how to generate one in CI. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/aibom-ai-bill-of-materials-nist-eo-14110-playbook ### SOC 2 + AI Workloads: How the Trust Services Criteria Actually Map to LLM Systems An auditor-grade mapping of AICPA Trust Services Criteria to LLM systems. Covers CC6 logical access for inference endpoints, CC7 incident management for prompt injection and drift, A1 inference availability, PI1 output integrity, and P1-P8 privacy of training data. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/soc-2-ai-workloads-trust-services-criteria-mapping ### HIPAA + Clinical AI: The 2026 Playbook for PHI in LLM Systems A clinical-AI playbook covering PHI in retrieval-augmented generation, de-identification for embeddings, BAA requirements for LLM vendors, Section 1557 clinical decision support, and FDA SaMD classification for clinical LLMs. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/hipaa-clinical-ai-protected-health-information-2026-playbook ### Open source LLMs vs proprietary models: the 2026 enterprise governance reality A 2026 comparison of open-weight LLMs (Llama, Mistral, DeepSeek, Qwen, Gemma) against proprietary models (GPT, Claude, Gemini) on data residency, fine-tuning rights, audit access, and licence terms. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/open-source-ai-vs-proprietary-llm-enterprise-governance-2026 ### AI incident response runbook: the 2026 playbook for prompt injection, model drift, and DLP breaches A practical AI incident response runbook mapping prompt injection, output toxicity, DLP breaches, and model supply-chain compromise to NIST SP 800-61r2 and the NIST AI 600-1 GAI Profile. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-incident-response-runbook-2026 ### Fine-tuning vs RAG vs prompt engineering: the 2026 compliance trade-off matrix A regulator-grounded comparison of fine-tuning, RAG, and prompt engineering across data residency, GDPR right to erasure, EU AI Act provider obligations, audit completeness, drift, and cost. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/llm-fine-tuning-vs-rag-compliance-tradeoffs-2026 ### AI Control Plane RFP template: the 87-question buyer's checklist for 2026 An 87-question RFP template for AI Control Plane evaluation, mapped to NIST AI 600-1, ISO 42001, SOC 2, EU AI Act, Gartner TRiSM, and ENISA AI threat landscape references. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-control-plane-rfp-template-2026 ### The 1-year AI governance retrospective: a template CISOs can actually use A 12-section retrospective template for CISOs running an AI governance program that turned one this year. Covers policy effectiveness, control coverage, incident review, training metrics, vendor performance, audit findings, regulatory drift, technology stack lessons, workforce capability, board confidence, year-2 priorities, and the 'what we would do differently' debrief - grounded in NIST AI 600-1, ISO/IEC 42001:2023, Gartner AI TRiSM, and the SANS 2024 AI Survey. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-governance-program-1-year-retrospective-template-2026 ### Quarterly AI governance board reporting: the 2026 template A 4-page section-by-section template for the quarterly AI governance board update - KPIs by quarter, AI risk heatmap, regulatory readiness scorecard, vendor risk matrix, incident summary, and recommended decisions - tuned to the tone of the NACD AI Director's Handbook 2024, ISS Sustainability Quality Score AI metrics, Glass Lewis 2024-2025 AI engagement guidance, and the UK Financial Reporting Council's 2024 board-level AI guidance. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/board-reporting-ai-governance-quarterly-template-2026 ### Cybersecurity insurance + AI: what's covered, what's excluded, what to demand in 2026 A deep dive into how cyber liability policies treat AI-related loss in 2026 - broad-form AI usage exclusions, deepfake exclusions, autonomous-system carveouts - with the LMA 5400 series of Lloyd's model wordings compared, AI claim scenarios mapped, and a negotiation checklist of clauses brokers should be demanding. Grounded in Lloyd's of London model exclusions LMA 5400 / 5401 / 5403, the NAIC Cybersecurity Insurance Data Call 2024, the Marsh State of Cyber 2024 report, the AON Global Risk Management Survey 2024, and the CISA Tabletop Exercise Packages for cyber insurance. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/cybersecurity-insurance-ai-coverage-exclusions-2026 ### Generative AI vendor risk questionnaire template: the 60-question 2026 update A 60-question vendor risk questionnaire (VRQ) template for generative AI and AI-feature SaaS vendors, organised into six sections (model and provider, data governance, security, compliance and audit, operational, contractual), with each question referenced to the source standard - SIG 2024, CSA CCM v4, ISO/IEC 27036, NIST SP 800-161, and HHS HIPAA Risk Analysis guidance. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/procurement-vrq-questionnaire-template-genai-saas-2026 ### The 2026 AI Governance OKR Template: 12 Quarterly Objectives Every CISO Should Consider An opinionated OKR template for CISOs running an AI governance programme in 2026. Twelve quarterly objectives covering policy coverage, control implementation, vendor management, training, incident response, and regulatory readiness - each tied to a NIST AI 600-1 function, ISO/IEC 42001:2023 control, or EU AI Act article, with a default first-quarter target a programme manager can adopt without redrafting. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/ai-governance-okr-template-2026 ### FDA AI/ML-Enabled Medical Devices + SaMD + Clinical Decision Support: The 2026 Governance Playbook How to map the FDA's predetermined change control plan (PCCP), the Software as a Medical Device (SaMD) framework, the software premarket guidance, and HHS Section 1557 to a production clinical decision support deployment in 2026. Includes the SaMD risk categorisation matrix, the PCCP minimum elements, the human-oversight expectations for clinical AI, the Section 1557 nondiscrimination obligations, and the audit-trail design that holds up to an FDA inspection. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/fda-ai-medical-device-samd-clinical-decision-support-2026 ### Legal AI: Protecting Attorney-Client Privilege + Work Product in 2026 A practical guide for law firms and in-house legal teams using generative AI in 2026. We map ABA Model Rules 1.1, 1.6, and 5.3 onto contemporary LLM usage, walk through the privilege and work-product risks created by foundation model sampling and provider data handling, and explain how to design AI workflows that survive both ethics scrutiny and judicial review. Includes coverage of Mata v. Avianca, the EDNY Park v. Kim sanctions, ABA Formal Opinion 512, and the California Bar GenAI ethics guidance. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/legal-services-ai-privilege-work-product-2026 ### Year-End 2026: The 30-Item AI Governance Checklist Before Fiscal Year-End A practical 30-item year-end checklist for CISOs and AI governance leads heading into the 2026 fiscal close. Covers vendor contract renewals (DPAs, AI addenda, SCC reaffirmations), policy reviews, training refreshes, the year-end incident retrospective, audit prep for the new fiscal year, the board reporting deck, and the compliance calendar setup for 2027 - mapped to NIST AI 600-1, NIST CSF 2.0, and the most current 2024-2025 sector surveys. Published: 2026-05-20 URL: https://www.areebi.com/resources/blog/year-end-2026-ai-governance-priorities-checklist ### NIST AI RMF GOVERN Function: Deep Dive for CISOs (2026) A CISO-focused deep dive into the NIST AI RMF GOVERN function and its six subcategories (GOVERN 1-6). Concrete policies, accountability structures, and third-party AI controls, mapped to Areebi platform capabilities and authoritative source documents (NIST AI 100-1, AI 600-1, OMB M-24-10, EO 14110, ISO/IEC 42001). Published: 2026-05-19 URL: https://www.areebi.com/resources/blog/nist-ai-rmf-govern-function-deep-dive ### The AI Control Plane: The Enterprise Guide to Centralized AI Management The definitive enterprise guide to AI control planes. Learn what an AI control plane is, why your organization needs one in 2026, the five pillars of effective AI control, industry use cases, deployment models, and how to evaluate platforms for centralized AI management and governance. Published: 2026-04-13 URL: https://www.areebi.com/resources/blog/ai-control-plane-enterprise-guide ### The ROI of AI Governance: Building the Business Case for Your CFO A comprehensive framework for quantifying AI governance ROI, including cost models, TCO comparisons, and a CFO-ready business case template. Learn how structured AI governance delivers 3-5x return within 18 months. Published: 2026-04-13 URL: https://www.areebi.com/resources/blog/ai-governance-roi-business-case ### Introducing Areebi: The AI Control Plane Built for Mid-Market Enterprise Areebi launches as the first AI control plane purpose-built for mid-market enterprise. Deploy a fully governed AI environment in days, not months, with SSO, DLP, audit logging, compliance automation, and multi-model access out of the box. Published: 2026-04-12 URL: https://www.areebi.com/resources/blog/areebi-platform-launch-april-2026 ### Getting Started with Areebi: A 30-Day Implementation Guide A week-by-week implementation guide for deploying Areebi's AI control plane. Covers SSO integration, DLP configuration, workspace setup, compliance automation, shadow AI discovery, and post-deployment optimization for mid-market enterprises. Published: 2026-04-11 URL: https://www.areebi.com/resources/blog/getting-started-areebi-implementation-guide ### The Global AI Compliance Landscape in 2026: Every Law You Need to Know A comprehensive guide to every major AI regulation in effect or pending in 2026, including the EU AI Act, NIST AI RMF, Colorado AI Act, UK principles, Australia Privacy Act amendments, and Singapore's Agentic AI framework. Comparison tables, enforcement dates, and penalties included. Published: 2026-04-10 URL: https://www.areebi.com/resources/blog/ai-compliance-landscape-2026 ### AI Control Plane vs AI Gateway: What's the Difference and Which Do You Need? AI gateways handle API routing and load balancing for LLM traffic. AI control planes provide full governance, DLP, compliance, and audit capabilities on top of routing. Learn the differences, when each is appropriate, and why enterprises increasingly need a control plane approach. Published: 2026-04-10 URL: https://www.areebi.com/resources/blog/ai-control-plane-vs-ai-gateway ### Prompt Injection Prevention for Enterprise AI: A Complete Defense Guide Prompt injection is the most critical vulnerability in enterprise LLM deployments. Learn how direct and indirect prompt injection attacks work, explore the OWASP LLM Top 10, and implement multi-layer defense strategies including input validation, output filtering, and architectural isolation. Published: 2026-04-10 URL: https://www.areebi.com/resources/blog/prompt-injection-prevention-enterprise ### Healthcare AI Governance: The 2026 CISO's Guide to HIPAA-Compliant AI A comprehensive guide for healthcare CISOs navigating HIPAA-compliant AI deployment in 2026. Covers PHI risks in clinical AI workflows, regulatory requirements, platform evaluation criteria, and a step-by-step implementation roadmap for governed AI in healthcare organizations. Published: 2026-04-10 URL: https://www.areebi.com/resources/blog/healthcare-ai-governance-ciso-guide-2026 ### Colorado AI Act 2026: What Enterprises Must Do Before June 30 The Colorado AI Act (SB 24-205) enforcement begins June 30, 2026. Learn the requirements for high-risk AI systems, impact assessments, consumer disclosures, and the duty of care obligation. Practical compliance steps for enterprise teams. Published: 2026-04-08 URL: https://www.areebi.com/resources/blog/colorado-ai-act-what-to-know ### How to Build an Enterprise AI Control Plane: A Step-by-Step Guide A practical step-by-step guide to building and deploying an enterprise AI control plane. Covers prerequisites, AI landscape assessment, policy definition, technical controls, compliance mapping, deployment, monitoring, and a build vs buy analysis for mid-market and enterprise organizations. Published: 2026-04-07 URL: https://www.areebi.com/resources/blog/building-enterprise-ai-control-plane ### AI Red Teaming: The Enterprise Guide to Adversarial Testing of LLMs AI red teaming is the practice of adversarially testing AI systems to discover vulnerabilities before attackers do. Learn the methodologies (NIST 600-1, Microsoft AI Red Team), attack types to test, and how to build a continuous adversarial testing program for enterprise LLM deployments. Published: 2026-04-07 URL: https://www.areebi.com/resources/blog/ai-red-teaming-guide ### NIST AI RMF Implementation: A Practical Guide for Enterprise Teams Step-by-step guide to implementing the NIST AI Risk Management Framework across all four core functions: Govern, Map, Measure, and Manage. Practical checklists, team structures, and tooling recommendations for enterprise AI governance. Published: 2026-04-05 URL: https://www.areebi.com/resources/blog/nist-ai-rmf-implementation-guide ### How an AI Control Plane Automates Compliance Across Every Framework Learn how an AI control plane automates compliance across the EU AI Act, HIPAA, SOC 2, GDPR, NIST AI RMF, and ISO 42001. Discover how compliance-as-code policies, continuous evidence generation, and automated audit readiness replace manual tracking and point-in-time audits. Published: 2026-04-04 URL: https://www.areebi.com/resources/blog/ai-control-plane-compliance-automation ### UK AI Regulation in 2026: Principles, Regulators, and What to Expect Comprehensive guide to UK AI regulation in 2026, covering the five core principles, sector-specific regulators (FCA, ICO, Ofcom, CMA), the AI Safety Institute, and the expected AI bill. Practical compliance guidance for enterprises operating in the UK market. Published: 2026-04-03 URL: https://www.areebi.com/resources/blog/uk-ai-regulation-guide ### AI Model Supply Chain Security: Protecting Enterprise AI from Third-Party Risk Third-party and open-source AI models introduce supply chain risks that most enterprises overlook. Learn about model provenance verification, serialization attacks like pickle exploits, model card requirements, and how to build a secure model vetting process for enterprise deployments. Published: 2026-04-03 URL: https://www.areebi.com/resources/blog/model-supply-chain-security ### ISO 42001 Certification for AI: Requirements, Timeline, and Cost Complete guide to ISO/IEC 42001 certification for AI management systems. Learn the requirements, typical costs ($30K-$150K+), audit process, timeline (6-12 months), and how to prepare your organization for the world's first AI-specific ISO standard. Published: 2026-03-30 URL: https://www.areebi.com/resources/blog/iso-42001-certification-guide ### What Is Shadow AI? The Complete Enterprise Guide Shadow AI is the use of unauthorized AI tools by employees without IT oversight. Learn how to detect, prevent, and govern shadow AI across your enterprise - without blocking productivity. Published: 2026-03-28 URL: https://www.areebi.com/resources/blog/what-is-shadow-ai ### The 10 Most Dangerous LLM Attack Vectors in 2026 A comprehensive guide to the 10 most dangerous attack vectors targeting large language models in 2026. From prompt injection and data poisoning to model extraction and agent tool misuse, learn how each attack works, its real-world impact, and enterprise defense strategies. Published: 2026-03-28 URL: https://www.areebi.com/resources/blog/llm-attack-vectors-2026 ### Australia Privacy Act Amendments 2026: AI Automated Decision-Making Rules Australia's 2026 Privacy Act amendments introduce mandatory transparency and contestability requirements for AI automated decision-making. Learn the new rules for notification, human review, explainability, and penalties up to AUD 50 million. Published: 2026-03-25 URL: https://www.areebi.com/resources/blog/australia-ai-privacy-act-2026 ### Data Poisoning Attacks on Enterprise AI: Detection and Defense Strategies Data poisoning attacks corrupt AI model behavior by manipulating training and fine-tuning data. Learn about backdoor attacks, clean-label attacks, fine-tuning data risks, detection techniques including anomaly detection and provenance tracking, and enterprise defense strategies. Published: 2026-03-21 URL: https://www.areebi.com/resources/blog/data-poisoning-enterprise-defense ### Enterprise AI Compliance Checklist: 50 Controls Across 12 Frameworks The definitive AI compliance checklist for enterprises: 50 essential controls mapped across 12 regulatory frameworks including EU AI Act, NIST AI RMF, ISO 42001, GDPR, Colorado AI Act, and more. Prioritized by risk level with implementation guidance. Published: 2026-03-20 URL: https://www.areebi.com/resources/blog/ai-compliance-checklist-enterprise ### US State AI Laws: Navigating the Patchwork of 2026 Regulations Comprehensive guide to US state AI laws in 2026 covering Colorado, California, Illinois, New York City, Virginia, and Texas. Includes a state-by-state comparison table, federal preemption analysis, and practical compliance strategies for enterprises. Published: 2026-03-18 URL: https://www.areebi.com/resources/blog/us-state-ai-laws-patchwork ### EU AI Act Compliance: What Mid-Market Companies Need to Know The EU AI Act creates binding obligations for AI systems in the European market. This guide covers risk tiers, compliance timelines, documentation requirements, and practical steps for mid-market companies. Published: 2026-03-15 URL: https://www.areebi.com/resources/blog/eu-ai-act-compliance-mid-market ### Why AI Security Is Not Just Application Security: What CISOs Need to Know Traditional application security tools and frameworks are insufficient for AI systems. Learn how AI changes the security model with non-deterministic behavior, natural language attack surfaces, and data-dependent behavior - and why CISOs need AI-specific security controls and governance. Published: 2026-03-14 URL: https://www.areebi.com/resources/blog/ai-security-vs-traditional-appsec ### Singapore's Agentic AI Governance Framework: First in the World Singapore's IMDA has published the world's first governance framework specifically for agentic AI systems. Learn about the framework's principles for autonomous AI agents, accountability structures, human oversight boundaries, and what it means for enterprise AI deployments. Published: 2026-03-12 URL: https://www.areebi.com/resources/blog/singapore-agentic-ai-governance ### AI Governance vs AI Compliance: Understanding the Difference AI governance and AI compliance are related but distinct disciplines. AI governance is the broader organizational framework for responsible AI, while AI compliance is the subset focused on meeting specific regulatory requirements. Learn the differences, overlaps, and why you need both. Published: 2026-03-08 URL: https://www.areebi.com/resources/blog/ai-governance-vs-ai-compliance ### AI Governance vs AI Security: What's the Difference? AI governance and AI security are related but distinct disciplines. Governance covers policies, accountability, and organizational controls. Security focuses on threat protection and data exposure prevention. Understanding both is essential for enterprise AI risk management. Published: 2026-02-27 URL: https://www.areebi.com/resources/blog/ai-governance-vs-ai-security ### The True Cost of Ungoverned AI: A 2026 Analysis Ungoverned AI costs mid-market enterprises an average of $4.2M annually through data breaches, compliance penalties, productivity loss, and vendor sprawl. This analysis quantifies each cost category with real-world examples and calculates the ROI of AI governance. Published: 2026-02-10 URL: https://www.areebi.com/resources/blog/cost-of-ungoverned-ai ### How to Build an AI Governance Program from Scratch A step-by-step framework for creating an AI governance program in a mid-market organization. Covers stakeholder alignment, policy development, tool selection, deployment, compliance mapping, and measurement with a 90-day implementation timeline. Published: 2026-01-20 URL: https://www.areebi.com/resources/blog/build-ai-governance-program ## Templates Free, expert-built AI governance templates and checklists. Each is authored by an Areebi practitioner, mapped to major compliance frameworks, and available as a downloadable PDF. ### The CISO's AI Security Policy Checklist A comprehensive 47-point checklist across 9 security domains to help CISOs build a board-ready AI governance policy. Covers acceptable use, data classification, shadow AI, vendor assessment, compliance mapping, incident response, and more. URL: https://www.areebi.com/resources/templates/ai-security-policy-checklist ### Enterprise AI Acceptable Use Policy Template A ready-to-customise 52-provision AI acceptable use policy template covering 8 policy domains. Built for CISOs and compliance teams who need a professional, board-ready policy document that employees actually understand and follow. Maps to HIPAA, SOC 2, GDPR, EU AI Act, ISO 42001, and NIST AI RMF. URL: https://www.areebi.com/resources/templates/ai-acceptable-use-policy-template ### AI Vendor Risk Assessment Questionnaire A structured 62-question vendor assessment questionnaire across 8 security domains that CISOs and procurement teams use to evaluate AI vendors before onboarding. Covers data privacy, security architecture, model transparency, compliance certifications, incident response, contractual protections, business continuity, and audit rights. URL: https://www.areebi.com/resources/templates/ai-vendor-risk-assessment-questionnaire ### Shadow AI Discovery & Remediation Playbook An 18-page operational playbook with 56 action items across 8 discovery phases for finding, assessing, and remediating unsanctioned AI usage across your organisation. Covers network-level detection, browser extension monitoring, SaaS auditing, department surveys, risk scoring, migration pathways, and ongoing safe harbour programmes. URL: https://www.areebi.com/resources/templates/shadow-ai-discovery-playbook ### AI Risk Register Template A structured 48-item risk register across 8 risk domains with a 5x5 scoring matrix to help CISOs identify, assess, treat, and track AI-specific risks. Covers data privacy, model reliability, bias, security, compliance, operational, and reputational risk categories with board-ready reporting dashboards. URL: https://www.areebi.com/resources/templates/ai-risk-register-template ### EU AI Act Compliance Checklist A comprehensive 58-control checklist across 9 compliance domains to help organisations achieve full conformity with the EU AI Act (Regulation (EU) 2024/1689). Covers AI system classification, prohibited practice screening, high-risk requirements, transparency obligations, data governance, human oversight, GPAI model compliance, risk management, and documentation requirements - mapped to specific Articles and Annexes of the regulation. URL: https://www.areebi.com/resources/templates/eu-ai-act-compliance-checklist ### Australian Privacy Act ADM Compliance Checklist A comprehensive 45-control checklist across 10 compliance domains to help organisations comply with Australia's Privacy Act automated decision-making transparency obligations under APP 1.7, 1.8, and 1.9. Covers system inventory, materiality assessment, privacy policy updates, DLP deployment, sensitive data controls, audit logging, alerting, kill switch implementation, and documentation - mapped to specific APP provisions and the Explanatory Memorandum. URL: https://www.areebi.com/resources/templates/australian-privacy-act-compliance-checklist ### NIST AI RMF Checklist 2026 (54 Controls) Free 54-control NIST AI RMF implementation checklist (PDF). Covers all four functions - Govern, Map, Measure, Manage - with every control mapped to its specific NIST AI RMF 1.0 subcategory. Built for federal contractors, regulated industries, and organisations building mature AI risk management programmes. URL: https://www.areebi.com/resources/templates/nist-ai-rmf-implementation-checklist ### AI Data Classification Framework Template A comprehensive data classification framework with 50 controls across 8 domains for governing data flows through AI systems. Defines 5 classification tiers (Public, Internal, Confidential, Restricted, Prohibited), DLP rule templates, workspace isolation patterns, and lifecycle management procedures to prevent data leakage, ensure regulatory compliance, and maintain auditability across every stage of the AI data pipeline. URL: https://www.areebi.com/resources/templates/ai-data-classification-framework ### AI Incident Response Plan Template A 20-page AI incident response plan template with 56 controls across 9 response phases - from detection through post-incident review. Covers severity classification for prompt injection, data leakage, model poisoning, hallucination harm, and bias incidents. Includes regulatory notification timelines for GDPR (72h), EU AI Act Art. 73 (72h), and HIPAA (60 days), plus a complete RACI matrix and communication protocols for AI-specific security incidents. URL: https://www.areebi.com/resources/templates/ai-incident-response-plan-template ### Board AI Risk Reporting Template A structured board reporting template with 48 items across 8 sections for presenting AI risk posture to directors and executives. Includes executive dashboard structure, risk scoring visualisation, compliance status tracking, incident reporting cadence, ROI metrics, peer benchmarking, and quarterly workflow guidance aligned to NIST AI RMF, EU AI Act, ISO/IEC 42001, and SOX requirements. URL: https://www.areebi.com/resources/templates/board-ai-risk-reporting-template ### ISO 42001 Gap Analysis Checklist A 56-control gap analysis checklist for ISO/IEC 42001:2023 AI Management Systems covering all normative clauses (4-10) plus Annex A controls. Designed for organisations preparing for AIMS certification, this checklist provides clause-by-clause conformity assessment, certification readiness scoring, remediation priority planning, and Stage 1/Stage 2 audit preparation guidance - mapped to specific sub-clauses and Annex A control objectives throughout. URL: https://www.areebi.com/resources/templates/iso-42001-gap-analysis-checklist ## Research ### The Australian AI Data-Governance Index 2026 A statistics report synthesising verified Australian public data on breaches and responsible-AI readiness. Triangulates the OAIC Notifiable Data Breaches Report (about 532 notifiable breaches in H1 2025, around 37% from human error, health and finance the most-affected sectors), the ASD Annual Cyber Threat Report 2024-25, and the National AI Centre and Fifth Quadrant Responsible AI Index 2025 (only about 12% of Australian organisations leading on responsible AI). Released under CC BY 4.0. URL: https://www.areebi.com/resources/research/australian-ai-data-governance-2026 ## Tools ### Privacy Act ADM Transparency Readiness Checker An interactive self-assessment for Australia's Privacy Act automated decision-making (ADM) transparency obligation, which commences on 10 December 2026. Answer a short series of questions to surface your gaps and the steps to update your privacy policy in time. URL: https://www.areebi.com/tools/privacy-act-adm-readiness-checker ### APRA CPS 230 AI Gap Analyzer An interactive gap assessment that maps an APRA-regulated entity's AI and LLM vendors against Prudential Standard CPS 230 - critical operations and tolerance levels, material service provider management, operational risk and incidents, and business continuity - aligned to APRA's April 2026 AI supervisory expectations. URL: https://www.areebi.com/tools/apra-cps-230-ai-gap-analyzer ### APRA CPS 234 AI Security Checker An interactive assessment of whether an APRA-regulated entity's information-security program covers its AI estate - models, training data, pipelines, and inference APIs - as CPS 234 information assets: identification and classification, security capability and controls, testing and assurance, and incident readiness, aligned to APRA's April 2026 AI supervisory expectations. URL: https://www.areebi.com/tools/apra-cps-234-ai-security-checker ### Sovereign AI Readiness Checker An interactive self-assessment of whether an Australian organisation's AI stack keeps personal information onshore, and whether Privacy Act APP 8 cross-border disclosure obligations are met when it does not - covering data flows, APP 8 controls, sovereignty architecture, and governance. URL: https://www.areebi.com/tools/sovereign-ai-readiness-checker ## Reference ### Australian AI Regulation Tracker A living reference of Australia's AI compliance obligations and deadlines, including the Privacy Act ADM transparency obligation (10 December 2026), APRA CPS 230 and CPS 234, the APRA Letter to Industry on AI (April 2026), the National AI Plan, the Guidance for AI Adoption, and ACCC AI-washing penalties. Each entry summarises what the obligation requires, when it applies, and what to do, with named primary sources. URL: https://www.areebi.com/resources/ai-regulation-tracker ## Pricing Areebi is priced per seat, per month. There is no seat minimum, so organisations can start with a single team and add seats as adoption grows. Every plan includes a 30-day free trial with no credit card required. Model API consumption and hosting are additional and scale with usage. - Secure Essentials: $20 per seat per month on annual billing ($25 month-to-month) - Core AI governance for teams getting started with secure AI adoption. Includes DLP, audit logging, and basic policy controls. - Compliance Pro: $50 per seat per month on annual billing ($60 month-to-month) - Full compliance automation with templates for 20+ frameworks, advanced policy engine, and dedicated compliance dashboard. - Enterprise Defense: Custom pricing - Complete AI control plane for 500+ seats, air-gapped deployments, or custom terms. Includes unlimited policies, custom integrations, dedicated support, and SLA guarantees. ## FAQ ### What is Areebi? Areebi is an AI governance platform that provides enterprise-grade security, compliance automation, and policy enforcement for organizations using AI. It acts as a control plane between users and AI models, ensuring data protection and regulatory compliance. ### How does Areebi protect sensitive data? Areebi uses real-time DLP scanning to detect and mask PII, financial data, health records, and custom-defined sensitive patterns in every AI prompt and response. Data is processed within your own infrastructure and never sent to external services. ### Which AI models does Areebi support? Areebi is model-agnostic and supports 30+ LLM providers including OpenAI, Anthropic, Google Gemini, Azure OpenAI, AWS Bedrock, Ollama, and many more. Any model accessible via API or local deployment can be governed through Areebi. ### How is Areebi deployed? Areebi deploys privately within your infrastructure. Supported methods include Docker containers, Kubernetes clusters, on-premises servers, and private cloud instances on AWS, Azure, or GCP. There is no shared multi-tenant deployment. ### What compliance frameworks does Areebi support? Areebi provides compliance templates and automation for 20+ frameworks including HIPAA, SOC 2, GDPR, the EU AI Act, Australian Privacy Act, NIST AI RMF, ISO 42001, CCPA, FERPA, SOX, GLBA, PCI DSS 4.0, FedRAMP, and more. ### What is shadow AI and how does Areebi address it? Shadow AI refers to unauthorized use of AI tools within an organization - employees using ChatGPT, Copilot, or other AI services without IT approval. Areebi detects shadow AI usage, provides visibility into unsanctioned tools, and can redirect users to governed AI channels. ### Can Areebi integrate with existing identity providers? Yes. Areebi integrates with Okta, Azure AD (Entra ID), and other SAML/OIDC identity providers for single sign-on and role-based access control. User permissions and group policies are synchronized automatically. ### How does Areebi's audit logging work? Every AI interaction is recorded in an immutable audit log that captures user identity, timestamps, model selection, prompt and response content, and policy actions. Logs are exportable in standard formats and configurable with retention policies to meet regulatory requirements. ### What makes Areebi different from AI security point solutions? Unlike tools that address only one aspect (prompt filtering, access control, or monitoring), Areebi provides a unified control plane covering DLP, policy enforcement, audit logging, compliance automation, and shadow AI detection in a single platform. This eliminates gaps between disconnected tools and provides a single source of truth. ### How long does it take to deploy Areebi? Most organizations are operational within days. Docker-based deployments can be running in hours. Kubernetes and enterprise deployments with custom integrations typically take 1-2 weeks, including policy configuration and identity provider integration. ## Citation quotes per compliance framework The following blocks restate the most cited facts from each compliance framework Areebi supports, as dated and attributed quote-shape citations. Each block lists three quotable sentences, then a key-facts summary, then the primary obligations Areebi helps operationalize. ### NIST AI Risk Management Framework (AI RMF 1.0) Compliance (United States (Federal)) Source: Areebi, dated 2026-05-19, https://www.areebi.com/compliance/nist-ai-rmf Three quotable facts about NIST AI Risk Management Framework (AI RMF 1.0) Compliance: 1. "The NIST AI Risk Management Framework (AI RMF 1.0), published by the National Institute of Standards and Technology on January 26, 2023, is the de facto standard for managing risks associated with artificial intelligence systems in the United States." - Areebi 2026-05-19 2. "Developed through extensive multi-stakeholder consultation, the framework provides organizations with a structured, flexible, and technology-neutral approach to identifying, assessing, and mitigating AI-related risks throughout the AI lifecycle." - Areebi 2026-05-19 3. "The AI RMF is organized around four core functions that provide a lifecycle-based approach to AI risk management." - Areebi 2026-05-19 Key facts: - Effective date: 2023-01-26 - Status: In Effect - Regulation type: framework - Jurisdiction: United States (Federal) - Last updated: 2026-05-19 - Topical keywords: NIST AI RMF compliance, NIST AI risk management framework, AI RMF implementation, NIST AI RMF 1.0, AI risk management, NIST AI framework, AI RMF core functions, AI governance framework Primary obligations (per Areebi 2026-05-19): - Establish an AI governance committee with executive sponsorship and cross-functional representation - Define and document AI use policies that are specific, enforceable, and machine-readable - Conduct a comprehensive inventory of all AI systems, including shadow AI tools - Classify AI systems by risk level based on intended use, data exposure, and decision impact - Deploy real-time monitoring and measurement capabilities across all AI systems - Implement DLP controls to prevent sensitive data exposure in AI interactions Common questions and dated answers: Q: Is the NIST AI RMF mandatory for private-sector organizations? A: "No, the AI RMF is voluntary for private-sector organizations. However, it is increasingly referenced in state laws (such as the Colorado AI Act), procurement requirements, and industry standards." - Areebi 2026-05-19 Q: How does the NIST AI RMF differ from the NIST Cybersecurity Framework (CSF)? A: "The NIST CSF focuses on cybersecurity risk management across IT systems, while the AI RMF specifically addresses risks unique to AI systems - including bias, fairness, transparency, explainability, and the non-deterministic nature of AI outputs. The AI RMF is designed to complement, not replace, the CSF." - Areebi 2026-05-19 Q: What is the NIST AI RMF Generative AI Profile? A: "The Generative AI Profile (NIST AI 600-1), released in July 2024, is a companion resource that maps the AI RMF's core functions to 12 risks specific to generative AI systems, including hallucination, data privacy, deepfakes, and information security. It provides practical guidance for organizations deploying LLMs and generative AI tools." - Areebi 2026-05-19 Related frameworks: https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/fedramp-ai For machine consumption: see https://www.areebi.com/api/mcp ### ISO/IEC 42001 AI Management Systems Compliance (International) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/iso-42001 Three quotable facts about ISO/IEC 42001 AI Management Systems Compliance: 1. "ISO/IEC 42001:2023 is the world's first international standard for Artificial Intelligence Management Systems (AIMS)." - Areebi 2026-04-13 2. "ISO 42001 follows the familiar Annex SL high-level structure used in other ISO management system standards (ISO 27001, ISO 9001, ISO 14001), making it integrable with existing management systems." - Areebi 2026-04-13 3. "ISO 42001 is organized into ten clauses, with Clauses 4 through 10 containing the mandatory requirements for certification." - Areebi 2026-04-13 Key facts: - Effective date: 2023-12-18 - Status: In Effect - Regulation type: standard - Jurisdiction: International - Last updated: 2026-04-13 - Topical keywords: ISO 42001 certification, ISO 42001 AI management, ISO IEC 42001, AI management system standard, ISO 42001 compliance, AI management system certification, ISO 42001 requirements Primary obligations (per Areebi 2026-04-13): - Define the scope of your AI Management System (AIMS) including all AI systems, roles, and boundaries - Obtain top management commitment and establish an AI policy with documented objectives - Assign roles and responsibilities for AIMS governance, including an AI management representative - Conduct a comprehensive AI risk assessment covering technical, ethical, and societal risks - Develop a Statement of Applicability mapping all 39 Annex A controls to your context - Implement technical controls for data governance, DLP, access control, and AI monitoring Common questions and dated answers: Q: What is ISO 42001 and why does it matter? A: "ISO/IEC 42001:2023 is the first international standard for AI Management Systems (AIMS). It provides a framework for organizations to responsibly develop, provide, or use AI systems." - Areebi 2026-04-13 Q: Who should pursue ISO 42001 certification? A: "Any organization that develops, provides, or uses AI systems can benefit from ISO 42001 certification. It is particularly valuable for AI vendors selling to enterprises or governments, organizations in regulated industries (financial services, healthcare, defense), and companies seeking to differentiate on responsible AI practices." - Areebi 2026-04-13 Q: How does ISO 42001 relate to ISO 27001? A: "Both standards follow the Annex SL high-level structure, making them highly compatible. ISO 27001 focuses on information security management, while ISO 42001 focuses on AI-specific management." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/oecd-ai-principles, https://www.areebi.com/compliance/uk-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### UK AI Governance & Regulation Compliance Guide (United Kingdom) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/uk-ai-governance Three quotable facts about UK AI Governance & Regulation Compliance Guide: 1. "The United Kingdom has adopted a principles-based, pro-innovation approach to AI regulation that stands in deliberate contrast to the EU's comprehensive AI Act." - Areebi 2026-04-13 2. "Rather than enacting a single AI-specific law, the UK government has empowered existing sector regulators to apply a common set of AI principles within their domains, preserving regulatory flexibility while establishing consistent expectations across the economy." - Areebi 2026-04-13 3. "The UK government has established five core principles that all sector regulators are expected to interpret and apply within their domains:." - Areebi 2026-04-13 Key facts: - Status: Principles-Based - Regulation type: guidance - Jurisdiction: United Kingdom - Last updated: 2026-04-13 - Topical keywords: UK AI regulation, UK AI governance, UK AI compliance, UK AI principles, AI Security Institute, UK AI Act, ICO AI guidance, UK AI framework Primary obligations (per Areebi 2026-04-13): - Map your AI systems against the five UK AI principles (safety, transparency, fairness, accountability, contestability) - Identify which UK sector regulators (ICO, FCA, Ofcom, CMA, MHRA) apply to your AI operations - Conduct a Data Protection Impact Assessment (DPIA) for all AI systems processing personal data - Ensure compliance with UK GDPR Article 22 for automated individual decision-making - Implement DLP controls to prevent unauthorized personal data processing by AI systems - Establish audit trails documenting all AI interactions and governance decisions Common questions and dated answers: Q: Does the UK have an AI law? A: "No, the UK does not currently have a comprehensive AI-specific law. The government has adopted a principles-based approach, empowering existing sector regulators to apply five core AI principles within their domains." - Areebi 2026-04-13 Q: Which UK regulators oversee AI? A: "Multiple sector regulators oversee AI within their domains: the ICO (data protection), FCA (financial services), Ofcom (communications and media), CMA (competition), and MHRA (healthcare). The AI Security Institute (AISI) provides technical safety evaluation but does not currently have enforcement powers." - Areebi 2026-04-13 Q: What is the AI Security Institute? A: "The AI Security Institute (AISI), rebranded from the AI Safety Institute in February 2025, is the UK government's technical body focused on evaluating and mitigating risks from advanced AI systems. It was established following the Bletchley Park AI Safety Summit in November 2023 and operates under the Department for Science, Innovation and Technology." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/uk-online-safety-act, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/oecd-ai-principles For machine consumption: see https://www.areebi.com/api/mcp ### Colorado AI Act (SB 24-205) Compliance Guide (United States (State)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/colorado-ai-act Three quotable facts about Colorado AI Act (SB 24-205) Compliance Guide: 1. "The Colorado AI Act (SB 24-205) is the first comprehensive state-level AI regulation in the United States." - Areebi 2026-04-13 2. "Signed into law by Governor Jared Polis on May 17, 2024, the Act creates a duty of care for developers and deployers of high-risk AI systems to protect consumers from algorithmic discrimination in consequential decisions." - Areebi 2026-04-13 3. "The Colorado AI Act applies specifically to high-risk AI systems - defined as any AI system that, when deployed, makes or is a substantial factor in making a consequential decision." - Areebi 2026-04-13 Key facts: - Effective date: 2024-05-17 - Enforcement date: 2026-06-30 - Status: Delayed - Regulation type: law - Jurisdiction: United States (State) - Penalty summary: Enforced by Colorado AG, civil penalties under CCPA, no private right of action - Last updated: 2026-04-13 - Topical keywords: Colorado AI Act, Colorado SB 205, algorithmic discrimination law, Colorado AI compliance, SB 24-205, high-risk AI system, algorithmic discrimination, Colorado AI regulation Primary obligations (per Areebi 2026-04-13): - Conduct inventory of all AI systems making or substantially factoring into consequential decisions - Classify AI systems by consequential decision category (employment, lending, housing, healthcare, insurance, education, legal) - Implement a documented risk management policy and program for high-risk AI systems - Deploy DLP controls to protect consumer data and prevent unauthorized data processing - Conduct initial impact assessments for each high-risk AI system - Establish consumer notification processes for AI-driven consequential decisions Common questions and dated answers: Q: When does the Colorado AI Act take effect? A: "The Colorado AI Act was signed on May 17, 2024. It was originally set to take effect on February 1, 2026, but enforcement was delayed to June 30, 2026 by SB 25B-004." - Areebi 2026-04-13 Q: Which AI systems are covered by the Colorado AI Act? A: "The Act covers high-risk AI systems - any AI system that makes or is a substantial factor in making a consequential decision. Consequential decisions include employment, education, financial services, essential government services, healthcare, housing, and legal services affecting Colorado consumers." - Areebi 2026-04-13 Q: What is algorithmic discrimination under the Colorado AI Act? A: "Algorithmic discrimination occurs when the use of an AI system results in unlawful differential treatment or impact on individuals based on their actual or perceived membership in a protected class, including age, color, disability, ethnicity, genetic information, national origin, race, religion, sex, and veteran..." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/california-ai-transparency, https://www.areebi.com/compliance/nyc-local-law-144, https://www.areebi.com/compliance/illinois-ai-video-interview For machine consumption: see https://www.areebi.com/api/mcp ### California AI Transparency Act (SB 942) Compliance Guide (United States (State)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/california-ai-transparency Three quotable facts about California AI Transparency Act (SB 942) Compliance Guide: 1. "The California AI Transparency Act (SB 942), signed by Governor Gavin Newsom on September 29, 2024, establishes transparency requirements for large AI platforms operating in California." - Areebi 2026-04-13 2. "The Act requires covered platforms to provide free AI content detection tools, implement content provenance measures including manifest and latent watermarks, and maintain publicly accessible documentation about their AI systems." - Areebi 2026-04-13 3. "However, organizations that build customer-facing AI tools exceeding the one million user threshold would also be covered." - Areebi 2026-04-13 Key facts: - Effective date: 2024-09-29 - Enforcement date: 2026-08-02 - Status: Enacted - Regulation type: law - Jurisdiction: United States (State) - Last updated: 2026-04-13 - Topical keywords: California AI transparency, SB 942, California AI law, AI transparency act, AI content detection, AI watermarking, California AI regulation, generative AI transparency Primary obligations (per Areebi 2026-04-13): - Determine whether your organization qualifies as a covered provider under SB 942 (1M+ monthly California users) - Inventory all generative AI systems that produce synthetic content (text, images, video, audio) - Assess current content provenance capabilities including manifest and latent watermarking - Implement or verify AI content detection tool availability for public access - Establish internal policies for preserving AI content watermarks in enterprise workflows - Deploy audit trails tracking AI-generated content provenance throughout the content lifecycle Common questions and dated answers: Q: What is the California AI Transparency Act (SB 942)? A: "SB 942 is a California law requiring large AI platforms (those with 1M+ monthly California users) to provide free AI content detection tools, implement content watermarking (both manifest and latent), and maintain public documentation about their AI systems. It was signed on September 29, 2024, with enforcement effective August 2, 2026." - Areebi 2026-04-13 Q: Does SB 942 apply to enterprise AI users? A: "SB 942 primarily targets large AI platform providers, not enterprise users. However, enterprise organizations should understand the requirements as they affect the platforms they use, implement processes to preserve AI content watermarks, and prepare for future legislation that may extend transparency requirements to enterprise AI." - Areebi 2026-04-13 Q: What are manifest and latent watermarks? A: "Manifest watermarks are visible or easily discoverable indicators that content was AI-generated, such as metadata labels or visible markers. Latent watermarks are imperceptible markers embedded in the content that can only be detected by specialized tools." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/ftc-ai-enforcement, https://www.areebi.com/compliance/sec-ai-disclosure For machine consumption: see https://www.areebi.com/api/mcp ### Australia AI Governance & Privacy Act Compliance Guide (Australia) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/australia-ai-governance Three quotable facts about Australia AI Governance & Privacy Act Compliance Guide: 1. "Australia has adopted a multi-layered, principles-based approach to AI governance that combines voluntary frameworks, privacy law amendments, and sector-specific regulation." - Areebi 2026-04-13 2. "While the country does not yet have comprehensive AI-specific legislation, the regulatory landscape is rapidly evolving with significant developments expected through 2026 and beyond." - Areebi 2026-04-13 3. "Australia's National AI Plan, released on 2 December 2025 by the Department of Industry, Science and Resources, is the centrepiece of the country's AI policy." - Areebi 2026-04-13 Key facts: - Enforcement date: 2026-12-10 - Status: Principles-Based - Regulation type: guidance - Jurisdiction: Australia - Last updated: 2026-04-13 - Topical keywords: Australia AI regulation, Australia Privacy Act AI, Australian AI governance, Australia AI Safety Institute, OAIC AI guidance, APRA CPS 230, Australian AI compliance, Privacy Act amendments AI Primary obligations (per Areebi 2026-04-13): - Inventory all AI systems processing personal data of Australian individuals - Assess compliance readiness for Privacy Act automated decision-making obligations (effective Dec 10, 2026) - Implement DLP controls to protect personal data in AI interactions - Establish transparency mechanisms for automated decision-making notifications - Create human review processes for significant automated decisions - Conduct privacy impact assessments for high-risk AI processing Common questions and dated answers: Q: Does Australia have an AI law? A: "Australia does not currently have comprehensive AI-specific legislation. However, the Privacy Act amendments effective December 10, 2026 introduce significant automated decision-making obligations that directly affect AI systems." - Areebi 2026-04-13 Q: What are the Privacy Act amendments affecting AI? A: "The Privacy Act amendments effective December 10, 2026 introduce transparency obligations for automated decision-making, explanation requirements, rights to human review, enhanced privacy impact assessment requirements, and strengthened data quality obligations for AI systems processing personal data." - Areebi 2026-04-13 Q: What is Australia's AI Safety Institute? A: "Australia's AI Safety Institute, established in early 2026 with AUD 29.9 million in funding, is the government's technical body for AI safety research and evaluation. It evaluates AI models for safety risks, publishes guidance, and coordinates with international AI safety bodies." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/new-zealand-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### Canada AI Governance & Post-AIDA Compliance Guide (Canada) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/canada-ai-governance Three quotable facts about Canada AI Governance & Post-AIDA Compliance Guide: 1. "Canada's AI governance landscape is in a period of transition." - Areebi 2026-04-13 2. "The Artificial Intelligence and Data Act (AIDA), which would have been Canada's first comprehensive AI law as Part 3 of Bill C-27, died in Parliament in January 2025 when the legislative session ended." - Areebi 2026-04-13 3. "PIPEDA applies to organizations that collect, use, or disclose personal information in the course of commercial activities." - Areebi 2026-04-13 Key facts: - Status: Proposed - Regulation type: guidance - Jurisdiction: Canada - Last updated: 2026-04-13 - Topical keywords: Canada AI regulation, PIPEDA AI, Canada AIDA, Canadian AI governance, Quebec Law 25 AI, Canada AI compliance, Canadian AI framework, Bill C-27 AI Primary obligations (per Areebi 2026-04-13): - Inventory all AI systems processing personal information of Canadians - Assess PIPEDA compliance for each AI system including consent, purpose limitation, and accountability - Implement DLP controls to prevent unauthorized personal information sharing with AI platforms - If operating in Quebec, ensure compliance with Law 25 automated decision-making obligations - Establish transparency mechanisms for AI-driven decisions affecting individuals - Create human review processes for significant automated decisions Common questions and dated answers: Q: What happened to Canada's AIDA (Artificial Intelligence and Data Act)? A: "AIDA, Part 3 of Bill C-27, died in Parliament in January 2025 when the legislative session ended. The government has confirmed it will not return in its original form, though a new AI framework is expected in a future parliamentary session." - Areebi 2026-04-13 Q: How does PIPEDA apply to AI systems? A: "PIPEDA applies to organizations that collect, use, or disclose personal information through AI systems in the course of commercial activities. Key obligations include obtaining meaningful consent, limiting collection to necessary purposes, ensuring accuracy, and maintaining accountability for data processed by AI systems and third-party AI providers." - Areebi 2026-04-13 Q: What are Quebec Law 25's requirements for AI? A: "Quebec Law 25 requires organizations to notify individuals when automated decisions are made about them, provide explanations on request, offer human review of automated decisions, conduct mandatory privacy impact assessments, and obtain enhanced consent for personal information processing." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/oecd-ai-principles, https://www.areebi.com/compliance/colorado-ai-act For machine consumption: see https://www.areebi.com/api/mcp ### Singapore Model AI Governance Framework Compliance Guide (Singapore) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/singapore-ai-governance Three quotable facts about Singapore Model AI Governance Framework Compliance Guide: 1. "Singapore has established itself as a global leader in AI governance through its pro-innovation, guidance-based approach that provides practical frameworks without imposing prescriptive legislation." - Areebi 2026-04-13 2. "The government has identified priority AI missions in manufacturing, finance, and healthcare, with governance frameworks designed to enable responsible innovation in these sectors." - Areebi 2026-04-13 3. "Internal Governance Structures and Measures Organizations should establish clear governance structures with defined roles and responsibilities for AI oversight." - Areebi 2026-04-13 Key facts: - Status: In Effect - Regulation type: framework - Jurisdiction: Singapore - Last updated: 2026-04-13 - Topical keywords: Singapore AI governance, Singapore AI framework, PDPA AI, Singapore Agentic AI, Model AI Governance Framework, Singapore AI compliance, IMDA AI governance, National AI Council Primary obligations (per Areebi 2026-04-13): - Adopt the Model AI Governance Framework as your baseline governance structure - Establish internal governance with clear roles, responsibilities, and accountability for AI - Determine appropriate human oversight level for each AI application based on risk - Implement PDPA-compliant data protection controls for all AI systems - Deploy DLP to prevent unauthorized personal data processing by AI - Configure guardrails and boundary settings for agentic AI applications Common questions and dated answers: Q: Does Singapore have an AI law? A: "Singapore does not have a dedicated AI law. Instead, it takes a pro-innovation, guidance-based approach through frameworks like the Model AI Governance Framework, the Generative AI Framework, and the Agentic AI Governance Framework." - Areebi 2026-04-13 Q: What is Singapore's Agentic AI Governance Framework? A: "Released in January 2026, it is the world's first governance framework specifically addressing autonomous AI agents. It covers accountability, boundary setting, monitoring, inter-agent governance, and safety measures for AI systems that can independently plan and execute tasks." - Areebi 2026-04-13 Q: How does the PDPA affect AI systems in Singapore? A: "The PDPA requires consent for personal data processing, purpose limitation, data accuracy, security protection, and breach notification. These obligations apply to AI systems that collect, use, or disclose personal data, with the PDPC providing additional AI-specific guidance." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/oecd-ai-principles For machine consumption: see https://www.areebi.com/api/mcp ### NYC Local Law 144 - AI Hiring Bias Audit Compliance (United States (State)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/nyc-local-law-144 Three quotable facts about NYC Local Law 144 - AI Hiring Bias Audit Compliance: 1. "NYC Local Law 144, effective July 5, 2023, is one of the first laws in the United States to regulate the use of AI in hiring decisions." - Areebi 2026-04-13 2. "The law requires employers and employment agencies in New York City to conduct annual independent bias audits of automated employment decision tools (AEDTs) before using them, publicly post audit results, and provide notice to candidates and employees subject to AEDT evaluation." - Areebi 2026-04-13 3. "Complete guide to NYC Local Law 144 compliance." - Areebi 2026-04-13 Key facts: - Effective date: 2023-07-05 - Status: In Effect - Regulation type: law - Jurisdiction: United States (State) - Penalty summary: Civil penalties: $500 for first violation, $500-$1,500 for subsequent violations per day - Last updated: 2026-04-13 - Topical keywords: NYC Local Law 144, NYC AI hiring law, AEDT bias audit, automated employment decision tool, NYC AI regulation, AI hiring bias, bias audit requirements, NYC AI compliance Primary obligations (per Areebi 2026-04-13): - Inventory all automated employment decision tools (AEDTs) used in hiring and promotion - Engage an independent auditor to conduct the annual bias audit - Compile historical data on AEDT usage including selection rates by race/ethnicity and sex/gender - Complete the bias audit and review results for disparate impact - Publish bias audit summary results on your website - Implement candidate notification processes at least 10 business days before AEDT use Common questions and dated answers: Q: What is an AEDT under NYC Local Law 144? A: "An Automated Employment Decision Tool (AEDT) is any computational process using machine learning, statistical modeling, or AI that issues a simplified output (score, classification, recommendation) used to substantially assist or replace discretionary decision-making for employment decisions including hiring and..." - Areebi 2026-04-13 Q: Who must comply with Local Law 144? A: "Any employer or employment agency that uses an AEDT to evaluate candidates or employees for employment decisions in New York City. This includes organizations headquartered outside NYC that use AEDTs to evaluate candidates for NYC-based positions." - Areebi 2026-04-13 Q: How often must bias audits be conducted? A: "Bias audits must be conducted annually - no more than one year before the AEDT is used for an employment decision. Organizations using multiple AEDTs must audit each one separately." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/illinois-ai-video-interview, https://www.areebi.com/compliance/ftc-ai-enforcement For machine consumption: see https://www.areebi.com/api/mcp ### PCI-DSS 4.0 Compliance for AI Systems (International) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/pci-dss-4 Three quotable facts about PCI-DSS 4.0 Compliance for AI Systems: 1. "PCI-DSS 4.0, effective March 31, 2025 (with the retirement of PCI-DSS 3.2.1), is the global security standard for organizations that store, process, or transmit payment card data." - Areebi 2026-04-13 2. "Any AI system that handles cardholder data (CHD) or operates within the cardholder data environment (CDE) must comply with PCI-DSS 4.0 requirements." - Areebi 2026-04-13 3. "PCI-DSS 4.0's 12 requirements must be applied to any AI system within the cardholder data environment:." - Areebi 2026-04-13 Key facts: - Effective date: 2025-03-31 - Status: In Effect - Regulation type: standard - Jurisdiction: International - Penalty summary: Non-compliance may result in fines from $5,000 to $100,000/month from payment brands, increased transaction fees, and loss of card processing privileges - Last updated: 2026-04-13 - Topical keywords: PCI DSS AI compliance, PCI DSS 4.0 AI, payment card AI security, PCI AI governance, PCI DSS 4.0 compliance, cardholder data AI, payment data AI protection Primary obligations (per Areebi 2026-04-13): - Identify all AI systems that process, store, or transmit cardholder data or operate within the CDE - Deploy DLP controls to prevent cardholder data from entering AI prompts and processing pipelines - Implement tokenization for cardholder data before AI processing where possible - Configure role-based access controls and MFA for AI systems within the CDE - Activate comprehensive audit logging for all AI interactions with cardholder data - Include AI systems in network segmentation and firewall rule reviews Common questions and dated answers: Q: Does PCI-DSS 4.0 apply to AI systems? A: "Yes, PCI-DSS 4.0 applies to any AI system that stores, processes, or transmits cardholder data, or that operates within the cardholder data environment. This includes AI used for fraud detection, customer service automation, transaction analysis, and personalized financial services." - Areebi 2026-04-13 Q: How can I reduce PCI scope for AI deployments? A: "The most effective strategy is preventing cardholder data from entering the AI environment entirely through tokenization, DLP enforcement, data pipeline controls, and network segmentation. Areebi's DLP controls automatically block cardholder data from AI interactions." - Areebi 2026-04-13 Q: What is the customized approach in PCI-DSS 4.0? A: "The customized approach allows organizations to implement alternative controls that meet PCI-DSS security objectives through different mechanisms. This is valuable for AI systems where traditional IT controls may not directly apply." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/nist-ai-rmf For machine consumption: see https://www.areebi.com/api/mcp ### FedRAMP for AI Platforms - Authorization Guide (United States (Federal)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/fedramp-ai Three quotable facts about FedRAMP for AI Platforms - Authorization Guide: 1. "The Federal Risk and Authorization Management Program (FedRAMP) is the US government's standardized approach to security assessment, authorization, and continuous monitoring for cloud services." - Areebi 2026-04-13 2. "Any cloud-based AI platform seeking to serve federal government agencies must obtain FedRAMP authorization - there is no alternative pathway." - Areebi 2026-04-13 3. "FedRAMP defines three impact levels based on the potential impact of a security breach: FedRAMP Low: Systems where a breach would have limited adverse effects." - Areebi 2026-04-13 Key facts: - Status: In Effect - Regulation type: certification - Jurisdiction: United States (Federal) - Last updated: 2026-04-13 - Topical keywords: FedRAMP AI, FedRAMP AI platform, government AI authorization, FedRAMP Rev 5, FedRAMP compliance AI, federal AI authorization, FedRAMP cloud AI, government cloud AI security Primary obligations (per Areebi 2026-04-13): - Determine the appropriate FedRAMP impact level (Low, Moderate, High) for your AI platform - Engage a FedRAMP-recognized Third Party Assessment Organization (3PAO) - Develop a System Security Plan (SSP) addressing all applicable NIST SP 800-53 Rev 5 controls - Implement DLP controls to prevent government data exposure through AI interactions - Configure role-based access controls with least privilege for AI platform access - Deploy comprehensive audit logging for all AI interactions and governance decisions Common questions and dated answers: Q: Is FedRAMP required for AI platforms serving the US government? A: "Yes, FedRAMP authorization is mandatory for any cloud-based service, including AI platforms, that processes federal government data. There is no alternative pathway for cloud-based AI platforms seeking to serve federal agencies." - Areebi 2026-04-13 Q: What impact level do AI platforms typically require? A: "Most enterprise AI platforms require FedRAMP Moderate authorization (approximately 325 controls). AI systems processing controlled unclassified information (CUI), law enforcement data, or supporting critical infrastructure may require FedRAMP High (approximately 421 controls)." - Areebi 2026-04-13 Q: How long does FedRAMP authorization take for AI platforms? A: "FedRAMP authorization typically takes 12-18 months for Moderate and 18-24 months for High. AI platforms may face additional scrutiny on data protection and AI-specific controls, which can extend timelines." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/sec-ai-disclosure For machine consumption: see https://www.areebi.com/api/mcp ### New Zealand AI Governance & Compliance Guide (New Zealand) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/new-zealand-ai-governance Three quotable facts about New Zealand AI Governance & Compliance Guide: 1. "New Zealand has adopted a light-touch, principles-based approach to AI governance, choosing not to enact AI-specific legislation." - Areebi 2026-04-13 2. "Instead, the government relies on existing laws - primarily the Privacy Act 2020 and the Human Rights Act 1993 - combined with voluntary guidance and international alignment, particularly with the OECD AI Principles." - Areebi 2026-04-13 3. "The Privacy Act 2020 is the primary law governing personal information collection, use, and disclosure in New Zealand." - Areebi 2026-04-13 Key facts: - Status: Principles-Based - Regulation type: guidance - Jurisdiction: New Zealand - Last updated: 2026-04-13 - Topical keywords: New Zealand AI regulation, NZ AI governance, New Zealand AI compliance, Privacy Act 2020 AI, NZ AI strategy, New Zealand AI framework Primary obligations (per Areebi 2026-04-13): - Assess Privacy Act 2020 compliance for all AI systems processing personal information - Implement DLP controls to prevent unauthorized personal information sharing with AI - Establish transparency practices for AI use, including stakeholder communication - Consider Māori data sovereignty principles in AI governance frameworks - Align with the Algorithm Charter if operating in the government sector - Deploy audit trails documenting all AI interactions and governance decisions Common questions and dated answers: Q: Does New Zealand have an AI law? A: "No, New Zealand does not have AI-specific legislation. AI governance relies on existing laws (Privacy Act 2020, Human Rights Act 1993), the Algorithm Charter for government agencies, and voluntary alignment with OECD AI Principles." - Areebi 2026-04-13 Q: How does the Privacy Act 2020 apply to AI? A: "The Privacy Act 2020's thirteen Information Privacy Principles apply to all AI processing of personal information, covering collection, storage, access, accuracy, retention, use, disclosure, and cross-border transfers. Mandatory breach notification requirements also apply to AI-related privacy breaches." - Areebi 2026-04-13 Q: What is Māori data sovereignty and how does it affect AI? A: "Māori data sovereignty is the right of Māori to exercise control over Māori data. AI systems processing data about or affecting Māori communities must consider principles of iwi engagement, cultural sensitivity, and Treaty of Waitangi obligations." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/oecd-ai-principles, https://www.areebi.com/compliance/iso-42001 For machine consumption: see https://www.areebi.com/api/mcp ### OECD AI Principles - International AI Governance Framework (International) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/oecd-ai-principles Three quotable facts about OECD AI Principles - International AI Governance Framework: 1. "The OECD Recommendation on Artificial Intelligence, adopted on May 22, 2019, and updated in 2024, is the most widely adopted international framework for responsible AI governance." - Areebi 2026-04-13 2. "Endorsed by all 38 OECD member countries plus additional partner nations, the Principles have profoundly influenced the development of national AI strategies, legislation, and frameworks worldwide - including the EU AI Act, the NIST AI RMF, and national frameworks in Australia, Canada, Singapore, and New Zealand." - Areebi 2026-04-13 3. "The OECD AI Principles define standards for responsible stewardship of trustworthy AI: 1." - Areebi 2026-04-13 Key facts: - Effective date: 2019-05-22 - Status: In Effect - Regulation type: framework - Jurisdiction: International - Last updated: 2026-04-13 - Topical keywords: OECD AI Principles, OECD AI guidelines, international AI governance, OECD AI recommendations, responsible AI principles, OECD AI framework Primary obligations (per Areebi 2026-04-13): - Map organizational AI practices against the five OECD AI Principles - Implement transparency measures including AI interaction audit trails and stakeholder disclosure - Deploy security controls including AI firewall, guardrails, and DLP for robustness and safety - Establish accountability structures with clear roles, responsibilities, and governance oversight - Implement fairness monitoring and human oversight for AI-assisted decisions - Align AI governance with complementary frameworks (NIST AI RMF, ISO 42001) Common questions and dated answers: Q: Are the OECD AI Principles legally binding? A: "No, the OECD AI Principles are non-binding recommendations. However, they have been adopted by all 38 OECD member countries and have directly influenced binding legislation including the EU AI Act and national AI laws." - Areebi 2026-04-13 Q: How many countries have adopted the OECD AI Principles? A: "All 38 OECD member countries have adopted the Principles, plus additional partner countries. This makes the OECD AI Principles the most widely endorsed international AI governance framework, providing a common baseline across most major economies." - Areebi 2026-04-13 Q: How were the OECD AI Principles updated in 2024? A: "The 2024 update addresses generative AI risks (misinformation, deepfakes), updates lifecycle governance guidance, increases emphasis on environmental impact, and strengthens focus on cross-jurisdictional interoperability of governance frameworks." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/uk-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### Illinois AI Video Interview Act Compliance Guide (United States (State)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/illinois-ai-video-interview Three quotable facts about Illinois AI Video Interview Act Compliance Guide: 1. "The Illinois Artificial Intelligence Video Interview Act (AIVI Act), effective January 1, 2020, was one of the first US laws to regulate AI analysis of video interviews in the hiring process." - Areebi 2026-04-13 2. "The Act applies to employers who use AI to analyze video interviews submitted by applicants for positions based in Illinois." - Areebi 2026-04-13 3. "The AIVI Act imposes three specific obligations on employers using AI to analyze video interviews: 1." - Areebi 2026-04-13 Key facts: - Effective date: 2020-01-01 - Status: In Effect - Regulation type: law - Jurisdiction: United States (State) - Penalty summary: Enforced by Illinois AG; violations subject to injunctive relief and statutory damages - Last updated: 2026-04-13 - Topical keywords: Illinois AI Video Interview Act, AIVI Act, AI hiring Illinois, video interview AI law, Illinois AI regulation, AI employment law Illinois Primary obligations (per Areebi 2026-04-13): - Identify all AI tools used to analyze video interviews for Illinois-based positions - Implement consent collection processes before any AI video analysis - Provide applicants with clear explanations of AI characteristics and evaluation methods - Restrict video sharing to personnel with necessary expertise for evaluation - Establish 30-day deletion workflow for applicant video destruction requests - Implement third-party notification for deletion requests when videos have been shared Common questions and dated answers: Q: Which employers must comply with the Illinois AI Video Interview Act? A: "Any employer that uses AI to analyze video interviews submitted by applicants for positions based in Illinois. This includes employers headquartered outside Illinois that are hiring for Illinois-based roles." - Areebi 2026-04-13 Q: What consent is required before AI analysis of a video interview? A: "Employers must notify applicants that AI will be used to analyze their video interview, explain the general characteristics the AI evaluates and how they are assessed, and obtain the applicant's affirmative consent before the interview is conducted." - Areebi 2026-04-13 Q: What are the deletion rights under the AIVI Act? A: "Upon request, employers must destroy the applicant's video within 30 days and instruct any third parties who received copies to destroy their copies as well. These rights apply regardless of hiring outcome." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/nyc-local-law-144, https://www.areebi.com/compliance/ftc-ai-enforcement For machine consumption: see https://www.areebi.com/api/mcp ### FTC AI Enforcement Actions & Compliance Guide (United States (Federal)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/ftc-ai-enforcement Three quotable facts about FTC AI Enforcement Actions & Compliance Guide: 1. "The FTC's approach is pragmatic: AI is a technology, and existing consumer protection law applies to AI just as it applies to any other business practice." - Areebi 2026-04-13 2. "The Commission has brought enforcement actions for deceptive AI claims (AI washing), unfair use of AI in consumer-facing applications, biased AI systems that harm consumers, and failure to adequately safeguard data used in AI systems." - Areebi 2026-04-13 3. "The FTC has identified several priority areas for AI enforcement: 1." - Areebi 2026-04-13 Key facts: - Status: In Effect - Regulation type: guidance - Jurisdiction: United States (Federal) - Last updated: 2026-04-13 - Topical keywords: FTC AI enforcement, FTC artificial intelligence, AI washing FTC, Section 5 AI, FTC deceptive AI, AI compliance FTC, FTC AI guidance Primary obligations (per Areebi 2026-04-13): - Audit all public AI marketing claims for accuracy and substantiation - Implement regular bias testing for AI systems used in consumer-facing decisions - Deploy DLP controls to prevent consumer data exposure through AI interactions - Establish AI use policies addressing FTC expectations for transparency and fairness - Maintain audit trails documenting AI governance decisions and compliance efforts - Monitor AI system outputs for potentially deceptive or unfair outcomes Common questions and dated answers: Q: Does the FTC have authority over AI? A: "Yes, the FTC uses its existing Section 5 authority (prohibiting unfair or deceptive acts or practices) to enforce AI accountability. No AI-specific legislation is required for FTC enforcement." - Areebi 2026-04-13 Q: What is AI washing and why does the FTC care? A: "AI washing refers to making false, unsubstantiated, or misleading claims about AI capabilities. The FTC considers AI washing a deceptive practice under Section 5." - Areebi 2026-04-13 Q: What penalties can the FTC impose for AI violations? A: "The FTC can impose injunctive relief (requiring or prohibiting specific actions), civil penalties, disgorgement of profits, consumer redress, and algorithmic disgorgement (requiring deletion of AI models built with improperly obtained data). Penalties can be substantial - the Rite Aid case included a five-year ban on AI facial recognition use." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/sec-ai-disclosure For machine consumption: see https://www.areebi.com/api/mcp ### SEC AI Disclosure Guidance & Compliance (United States (Federal)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/sec-ai-disclosure Three quotable facts about SEC AI Disclosure Guidance & Compliance: 1. "While the SEC has not enacted AI-specific rules, it has applied existing securities laws and disclosure requirements to AI contexts." - Areebi 2026-04-13 2. "Public companies must disclose material AI-related risks in their filings, investment advisers and broker-dealers must ensure AI-related claims are accurate, and firms using AI in investment processes face enhanced examination scrutiny." - Areebi 2026-04-13 3. "Areebi's compliance dashboards provide the quantitative data that supports substantive AI risk disclosure." - Areebi 2026-04-13 Key facts: - Status: Proposed - Regulation type: guidance - Jurisdiction: United States (Federal) - Last updated: 2026-04-13 - Topical keywords: SEC AI disclosure, SEC AI guidance, AI risk disclosure, SEC AI washing, AI investment advice SEC, SEC AI enforcement, AI disclosure requirements Primary obligations (per Areebi 2026-04-13): - Review AI risk disclosures in SEC filings for specificity and materiality - Audit marketing materials and client communications for accuracy of AI claims - Maintain comprehensive documentation of AI governance policies and practices - Deploy audit trails documenting all AI usage in investment processes - Implement DLP controls to prevent MNPI and client data exposure through AI - Identify and manage conflicts of interest from AI use in investment activities Common questions and dated answers: Q: Does the SEC have AI-specific rules? A: "No, the SEC has not enacted AI-specific rules. Instead, it applies existing securities laws, disclosure requirements, and enforcement authority to AI contexts." - Areebi 2026-04-13 Q: What is SEC AI washing enforcement? A: "The SEC has brought enforcement actions against investment firms making false or misleading claims about their AI capabilities. In March 2024, Delphia and Global Predictions settled charges for $400,000 combined for misrepresenting AI use in investment processes." - Areebi 2026-04-13 Q: What AI risks must public companies disclose? A: "Companies must disclose material AI-related risks including AI deployment risks, regulatory exposure, AI-dependent operations, cybersecurity threats, and governance practices. The SEC expects specific, substantive disclosures rather than generic boilerplate language." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/ftc-ai-enforcement, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/fedramp-ai For machine consumption: see https://www.areebi.com/api/mcp ### UK Online Safety Act & AI Compliance Guide (United Kingdom) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/uk-online-safety-act Three quotable facts about UK Online Safety Act & AI Compliance Guide: 1. "The UK Online Safety Act 2023, which received Royal Assent on October 26, 2023, is the UK's comprehensive framework for regulating online platforms." - Areebi 2026-04-13 2. "While not an AI-specific law, the Act has significant implications for AI systems, particularly in three areas: AI-generated harmful content (including deepfakes), AI-powered content moderation, and AI-driven recommender systems." - Areebi 2026-04-13 3. "This includes AI-powered content moderation systems that can detect AI-generated material." - Areebi 2026-04-13 Key facts: - Effective date: 2023-10-26 - Status: In Effect - Regulation type: law - Jurisdiction: United Kingdom - Penalty summary: Ofcom can impose fines up to GBP 18 million or 10% of global annual revenue, whichever is higher - Last updated: 2026-04-13 - Topical keywords: UK Online Safety Act, Online Safety Act AI, AI content moderation UK, deepfakes UK law, Ofcom AI guidance, online safety AI, AI-generated content UK Primary obligations (per Areebi 2026-04-13): - Determine your platform's category under the Online Safety Act (Category 1, 2A, or 2B) - Implement AI content guardrails to prevent generation of illegal and harmful content - Deploy deepfake and synthetic media detection capabilities - Establish user reporting mechanisms for AI-generated harmful content - Implement age assurance measures for services accessible to children - Deploy audit trails documenting all AI content moderation decisions Common questions and dated answers: Q: How does the Online Safety Act affect AI? A: "The Act creates duties for platforms using AI in three areas: AI-generated harmful content (including deepfakes), AI-powered content moderation systems, and AI-driven recommender algorithms. Platforms must ensure AI systems comply with safety duties and report on AI use in transparency reports." - Areebi 2026-04-13 Q: Are deepfakes illegal under the Online Safety Act? A: "Creating or sharing non-consensual AI-generated intimate images is a criminal offence under the Act, carrying penalties up to two years' imprisonment. Platforms have a duty to prevent the sharing of such content and must implement effective detection and takedown mechanisms." - Areebi 2026-04-13 Q: What penalties does the Online Safety Act impose? A: "Ofcom can impose fines of up to GBP 18 million or 10% of a company's global annual revenue, whichever is higher. Senior managers may also face criminal liability for failing to comply with Ofcom information notices." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/uk-ai-governance, https://www.areebi.com/compliance/california-ai-transparency, https://www.areebi.com/compliance/oecd-ai-principles For machine consumption: see https://www.areebi.com/api/mcp ### CCPA and AI: California Consumer Privacy Act Compliance (United States (State)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/ccpa Three quotable facts about CCPA and AI: California Consumer Privacy Act Compliance: 1. "The California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), establishes comprehensive data privacy rights for California consumers." - Areebi 2026-04-13 2. "When AI systems process personal information of California residents, organizations must comply with CCPA/CPRA requirements for data access, deletion, opt-out, and automated decision-making transparency." - Areebi 2026-04-13 3. "AI systems that process California consumer personal information trigger multiple CCPA/CPRA obligations:." - Areebi 2026-04-13 Key facts: - Effective date: 2020-01-01 - Status: In Effect - Regulation type: law - Jurisdiction: United States (State) - Penalty summary: $2,500 per violation; $7,500 per intentional violation - Last updated: 2026-04-13 - Topical keywords: CCPA AI compliance, California Consumer Privacy Act AI, CPRA automated decision-making, CCPA data deletion AI, AI opt-out rights California, CCPA AI governance, California AI data privacy, CPRA AI profiling Primary obligations (per Areebi 2026-04-13): - Identify all AI systems that process California consumer personal information - Deploy DLP controls to detect and block consumer PII in AI interactions - Implement opt-out enforcement mechanisms for AI-driven profiling and automated decisions - Configure audit logging for all AI-assisted consumer decisions to support access requests - Establish sensitive personal information classification rules for AI interactions - Prevent consumer data from entering AI training or fine-tuning pipelines Common questions and dated answers: Q: Does the CCPA apply to AI systems? A: "Any AI system that processes personal information of California consumers is subject to CCPA/CPRA. This includes AI used for profiling, automated decision-making, personalization, and data analysis." - Areebi 2026-04-13 Q: What is the CPRA automated decision-making right? A: "CPRA Section 1798.185(a)(16) directs the CPPA to establish regulations giving consumers the right to opt out of automated decision-making technology, access information about the logic involved in profiling, and request human review of significant automated decisions. The CPPA is actively finalizing these ADMT regulations." - Areebi 2026-04-13 Q: How does data deletion apply to AI training data? A: "When consumers request deletion of their personal information under CCPA, organizations must consider whether that data was used to train AI models. Areebi helps organizations avoid this complexity by preventing consumer data from reaching AI training pipelines through DLP controls, limiting deletion obligations to interaction logs rather than model parameters." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/california-ai-transparency, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/ftc-ai-enforcement For machine consumption: see https://www.areebi.com/api/mcp ### FERPA and AI: Educational Data Privacy Compliance (United States (Federal)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/ferpa Three quotable facts about FERPA and AI: Educational Data Privacy Compliance: 1. "The Family Educational Rights and Privacy Act (FERPA) protects the privacy of student education records at institutions receiving federal funding." - Areebi 2026-04-13 2. "As educational institutions and EdTech companies deploy AI tools for tutoring, grading, student advising, learning analytics, and administrative automation, FERPA compliance becomes a critical governance requirement." - Areebi 2026-04-13 3. "FERPA creates specific obligations when AI systems access or process student education records:." - Areebi 2026-04-13 Key facts: - Effective date: 1974-08-21 - Status: In Effect - Regulation type: law - Jurisdiction: United States (Federal) - Penalty summary: Loss of federal funding - Last updated: 2026-04-13 - Topical keywords: FERPA AI compliance, student data AI governance, educational AI privacy, EdTech AI governance, FERPA school official exception AI, student records AI protection, FERPA parental consent AI, education data AI compliance Primary obligations (per Areebi 2026-04-13): - Inventory all AI systems that process student education records - Verify school official exception eligibility for each AI vendor - Deploy DLP controls to detect and block student PII in AI interactions - Configure policies restricting AI processing to specified educational purposes - Activate audit logging for all AI interactions involving student data - Establish re-disclosure prevention controls for AI-generated outputs Common questions and dated answers: Q: Does FERPA apply to AI tools used in education? A: "FERPA applies to any disclosure of student education records, including disclosure to AI systems. When AI tools process grades, attendance, disciplinary records, or other education records, institutions must comply with FERPA's consent requirements or qualify under an exception such as the school official exception." - Areebi 2026-04-13 Q: Can AI vendors qualify under FERPA's school official exception? A: "Yes, if the AI vendor meets all four criteria: performs an institutional service or function, has a legitimate educational interest, is under direct institutional control, and does not re-disclose student PII. The 'direct control' requirement is the most challenging for AI vendors, as institutions must demonstrate oversight of how AI systems use and maintain student data." - Areebi 2026-04-13 Q: What happens if an institution violates FERPA with AI? A: "FERPA violations can result in the loss of all federal funding received by the institution, a severe consequence that affects the entire institution, not just the non-compliant program. The Department of Education investigates complaints and can compel corrective action." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/california-ai-transparency, https://www.areebi.com/compliance/ftc-ai-enforcement For machine consumption: see https://www.areebi.com/api/mcp ### SOX and AI: Sarbanes-Oxley Compliance for AI-Driven Financial Reporting (United States (Federal)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/sox-ai Three quotable facts about SOX and AI: Sarbanes-Oxley Compliance for AI-Driven Financial Reporting: 1. "The Sarbanes-Oxley Act (SOX) requires public companies to maintain effective internal controls over financial reporting (ICFR) and holds executives personally liable for the accuracy of financial disclosures." - Areebi 2026-04-13 2. "As AI tools increasingly participate in financial reporting processes - generating estimates, analyzing financial data, drafting disclosures, and automating reconciliations - SOX compliance obligations extend directly to these AI systems." - Areebi 2026-04-13 3. "Several SOX provisions directly apply to AI systems involved in financial reporting:." - Areebi 2026-04-13 Key facts: - Effective date: 2002-07-30 - Status: In Effect - Regulation type: law - Jurisdiction: United States (Federal) - Penalty summary: Up to $5M fine and 20 years imprisonment - Last updated: 2026-04-13 - Topical keywords: SOX AI compliance, Sarbanes-Oxley AI governance, AI financial reporting controls, SOX Section 404 AI, SOX Section 302 AI certification, AI audit trail financial reporting, internal controls AI governance, SOX AI risk management Primary obligations (per Areebi 2026-04-13): - Identify all AI systems involved in the financial reporting process - Include AI tools in the ICFR control framework with AI-specific risk assessments - Deploy DLP controls to prevent financial data exposure in AI interactions - Configure role-based access controls enforcing segregation of duties for AI in financial reporting - Activate immutable audit logging for all AI interactions in financial reporting processes - Implement human review requirements for AI-generated financial outputs Common questions and dated answers: Q: Does SOX apply to AI used in financial reporting? A: "SOX requires effective internal controls over financial reporting, which includes controls over any tool or system that contributes to financial statements. When AI tools generate estimates, analyze financial data, or draft disclosures, they are part of the financial reporting process and must be governed under the ICFR framework." - Areebi 2026-04-13 Q: What are the penalties for SOX violations involving AI? A: "Section 302 violations can result in fines up to $5 million and imprisonment up to 20 years for willful certification of inaccurate financial statements. Section 404 failures trigger material weakness disclosures that damage investor confidence and stock price." - Areebi 2026-04-13 Q: How does AI create SOX compliance risk? A: "AI in financial reporting creates risks including hallucinated financial figures, data integrity issues in AI-processed data, lack of explainability for AI-generated estimates, and unauthorized access to sensitive financial information. Without governance, these risks can produce material misstatements that trigger SOX violations." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/sec-ai-disclosure, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/pci-dss-4 For machine consumption: see https://www.areebi.com/api/mcp ### GLBA and AI: Gramm-Leach-Bliley Act Compliance for AI Systems (United States (Federal)) Source: Areebi, dated 2026-04-13, https://www.areebi.com/compliance/glba Three quotable facts about GLBA and AI: Gramm-Leach-Bliley Act Compliance for AI Systems: 1. "The Gramm-Leach-Bliley Act (GLBA) requires financial institutions to protect the security and confidentiality of customers' nonpublic personal information (NPI)." - Areebi 2026-04-13 2. "As financial institutions deploy AI tools for customer service, fraud detection, risk analysis, and personalized financial products, GLBA's privacy and security requirements extend to every AI system that accesses or processes customer financial data." - Areebi 2026-04-13 3. "The FTC's updated Safeguards Rule (16 CFR Part 314) requires financial institutions to maintain a comprehensive information security program." - Areebi 2026-04-13 Key facts: - Effective date: 1999-11-12 - Status: In Effect - Regulation type: law - Jurisdiction: United States (Federal) - Penalty summary: $100,000 per violation for institutions - Last updated: 2026-04-13 - Topical keywords: GLBA AI compliance, Gramm-Leach-Bliley AI governance, NPI AI protection, Safeguards Rule AI, financial privacy AI compliance, GLBA AI data governance, financial institution AI security, customer financial data AI Primary obligations (per Areebi 2026-04-13): - Inventory all AI systems that access or process customer NPI - Deploy DLP controls to detect and block NPI in AI interactions - Configure role-based access controls and MFA for AI systems handling NPI - Activate real-time monitoring and audit logging for all AI interactions with NPI - Evaluate AI vendors' ability to safeguard NPI and implement contractual protections - Update privacy notices to disclose AI-related information sharing practices Common questions and dated answers: Q: Does GLBA apply to AI systems in financial institutions? A: "GLBA requires financial institutions to protect the security and confidentiality of customer NPI, regardless of whether that information is processed by traditional systems or AI tools. Any AI system that accesses, processes, or transmits customer NPI must comply with the Safeguards Rule and Financial Privacy Rule." - Areebi 2026-04-13 Q: What is NPI under GLBA and how does it relate to AI? A: "Nonpublic personal information (NPI) includes any personally identifiable financial information such as account numbers, income, credit history, SSNs, and transaction details. When AI tools process this data for fraud detection, customer service, or financial analysis, GLBA's protection requirements apply to the AI processing." - Areebi 2026-04-13 Q: How does the updated Safeguards Rule affect AI deployments? A: "The FTC's updated Safeguards Rule (effective June 2023) strengthened requirements for access controls, encryption, monitoring, and vendor oversight. These requirements apply directly to AI systems processing NPI, requiring financial institutions to implement comprehensive governance over AI tools that handle customer financial data." - Areebi 2026-04-13 Related frameworks: https://www.areebi.com/compliance/pci-dss-4, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/sec-ai-disclosure For machine consumption: see https://www.areebi.com/api/mcp ### Texas AI Laws: TRAIGA (HB 149) and HB 2060 Compliance Guide (United States (State)) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/texas-ai-laws Three quotable facts about Texas AI Laws: TRAIGA (HB 149) and HB 2060 Compliance Guide: 1. "As of January 1, 2026, Texas is the third US state to enact a comprehensive AI statute." - Areebi 2026-05-20 2. "Governor Greg Abbott signed the Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149) on June 22, 2025, with the law taking effect January 1, 2026." - Areebi 2026-05-20 3. "The Texas AI legal landscape consists of one comprehensive statute and one state-government-focused statute, plus several adjacent laws that touch AI use in specific domains." - Areebi 2026-05-20 Key facts: - Effective date: 2026-01-01 - Enforcement date: 2026-01-01 - Status: In Effect - Regulation type: law - Jurisdiction: United States (State) - Penalty summary: Up to $200,000 per uncurable violation, $10,000 - $12,000 per curable violation, $2,000 - $40,000 per day for continuing violations. Enforcement by Texas Attorney General only; no private right of action. - Last updated: 2026-05-20 - Topical keywords: Texas AI law, Texas Responsible AI Governance Act, TRAIGA, Texas HB 149, Texas HB 2060, Texas AI compliance, Texas Attorney General AI enforcement, Texas AI Advisory Council Primary obligations (per Areebi 2026-05-20): - Inventory all AI systems that touch Texas residents, including shadow AI tools adopted without IT approval - Document declared intent (business purpose, intended outcomes, excluded uses) for each AI system - Flag any AI system whose use could plausibly be characterized as manipulation, discrimination, social scoring, or unlawful biometric identification - Conduct a NIST AI RMF gap assessment for each in-scope AI system - Map generative AI systems to the NIST AI 600-1 Generative AI Profile's 12 risk areas - Deploy policy enforcement that blocks prohibited use cases by design Common questions and dated answers: Q: What is the Texas Responsible Artificial Intelligence Governance Act (TRAIGA / HB 149)? A: "TRAIGA is the Texas AI law enacted as HB 149, signed by Governor Greg Abbott on June 22, 2025, and effective January 1, 2026." - Areebi 2026-05-20 Q: When did TRAIGA take effect? A: "Governor Abbott signed the bill on June 22, 2025, giving organizations approximately six months to prepare. Enforcement is active as of the effective date, although the Texas Attorney General must provide a 60-day cure period before bringing an enforcement action." - Areebi 2026-05-20 Q: Does TRAIGA apply to organizations outside Texas? A: "TRAIGA applies to any developer or deployer of an AI system that affects Texas residents, regardless of where the developer or deployer is headquartered. This Texas-effects standard parallels the scope used in the Texas Data Privacy and Security Act." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/colorado-ai-act, https://www.areebi.com/compliance/iso-42001 For machine consumption: see https://www.areebi.com/api/mcp ### Japan AI Guidelines for Business: METI/MIC, Hiroshima Process, and the AI Promotion Act (International) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/japan-ai-guidelines Three quotable facts about Japan AI Guidelines for Business: METI/MIC, Hiroshima Process, and the AI Promotion Act: 1. "Japan publishes its primary AI rulebook as voluntary guidance, not statute." - Areebi 2026-05-20 2. "A revised version 1.1 was issued in March 2025 with limited substantive updates, and METI continues to maintain the document through periodic addenda." - Areebi 2026-05-20 3. "Japan's AI policy landscape consists of one consolidated voluntary guideline, one international voluntary code, one proposed statute, and a series of adjacent laws that supply real enforcement teeth." - Areebi 2026-05-20 Key facts: - Effective date: 2024-04-19 - Status: Principles-Based - Regulation type: guidance - Jurisdiction: International - Penalty summary: Japan's AI Guidelines are soft law - the framework itself carries no direct civil or criminal penalty. Enforcement risk flows through adjacent statutes (APPI for personal data, Antimonopoly Act, Consumer Contract Act, Civil Code tort liability, Copyright Act). The proposed AI Promotion Act, as drafted, focuses on government coordination and study obligations rather than new corporate penalties; future amendments may introduce sectoral duties. - Last updated: 2026-05-20 - Topical keywords: Japan AI guidelines, METI AI, Japan AI governance, AI Guidelines for Business Japan, Hiroshima AI Process, G7 Code of Conduct AI, Japan AI Promotion Act, MIC AI principles Primary obligations (per Areebi 2026-05-20): - Identify the Developer, Provider, and Business User tier roles your organisation occupies for each AI system in use - Inventory all AI systems including shadow AI tools adopted without IT approval - Map prompts, responses, and training data residency in light of APPI cross-border transfer rules - Conduct a self-assessment against Japan's ten common Guiding Principles for each in-scope AI system - Document tier-specific recommended practices and address gaps for each AI system - Confirm APPI compliance for personal information processed by AI systems, including consent posture and PPC notification rules Common questions and dated answers: Q: What are Japan's AI Guidelines for Business? A: "The AI Guidelines for Business are voluntary guidance issued jointly by Japan's Ministry of Economy, Trade and Industry (METI) and Ministry of Internal Affairs and Communications (MIC). Version 1.0 was finalised on April 19, 2024, consolidating earlier 2019 and 2021 instruments." - Areebi 2026-05-20 Q: Are Japan's AI Guidelines legally binding? A: "The AI Guidelines for Business are voluntary guidance with no direct civil or criminal penalty. Enforcement teeth come from adjacent statutes - the Act on the Protection of Personal Information (APPI), the Antimonopoly Act, the Consumer Contract Act, the Copyright Act, the Financial Instruments and Exchange Act, sector-specific statutes, and Civil Code tort liability." - Areebi 2026-05-20 Q: What is the Hiroshima AI Process? A: "The Hiroshima AI Process is a G7 initiative launched at the May 2023 Hiroshima Summit under Japan's G7 Presidency. It produced two voluntary instruments finalised on October 30, 2023, and endorsed by G7 leaders on December 6, 2023: the International Guiding Principles for All AI Actors and the International Code of Conduct for Organizations Developing Advanced AI Systems." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/oecd-ai-principles, https://www.areebi.com/compliance/eu-ai-act, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/nist-ai-rmf For machine consumption: see https://www.areebi.com/api/mcp ### South Korea AI Basic Act (AI Framework Act): 2026 Compliance Guide (International) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/south-korea-ai-act Three quotable facts about South Korea AI Basic Act (AI Framework Act): 2026 Compliance Guide: 1. "South Korea is the second jurisdiction in the world - after the European Union - to enact a comprehensive horizontal AI statute." - Areebi 2026-05-20 2. "The National Assembly passed the Act on Promotion of Artificial Intelligence Development and Establishment of a Foundation for Trust (often translated as the "AI Basic Act" or "AI Framework Act") on December 26, 2024." - Areebi 2026-05-20 3. "The Korean AI regulatory architecture has one horizontal statute, a growing set of subordinate instruments, and a small constellation of adjacent laws and standards that supply enforcement infrastructure." - Areebi 2026-05-20 Key facts: - Effective date: 2026-01-22 - Enforcement date: 2026-01-22 - Status: In Effect - Regulation type: law - Jurisdiction: International - Penalty summary: Administrative fines up to KRW 30 million for breaches of high-impact AI, transparency, and generative-AI marking duties, plus corrective orders, suspension of operations, and on-site investigation powers held by the Ministry of Science and ICT (MSIT). Adjacent statutes - notably the Personal Information Protection Act enforced by the Personal Information Protection Commission (PIPC) and the Telecommunications Business Act enforced by the Korea Communications Commission (KCC) - supply additional penalty exposure where AI use intersects with personal data or telecommunications services. - Last updated: 2026-05-20 - Topical keywords: South Korea AI Act, Korea AI Basic Act, AI Framework Act Korea, Korea AI law 2026, MSIT AI, Korea high-impact AI, KAISI Korea AI Safety Institute, PIPC AI Primary obligations (per Areebi 2026-05-20): - Inventory all AI systems that are provided to or used by Korean users, including shadow AI tools adopted without IT approval - Map each system to the likely high-impact AI scope once the Presidential Decree is finalised - Designate a domestic representative in Korea and document the appointment in writing (foreign operators) - Confirm that the PIPA domestic representative requirement is also satisfied - Deploy clear-and-conspicuous user notices for generative AI interactions with Korean users - Implement output marking for generative AI outputs (visible label, metadata-based credentials, or watermarking) Common questions and dated answers: Q: What is the South Korea AI Basic Act? A: "The South Korea AI Basic Act (formally the Act on Promotion of AI Development and Establishment of a Foundation for Trust, also called the AI Framework Act) is South Korea's comprehensive horizontal AI statute. The National Assembly passed it on December 26, 2024, the government promulgated it on January 21, 2025, and the law takes effect on January 22, 2026." - Areebi 2026-05-20 Q: When does the Korea AI Basic Act take effect? A: "The Act takes effect on January 22, 2026, one year after promulgation on January 21, 2025. Some commentators reference 'January 2026' generally; the specific date should be confirmed against the official Korean government gazette publication and the final text of the law." - Areebi 2026-05-20 Q: Does the Korea AI Basic Act apply to foreign companies? A: "The Act applies to AI systems that are provided to or used by Korean users, regardless of where the developer or provider is located. Foreign businesses without an establishment in Korea must designate a domestic representative in Korea to receive regulatory communications and cooperate with MSIT investigations." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/eu-ai-act, https://www.areebi.com/compliance/japan-ai-guidelines, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/iso-42001 For machine consumption: see https://www.areebi.com/api/mcp ### India AI Regulation: DPDPA 2023 and the Proposed Digital India Act (India) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/india-digital-india-act-ai Three quotable facts about India AI Regulation: DPDPA 2023 and the Proposed Digital India Act: 1. "India's AI governance framework is layered and still maturing." - Areebi 2026-05-20 2. "As of May 2026, the operational baseline is the Digital Personal Data Protection Act 2023 (DPDPA), which received presidential assent on August 11, 2023, with the Ministry of Electronics and Information Technology (MeitY) phasing in operative provisions through 2025." - Areebi 2026-05-20 3. "The Indian AI legal landscape consists of one in-force statute, multiple operative advisories, a draft framework bill, and a national AI strategy document." - Areebi 2026-05-20 Key facts: - Effective date: 2023-08-11 - Enforcement date: 2025-01-01 - Status: In Effect - Regulation type: law - Jurisdiction: India - Penalty summary: Up to INR 250 crore (approximately USD 30 million) per instance of breach under the DPDPA 2023. Penalties imposed by the Data Protection Board of India following inquiry. The proposed Digital India Act could introduce additional algorithmic-harm and platform-accountability penalties once enacted. - Last updated: 2026-05-20 - Topical keywords: India AI regulation, Digital India Act AI, DPDPA AI, Digital Personal Data Protection Act 2023, MeitY AI advisory, India AI compliance, Significant Data Fiduciary, Data Protection Board of India Primary obligations (per Areebi 2026-05-20): - Inventory all AI systems that process personal data of Indian residents, including shadow AI tools - Document the lawful basis and purpose for each AI processing activity - Rebuild consent flows to satisfy DPDPA Section 5 (free, specific, informed, unconditional, unambiguous, clear affirmative action) - Rewrite notices in clear and plain language including AI processing as a stated purpose - Implement consent state tracking that can demonstrate the consent basis for every AI inference involving personal data - Deploy AI DLP to prevent personal data exposure to third-party models Common questions and dated answers: Q: Is the Digital India Act in force? A: "The Digital India Act is a draft framework. MeitY released principles in 2023 - 2024 and held consultations, but the DIA bill has not been introduced in Parliament as of May 2026." - Areebi 2026-05-20 Q: Does the DPDPA apply to AI systems? A: "The DPDPA does not single out AI by name, but its data fiduciary obligations apply to any system that processes personal data of Indian residents. AI training, fine-tuning, and inference using personal data are all in scope." - Areebi 2026-05-20 Q: What are the DPDPA penalties for AI-related breaches? A: "The Data Protection Board of India is the imposing authority, with appeals to the TDSAT." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/singapore-ai-governance, https://www.areebi.com/compliance/japan-ai-guidelines, https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/iso-42001 For machine consumption: see https://www.areebi.com/api/mcp ### Brazil AI Regulation: LGPD and the Proposed Marco Legal da IA (PL 2338/2023) (Brazil) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/brazil-lgpd-ai Three quotable facts about Brazil AI Regulation: LGPD and the Proposed Marco Legal da IA (PL 2338/2023): 1. "Brazil's AI governance framework is layered and still maturing." - Areebi 2026-05-20 2. "As of May 2026, the operational baseline is the Lei Geral de Proteção de Dados Pessoais (LGPD, Lei 13.709/2018), which has been in force since September 18, 2020 and has been actively enforced by the Autoridade Nacional de Proteção de Dados (ANPD) since the first sanctions were imposed in late 2023." - Areebi 2026-05-20 3. "The Brazilian AI legal landscape consists of one in-force statute, multiple ANPD regulations and pareceres (technical opinions), a Senate-passed bill awaiting Chamber consideration, and several sector-specific overlays." - Areebi 2026-05-20 Key facts: - Effective date: 2020-09-18 - Enforcement date: 2021-08-01 - Status: In Effect - Regulation type: law - Jurisdiction: Brazil - Penalty summary: Up to 2% of revenue in Brazil (limited to BRL 50 million per infraction) under LGPD Article 52. Daily fines for ongoing violations. The Autoridade Nacional de Proteção de Dados (ANPD) has imposed fines since 2023. The proposed PL 2338/2023 would add high-risk AI specific obligations. - Last updated: 2026-05-20 - Topical keywords: Brazil AI regulation, LGPD AI, Marco Legal da IA, PL 2338/2023, ANPD AI, Brazil DPO, LGPD penalties, Brazil data protection AI Primary obligations (per Areebi 2026-05-20): - Inventory all AI systems that process personal data of Brazilian residents, including shadow AI tools - Document the LGPD Article 7 lawful basis and purpose for each AI processing activity - Identify sensitive personal data (Article 11) flows and confirm the more restrictive legal bases - Designate an encarregado (DPO) with knowledge of the LGPD and the technical AI stack - Publish the encarregado's identity and contact information on the controller's website - Build the Article 20 automated decision review channel with HITL routing and reason capture Common questions and dated answers: Q: Is PL 2338/2023 (Marco Legal da IA) in force? A: "The Federal Senate approved a substitute text in December 2024, but PL 2338/2023 is currently in the Chamber of Deputies and has not been enacted as of May 2026. The operative AI compliance baseline is the LGPD (Lei 13.709/2018), which is in force and actively enforced by the ANPD." - Areebi 2026-05-20 Q: Does the LGPD apply to AI systems? A: "The LGPD does not single out AI by name, but its controller and operator obligations apply to any system that processes personal data of individuals in Brazil. Article 7 lawful basis, Article 18 rights, Article 20 review of automated decisions, Article 38 RIPDs, and Article 41 encarregado obligations all reach AI training and inference." - Areebi 2026-05-20 Q: What are the LGPD penalties for AI-related violations? A: "Resolution CD/ANPD Nº 4/2023 sets the dosimetry methodology that calibrates the calculated fine." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/eu-ai-act-compliance-mid-market, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/india-digital-india-act-ai For machine consumption: see https://www.areebi.com/api/mcp ### UAE AI Compliance: PDPL (Federal Decree-Law 45/2021) + DIFC + ADGM data laws (United Arab Emirates) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/uae-pdpl Three quotable facts about UAE AI Compliance: PDPL (Federal Decree-Law 45/2021) + DIFC + ADGM data laws: 1. "The United Arab Emirates does not yet have a single AI-specific statute, but it has built a layered governance framework that already binds AI systems processing personal data of UAE residents." - Areebi 2026-05-20 2. "Four layers operate in parallel as of May 2026: the federal Personal Data Protection Law (Federal Decree-Law No." - Areebi 2026-05-20 3. "The operative UAE framework for AI consists of three data-protection regimes (one federal, two free-zone), one strategic AI charter, and sector-specific regulator guidance." - Areebi 2026-05-20 Key facts: - Effective date: 2022-01-02 - Status: In Effect - Regulation type: law - Jurisdiction: United Arab Emirates - Penalty summary: Federal PDPL: administrative penalties up to AED 5 million per violation imposed by the UAE Data Office. DIFC DP Law: fines up to USD 1M per contravention. ADGM Data Protection Regulations: comparable fines plus enforcement by the Office of Data Protection. The UAE Data Office gained enforcement powers under the Executive Regulations published in 2023. - Last updated: 2026-05-20 - Topical keywords: UAE AI compliance, UAE PDPL, Federal Decree-Law 45/2021, DIFC data protection, ADGM data protection, UAE Data Office, UAE Council for AI, UAE AI Charter Primary obligations (per Areebi 2026-05-20): - Inventory all AI systems that process personal data of UAE residents or data collected in the UAE - Identify each legal entity's licence type (federal/onshore, DIFC, ADGM) and map to applicable regime - Document the lawful basis (PDPL Article 5-6; DIFC Article 10; ADGM Section 7) for each AI processing activity - Rebuild consent flows to satisfy unambiguous-affirmative-action expectations across the three regimes - Provide notice surfaces in Arabic and English describing AI processing and data subject rights - Appoint a Data Protection Officer where processing is likely to result in high risk Common questions and dated answers: Q: Is the UAE PDPL already in force? A: "45 of 2021 came into force on January 2, 2022. The Executive Regulations were published in 2023, operationalising the framework and giving the UAE Data Office its enforcement remit." - Areebi 2026-05-20 Q: Does the PDPL apply to AI systems specifically? A: "The PDPL does not name AI specifically, but its obligations apply to any system that processes personal data of UAE residents or data collected in the UAE. AI training, fine-tuning, and inference using personal data are all in scope." - Areebi 2026-05-20 Q: How do the DIFC and ADGM regimes differ from the federal PDPL? A: "The DIFC DP Law 5/2020 and ADGM DP Regulations 2021 are GDPR-equivalent free-zone laws administered by their own competent authorities (the DIFC Commissioner of Data Protection and the ADGM Office of Data Protection). They closely track the GDPR in lawful-basis structure, data-subject rights, DPIA expectations, and breach notification." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/singapore-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### NIS2 Directive + AI: cybersecurity obligations for AI-enabled essential entities (EU 2022/2555) (European Union) Source: Areebi, dated 2026-05-20, https://www.areebi.com/compliance/nis2-directive-ai Three quotable facts about NIS2 Directive + AI: cybersecurity obligations for AI-enabled essential entities (EU 2022/2555): 1. "The Network and Information Security Directive 2 (NIS2), formally Directive (EU) 2022/2555, is the European Union's cybersecurity baseline for essential and important entities." - Areebi 2026-05-20 2. "Adopted on December 14, 2022, NIS2 replaces the original NIS Directive (2016/1148) with a substantially expanded scope, more prescriptive risk-management measures, faster incident reporting, harder sanctions, and direct management liability." - Areebi 2026-05-20 3. "NIS2 itself is a directive: it sets the obligations and requires Member States to transpose them into national law." - Areebi 2026-05-20 Key facts: - Effective date: 2024-10-18 - Status: In Effect - Regulation type: law - Jurisdiction: European Union - Penalty summary: For essential entities: administrative fines up to EUR 10 million OR 2% of global annual turnover (whichever higher). For important entities: up to EUR 7M or 1.4% of global turnover. Plus management liability under Article 32 - directors personally accountable for cybersecurity risk management failures. - Last updated: 2026-05-20 - Topical keywords: NIS2 Directive AI, EU 2022/2555, NIS2 essential entities, NIS2 important entities, NIS2 supply chain, NIS2 incident reporting, NIS2 board liability, NIS2 AI risk management Primary obligations (per Areebi 2026-05-20): - Confirm NIS2 scope per Member State transposition (essential, important, or out-of-scope) - Establish a board-level cybersecurity committee with AI governance as a standing item - Document management body approval of cybersecurity risk management measures (Article 20(1)) - Provide management body training on cybersecurity and AI risk (Article 20(2)) - Implement comprehensive risk analysis covering ENISA AI Threat Landscape threats - Build incident handling capability with AI-specific incident types in scope Common questions and dated answers: Q: Is NIS2 already in force? A: "Directive (EU) 2022/2555 was adopted on December 14, 2022, with a Member State transposition deadline of October 17, 2024. Most Member States completed transposition in 2024 or 2025; the European Commission opened infringement proceedings in 2025 against late-transposing Member States." - Areebi 2026-05-20 Q: Does NIS2 regulate AI? A: "NIS2 regulates cybersecurity for entities operating in critical sectors." - Areebi 2026-05-20 Q: What are the maximum NIS2 penalties? A: "Article 34 sets administrative fines up to EUR 10 million or 2% of global annual turnover (whichever higher) for essential entities, and up to EUR 7 million or 1.4% of global annual turnover for important entities. In addition, Article 32 imposes personal liability on senior management for breach of duty, with Member States required to permit measures including temporary prohibition from exercising managerial functions." - Areebi 2026-05-20 Related frameworks: https://www.areebi.com/compliance/iso-42001, https://www.areebi.com/compliance/nist-ai-rmf, https://www.areebi.com/compliance/uk-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### APRA CPS 230 and AI: Operational Risk for Australian Financial Services (Australia) Source: Areebi, dated 2026-07-31, https://www.areebi.com/compliance/apra-cps-230-ai Three quotable facts about APRA CPS 230 and AI: Operational Risk for Australian Financial Services: 1. "AI is in scope by function, not by name." - Areebi 2026-07-31 2. "It applies to authorised deposit-taking institutions (ADIs), general, life and health insurers, and registrable superannuation entity (RSE) licensees." - Areebi 2026-07-31 3. "Under CPS 230 paragraph 35, a critical operation is a process that, if disrupted beyond tolerance levels, would have a material adverse impact on depositors, policyholders, beneficiaries or other customers, or on the entity's role in the financial system." - Areebi 2026-07-31 Key facts: - Effective date: 2025-07-01 - Enforcement date: 2026-07-01 - Status: In Effect - Regulation type: standard - Jurisdiction: Australia - Penalty summary: CPS 230 is an enforceable prudential standard made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995, Private Health Insurance (Prudential Supervision) Act 2015 and Superannuation Industry (Supervision) Act 1993. Non-compliance is not penalised by fixed civil fines; instead APRA may use its full supervisory and enforcement toolkit, including additional licence conditions, directions, increased capital or prudential requirements, enforceable undertakings, and (for accountable persons) consequences under the Financial Accountability Regime (FAR), which APRA and ASIC jointly administer. Pre-existing contracts with material service providers had to comply by the earlier of next renewal or 1 July 2026 - that transition is now complete, so all in-scope arrangements are covered. - Last updated: 2026-07-31 - Topical keywords: APRA CPS 230 AI, CPS 230 material service providers AI, APRA AI operational risk, CPS 230 artificial intelligence, APRA AI vendor concentration risk, CPS 230 critical operations AI, APRA operational resilience AI, APRA AI letter 2026 Primary obligations (per Areebi 2026-07-31): - Inventory every AI system, model and embedded AI capability in use, including shadow AI, and link each to the critical operations it supports. - Classify AI and LLM vendors that support critical operations or create material operational risk as material service providers and add them to your CPS 230 register (APRA requested the first register submission, using its template, by 1 October 2025). - Confirm board-approved tolerance levels (maximum downtime, data loss and minimum service level) apply to each AI-dependent critical operation. - Document and test a viable fallback for every AI-dependent critical operation - a non-AI process, substitute model or degraded mode that operates within tolerance. - Map AI vendor concentration across critical operations, including upstream foundation-model and fourth-party dependencies, and test a credible exit or substitution strategy. - Update material service provider agreements to address audit access, data ownership, model and data-handling changes and incident notification, and assess concentration risk as part of due diligence - confirming pre-existing contracts were brought into line during the transition that ended 1 July 2026, and remediating any that were missed. Common questions and dated answers: Q: When did APRA CPS 230 take effect and who does it apply to? A: "CPS 230 Operational Risk Management took effect on 1 July 2025. It is a cross-industry prudential standard applying to all APRA-regulated entities - authorised deposit-taking institutions (banks/ADIs), general, life and health insurers, and registrable superannuation entity (RSE) licensees." - Areebi 2026-07-31 Q: Does CPS 230 mention artificial intelligence? A: "CPS 230 is deliberately technology and vendor agnostic and does not use the term "artificial intelligence". AI is captured by function: any AI system that underpins a critical operation or exposes the entity to material operational risk falls within scope." - Areebi 2026-07-31 Q: Can an AI or LLM vendor be a material service provider under CPS 230? A: "Under CPS 230 paragraph 49, a material service provider is one relied on to undertake a critical operation or that exposes the entity to material operational risk. An AI or LLM vendor underpinning credit decisioning, claims, fraud detection or customer servicing meets this threshold, triggering register, formal-agreement and concentration-risk obligations." - Areebi 2026-07-31 Related frameworks: https://www.areebi.com/compliance/apra-cps-234-ai, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/australia-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### APRA CPS 234 & AI: Securing AI Models, Pipelines and Inference APIs (Australia) Source: Areebi, dated 2026-07-31, https://www.areebi.com/compliance/apra-cps-234-ai Three quotable facts about APRA CPS 234 & AI: Securing AI Models, Pipelines and Inference APIs: 1. "APRA Prudential Standard CPS 234 (Information Security) applies to AI even though the word "AI" never appears in the text - because AI models, training and fine-tuning data, vector and embedding stores, and inference/API endpoints are all "information assets" within scope." - Areebi 2026-07-31 2. "CPS 234 defines an information asset as "information and information technology, including software, hardware and data (both soft and hard copy)", which squarely captures the modern AI stack." - Areebi 2026-07-31 3. "CPS 234 requires an entity to classify its information assets "by criticality and sensitivity" (paragraph 20) and to implement controls commensurate with the threats, vulnerabilities and consequences associated with those assets (paragraphs 21-22)." - Areebi 2026-07-31 Key facts: - Effective date: 2019-07-01 - Enforcement date: 2019-07-01 - Status: In Effect - Regulation type: standard - Jurisdiction: Australia - Penalty summary: CPS 234 is an enforceable prudential standard made under the Banking Act 1959, Insurance Act 1973, Life Insurance Act 1995, Private Health Insurance (Prudential Supervision) Act 2015 and Superannuation Industry (Supervision) Act 1993. Non-compliance is a breach of prudential requirements rather than a fixed civil penalty: APRA can issue directions, impose additional licence conditions, require independent reviews, escalate accountability under the Financial Accountability Regime (FAR) against the relevant accountable persons, and ultimately vary, suspend or cancel an entity's licence. Failing to lodge the mandatory 72-hour incident notification or 10-business-day control-weakness notification is itself a reportable breach. - Last updated: 2026-07-31 - Topical keywords: APRA CPS 234 AI, CPS 234 information security AI, CPS 234 AI models, securing AI inference APIs APRA, AI information assets CPS 234, CPS 234 CPS 230 AI, APRA AI security compliance, BFSI AI governance Australia Primary obligations (per Areebi 2026-07-31): - Maintain a live inventory of every AI model, training and fine-tuning dataset, vector or embedding store, system prompt and inference/API endpoint, and classify each by criticality and sensitivity (CPS 234 para 20). - Name an accountable owner for each AI system and ensure information-security accountability sits with the relevant accountable person under the Financial Accountability Regime, with AI security risk reported to the Board as a whole-of-business risk (CPS 234 para 12-14). - Implement information-security controls at the inference boundary - DLP, access control and MFA for high-risk and privileged activities, and prompt-injection guardrails - sized to each asset's sensitivity (CPS 234 para 21-22). - Address the OWASP Top 10 for LLM Applications 2025 risks, in particular prompt injection, sensitive information disclosure, supply chain, data and model poisoning, and system prompt leakage, within your CPS 234 control set. - Assess every third-party AI provider's information-security capability and the design and operating effectiveness of its controls, and pair this with CPS 230 material-service-provider due diligence and contracts (CPS 234 para 15-16, 28). - Systematically test AI control effectiveness, including red-teaming models and inference APIs for jailbreaks, extraction and data leakage, at a frequency commensurate with risk and change (CPS 234 para 27-31). Common questions and dated answers: Q: Does CPS 234 mention AI? A: "The word "AI" does not appear in CPS 234. But the standard applies to AI because it governs "information assets" - defined as information and information technology including software, hardware and data - and AI models, training data, fine-tuning pipelines, vector stores and inference APIs all fall within that definition." - Areebi 2026-07-31 Q: When did CPS 234 come into force and who does it apply to? A: "CPS 234 (Information Security) has been in force since 1 July 2019. It applies to all APRA-regulated entities - authorised deposit-taking institutions, general, life and private health insurers, and registrable superannuation entity (RSE) licensees - and its requirements extend to information assets managed by third parties and related parties." - Areebi 2026-07-31 Q: Is a customer-facing LLM inference API an information asset under CPS 234? A: "An inference or API endpoint is an availability-critical information asset and a primary attack surface for prompt injection, model extraction and sensitive-information disclosure. It must be inventoried, classified by criticality and sensitivity (para 20), protected with controls commensurate to its risk (para 21-22), and tested for effectiveness (para 27-31), the same as any other production system." - Areebi 2026-07-31 Related frameworks: https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/australia-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### Privacy Act Automated Decision-Making (ADM) Transparency: The 10 December 2026 Deadline (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/privacy-act-adm-transparency Three quotable facts about Privacy Act Automated Decision-Making (ADM) Transparency: The 10 December 2026 Deadline: 1. "This is a privacy-policy transparency duty, not a ban on automated decision-making." - Areebi 2026-06-08 2. "The obligation was introduced by the Privacy and Other Legislation Amendment Act 2024, which received Royal Assent on 10 December 2024." - Areebi 2026-06-08 3. "The new provisions add three specific disclosures to the existing privacy-policy requirements in APP 1.3-1.4." - Areebi 2026-06-08 Key facts: - Effective date: 2026-12-10 - Enforcement date: 2026-12-10 - Status: Enacted - Regulation type: law - Jurisdiction: Australia - Penalty summary: The transparency obligation is an Australian Privacy Principle, so a breach is an interference with privacy enforceable under the regime strengthened by the Privacy and Other Legislation Amendment Act 2024. The OAIC can issue infringement notices and compliance notices for lower-tier and administrative breaches, and pursue civil penalties. The top-tier penalty for serious interferences with privacy (s 13G) is the greater of A$50 million, three times the benefit obtained, or 30% of adjusted turnover during the breach period. Separately, the statutory tort for serious invasions of privacy (in force 10 June 2025) caps damages for non-economic loss at the greater of A$478,550 or the maximum available for non-economic loss in defamation. - Last updated: 2026-06-08 - Topical keywords: Privacy Act automated decision-making, APP 1.7 ADM transparency, 10 December 2026 ADM deadline, Privacy and Other Legislation Amendment Act 2024, OAIC automated decision-making guidance, automated decision-making privacy policy Australia, ADM transparency obligation, computer program decision Privacy Act Primary obligations (per Areebi 2026-06-08): - Confirm whether your organisation is an APP entity bound by the Privacy Act (turnover above A$3M, or a covered entity regardless of turnover, or an overseas business carrying on business in Australia) - Build an inventory of every system - built, bought or shadow - that makes or materially assists decisions using personal information - Apply the two-limb trigger test to each system: does it use personal information, and could the decision significantly affect an individual's rights or interests - Record, for each in-scope system, whether decisions are made solely by the computer program or substantially and directly assisted by it (and note that refusing or failing to decide counts) - Document the kinds of personal information used by in-scope computer programs to support the APP 1.7(a) disclosure - Draft plain-English privacy-policy disclosures for categories (a) kinds of personal information, (b) kinds of solely-automated decisions, and (c) kinds of substantially-assisted decisions Common questions and dated answers: Q: When does the Privacy Act automated decision-making transparency obligation start? A: "New APP 1.7, 1.8 and 1.9 were introduced by the Privacy and Other Legislation Amendment Act 2024 (Royal Assent 10 December 2024) with a 24-month grace period, and apply to decisions made on or after 10 December 2026." - Areebi 2026-06-08 Q: What does my privacy policy have to say about automated decision-making? A: "Where a computer program makes, or substantially and directly assists, decisions using personal information that could significantly affect a person's rights or interests, your privacy policy must disclose the kinds of personal information used, the kinds of decisions made solely by the program, and the kinds of..." - Areebi 2026-06-08 Q: Does generative AI count as a "computer program" under APP 1.7? A: "On its ordinary, technology-neutral meaning, yes. The Act uses "computer program" without a narrow definition, and that ordinary reading captures generative AI tools such as chatbots and text, image or code generators, as well as rules-based and machine-learning systems." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/apra-cps-234-ai, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/australia-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### Australia's AI Rules in 2026: No AI Act, the National AI Plan and the 6 Essential Practices (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard Three quotable facts about Australia's AI Rules in 2026: No AI Act, the National AI Plan and the 6 Essential Practices: 1. "As of 2026 there is no Australian AI Act, no mandatory AI guardrails, and none planned." - Areebi 2026-06-08 2. "The National AI Plan (2 December 2025) chose to govern AI through existing technology-neutral laws and sector regulators, supported by voluntary guidance and a new advisory AI Safety Institute - not a standalone AI statute." - Areebi 2026-06-08 3. "The National AI Plan, released on 2 December 2025 by the Department of Industry, Science and Resources, is Australia's most comprehensive AI policy statement to date." - Areebi 2026-06-08 Key facts: - Status: Principles-Based - Regulation type: guidance - Jurisdiction: Australia - Last updated: 2026-06-08 - Topical keywords: Australia AI rules 2026, Australian Voluntary AI Safety Standard, Guidance for AI Adoption, 6 essential practices AI, National AI Plan, Australia AI Safety Institute, is there an Australian AI Act, AS ISO/IEC 42001 Australia Primary obligations (per Areebi 2026-06-08): - Confirm internally that Australia has no AI Act and no mandatory guardrails, and brief the board so AI risk is governed under existing law, not a hypothetical future statute - Map your AI use cases to the laws that already bind them: Privacy Act 1988, Australian Consumer Law, anti-discrimination law, the Corporations Act, and any sector regime (APRA CPS 230 and CPS 234, ASIC, TGA, SOCI Act) - Adopt the 6 Essential Practices from the Guidance for AI Adoption (21 October 2025) as your voluntary baseline - Download and deploy the Government's AI screening tool, AI register template and AI policy template from industry.gov.au - Assign a named accountable executive and board-level oversight for AI (Essential Practice 1) - Build and maintain an inventory of all AI systems in use, including shadow AI, and screen each for impact and risk Common questions and dated answers: Q: Is there an Australian AI Act in 2026? A: "As of 2026 Australia has no AI Act and none is planned. The National AI Plan (2 December 2025) decided to govern AI through existing technology-neutral laws and sector regulators, plus voluntary guidance and an advisory AI Safety Institute, rather than a standalone AI statute or mandatory guardrails." - Areebi 2026-06-08 Q: What happened to the proposed mandatory guardrails for high-risk AI? A: "The September 2024 Proposals Paper on mandatory guardrails for AI in high-risk settings was not legislated. The Government instead reaffirmed a principles-based, pro-adoption approach in the National AI Plan, relying on existing law plus the voluntary 6 Essential Practices." - Areebi 2026-06-08 Q: What are the 6 Essential Practices for AI in Australia? A: "They are Australia's voluntary baseline for responsible AI: (1) governance and accountability, (2) impact assessment, (3) risk management, (4) transparency, (5) testing and monitoring, and (6) human oversight. They are set out in the Guidance for AI Adoption (21 October 2025) and consolidate the 2024 Voluntary AI Safety Standard's ten guardrails." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/apra-cps-234-ai, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/australia-ai-governance For machine consumption: see https://www.areebi.com/api/mcp ### Sovereign and Self-Hosted AI in Australia: Data Residency, Sovereignty and Compliance (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/sovereign-ai-australia Three quotable facts about Sovereign and Self-Hosted AI in Australia: Data Residency, Sovereignty and Compliance: 1. "Onshore storage alone is not enough: a US-controlled provider can be compelled under the US CLOUD Act regardless of where the servers sit, so true sovereignty depends on who controls the system, not just where the disk lives." - Areebi 2026-06-08 2. "Two concepts are routinely conflated and must be separated." - Areebi 2026-06-08 3. "Data residency is a question of geography; data sovereignty is a question of jurisdiction and control." - Areebi 2026-06-08 Key facts: - Status: Principles-Based - Regulation type: guidance - Jurisdiction: Australia - Last updated: 2026-06-08 - Topical keywords: sovereign AI Australia, self-hosted AI Australia, data residency AI, data sovereignty AI, APP 8 cross-border disclosure AI, US CLOUD Act Australian data, on-premises LLM Australia, private cloud AI Australia Primary obligations (per Areebi 2026-06-08): - Map every AI data flow - prompts, outputs, embeddings/vector stores, fine-tuning data and logs - and identify any point where data leaves your perimeter to a foreign-controlled model endpoint. - Distinguish data residency (physical location) from data sovereignty (governing law and foreign-government access risk) for each AI service, and assess CLOUD Act and similar exposure for any provider in scope. - Before any cross-border AI use, test APP 8.1 reasonable steps and recognise that section 16C makes you accountable for the overseas recipient's handling of personal information as if it were your own act. - Treat routing personal information to an overseas-hosted LLM as a cross-border disclosure, not a neutral technical decision, and prefer self-hosting that keeps data under your effective control (a use, not a disclosure). - For government and government-adjacent workloads, run AI in IRAP-assessable, ISM/PSPF-aligned environments with Australian data residency, and confirm hosting meets Hosting Certification Framework and any SOCI obligations. - Place the model, inference endpoint, vector store and logs inside the assessed boundary - do not let an AI feature silently call a public foreign API from within an accredited system. Common questions and dated answers: Q: What is the difference between data residency and data sovereignty for AI? A: "Data residency is where data is physically stored and processed - for example, in an Australian cloud region. Data sovereignty is whose laws and courts govern that data, and which foreign governments can compel access to it." - Areebi 2026-06-08 Q: Does sending personal data to an overseas AI model breach Australian Privacy Principle 8? A: "Sending personal information to an overseas-hosted AI model is a cross-border disclosure under APP 8. You must take reasonable steps under APP 8.1 to ensure the recipient does not breach the APPs, and under section 16C of the Privacy Act the recipient's breach is taken to be your breach." - Areebi 2026-06-08 Q: Can the US CLOUD Act reach Australian data stored in an Australian cloud region? A: "The US CLOUD Act (March 2018) lets US authorities compel US-based providers to produce data they hold or control regardless of where it is stored, so data physically resident in Australia but operated by a US-controlled entity can still be in scope. Australian residency alone does not extinguish foreign-government access risk - sovereignty depends on who controls the system, not just where the disk is." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/apra-cps-234-ai For machine consumption: see https://www.areebi.com/api/mcp ### DTA Policy for the Responsible Use of AI in Government: 2026 Mandatory Requirements (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/dta-ai-policy Three quotable facts about DTA Policy for the Responsible Use of AI in Government: 2026 Mandatory Requirements: 1. "The Policy for the responsible use of AI in government is the Australian Government's mandatory whole-of-government policy, issued by the Digital Transformation Agency (DTA), that sets binding requirements for how non-corporate Commonwealth entities adopt and use artificial intelligence." - Areebi 2026-06-08 2. "Version 2.0 took effect on 15 December 2025 and, for the first time, introduced mandatory requirements: a designated accountable official for AI, an internal AI use case register, mandatory AI impact assessments before deployment, and public AI transparency statements published to a central register." - Areebi 2026-06-08 3. "Version 2.0 introduces four interlocking mandatory requirements for in-scope AI use cases, supported by a mandatory strategic position on AI adoption, mandatory foundational AI training and ongoing review." - Areebi 2026-06-08 Key facts: - Effective date: 2025-12-15 - Enforcement date: 2026-06-15 - Status: In Effect - Regulation type: guidance - Jurisdiction: Australia - Penalty summary: The Policy is a mandatory whole-of-government requirement for non-corporate Commonwealth entities issued under the Public Governance, Performance and Accountability Act 2013 and the Digital and ICT Investment Oversight Framework, not a statute carrying civil penalties. It does not impose fines. Non-compliance is managed as a governance and accountability matter: accountable officials are answerable to their agency head, and adherence is visible through whole-of-government reporting to the DTA, the published central register of AI transparency statements, and oversight by the Data and Digital Ministers. Underlying obligations (privacy, security, administrative law) carry their own separate enforcement. - Last updated: 2026-06-08 - Topical keywords: DTA AI policy, responsible use of AI in government, DTA policy version 2.0, AI accountable official, AI impact assessment government, AI transparency statement, AI use case register, Commonwealth AI policy 2026 Primary obligations (per Areebi 2026-06-08): - Identify and notify your designated accountable official(s) for AI to the DTA within 90 days of the 15 December 2025 effect date (by approximately 15 March 2026). - Develop and communicate a strategic position on AI adoption to staff within 6 months (by 15 June 2026). - Publish a public AI transparency statement describing your approach to adopting and using AI within 6 months (by 15 June 2026) and list it on the central register on digital.gov.au. - Establish and maintain an internal AI use case register with an accountable use case owner for each in-scope use case, created within 12 months (by 15 December 2026), and share it with the DTA every 6 months from the date you create it. - Complete an AI impact assessment using the DTA's 12-section tool before deploying each in-scope use case, with the mandatory requirement in force by 15 December 2026. - Assess each AI impact assessment against Australia's 8 AI Ethics Principles and ensure it complements existing privacy, security and administrative-law assessments rather than duplicating them. Common questions and dated answers: Q: Is the DTA Policy for the responsible use of AI in government mandatory? A: "Version 2.0, effective 15 December 2025, is mandatory for non-corporate Commonwealth entities and introduces binding requirements: a designated accountable official, an AI use case register, AI impact assessments before deployment, and public transparency statements. Corporate Commonwealth entities are strongly encouraged to apply it." - Areebi 2026-06-08 Q: When do the DTA AI policy mandatory requirements start? A: "The Policy took effect on 15 December 2025, but the requirements are phased. The first new mandatory requirement begins 15 June 2026 (6 months in), which includes publishing a public AI transparency statement and developing a strategic position on AI adoption." - Areebi 2026-06-08 Q: Who is the accountable official under the DTA AI policy? A: "Each in-scope entity must designate one or more accountable officials responsible for implementing the Policy and overseeing the entity's responsible use of AI. The official(s) must be designated and notified to the DTA within 90 days of the 15 December 2025 effect date, and they are answerable to the agency head for compliance." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/apra-cps-230-ai For machine consumption: see https://www.areebi.com/api/mcp ### ASD Essential Eight and AI: Securing AI Systems to the Australian Cyber Baseline (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/essential-eight-ai Three quotable facts about ASD Essential Eight and AI: Securing AI Systems to the Australian Cyber Baseline: 1. "AI is in scope; it is not a special case." - Areebi 2026-06-08 2. "The Essential Eight is the Australian Signals Directorate's (ASD) prioritised baseline of eight mitigation strategies, drawn from its broader Strategies to Mitigate Cyber Security Incidents." - Areebi 2026-06-08 3. "Each of the eight strategies has a concrete AI interpretation." - Areebi 2026-06-08 Key facts: - Status: In Effect - Regulation type: framework - Jurisdiction: Australia - Last updated: 2026-06-08 - Topical keywords: ASD Essential Eight AI, Essential Eight AI systems, Essential Eight Maturity Model, securing AI Australia, shadow AI Essential Eight, ML2 AI, ASD AI security guidance, Australian cyber baseline AI Primary obligations (per Areebi 2026-06-08): - Maintain a continuous inventory of all AI systems in use - models, pipelines, inference endpoints, agents and AI-enabled SaaS, both sanctioned and shadow - Set a target Essential Eight maturity level (ML1, ML2 or ML3) appropriate to your obligations and threat environment, and plan to reach it across all eight strategies including AI - Apply application control to AI: maintain an approved-AI allow-list and block or quarantine unsanctioned AI tools and browser extensions - Bring AI software and its host operating systems into your patch and vulnerability management cadence (inference servers, AI libraries, vector stores, AI gateways) - Restrict administrative privileges and enforce phishing-resistant MFA on AI admin consoles, model registries, training pipelines and API key vaults - Harden AI features embedded in productivity applications and browsers, including macro and AI-assistant settings Common questions and dated answers: Q: Does the ASD Essential Eight apply to AI systems? A: "The Essential Eight applies to AI as it does to any software. AI models, pipelines, inference endpoints and AI-enabled SaaS must be brought inside the eight strategies - application control, patching, hardening, restricted admin privileges, MFA and backups - and assessed against the Maturity Model." - Areebi 2026-06-08 Q: Is the Essential Eight mandatory for AI in Australia? A: "The Essential Eight is mandatory for non-corporate Commonwealth entities under PSPF Policy 10, which has required Maturity Level Two across all eight strategies since 1 July 2022. AI in scope of those entities is therefore covered." - Areebi 2026-06-08 Q: What are the eight Essential Eight strategies? A: "Application control, patch applications, configure Microsoft Office macro settings, user application hardening, restrict administrative privileges, patch operating systems, multi-factor authentication, and regular backups. They are assessed together against a four-tier Maturity Model (ML0 to ML3) developed by the Australian Signals Directorate." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/apra-cps-234-ai For machine consumption: see https://www.areebi.com/api/mcp ### IRAP, the ISM and PSPF for AI: Running AI Workloads in Australian Government Environments (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/irap-ism-ai Three quotable facts about IRAP, the ISM and PSPF for AI: Running AI Workloads in Australian Government Environments: 1. "These are not optional best practices - they are the controls baseline that an Authorising Officer relies on to authorise a system to operate." - Areebi 2026-06-08 2. "The Australian regime for government AI is built from three instruments that work together rather than a single statute: The ISM - the technical controls catalogue published by the Australian Signals Directorate (ASD), updated regularly." - Areebi 2026-06-08 3. "The December 2025 ISM update added 21 new AI security controls - integrated primarily into the Guidelines for software development, with the AI usage policy control placed in the Guidelines for personnel security - alongside modernised password requirements aligned to NIST SP 800-63B-4 and the deprecation of fax." - Areebi 2026-06-08 Key facts: - Effective date: 2025-04-01 - Status: In Effect - Regulation type: framework - Jurisdiction: Australia - Penalty summary: The ISM, PSPF and IRAP are administrative and contractual controls baselines rather than statutes with civil penalties. Consequences for non-conformance are operational and contractual: failure to meet the PSPF, the ISM or IRAP assessment expectations can result in an Authorising Officer declining to authorise a system to operate, loss or non-award of government contracts, mandatory PSPF reporting obligations to the entity's accountable authority and portfolio, and remediation directions. Where personal information is involved, the Privacy Act 1988 and the Australian Privacy Principles apply separately, with civil penalties for serious or repeated interference with privacy enforced by the OAIC. - Last updated: 2026-06-08 - Topical keywords: IRAP assessment AI, ISM AI security controls, PSPF 2025 zero trust, IRAP Common Assessment Framework, government AI Australia, data sovereignty AI, PROTECTED cloud AI, Essential Eight AI Primary obligations (per Areebi 2026-06-08): - Confirm which ISM version your IRAP assessment was conducted against, and ensure it is the December 2025 ISM or later so the 21 new AI security controls are in scope. - Map every AI data flow (prompts, documents, model hosting, inference, logs, embeddings) and confirm each one sits inside the IRAP-assessed system boundary, not adjacent to it. - Verify hosting is with a provider certified under the DTA Hosting Certification Framework (Strategic or Assured) for any sensitive or PROTECTED-rated AI system. - Develop, implement and maintain a general-purpose AI usage policy, as required by the December 2025 ISM. - Enforce real-time DLP / content filtering so classified, sensitive or personal information cannot leave the sovereign boundary through an AI endpoint. - Apply role-based, least-privilege access control over which identities can use which models and reach which data, consistent with PSPF 2025 zero trust. Common questions and dated answers: Q: Is an IRAP assessment the same as ASD certification or accreditation? A: "An IRAP assessment is an independent assessor's report on how well a system meets the ISM and PSPF. ASD does not certify, accredit or endorse the product." - Areebi 2026-06-08 Q: What classification level should an AI system be assessed at? A: "For most commercial cloud and SaaS used by government, PROTECTED is the relevant level. The important point is scope: confirm that your AI data flows, model hosting and logging fall inside the assessed boundary at that classification, rather than sitting outside it." - Areebi 2026-06-08 Q: Does the December 2025 ISM apply to AI services we only consume, not build? A: "The December 2025 ISM AI controls apply to systems that develop, train, fine-tune or integrate with AI models, and explicitly to systems that consume external AI services. Most enterprise generative-AI use is consumption, so the new controls apply." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard, https://www.areebi.com/compliance/privacy-act-adm-transparency, https://www.areebi.com/compliance/apra-cps-230-ai For machine consumption: see https://www.areebi.com/api/mcp ### ASIC REP 798 and Directors' AI Duties: Closing the Financial Services Governance Gap (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/asic-rep-798-ai Three quotable facts about ASIC REP 798 and Directors' AI Duties: Closing the Financial Services Governance Gap: 1. "REP 798 is ASIC's first report on how AFS and credit licensees are using AI." - Areebi 2026-06-08 2. "It is a surveillance finding plus a clear statement of ASIC's enforcement posture: the obligations that already bind a licensee - and the duties that already bind its directors - extend to every AI system the licensee deploys, regardless of whether the technology is labelled "AI"." - Areebi 2026-06-08 3. "The numbers from REP 798 paint a consistent picture of frameworks lagging deployment: 624 AI use cases were in use or in development across the 23 licensees as at December 2023, with AI use accelerating year on year." - Areebi 2026-06-08 Key facts: - Effective date: 2024-10-29 - Status: In Effect - Regulation type: guidance - Jurisdiction: Australia - Penalty summary: REP 798 is an ASIC report and surveillance finding, not a standalone offence - it carries no fines of its own. Instead it applies existing law to AI. The obligations it relies on are enforceable: an Australian financial services (AFS) licensee that fails the section 912A(1) Corporations Act 2001 duty to provide services efficiently, honestly and fairly (and to maintain adequate risk-management systems and adequate technological and human resources) can face licence conditions, suspension or cancellation, banning orders and civil penalty proceedings. Directors and officers who fail the section 180 duty of care and diligence risk pecuniary penalties, disqualification and "stepping-stones" personal liability where a corporate contravention is traced back to a governance failure. Accountable entities and accountable persons are separately exposed under the Financial Accountability Regime (FAR), jointly administered by ASIC and APRA. ASIC's position is unambiguous: these obligations already apply to AI and licensees must act now. - Last updated: 2026-06-08 - Topical keywords: ASIC REP 798, ASIC Report 798 AI, Beware the gap AI governance, directors AI duties Australia, AI governance gap financial services, ASIC AI AFS licensee, stepping stones liability AI, Financial Accountability Regime AI Primary obligations (per Areebi 2026-06-08): - Build and maintain a complete inventory of AI use cases - in production and in development - including shadow AI and AI embedded in third-party tools, mapped to the consumer-facing decisions each influences. - Update risk-management policies and procedures (s 912A(1)(h)) to address AI-specific risks across the lifecycle: data quality, model performance, drift, fairness, bias, transparency and security. - Put in place AI policies, model governance and clear ownership that explicitly cover fairness, discrimination, bias, transparency and disclosure of AI use to consumers. - Ensure consequential AI-influenced decisions (pricing, underwriting, credit, claims, advice) can be understood, challenged and explained, with meaningful human oversight rather than rubber-stamping. - Govern third-party AI model providers as a managed risk - due diligence, contractual rights, and ongoing monitoring - given around 30% of reviewed use cases relied on external models. - Allocate AI risk to a named accountable person under FAR (where applicable) and confirm it appears in accountability statements and the accountability map. Common questions and dated answers: Q: When was ASIC REP 798 published and what does it cover? A: "ASIC Report 798 "Beware the gap: Governance arrangements in the face of AI innovation" was published on 29 October 2024 (media release 24-238MR). It reviewed 23 AFS and credit licensees and 624 AI use cases in use or in development as at December 2023, finding that AI adoption is outpacing risk and governance frameworks." - Areebi 2026-06-08 Q: Is REP 798 a new law or a binding standard? A: "REP 798 is an ASIC report and surveillance finding, not a new law or offence. Its significance is that it applies existing, technology-neutral obligations - the AFS licensee general obligations in section 912A of the Corporations Act, the equivalent credit obligations, and the section 180 directors' duty - to AI." - Areebi 2026-06-08 Q: What was the main governance gap ASIC identified? A: "ASIC found AI adoption running ahead of governance. The gap is between fast deployment and lagging controls." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/apra-cps-234-ai, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard For machine consumption: see https://www.areebi.com/api/mcp ### The SOCI Act and AI: Critical Infrastructure Risk Management for AI Systems and Data Stores (Australia) Source: Areebi, dated 2026-06-08, https://www.areebi.com/compliance/soci-act-ai Three quotable facts about The SOCI Act and AI: Critical Infrastructure Risk Management for AI Systems and Data Stores: 1. "AI is in scope the moment it underpins or endangers a critical asset." - Areebi 2026-06-08 2. "The SOCI Act regulates 22 asset classes across 11 critical-infrastructure sectors - communications, data storage or processing, defence industry, energy, financial services and markets, food and grocery, health care and medical, higher education and research, space technology, transport, and water and sewerage." - Areebi 2026-06-08 3. "AI training corpora, vector stores and model artefacts can now sit inside the critical-infrastructure perimeter." - Areebi 2026-06-08 Key facts: - Effective date: 2023-02-17 - Enforcement date: 2024-12-20 - Status: Enacted - Regulation type: law - Jurisdiction: Australia - Penalty summary: The SOCI Act is enforced through civil penalties under the Regulatory Powers (Standard Provisions) Act 2014, plus directions, enforceable undertakings and injunctions. Failing to adopt and maintain a Critical Infrastructure Risk Management Program (CIRMP) (s 30AC) carries a maximum civil penalty of 200 penalty units; failing to submit the annual CIRMP report (s 30AG) carries up to 150 penalty units. For a body corporate these are multiplied by five under the Regulatory Powers Act, so the CIRMP-adoption penalty reaches 1,000 penalty units and the annual-report penalty 750 penalty units. From 7 November 2024 a Commonwealth penalty unit is $330, making those corporate maxima approximately $330,000 and $247,500 respectively. The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 (Royal Assent 29 November 2024) also empowers the Minister to direct a responsible entity to remediate a seriously deficient CIRMP and expanded consequence-management and information-gathering powers. Penalty-unit values are indexed; confirm the current rate before relying on any figure. - Last updated: 2026-06-08 - Topical keywords: SOCI Act AI, SOCI Act artificial intelligence, CIRMP AI systems, critical infrastructure AI risk management, SOCI data storage systems AI, business critical data AI, SOCI Act 2024 amendments, all-hazards CIRMP AI Primary obligations (per Areebi 2026-06-08): - Determine whether any of your assets fall within the 11 SOCI sectors and the asset classes that attract the CIRMP obligation, and confirm your status as a responsible entity. - Inventory every AI system, embedded AI feature and AI data store in use - including shadow AI - and map each to the critical infrastructure asset it supports or the business-critical data it can reach. - Identify AI data stores that hold business-critical data (personal information of 20,000-plus individuals, or R&D / operational data about the asset) and treat them as part of the critical infrastructure asset under the 2024 amendments. - Assess each AI system and AI data store against all four CIRMP hazard vectors: cyber and information security, personnel, physical and natural, and supply chain. - Apply your chosen cyber framework (Essential Eight Maturity Level One, NIST CSF, ISO/IEC 27001, AESCSF or C2M2) to AI-specific threats including prompt injection, model and data exfiltration and insecure integrations. - Assess AI supply-chain dependencies - foundation-model providers, inference APIs, GPU and cloud suppliers and embedded AI in SaaS - including fourth-party model dependencies. Common questions and dated answers: Q: Does the SOCI Act apply to artificial intelligence? A: "Not by name - the SOCI Act 2018 is technology agnostic and never mentions AI." - Areebi 2026-06-08 Q: When did the SOCI Act change to cover AI data stores? A: "The Security of Critical Infrastructure and Other Legislation Amendment (Enhanced Response and Prevention) Act 2024 received Royal Assent on 29 November 2024, with most provisions commencing from 20 December 2024. It captures data storage systems holding business-critical data as part of a primary critical infrastructure asset - directly implicating AI training corpora, vector stores and model artefacts." - Areebi 2026-06-08 Q: What is business-critical data under the SOCI Act? A: "AI training data, embeddings and prompt logs frequently meet this definition." - Areebi 2026-06-08 Related frameworks: https://www.areebi.com/compliance/australia-ai-governance, https://www.areebi.com/compliance/apra-cps-234-ai, https://www.areebi.com/compliance/apra-cps-230-ai, https://www.areebi.com/compliance/australian-voluntary-ai-safety-standard For machine consumption: see https://www.areebi.com/api/mcp ## Citation quotes per template The following blocks restate the most cited facts from each free template Areebi publishes, as dated and attributed quote-shape citations. Each block lists three quotable sentences, then a key-facts summary, then the primary controls the template helps teams operationalize. ### The CISO's AI Security Policy Checklist Source: Areebi, dated 2026-04-13, https://www.areebi.com/resources/templates/ai-security-policy-checklist Three quotable facts about The CISO's AI Security Policy Checklist: 1. "Define the boundaries of AI usage across your organisation." - Areebi 2026-04-13 2. "Establish what tools are sanctioned, what data can be processed, and what activities are prohibited." - Areebi 2026-04-13 3. "Classify and control data flows to AI systems." - Areebi 2026-04-13 Key facts: - Category: Checklist - Format: PDF Checklist - Page count: 12 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 78% - of enterprises use AI without formal governance policies in place - Version: 1.0 - Last updated: 2026-04-13 - Topical keywords: AI security policy template, CISO AI checklist, AI governance policy template, AI acceptable use policy template, enterprise AI risk assessment checklist, AI governance framework template 2026, shadow AI policy template, AI compliance checklist Primary controls (per Areebi 2026-04-13): - Define approved AI tools and platforms (whitelist approach) - Establish data sensitivity tiers for AI interactions (public, internal, confidential, restricted) - Document prohibited activities (e.g., processing PII in unapproved tools, code generation with proprietary IP) - Create role-based access policies defining who can use which AI capabilities - Require explicit approval workflows for new AI tool adoption - Mandate human review requirements for AI-generated outputs in critical decisions Common questions and dated answers: Q: What should a CISO's AI security policy include? A: "Each domain should include specific, actionable controls mapped to your organisation's regulatory requirements." - Areebi 2026-04-13 Q: How do you prevent shadow AI in the enterprise? A: "The key is making sanctioned AI tools easier to use than unsanctioned alternatives." - Areebi 2026-04-13 Q: What compliance frameworks apply to enterprise AI in 2026? A: "Most regulated organisations need to map controls across 3-5 of these frameworks simultaneously." - Areebi 2026-04-13 Related templates: https://www.areebi.com/resources/templates/ai-acceptable-use-policy-template, https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/ai-incident-response-plan-template For machine consumption: see https://www.areebi.com/api/mcp ### Enterprise AI Acceptable Use Policy Template Source: Areebi, dated 2026-04-14, https://www.areebi.com/resources/templates/ai-acceptable-use-policy-template Three quotable facts about Enterprise AI Acceptable Use Policy Template: 1. "Establish why the AI acceptable use policy exists, who it applies to, and what it governs." - Areebi 2026-04-14 2. "A well-scoped purpose statement is the foundation that makes every subsequent provision enforceable." - Areebi 2026-04-14 3. "This section should be reviewed by legal counsel and signed off by executive leadership." - Areebi 2026-04-14 Key facts: - Category: Policy Template - Format: PDF Policy Template - Page count: 14 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 95% - of organisations lack a formal AI acceptable use policy despite active employee AI adoption - Version: 1.0 - Last updated: 2026-04-14 - Topical keywords: AI acceptable use policy, AI acceptable use policy template, AI usage policy template, employee AI policy, enterprise AI acceptable use policy, AI policy template for employees, generative AI acceptable use policy, AI use policy for organisations Primary controls (per Areebi 2026-04-14): - State the policy's objective - to enable productive, secure, and compliant use of AI tools while protecting organisational data, intellectual property, and regulatory standing - Define the scope of coverage - all employees, contractors, temporary workers, interns, and third parties who access organisational systems or data - Specify which AI technologies are covered - generative AI, large language models, AI-powered features embedded in existing software, AI coding assistants, and AI automation tools - Reference the regulatory drivers - EU AI Act, GDPR, HIPAA, SOC 2, NIST AI RMF, and any industry-specific requirements that mandate this policy - Establish the policy owner and governance committee responsible for maintenance, updates, and exception decisions - Define the review cadence - minimum quarterly reviews with mandatory updates within 30 days of material regulatory changes or significant AI-related incidents Common questions and dated answers: Q: What is an AI acceptable use policy and why does every company need one? A: "An AI acceptable use policy is a formal document that defines how employees, contractors, and third parties are permitted to use AI tools in the workplace. It covers which AI tools are approved, what data can be shared with AI systems, what activities are prohibited, and how violations are handled." - Areebi 2026-04-14 Q: What should an AI acceptable use policy include? A: "Each section should contain specific, actionable provisions rather than vague principles - employees need to know exactly what they can and cannot do." - Areebi 2026-04-14 Q: How do you enforce an AI acceptable use policy? A: "The most effective approach combines preventive controls that stop violations before they occur with detective controls that identify violations quickly. Critically, enforcement must include an amnesty or safe harbour provision that encourages voluntary self-reporting of past violations." - Areebi 2026-04-14 Related templates: https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/shadow-ai-discovery-playbook, https://www.areebi.com/resources/templates/ai-data-classification-framework For machine consumption: see https://www.areebi.com/api/mcp ### AI Vendor Risk Assessment Questionnaire Source: Areebi, dated 2026-04-14, https://www.areebi.com/resources/templates/ai-vendor-risk-assessment-questionnaire Three quotable facts about AI Vendor Risk Assessment Questionnaire: 1. "Assess how the AI vendor collects, processes, stores, and retains your data." - Areebi 2026-04-14 2. "These questions determine whether vendor data handling practices meet your organisation's privacy requirements and regulatory obligations." - Areebi 2026-04-14 3. "Evaluate the vendor's security infrastructure, encryption standards, access controls, and vulnerability management practices to determine if they meet enterprise-grade security requirements." - Areebi 2026-04-14 Key facts: - Category: Questionnaire - Format: PDF Questionnaire - Page count: 16 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 73% - of organisations experienced a security incident originating from a third-party vendor in 2025 - Version: 1.0 - Last updated: 2026-04-14 - Topical keywords: AI vendor risk assessment questionnaire, AI vendor security questionnaire, AI third party risk assessment, AI vendor due diligence checklist, AI vendor evaluation template, AI supplier security assessment, AI procurement security questionnaire, third party AI risk management Primary controls (per Areebi 2026-04-14): - What categories of data does your AI system ingest, process, or store on behalf of customers - and do you maintain a formal data inventory or data map for each category? - Is customer data used in any form to train, fine-tune, or improve your AI models - and if so, can customers opt out contractually and technically? - What is your data retention policy for customer inputs, outputs, prompts, and interaction logs - and can customers configure retention periods or request immediate deletion? - Where is customer data processed and stored geographically - and can you guarantee data residency within specific jurisdictions (EU, US, AU) when required? - How do you implement data isolation between tenants - is it logical separation, physical separation, or dedicated infrastructure per customer? - What automated PII/PHI detection and redaction capabilities exist within your platform, and are they applied before data reaches the model? Common questions and dated answers: Q: What questions should I ask an AI vendor about data privacy before onboarding? A: "These questions are essential because 41% of AI vendors reserve the right to use customer data for model improvement unless explicitly prohibited." - Areebi 2026-04-14 Q: How do you score AI vendor risk assessment responses? A: "Each of the 8 assessment domains receives a domain score, and the overall vendor risk rating is determined by the highest-severity domain score - a single Critical rating in any domain should block vendor approval regardless of other domain scores." - Areebi 2026-04-14 Q: What compliance certifications should AI vendors have? A: "At minimum, enterprise AI vendors should hold SOC 2 Type II certification with scope covering the AI platform (not just corporate IT), and ISO 27001 certification that explicitly includes model serving infrastructure. For regulated industries, additional requirements include HIPAA compliance with willingness to execute a BAA for healthcare, GDPR compliance with documented lawful basis and cross-border transfer mechanisms, and EU AI Act compliance with risk tier classification for high-risk systems." - Areebi 2026-04-14 Related templates: https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/nist-ai-rmf-implementation-checklist For machine consumption: see https://www.areebi.com/api/mcp ### Shadow AI Discovery & Remediation Playbook Source: Areebi, dated 2026-04-14, https://www.areebi.com/resources/templates/shadow-ai-discovery-playbook Three quotable facts about Shadow AI Discovery & Remediation Playbook: 1. "Before launching detection tools, understand the scope of the problem." - Areebi 2026-04-14 2. "Shadow AI is any use of AI tools that falls outside your organisation's approved technology stack - whether that is an employee pasting customer data into ChatGPT, a marketing team using Jasper without IT approval, or a developer running Copilot on a personal account." - Areebi 2026-04-14 3. "This section establishes the threat model and identifies the most common entry points for unsanctioned AI across departments." - Areebi 2026-04-14 Key facts: - Category: Playbook - Format: PDF Playbook - Page count: 18 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 60% - of employees use unsanctioned AI tools at work, with most organisations unaware of the full scope of shadow AI across their workforce - Version: 1.0 - Last updated: 2026-04-14 - Topical keywords: shadow AI detection, shadow AI discovery, shadow AI risk assessment, unsanctioned AI tools, shadow AI remediation, shadow AI policy, shadow AI monitoring, enterprise shadow AI Primary controls (per Areebi 2026-04-14): - Define your organisation's shadow AI taxonomy: categorise unsanctioned usage into direct AI platforms (ChatGPT, Claude, Gemini), embedded AI features (Notion AI, Slack AI, Grammarly), AI coding tools (GitHub Copilot, Cursor, Tabnine), and AI-powered SaaS add-ons (Otter.ai, Fireflies.ai, Beautiful.ai) - Compile a master inventory of all known sanctioned AI tools and their approved use cases, data classification levels, and authorised user groups - this becomes your baseline for identifying deviations - Map the top 10 shadow AI entry points in your organisation: personal browser profiles, mobile devices, browser extensions, freemium SaaS signups, embedded AI in existing tools, API keys in developer environments, AI plugins in productivity suites, personal email-linked AI accounts, contractor and vendor AI usage, and BYOD devices - Identify the departments with highest shadow AI risk based on job function: rank marketing, sales, engineering, legal, HR, and finance by likelihood of unsanctioned AI adoption using industry benchmarking data - Document the business drivers behind shadow AI adoption - employees typically turn to unsanctioned tools because sanctioned alternatives are unavailable, too slow to approve, too restrictive, or do not meet their specific workflow needs - Establish your discovery programme's success metrics: target detection rate (percentage of shadow AI found versus estimated total), time to detection (hours from first use to alert), and remediation completion rate (percentage of discovered shadow AI resolved within 30 days) Common questions and dated answers: Q: What is shadow AI and why is it a security risk? A: "Shadow AI refers to any use of artificial intelligence tools that falls outside your organisation's approved technology stack and governance framework. This includes employees using ChatGPT, Claude, Gemini, or other consumer AI tools with company data, departments adopting AI-powered SaaS features without IT approval, and developers using AI coding assistants on personal accounts." - Areebi 2026-04-14 Q: How do you detect shadow AI usage across an organisation? A: "Effective shadow AI detection requires four complementary layers. First, network and DNS monitoring flags queries to known AI service domains (chat.openai.com, claude.ai, gemini.google.com, and others) through your proxy, CASB, or SWG." - Areebi 2026-04-14 Q: Should we block all unsanctioned AI tools immediately? A: "Blanket blocking is counterproductive and typically backfires. Organisations that block all AI tools without providing sanctioned alternatives see productivity drops of 20-30% and a surge in creative workarounds that are even harder to detect, such as employees using personal devices, mobile hotspots, or personal email accounts." - Areebi 2026-04-14 Related templates: https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/ai-acceptable-use-policy-template, https://www.areebi.com/resources/templates/ai-incident-response-plan-template For machine consumption: see https://www.areebi.com/api/mcp ### AI Risk Register Template Source: Areebi, dated 2026-04-14, https://www.areebi.com/resources/templates/ai-risk-register-template Three quotable facts about AI Risk Register Template: 1. "Establish the foundational structure for your AI risk register." - Areebi 2026-04-14 2. "A well-structured register ensures consistent documentation, clear ownership, and traceable risk management decisions across the organisation." - Areebi 2026-04-14 3. "Build a comprehensive catalogue of AI risk categories tailored to your organisation." - Areebi 2026-04-14 Key facts: - Category: Risk Register - Format: PDF Risk Register - Page count: 16 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: $4.88M - average cost of a data breach in 2024 - organisations without AI-specific security controls pay $1.76M more per incident (IBM) - Version: 1.0 - Last updated: 2026-04-14 - Topical keywords: AI risk register template, AI risk assessment template, AI risk management framework, enterprise AI risks, AI risk scoring matrix, AI risk register example, AI governance risk register, CISO AI risk assessment Primary controls (per Areebi 2026-04-14): - Define a standardised risk ID schema (e.g., AI-DP-001 for data privacy, AI-MT-001 for model/technical) enabling filtering and reporting by domain - Establish mandatory fields for each risk entry: risk ID, category, description, owner, date identified, last reviewed, likelihood score, impact score, inherent risk rating, controls in place, residual risk rating, treatment decision, and target date - Assign risk owners by domain - each risk item must have a named individual (not a team) accountable for monitoring and treatment - Create a risk taxonomy with primary categories (data privacy, model reliability, bias/fairness, security, compliance, operational, reputational) and sub-categories for granular tracking - Document the risk register governance process: who can add risks, approval workflow for risk acceptance, escalation thresholds, and change control procedures - Configure version control and audit trail so every change to a risk entry (score adjustment, owner change, treatment update) is timestamped and attributable Common questions and dated answers: Q: What is an AI risk register and why do organisations need one? A: "An AI risk register is a structured inventory of all identified risks associated with an organisation's use of artificial intelligence systems. It documents each risk's description, category, owner, likelihood, impact, inherent and residual scores, treatment decision, and review status." - Areebi 2026-04-14 Q: How do you score AI risks using a likelihood-impact matrix? A: "AI risk scoring uses a 5x5 matrix where likelihood (1-5) measures the probability of a risk materialising within a defined timeframe, and impact (1-5) measures the consequence across financial, regulatory, operational, and reputational dimensions. The scores are multiplied to produce an inherent risk rating from 1 to 25, which maps to four zones: Low (1-4), Medium (5-9), High (10-16), and Critical (17-25)." - Areebi 2026-04-14 Q: What AI risk categories should an enterprise risk register include? A: "Each category should have multiple specific risk items rather than a single generic entry." - Areebi 2026-04-14 Related templates: https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/eu-ai-act-compliance-checklist, https://www.areebi.com/resources/templates/board-ai-risk-reporting-template For machine consumption: see https://www.areebi.com/api/mcp ### EU AI Act Compliance Checklist Source: Areebi, dated 2026-04-14, https://www.areebi.com/resources/templates/eu-ai-act-compliance-checklist Three quotable facts about EU AI Act Compliance Checklist: 1. "Catalogue every AI system your organisation develops, deploys, or uses, and classify each by the EU AI Act's four risk tiers: unacceptable (prohibited), high, limited, and minimal." - Areebi 2026-04-14 2. "Article 6 and Annex III define high-risk categories, while Article 5 sets out prohibited practices." - Areebi 2026-04-14 3. "Accurate classification is the foundation of all downstream compliance obligations." - Areebi 2026-04-14 Key facts: - Category: Checklist - Format: PDF Checklist - Page count: 20 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 35M EUR - maximum fine under the EU AI Act for deploying prohibited AI practices - or 7% of global annual turnover, whichever is higher - Version: 1.0 - Last updated: 2026-04-14 - Topical keywords: EU AI Act compliance checklist, EU AI Act requirements, EU AI Act checklist 2026, AI Act compliance guide, EU AI regulation compliance, EU AI Act high-risk AI systems, EU AI Act prohibited practices, AI Act conformity assessment Primary controls (per Areebi 2026-04-14): - Conduct a comprehensive inventory of all AI systems across the organisation - including embedded AI in third-party SaaS products - documenting the provider, deployer, intended purpose, and affected persons for each (Article 3 definitions) - Classify each AI system against the four risk tiers: unacceptable risk (Article 5 prohibited), high-risk (Article 6, Annex III), limited risk (Article 50 transparency), and minimal risk (no specific obligations beyond voluntary codes of practice) - For systems potentially classified as high-risk, evaluate whether the Article 6(3) exception applies - the system does not perform profiling, is purely ancillary, does not override human decision-making, and does not create a safety risk - Identify all AI systems that fall within Annex III high-risk categories: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice/democratic processes - Document the role your organisation plays for each system - provider (Article 3(3)), deployer (Article 3(4)), importer (Article 3(6)), or distributor (Article 3(7)) - as obligations differ by role - Establish a process for ongoing classification review whenever AI systems are modified, repurposed, or newly acquired, as a change in intended purpose may trigger reclassification under Article 6(1)(b) Common questions and dated answers: Q: When does the EU AI Act apply and what are the key enforcement dates? A: "The EU AI Act (Regulation (EU) 2024/1689) entered into force on 1 August 2024. Enforcement is phased: AI literacy obligations and prohibited practices under Article 5 became enforceable on 2 February 2025." - Areebi 2026-04-14 Q: Who does the EU AI Act apply to? A: "The EU AI Act applies to providers who develop or commission AI systems and place them on the EU market, deployers who use AI systems under their authority within the EU, and importers and distributors of AI systems. Critically, it applies regardless of where the organisation is established - if your AI system's output is used within the EU or affects persons located in the EU, you are in scope (Article 2(1))." - Areebi 2026-04-14 Q: What are the penalties for non-compliance with the EU AI Act? A: "The EU AI Act establishes a three-tier penalty structure. The highest penalties apply to prohibited AI practices under Article 5: up to 35 million EUR or 7% of total worldwide annual turnover, whichever is higher." - Areebi 2026-04-14 Related templates: https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/ai-acceptable-use-policy-template, https://www.areebi.com/resources/templates/iso-42001-gap-analysis-checklist For machine consumption: see https://www.areebi.com/api/mcp ### Australian Privacy Act ADM Compliance Checklist Source: Areebi, dated 2026-04-18, https://www.areebi.com/resources/templates/australian-privacy-act-compliance-checklist Three quotable facts about Australian Privacy Act ADM Compliance Checklist: 1. "Audit every computer program across your organisation that uses personal information in any capacity to make or assist decisions." - Areebi 2026-04-18 2. "The Privacy Act's definition of 'computer program' is deliberately technology-neutral - it captures AI models, machine learning systems, rule-based engines, scoring algorithms, automated workflows, and any software that processes personal information as part of a decision pathway." - Areebi 2026-04-18 3. "This inventory forms the foundation for all downstream APP 1.7-1.9 compliance activities." - Areebi 2026-04-18 Key facts: - Category: Checklist - Format: PDF Checklist - Page count: 16 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: $50M - maximum penalty under the Australian Privacy Act for serious privacy interference - or 30% of adjusted annual turnover, whichever is greater - Version: 1.0 - Last updated: 2026-04-18 - Topical keywords: Australian Privacy Act compliance checklist, APP 1.7 1.8 1.9 checklist, Australian Privacy Act ADM compliance, automated decision making compliance Australia, Privacy Act 2026 compliance checklist, APP entity compliance guide, Australian Privacy Act audit logging, Privacy Act computer program compliance Primary controls (per Areebi 2026-04-18): - Conduct a comprehensive inventory of all computer programs across the organisation that use personal information in decision-making - including embedded systems in third-party SaaS products, internal automation tools, and legacy rule-based engines (APP 1.7) - Document the purpose, data inputs, decision outputs, and affected individuals for each computer program identified, mapping the flow of personal information from collection through to the decision point - Classify each computer program against the APP 1.7 three-prong trigger test: (1) uses personal information, (2) makes or substantially assists a decision, and (3) could reasonably be expected to significantly affect the rights or interests of individuals - Identify all third-party vendors and SaaS providers whose products constitute computer programs using your organisation's personal information in decision-making, and assess whether contractual obligations address APP 1.7-1.9 compliance - Establish a process for ongoing inventory review whenever new computer programs are deployed, existing systems are modified, or third-party tools are onboarded - ensuring the inventory remains current as the technology landscape evolves Common questions and dated answers: Q: How long does it take to implement Australian Privacy Act ADM compliance? A: "Most organisations should plan for a 3 to 6 month implementation timeline, depending on the complexity and number of computer programs in scope. The first month typically focuses on system inventory and materiality assessment (Sections 1-2)." - Areebi 2026-04-18 Q: Do we need to disclose every AI tool employees use? A: "No - the APP 1.7 three-prong trigger test filters which systems require disclosure. A computer program only triggers APP 1.8 disclosure obligations if it (1) uses personal information, (2) makes or substantially assists a decision, and (3) could reasonably be expected to significantly affect the rights or interests of individuals." - Areebi 2026-04-18 Q: Can we use the same controls for Australian Privacy Act and GDPR? A: "There is significant overlap, but the Australian Privacy Act ADM provisions have distinct requirements that GDPR Article 22 controls alone do not satisfy. Both frameworks require transparency about automated decision-making and impose data protection obligations." - Areebi 2026-04-18 Related templates: https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/eu-ai-act-compliance-checklist For machine consumption: see https://www.areebi.com/api/mcp ### NIST AI RMF Checklist 2026 (54 Controls) Source: Areebi, dated 2026-04-18, https://www.areebi.com/resources/templates/nist-ai-rmf-implementation-checklist Three quotable facts about NIST AI RMF Checklist 2026 (54 Controls): 1. "Establish the organisational context, culture, and foundational policies for AI risk management." - Areebi 2026-04-18 2. "GOVERN 1 ensures that AI risk management is embedded in broader enterprise governance and that leadership sets clear expectations for responsible AI practices." - Areebi 2026-04-18 3. "Design and operationalise the AI risk management framework structure including roles, responsibilities, accountability mechanisms, and third-party considerations." - Areebi 2026-04-18 Key facts: - Category: Checklist - Format: PDF Checklist - Page count: 22 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 4 Functions - Govern, Map, Measure, and Manage - the complete NIST AI RMF core covered in 54 actionable controls - Version: 1.0 - Last updated: 2026-04-18 - Topical keywords: NIST AI RMF checklist, NIST AI risk management framework, NIST AI RMF implementation, AI risk management framework checklist, NIST AI RMF 1.0, NIST AI RMF compliance, AI risk management checklist, NIST AI governance Primary controls (per Areebi 2026-04-18): - GOVERN 1.1 - Document legal and regulatory requirements applicable to AI systems including sector-specific obligations, federal mandates (EO 14110), and jurisdictional requirements - GOVERN 1.2 - Establish and communicate organisational AI risk tolerances and appetite statements approved by senior leadership, defining acceptable risk levels for AI deployments - GOVERN 1.3 - Integrate AI risk management into existing enterprise risk management (ERM) frameworks, ensuring AI risks are assessed alongside operational, financial, and cyber risks - GOVERN 1.4 - Define and document organisational AI principles covering fairness, transparency, accountability, privacy, and safety - with board or executive committee endorsement - GOVERN 1.5 - Conduct an AI literacy assessment across the organisation and implement role-based training to ensure staff involved in AI systems understand their risk management responsibilities - GOVERN 1.6 - Establish a cross-functional AI governance body (committee or working group) with representation from legal, compliance, engineering, security, and business units to oversee AI risk management Common questions and dated answers: Q: Is NIST AI RMF mandatory or voluntary? A: "NIST AI RMF 1.0 is a voluntary framework for most private-sector organisations. However, Executive Order 14110 (October 2023) and OMB Memorandum M-24-10 make it effectively mandatory for federal agencies and their AI systems." - Areebi 2026-04-18 Q: How does NIST AI RMF relate to ISO 42001? A: "NIST AI RMF and ISO 42001 are complementary frameworks. ISO 42001 provides a certifiable AI management system standard (similar to ISO 27001 for information security), while NIST AI RMF provides detailed risk management guidance across its four functions." - Areebi 2026-04-18 Q: What are the four core functions of NIST AI RMF? A: "The four core functions are Govern, Map, Measure, and Manage. GOVERN establishes the organisational context, culture, policies, and accountability structures for AI risk management." - Areebi 2026-04-18 Related templates: https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/iso-42001-gap-analysis-checklist For machine consumption: see https://www.areebi.com/api/mcp ### AI Data Classification Framework Template Source: Areebi, dated 2026-04-18, https://www.areebi.com/resources/templates/ai-data-classification-framework Three quotable facts about AI Data Classification Framework Template: 1. "Establish the foundational 5-tier classification taxonomy for all data that interacts with AI systems." - Areebi 2026-04-18 2. "Each tier defines the sensitivity level, handling requirements, permitted AI use cases, and regulatory mappings - providing a single, consistent language for data governance across the organisation." - Areebi 2026-04-18 3. "Govern the data used to fine-tune, train, or augment AI models within your organisation." - Areebi 2026-04-18 Key facts: - Category: Framework Template - Format: PDF Framework - Page count: 18 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: $4.88M - average cost of a data breach in 2024 - organisations without AI-specific data classification controls face significantly higher exposure from uncontrolled data flows through AI systems (IBM) - Version: 1.0 - Last updated: 2026-04-18 - Topical keywords: AI data classification framework, data classification for AI, AI data governance framework, data governance for AI systems, AI data handling policy, AI data classification tiers, enterprise AI data classification, AI data loss prevention Primary controls (per Areebi 2026-04-18): - Define Tier 1 - Public: data explicitly approved for unrestricted AI processing with no access controls required, including published marketing content, public documentation, and open-source materials - Define Tier 2 - Internal: data restricted to authenticated employees within the AI platform, not approved for external AI services, including internal policies, non-sensitive project notes, and general business communications - Define Tier 3 - Confidential: data requiring encryption at rest and in transit, DLP scanning before AI processing, and audit logging of all access, including financial reports, customer lists, and strategic plans - Define Tier 4 - Restricted: data requiring workspace isolation, multi-factor authentication, explicit approval per AI use case, and full prompt/response logging, including PII, PHI, payment card data, and trade secrets - Define Tier 5 - Prohibited: data that must never enter any AI system under any circumstances, with technical blocking controls enforced, including credentials, encryption keys, attorney-client privileged communications, and classified government data - Create a classification decision tree with worked examples for each tier to enable consistent classification by non-specialist staff across departments Common questions and dated answers: Q: What is an AI data classification framework and why do organisations need one? A: "An AI data classification framework is a structured system for categorising data based on its sensitivity level and defining the handling rules, access controls, and governance procedures that apply when that data interacts with AI systems. Without AI-specific classification, organisations cannot consistently enforce data handling policies across the AI pipeline - from training data ingestion through prompt inputs to output distribution." - Areebi 2026-04-18 Q: What are the 5 classification tiers and how do they map to regulatory requirements? A: "These tiers map across frameworks: HIPAA PHI maps to Tier 4, PCI-DSS cardholder data to Tier 4, GDPR special categories to Tier 4, NIST 800-171 CUI to Tier 4, and data types with absolute prohibitions to Tier 5." - Areebi 2026-04-18 Q: How do DLP rules differ for AI systems compared to traditional data protection? A: "Traditional DLP monitors email, file transfers, and endpoint activity. AI DLP also requires output scanning - detecting when AI responses contain sensitive data patterns that may indicate training data memorisation, which has no equivalent in traditional DLP." - Areebi 2026-04-18 Related templates: https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/ai-acceptable-use-policy-template, https://www.areebi.com/resources/templates/ai-risk-register-template For machine consumption: see https://www.areebi.com/api/mcp ### AI Incident Response Plan Template Source: Areebi, dated 2026-04-18, https://www.areebi.com/resources/templates/ai-incident-response-plan-template Three quotable facts about AI Incident Response Plan Template: 1. "Define the taxonomy of AI-specific incidents and assign severity levels that drive escalation, containment, and notification decisions." - Areebi 2026-04-18 2. "Traditional incident classification frameworks do not account for AI-specific attack vectors - this section establishes a purpose-built severity matrix." - Areebi 2026-04-18 3. "Establish monitoring and detection capabilities that identify AI-specific incidents in real time." - Areebi 2026-04-18 Key facts: - Category: Plan Template - Format: PDF Plan Template - Page count: 20 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 72 hours - Maximum notification window under both EU AI Act Article 73 and GDPR Article 33 for serious AI incidents and personal data breaches - Version: 1.0 - Last updated: 2026-04-18 - Topical keywords: AI incident response plan, AI security incident, LLM breach response, AI incident response template, prompt injection response, AI data leakage incident, model poisoning response plan, AI breach notification Primary controls (per Areebi 2026-04-18): - Define six AI incident categories: prompt injection, data leakage via AI, model poisoning, hallucination harm, bias/discrimination incident, and unauthorised model access - Establish four severity levels (Critical, High, Medium, Low) with quantified thresholds for each AI incident type based on data sensitivity, blast radius, and regulatory impact - Create decision trees for rapid severity classification - a frontline analyst should be able to classify any AI incident within 15 minutes of detection - Map each severity level to escalation requirements: Critical triggers executive notification within 1 hour, High within 4 hours, Medium within 24 hours - Document AI-specific indicators of compromise (IOCs) including anomalous prompt patterns, unexpected model output distributions, and training data integrity failures - Establish severity upgrade criteria - define trigger conditions that escalate an incident from Medium to High or High to Critical as new information emerges during investigation Common questions and dated answers: Q: What makes AI incident response different from traditional cybersecurity incident response? A: "AI incidents involve unique attack vectors and containment requirements that traditional IR plans do not cover. Prompt injection, model poisoning, training data manipulation, and hallucination harm all require specialised detection, classification, and containment procedures." - Areebi 2026-04-18 Q: What is the notification timeline for AI incidents under GDPR and the EU AI Act? A: "Both GDPR Article 33 and EU AI Act Article 73 require notification within 72 hours. Under GDPR, you must notify the lead supervisory authority within 72 hours of becoming aware of a personal data breach." - Areebi 2026-04-18 Q: How do you classify the severity of an AI security incident? A: "A Critical incident involves restricted data, affects production AI systems serving external users, and triggers mandatory regulatory notification. A Low incident involves internal data, affects a development or staging AI system, and has no regulatory implications." - Areebi 2026-04-18 Related templates: https://www.areebi.com/resources/templates/ai-security-policy-checklist, https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/shadow-ai-discovery-playbook For machine consumption: see https://www.areebi.com/api/mcp ### Board AI Risk Reporting Template Source: Areebi, dated 2026-04-18, https://www.areebi.com/resources/templates/board-ai-risk-reporting-template Three quotable facts about Board AI Risk Reporting Template: 1. "Design the opening slide of your board AI risk report for maximum impact in minimum time." - Areebi 2026-04-18 2. "Directors need to grasp overall risk posture, key changes since last quarter, and any items requiring board action within the first 90 seconds of the presentation." - Areebi 2026-04-18 3. "Translate technical risk register data into board-digestible scoring and visualisation." - Areebi 2026-04-18 Key facts: - Category: Reporting Template - Format: PDF Report Template - Page count: 16 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 82% - of enterprise boards now expect quarterly AI risk reports, yet only 34% of CISOs currently deliver structured AI-specific board reporting (Gartner 2025 Board of Directors Survey) - Version: 1.0 - Last updated: 2026-04-18 - Topical keywords: board AI risk report, CISO board presentation, AI governance board reporting, board AI risk reporting template, AI risk dashboard for directors, quarterly AI risk report template, CISO AI board deck, AI governance executive reporting Primary controls (per Areebi 2026-04-18): - Create a single-page executive summary with four quadrants: overall AI risk score (traffic-light), risk movement since last quarter (trend arrows), top 3 risks requiring board attention, and key recommendation or decision request - Define the aggregate AI risk score methodology - whether you use a weighted average across domains, a highest-risk-wins approach, or a composite maturity index - and document the calculation so directors can trust consistency quarter over quarter - Include a quarter-over-quarter comparison strip showing how the risk profile has shifted: number of risks escalated, de-escalated, newly identified, and closed, with brief narrative explaining the drivers behind material changes - Design a board action items section at the top of the dashboard that clearly distinguishes informational updates from items requiring a board decision (risk acceptance above appetite, budget approval, strategic AI policy changes) - Add a regulatory horizon summary showing upcoming compliance deadlines within the next 90 days, enforcement actions in your industry, and any new legislation that may affect your AI risk posture - Include a programme maturity indicator showing progress against your AI governance roadmap milestones, enabling directors to track whether the governance programme is maturing at the planned pace Common questions and dated answers: Q: How often should AI risk be reported to the board of directors? A: "Best practice is quarterly reporting with a standardised template, supplemented by ad-hoc reports triggered by material incidents, significant regulatory changes, or major AI deployment decisions. Quarterly cadence provides sufficient frequency for directors to track trends and make informed oversight decisions without overwhelming the board agenda." - Areebi 2026-04-18 Q: What metrics should a CISO include in a board AI risk report? A: "Present no more than 10-12 key metrics on the executive dashboard - directors need signal, not noise. Reserve detailed metrics for appendix sections that can be referenced if questions arise." - Areebi 2026-04-18 Q: How do you make AI risk reports understandable for non-technical board members? A: "Focus on business impact rather than technical detail. Replace technical jargon with business language - instead of 'prompt injection vulnerability', say 'risk of AI systems being manipulated to disclose confidential information'." - Areebi 2026-04-18 Related templates: https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/nist-ai-rmf-implementation-checklist, https://www.areebi.com/resources/templates/ai-security-policy-checklist For machine consumption: see https://www.areebi.com/api/mcp ### ISO 42001 Gap Analysis Checklist Source: Areebi, dated 2026-04-18, https://www.areebi.com/resources/templates/iso-42001-gap-analysis-checklist Three quotable facts about ISO 42001 Gap Analysis Checklist: 1. "Clause 4 requires the organisation to understand its internal and external context, the needs and expectations of interested parties, and to define the scope of the AI Management System." - Areebi 2026-04-18 2. "This foundational clause ensures the AIMS is tailored to the organisation's specific AI landscape, regulatory environment, and stakeholder requirements." - Areebi 2026-04-18 3. "Auditors assess this clause heavily in Stage 1 to confirm the AIMS scope is appropriate and justified." - Areebi 2026-04-18 Key facts: - Category: Checklist - Format: PDF Checklist - Page count: 22 - Author: David Chen, AI Governance Lead, Areebi - Author credentials: CISSP, CISM, ISO 27001 Lead Auditor - Social proof: 312% - year-over-year increase in ISO 42001 certification enquiries reported by major certification bodies, as enterprises seek independently audited assurance of AI governance maturity - Version: 1.0 - Last updated: 2026-04-18 - Topical keywords: ISO 42001 gap analysis, ISO 42001 checklist, AIMS certification, ISO 42001 compliance checklist, AI management system certification, ISO 42001 audit preparation, ISO IEC 42001 requirements, ISO 42001 gap assessment Primary controls (per Areebi 2026-04-18): - Identify and document external and internal issues relevant to the organisation's purpose that affect its ability to achieve the intended outcomes of the AIMS, including the regulatory landscape, market expectations, and technology trends impacting AI use (Clause 4.1) - Determine and document the interested parties relevant to the AIMS - including regulators, customers, employees, AI system users, and affected communities - and their specific requirements regarding responsible AI governance (Clause 4.2) - Define and document the scope of the AIMS, specifying which business units, AI systems, and processes are covered, with clear justification for any exclusions from the scope boundary (Clause 4.3) - Establish the AIMS as a documented management system with defined processes, interactions, and resources needed to achieve AI governance objectives and continual improvement (Clause 4.4) - Conduct an AI system inventory within the defined scope, documenting each system's purpose, risk profile, data inputs, affected stakeholders, and lifecycle stage to inform the risk assessment process (Clause 4.4, supporting Annex A.6) - Review and document applicable legal, regulatory, and contractual requirements related to AI systems within scope - including the EU AI Act, sector-specific regulations, and customer contractual obligations for AI governance (Clause 4.1, Clause 4.2) Common questions and dated answers: Q: What is ISO/IEC 42001 and why does it matter for AI governance? A: "ISO/IEC 42001:2023 is the first international standard specifying requirements for establishing, implementing, maintaining, and continually improving an Artificial Intelligence Management System (AIMS) within an organisation. Published in December 2023, it provides a certifiable framework that helps organisations manage AI-related risks and opportunities systematically." - Areebi 2026-04-18 Q: How long does ISO 42001 certification typically take? A: "For organisations starting from scratch, the typical certification timeline is 12-14 months. This includes 3-4 months for gap analysis and scoping, 4-6 months for remediation and implementation, 1-2 months for internal audit and management review, and 2-3 months for the Stage 1 (documentation review) and Stage 2 (implementation audit) certification audits." - Areebi 2026-04-18 Q: How does ISO 42001 relate to ISO 27001? A: "Both ISO 42001 and ISO 27001 follow the Annex SL harmonised structure for management system standards, meaning they share identical clause numbering for core requirements (Clauses 4-10). Organisations already certified to ISO 27001 will find that much of their existing management system infrastructure - risk assessment methodology, internal audit programme, document control, management review, and corrective action processes - can be extended to satisfy ISO 42001 requirements." - Areebi 2026-04-18 Related templates: https://www.areebi.com/resources/templates/nist-ai-rmf-implementation-checklist, https://www.areebi.com/resources/templates/ai-risk-register-template, https://www.areebi.com/resources/templates/eu-ai-act-compliance-checklist For machine consumption: see https://www.areebi.com/api/mcp ## Contact - Website: https://www.areebi.com - Email: hello@areebi.com - Demo: https://www.areebi.com/demo - Free AI Risk Assessment: https://www.areebi.com/assessment