Writing
Control mappings, disclosure measurement, and evidence tooling for systems that call large language models. Mostly primary-source: the regulation, the criteria document, and code you can run.
Compliance and evidence
Grimwatch
5 September 2026
A Type II opinion covers a period; every compliance tool shows you today.
Grimwatch assembles point-in-time snapshots into the period record — the blind
window before the first scan, the exposure a gap between scans cannot exclude,
and the resolution the whole report is accurate to.
AI Controls for SOC 2 Type II
5 September 2026
Thirty-two controls mapped to the 2017 Trust Services Criteria, each with a
test procedure written for a period rather than a moment. There is no AI
criterion in the TSC, so somebody has to write the mapping, and your auditor
expects it to be you.
You cannot filter your way to compliance
5 September 2026
What the EU AI Act actually asks of an LLM deployment, and why the control most
vendors sell you is the one least able to deliver it.
Your observability tool cannot be your evidence
5 September 2026
Honeycomb said it themselves in 2023: observability and compliance workloads are
orthogonal. Sampling is the product and retention is 60 days. What actually
finishing the other tier takes, and the sampler-ordering trap that quietly makes
an archive worthless.
The strongest test in your AI controls checklist doesn’t run
5 September 2026
Reconcile logged request counts against provider invoices, month by month. It is
the best test in every AI control mapping, including mine. AWS billing data
contains no request counts — here is what to reconcile instead.
Disclosure and extraction
Settability decides what your adverse action notice leaks
5 September 2026
Whether explanation mandates and model-extraction risk really conflict. Five
measurements say the cost depends on whether the requester can set the
quantities an explanation names — and that Regulation B had already drawn the
line.
What does an explanation actually leak?
5 September 2026
The measurements in full, including the two that came out negative and the one
I later had to retract.
The CFPB’s own form fails the disclosure rule
5 September 2026
The disclosure rule applied to the adverse action notice the CFPB publishes,
row by row.
Systems
Five incidents your taxonomy has no row for
5 September 2026
Five classes of supply-chain incident involving automated decision systems that
conventional taxonomies have no row for. The claim is not that they are common
— it is that we would not know if they were.
Code: github.com/Grace — warden (disclosure
contracts and linter), paladin (instruction-file integrity), injection-study
(the measurement harness behind the filtering numbers).
Corrections welcome, and several of these have needed them.