← Mandate Registry · 7 mandate layers · data_poisoning
tech_data · EU AI Act Article 10 · NIST AI RMF · ISO 42001
Data Poisoning / Supply Chain
Poisoned training data — prove data hash at ingestion or model compromise indefensible
—NYDFS AI guidance + Local Law 144 enforcement
Regulatory exposure — commonly overlooked:
Enterprise fine-tunes on poisoned dataset — enterprise owns breach, data vendor owns ToS. · Local Law 144 requires annual bias audit — Velaru receipts are continuous audit, not annual snapshot.
SolarWinds parallel
AI supply chain compromise — receipt at data ingestion is detection point.
ISO 42001
AI management system requires data integrity controls — receipt satisfies control.
Incident response
CISA reporting — poisoned model decision receipt proves attack vector.
[New York] Financial capital
NYDFS regulates insurers AND banks — same receipt primitive for both books.
[New York] Hiring audit law
NYC AEDT law is template for other cities — receipt architecture scales municipally.
[Text / Chat] Modality hook
Baseline — all frameworks apply to text decisions.
7 mandate layers (live)
Regulatory Clock
Countdown to operative regulatory deadline — NAIC adoption, GSE mandate, EU transposition.
Open →
Domain Classifier
Industry-specific SAFE/CRISIS/VIOLATION with regulatory framework mapping.
Open →
Exhibit / Filing Pack
Regulator-ready external validation — NAIC Exhibit D, Fannie QC, EU FRIA, FDA Part 11.
Open →
Mandate Registry
Enroll deployers/insureds under vertical-specific governance mandate.
Open →
Bind / Action Gate
ALLOW/BLOCK before consequential action — bind policy, sell loan, deactivate worker.
Open →
Compliance Certificate
Deployer-facing downloadable cert — forward to counsel, auditor, regulator.
Open →
Actuarial / Risk Feed
Anonymized asymmetry signals for pricing, reserving, reinsurance correlation.
Open →