Guides for regulated AI teams
Practical, examiner-aware guides on AI governance, audit readiness, and vendor evaluation, written by the team that builds and operates PrivateStack.
AI Audit Trail Requirements: A Checklist for Regulated Teams
The 10 audit-trail controls examiners expect for AI use, plus how to evaluate a vendor against each one: per-request attribution, model identity, retention, export, role-based access, and auditor-ready evidence.
Last reviewed: 2026-07-15Read the guideZero Data Retention vs No Training: What Each One Actually Covers
Zero retention and no training are separate promises on separate axes. A map of the eight planes a single AI request can leave content on, who controls each clock, and the question to ask a vendor about each.
Last reviewed: 2026-08-25Read the guideHow Can AI Be Zero Retention and Still Have Audit Logs?
Zero retention and audit logging answer different questions, so they coexist by design. The three defensible logging modes — full-content, redacted field-level, and metadata-plus-hash — with a decision tree and where each fails: books-and-records reconstruction, audit controls, data minimisation, and incident forensics.
Last reviewed: 2026-08-28Read the guideAI Audit Log Schema Template: 21 Fields, Annotated (JSON + CSV)
A vendor-neutral AI audit log schema you can copy: 21 fields across attribution, model identity, a declared content plane, and lifecycle — each with type, required/optional status, an example value, and the control or rule family it supports. Rendered in full on the page, with JSON and CSV blocks.
Last reviewed: 2026-08-28Read the guideAI Prompt Log Retention Requirements: A Crosswalk by Record Type
There is no universal retention period for AI prompt logs — the period follows the record type. A crosswalk of seven record types against four dispositions (retain content, retain metadata, legal hold, minimise), every period cited to the instrument's own text, plus a worksheet for building your own schedule.
Last reviewed: 2026-08-28Read the guideFINRA Generative AI Recordkeeping Requirements: What Is Actually a Record
FINRA has no AI-specific recordkeeping rule — and not every AI interaction is automatically a required record. The obligation stack (Rule 4511, 17 CFR 240.17a-3/17a-4, Regulatory Notice 24-09), five tests that draw the record/non-record line, the translation into a deployable log design, and a nine-item examiner checklist phrased as evidence to produce.
Last reviewed: 2026-08-28Read the guideRegulation S-P AI Vendor Due Diligence: A Questionnaire for Smaller Advisers
The 2024 amendments are in force for advisers of every size: an incident response program, 30-day individual notification, and service-provider oversight with a 72-hour breach-notification term. What the amended 17 CFR 248.30 requires, why AI vendors are squarely inside it, and a ten-question due-diligence addendum written for firms without a dedicated technology function.
Last reviewed: 2026-08-28Read the guideSR 11-7 and Generative AI: What the 2026 Supersession Actually Changed
SR 11-7 is no longer in effect — SR letter 26-2 (April 17, 2026) supersedes it, and the revised joint guidance expressly excludes generative and agentic AI from scope while an interagency request for information is pending. What changed, verified from the regulators' own publications, and a control map translating the guidance's enduring disciplines to generative-AI deployments.
Last reviewed: 2026-08-28Read the guideAI Vendor Security Questionnaire: 21 Questions, Scored (XLSX + Web Tool)
A vendor security questionnaire built for AI: 21 questions across seven domains — data flow and subprocessors, retention and deletion, logging and export, isolation and deployment boundary, model and training use, incident response, access control. Per question: what a good answer looks like, required evidence, the red flag, a compensating control, and the contract clause. Score it in the browser or download the XLSX.
Last reviewed: 2026-08-28Read the guideBYOC AI Platform on AWS: What "Runs in Your Account" Actually Means
BYOC becomes true or false in six verifiable places: the IAM role a vendor assumes, the network path and egress inventory, whose KMS key policies govern content stores, how vendor updates reach your account, break-glass versus standing support access, and the written shared-responsibility split. A component-by-component control-plane/data-plane table, the six dimensions with red flags, and a responsibility matrix.
Last reviewed: 2026-08-28Read the guidePrivate AI vs Self-Hosted AI vs BYOC: Five Architectures, Scored Honestly
Closed API, governed private SaaS, managed BYOC on AWS, self-hosted open source, and on-premises/air-gapped — scored on control, time to deploy, evidence, staffing, egress, and cost predictability, with the reasoning visible in every cell. Plus the section vendors skip: when each architecture, including the ones we sell, is the wrong answer.
Last reviewed: 2026-08-28Read the guideCan Law Firms Use ChatGPT with Confidential Client Information?
Yes-with-conditions, and the tier matters more than the brand — but the real answer requires separating two duties most pages conflate: the ethics duty of confidentiality (Model Rule 1.6, the subject of ABA Formal Opinion 512) and evidentiary privilege (waivable by disclosure to third parties, and something no vendor architecture can guarantee). What Opinion 512 actually requires, a consumer/enterprise/private deployment comparison, and a ten-item review checklist for firms evaluating any AI tool.
Last reviewed: 2026-08-28Read the guideAI Vendor Checklist for HIPAA-Regulated Teams: 14 Checks Across the Full PHI Path
Fourteen checks for evaluating any AI vendor that will touch protected health information, built around tracing the full PHI path — prompts and uploads, inference, storage, embeddings and derived data, audit logs, and deletion at termination. Business-associate status first (including no-view services), satellite agreements down the subprocessor chain, the embeddings question competing checklists skip, and the 60-day breach-notification clocks of 45 CFR 164.404 and 164.410 — every item cited to the instrument's own text.
Last reviewed: 2026-08-28Read the guideCMMC and AI Tools Handling CUI: When Prompts, Outputs, and Logs Enter Scope
CUI in a prompt makes the prompt CUI; output derived from CUI carries it forward; embeddings built from CUI should be treated as inside the CUI boundary absent a documented determination; and a log that captures content becomes a CUI store. The scoping consequence under 32 CFR 170.19 — CUI Assets, Security Protection Assets, and the rest of the table-3 categories — plus the cloud condition of DFARS 252.204-7012 and a ten-step scoping worksheet for organizations seeking assessment.
Last reviewed: 2026-08-28Read the guideAI Acceptable-Use Policy Templates: Four Verticals, Four Different Policies
Four distinct AI acceptable-use policy templates — law firm, registered adviser / broker-dealer, healthcare organizations with HIPAA-regulated workloads, and defense contractors handling CUI — each with ten numbered clauses written as adoptable policy language and annotated with the obligation behind it: ABA Formal Opinion 512's consent gate, 17 CFR 240.17a-4(f)'s designated record store, 45 CFR 164.502(e)(1)(i)'s agreement-before-PHI condition, and 32 CFR 170.19's CUI Asset scoping. Plus the governance steps that turn a template into a program, and what the templates deliberately do not do.
Last reviewed: 2026-08-28Read the guide