← Back
Insights
(c) MMXXVI
EM

Field Note

Date
May 15, 2026
Format
Field Note

← All Insights

Field Note

The Compliance Surface of Production AI

Most enterprise AI failure is not model failure. It is compliance surface — the gap between what a model can do, what regulation permits, and what an organisation can prove.

The four control points

Every production system needs:

  1. Input lineage. Every prompt input, traced to a known data source with a known classification.
  2. Output attribution. Every generation, linked back to the retrieval or reasoning step that produced it.
  3. Policy interception. A non-negotiable layer that can block, redact, or escalate before a response leaves the system.
  4. Audit replay. The ability to reconstruct any interaction six months later, exactly as it ran.

Why teams skip this

Because the demo works without it. The compliance surface only becomes visible when something fails — by which point it is the regulator, not the engineering team, who is asking the questions.

More Insights

Subscribe

RSS feed →