AI GRC Newsletters AI Governance Risk Program Enablement Discovery Tool Great Insights on GRC Programs AI GRC Newsletters AI Governance Risk Program Enablement Discovery Tool Great Insights on GRC Programs
AI GRC Intelligence

Navigate AI Governance, Risk & Compliance

The regulatory landscape for AI is shifting rapidly. Compsilon delivers curated intelligence on what's changing, what matters, and what to act on.

Get the Newsletter Learn More

Foundation
What is AI GRC?
Extending governance, risk and compliance to the AI systems an organisation builds, buys and runs. The disciplines are not new. What they now have to cover is.
G

Governance

Who may deploy AI, within what limits, and who answers for what it does.

R

Risk

What the system can get wrong, how badly, how likely, and what reduces it.

C

Compliance

Which obligations apply to those systems, and the evidence that proves you met them.

How AI GRC operates

Doing this well does not require AI tooling. Automating it is a separate decision — and the subject of AI GRC engineering.

How AI GRC operatesThe AI GRC layer applies four disciplines with AI in the workflow below, chases six departments for evidence, and sends four flows upward across a waterline into results that reach leadership, with an oversight gap on the right. CISO · SLT · ELT Clean audit report Green dashboard Certificate renewed Deals closed WHAT LEADERSHIP SEES AND EXPECTS WHAT IT TAKES TO PRODUCE IT Legal contracts DPAs Finance audit controls Dev & Eng config, QA SDLC SOC incident response SIEM · EDR/MDR/ADR Sales customer questionnaires HR policy training The GRC battle chasing owners for evidence and answers AI GRC — the backend operations layer The same disciplines, now covering AI systems and increasingly run with AI Governance Policies Enforcement Oversight Direction Risk management NIST RMF NIST AI RMF ISMS Tooling AI risk intake Compliance Assurance Audits Common controls framework Gap analysis AI IN THE WORKFLOW Models in production Vendor-embedded AI Risk triage AI questionnaires Cross-mapping & gap analysis POTENTIAL OVERSIGHT GAP

The Stakes
Why AI GRC Matters Most Now
The tooling arrived before the governance did — and it is already in everyone's hands.
Access

AI Is Already Inside the Organisation

Not shadow tooling — approved tooling. Assistants and copilots are sanctioned in weeks rather than budget cycles, and once a model is on the approved list every team inside the perimeter can reach it. Capability now arrives faster than the controls built around it.

Speed

Time Returned to the Function

Evidence packs and questionnaire responses that consumed days now take hours, freeing the hours that actually require judgement.

Effort

Manual Work Eliminated

Screenshot collection, spreadsheet reconciliation, and copying the same control answer between four frameworks stop being a person’s job.

Coverage

Optimisation Without Headcount

The same team covers more frameworks, and controls get tested continuously rather than sampled once a quarter.

Proof

Assurance Buyers Can Verify

Enterprise customers ask how AI is governed before they sign. A clear answer shortens the sale; a vague one stalls it in procurement.

Judgement

Automation Raises the Bar, and the Stakes

Faster output is only an advantage if it is right. Every hour saved should be reinvested in the part no model can own — deciding whether the evidence supports the conclusion, and signing your name to it.


Frameworks
Standards and Regulations You Will Be Held To
Regulators are folding AI into regimes organisations already answer to. Here is what compliance actually asks of you.
EU

EU AI Act

BINDING · EXTRATERRITORIAL

Risk-tiered obligations for providers and deployers. Article 50 transparency duties applied from August 2026; high-risk obligations were deferred to December 2027 for standalone systems and August 2028 for AI embedded in regulated products.

What it takes: a maintained AI inventory with risk classification, technical documentation, logging, human oversight by design, post-market monitoring and AI literacy across staff.
ISO

ISO/IEC 42001

CERTIFIABLE · PROCUREMENT-DRIVEN

The AI management system standard, structured like ISO 27001 and increasingly named in enterprise procurement before any regulator asks.

What it takes: scope and AI policy, allocated roles, AI risk and impact assessments, Annex A control selection with justification, internal audit and management review — then certification by an accredited body.
NIST

AI Risk Management Framework

VOLUNTARY · CONTRACTUALLY ENFORCED

Govern, Map, Measure, Manage. No legal force, but written into US federal and enterprise contracts, so it arrives as a customer requirement rather than a regulatory one.

What it takes: a documented governance structure, context mapping per system, measurable evaluation of performance and bias, and evidence that findings change decisions.
KOREA

AI Basic Act

BINDING · IN FORCE

In effect since January 2026, joining the EU AI Act as a comprehensive regime with confirmed extraterritorial reach. Fines sit under a grace period, except where serious harm is involved.

What it takes: notify users of high-impact or generative AI, label AI-generated content, run lifecycle risk management for high-impact systems, and appoint a domestic representative above set thresholds.
US-CO

Colorado ADMT Act

BINDING · FROM JANUARY 2027

Signed May 2026, repealing and replacing the Colorado AI Act with a narrower transparency and disclosure regime. The retreat matters: the direction of travel is not uniformly stricter.

What it takes: know where automated decisions materially affect people, give clear notice, run a structured human review of adverse outcomes, and retain records for at least three years.
UK

No AI Act — Regulators Instead

SECTORAL · INCREMENTAL

The UK has passed no AI-specific statute and none was announced in the 2026 King’s Speech. The ICO, Ofcom and the FCA apply existing law to AI within their remits, with change arriving as amendments rather than a single Act.

What it takes: treat AI as in scope for the frameworks you already answer to — data protection, consumer duty, operational resilience — rather than waiting for an AI rulebook that may not come.

Coverage
Topics We Cover
Full-spectrum AI GRC intelligence every week.
Regulatory Developments
AI Risk Management
Governance Frameworks
AI Auditing & Assurance
Data Governance
AI Safety Research
Ethical AI Design
Enforcement & Litigation
Sector Deep-Dives
AI Threat Intelligence
Vendor Risk
AI Agents

About Compsilon

Why This Exists

Compsilon was founded by Darshan Krishnappa, a governance, risk and compliance practitioner with fifteen years across risk, compliance and audit, to help organisations make one specific move: out of traditional GRC and into AI GRC, before the ground shifts underneath them. The engineering is already well underway. Everything from risk triage to continuous compliance is being automated, much of it handed to autonomous agents. The conviction behind Compsilon is that automation alone does not get you there. Remove the human from the loop and you have not built assurance — you have built a faster route to an unverified answer. So AI governance has to be actively sought, not assumed. It keeps a named human accountable at every consequential step, and it constrains the agent to what the evidence actually says: nothing invented, nothing fabricated, nothing asserted beyond the source.

Compsilon newsletters focus heavily on how this shift is happening across governance, risk and compliance programmes. The content is curated to guide you through the next steps of the transformation — traditional GRC to AI-based continuous compliance, while meeting customer demand across SOC 1, SOC 2, PCI DSS, ISO 42001, DORA and NIS2 simultaneously.

Are you also part of any such transformation?

Or are you curious to know how it can be done irrespective of company size, from start-ups to large organisations? Start-ups are mostly the ones heavily dependent on and seeking benefits from AI transformation. Or are you in the middle of the shift or transformation within your own function? Reach out to Darshan Krishnappa at hellocompsilon@gmail.com for an open collaboration and assistance.

Darshan Krishnappa
Darshan Krishnappa
Senior GRC TPM/Manager | AI GRC | GRC Engineering |
CGRCP | AWS Cloud Practitioner | ISO 27001 LA | SOC1/SOC2 | ITGC | PCI DSS
View Profile
Subscribe here to get the latest newsletters.

Stay Ahead of AI Regulation

Weekly intelligence delivered every Monday. Free.

Welcome, and thank you for showing interest in this newsletter.