Request Demo

Regulation

16 posts filed under Regulation — all posts →

Mapping a Reg E Dispute to a Reasoning Graph
Mapping a Reg E Dispute to a Reasoning Graph

The best-kept secret of graph design in regulated domains: the decomposition is already written. Regulation E’s error-resolution framework is a set of elements, each with its own evidence and its own clock — which is to say, it is a reasoning graph waiting to be transcribed. A worked example, element by element.

Read
The Transcript Is Not Evidence: What CoT Faithfulness Research Means for Examiners
The Transcript Is Not Evidence: What CoT Faithfulness Research Means for Examiners

Two research groups asked whether a model’s written reasoning actually explains its answer. Turpin et al. planted biases in prompts and watched answers shift while explanations never mentioned the bias; Lanham et al. cut and corrupted reasoning text and watched answers stay put. The lesson for anyone reviewing an AI decision file: a chain-of-thought transcript is testimony, not evidence.

Read
What to Ask the Vendor: An Examiner's Question Bank
What to Ask the Vendor: An Examiner's Question Bank

Every vendor demo is fluent — fluency is the one property the technology guarantees. These twelve questions ignore the demo and probe the architecture: can the reasoning be inspected, re-run, bounded, and challenged? Each comes with what a good answer looks like, and what a bad one sounds like.

Read
What Makes a SAR Narrative Defensible
What Makes a SAR Narrative Defensible

AI-drafted SAR narratives are proliferating, and most of them optimize for exactly the wrong thing: fluency. A defensible narrative is not well-written — it is well-grounded: every factual claim traceable to the case file, the suspicion articulated as reasoning, nothing material omitted. Examiners are starting to ask how the narrative was produced. Institutions need an answer.

Read
The Examiner Is the User
The Examiner Is the User

Every AI system in a regulated workflow has two users: the operator who requests the output today, and the examiner who reviews it later — with subpoena-grade patience and no goodwill. Almost all AI product design serves the first user. The systems that reach core workflows will be the ones designed for the second.

Read
The 10/45/90-Day Problem: Reg E Error Resolution at Understaffed Scale
The 10/45/90-Day Problem: Reg E Error Resolution at Understaffed Scale

Reg E’s error-resolution deadlines are absolute: 10 business days to investigate, 45 or 90 calendar days with provisional credit, no tolling for backlogs or turnover. Dispute volume has exploded with P2P fraud while investigation teams haven’t grown. The failure mode isn’t missing deadlines — it’s making them with investigations that can’t survive an exam.

Read
The Agencies Carved Gen-AI Out of SR 26-2. So Who Governs It?
The Agencies Carved Gen-AI Out of SR 26-2. So Who Governs It?

Buried in the April guidance is the sentence almost nobody is writing about: generative and agentic AI models are out of scope. That is not an exemption. It leaves bank LLM deployments with no tailored framework, full supervisory exposure, and a question every examiner can still ask: show me how this system reached this decision.

Read
The EU’s Omnibus Delay: High-Risk AI Obligations Move to December 2027
The EU’s Omnibus Delay: High-Risk AI Obligations Move to December 2027

The Digital Omnibus on AI cleared its final vote: the high-risk obligations that were due August 2 now arrive December 2, 2027. The content of the obligations survives; the deadline moved for standards readiness. The verified facts, what changed and what didn’t, and the implication that actually matters: the runway got longer, and undocumented decisions still don’t backfill.

Read
Colorado’s Reset: What SB 26-189 Actually Asks of AI Deployers
Colorado’s Reset: What SB 26-189 Actually Asks of AI Deployers

Colorado repealed its landmark AI Act before it ever took effect and replaced it with something narrower: SB 26-189, built around automated decision-making technology, disclosure, and a consumer right to meaningful human review, effective January 1, 2027. The mandate list shrank. The question that survives — review of what, exactly? — is the one worth preparing for.

Read
Active vs. Passive Governance: The Distinction That Decides What AI Can Do
Active vs. Passive Governance: The Distinction That Decides What AI Can Do

GRC platforms govern policy, not outcomes. They can tell you an AI system exists, that it was approved, and what it produced — after it produced it. If you want to actively manage what AI models output, governance has to operate inside the reasoning process, not around it. That is the line between passive and active governance.

Read
SR 26-2 Supersedes SR 11-7 — and the Arcus SR 26-2 Model Risk Suite Is Available Today
SR 26-2 Supersedes SR 11-7 — and the Arcus SR 26-2 Model Risk Suite Is Available Today

On April 17, 2026, the banking agencies superseded SR 11-7 with SR 26-2, moving model risk management from a prescriptive checklist to a risk-based posture. We absorbed the change by re-pointing a citation pack, not rebuilding an engine — and the SR 26-2 Model Risk Management Graph Suite is now available as an enterprise offering.

Read
The Colorado AI Act: What It Required — and What Replaced It
The Colorado AI Act: What It Required — and What Replaced It

Updated: Colorado repealed SB 24-205 before it ever took effect and replaced it with the narrower SB 26-189, effective January 1, 2027. The original analysis stands on the record, with what the replacement dropped and what survives — including the question that outlives both statutes: can you document how the system reasoned?

Read
What Model Validation Looks Like When the Model Is an LLM
What Model Validation Looks Like When the Model Is an LLM

Traditional validation assumes you can read a model’s mechanics, test it on holdout data, and stress-test it against known scenarios. LLMs break all three assumptions. What validation teams actually need isn’t holdout accuracy—it’s reasoning traces.

Read
EU AI Act Articles 9–15: A Technical Reading for Engineering Teams
EU AI Act Articles 9–15: A Technical Reading for Engineering Teams

Most EU AI Act coverage is written by lawyers for lawyers. But the Act’s requirements for high-risk AI systems aren’t just policy obligations—they’re architectural ones. Engineering teams need a different reading of Articles 9 through 15.

Read
What SR 11-7 Means for AI-Driven Decision Making
What SR 11-7 Means for AI-Driven Decision Making

SR 11-7, the Federal Reserve's model risk management guidance, was written for statistical models with inspectable coefficients. LLMs break every assumption the framework rests on. When an examiner asks how the model arrived at a specific decision, the answer "we trust the output" is not an answer.

Read
The Difference Between Logging and Governance in AI Systems
The Difference Between Logging and Governance in AI Systems

There is a difference between knowing what your AI did and knowing how it got there. Most governance platforms answer the first question. They log the model, the timestamp, the guardrail result. The second question requires a reasoning trace.

Read