The regulatory landscape for AI is shifting rapidly. Compsilon delivers curated intelligence on what's changing, what matters, and what to act on.
Who may deploy AI, within what limits, and who answers for what it does.
What the system can get wrong, how badly, how likely, and what reduces it.
Which obligations apply to those systems, and the evidence that proves you met them.
Doing this well does not require AI tooling. Automating it is a separate decision — and the subject of AI GRC engineering.
Not shadow tooling — approved tooling. Assistants and copilots are sanctioned in weeks rather than budget cycles, and once a model is on the approved list every team inside the perimeter can reach it. Capability now arrives faster than the controls built around it.
Evidence packs and questionnaire responses that consumed days now take hours, freeing the hours that actually require judgement.
Screenshot collection, spreadsheet reconciliation, and copying the same control answer between four frameworks stop being a person’s job.
The same team covers more frameworks, and controls get tested continuously rather than sampled once a quarter.
Enterprise customers ask how AI is governed before they sign. A clear answer shortens the sale; a vague one stalls it in procurement.
Faster output is only an advantage if it is right. Every hour saved should be reinvested in the part no model can own — deciding whether the evidence supports the conclusion, and signing your name to it.
Risk-tiered obligations for providers and deployers. Article 50 transparency duties applied from August 2026; high-risk obligations were deferred to December 2027 for standalone systems and August 2028 for AI embedded in regulated products.
The AI management system standard, structured like ISO 27001 and increasingly named in enterprise procurement before any regulator asks.
Govern, Map, Measure, Manage. No legal force, but written into US federal and enterprise contracts, so it arrives as a customer requirement rather than a regulatory one.
In effect since January 2026, joining the EU AI Act as a comprehensive regime with confirmed extraterritorial reach. Fines sit under a grace period, except where serious harm is involved.
Signed May 2026, repealing and replacing the Colorado AI Act with a narrower transparency and disclosure regime. The retreat matters: the direction of travel is not uniformly stricter.
The UK has passed no AI-specific statute and none was announced in the 2026 King’s Speech. The ICO, Ofcom and the FCA apply existing law to AI within their remits, with change arriving as amendments rather than a single Act.
Compsilon was founded by Darshan Krishnappa, a governance, risk and compliance practitioner with fifteen years across risk, compliance and audit, to help organisations make one specific move: out of traditional GRC and into AI GRC, before the ground shifts underneath them. The engineering is already well underway. Everything from risk triage to continuous compliance is being automated, much of it handed to autonomous agents. The conviction behind Compsilon is that automation alone does not get you there. Remove the human from the loop and you have not built assurance — you have built a faster route to an unverified answer. So AI governance has to be actively sought, not assumed. It keeps a named human accountable at every consequential step, and it constrains the agent to what the evidence actually says: nothing invented, nothing fabricated, nothing asserted beyond the source.
Compsilon newsletters focus heavily on how this shift is happening across governance, risk and compliance programmes. The content is curated to guide you through the next steps of the transformation — traditional GRC to AI-based continuous compliance, while meeting customer demand across SOC 1, SOC 2, PCI DSS, ISO 42001, DORA and NIS2 simultaneously.
Or are you curious to know how it can be done irrespective of company size, from start-ups to large organisations? Start-ups are mostly the ones heavily dependent on and seeking benefits from AI transformation. Or are you in the middle of the shift or transformation within your own function? Reach out to Darshan Krishnappa at hellocompsilon@gmail.com for an open collaboration and assistance.
Weekly intelligence delivered every Monday. Free.
Welcome, and thank you for showing interest in this newsletter.