<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
  <title>Grace — Distributed systems, observability, and ML infrastructure</title>
  <subtitle>Control mappings, disclosure measurement, and evidence tooling for systems that call large language models. Primary-source research on SOC 2, the EU AI Act, and Regulation B.</subtitle>
  <link href="https://grace.github.io/writing/feed.xml" rel="self"/>
  <link href="https://grace.github.io/writing/"/>
  <updated>2026-09-08T01:39:57+00:00</updated>
  <id>https://grace.github.io/writing/</id>
  <author><name>Grace</name><email>grace@gracefulco.de</email></author>
  
  
  <entry>
    <title>You cannot filter your way to compliance</title>
    <link href="https://grace.github.io/writing/structural-controls/"/>
    <id>https://grace.github.io/writing/structural-controls/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>What the EU AI Act actually asks of an LLM deployment, and why the control most vendors sell you is the one least able to deliver it.</summary>
  </entry>
  
  <entry>
    <title>Settability decides what your adverse action notice leaks</title>
    <link href="https://grace.github.io/writing/settability-and-observability/"/>
    <id>https://grace.github.io/writing/settability-and-observability/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Five measurements on whether explanation mandates and model-extraction risk actually conflict. The cost turns out to depend on whether the requester can set the quantities an explanation names.</summary>
  </entry>
  
  <entry>
    <title>Your observability tool cannot be your evidence</title>
    <link href="https://grace.github.io/writing/observability-is-not-evidence/"/>
    <id>https://grace.github.io/writing/observability-is-not-evidence/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Honeycomb said it themselves in 2023: observability and compliance workloads are orthogonal. Sampling is the product; retention is 60 days. Three years on, the answer for the other workload is still &apos;build a data lake&apos; — here is what actually finishing that takes.</summary>
  </entry>
  
  <entry>
    <title>The strongest test in your AI controls checklist doesn&apos;t run</title>
    <link href="https://grace.github.io/writing/invoice-reconciliation/"/>
    <id>https://grace.github.io/writing/invoice-reconciliation/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Reconcile logged request counts against provider invoices, month by month. It is the best test in every AI control mapping, including the one I wrote. AWS billing data contains no request counts.</summary>
  </entry>
  
  <entry>
    <title>Grimwatch</title>
    <link href="https://grace.github.io/writing/grimwatch/"/>
    <id>https://grace.github.io/writing/grimwatch/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>A SOC 2 Type II opinion covers a period. Every compliance tool shows you today. Grimwatch assembles point-in-time snapshots into the period record an auditor actually asks for — including the gaps between scans.</summary>
  </entry>
  
  <entry>
    <title>The CFPB&apos;s own form fails the disclosure rule</title>
    <link href="https://grace.github.io/writing/form-c1-audit/"/>
    <id>https://grace.github.io/writing/form-c1-audit/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Applying a security disclosure rule to the adverse action notice the CFPB actually publishes. What leaks, what does not, and where Regulation B already drew the line.</summary>
  </entry>
  
  <entry>
    <title>What does an explanation actually leak?</title>
    <link href="https://grace.github.io/writing/explanation-disclosure/"/>
    <id>https://grace.github.io/writing/explanation-disclosure/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Five reproducible measurements on the assumed conflict between explanation mandates and model extraction. Two negative results, and one positive result narrower than the question.</summary>
  </entry>
  
  <entry>
    <title>Five incidents your taxonomy has no row for</title>
    <link href="https://grace.github.io/writing/decision-layer-incidents/"/>
    <id>https://grace.github.io/writing/decision-layer-incidents/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Five classes of supply-chain incident involving automated decision systems that conventional incident taxonomies have no row for, and the instrumentation that would make them visible.</summary>
  </entry>
  
  <entry>
    <title>AI Controls for SOC 2 Type II</title>
    <link href="https://grace.github.io/writing/ai-controls-soc2/"/>
    <id>https://grace.github.io/writing/ai-controls-soc2/</id>
    <updated>2026-09-05T00:00:00+00:00</updated>
    <summary>Thirty-two controls for systems that call large language models, mapped to the 2017 Trust Services Criteria, each with a test procedure written for a period rather than a moment.</summary>
  </entry>
  
</feed>
