Why Nexovern
Support Request a demo

Home  /  Resources

The incident library and the regulatory map.

The fastest way to understand app + OS correlated security is through the failures that demanded it and the frameworks that now require it. Start here.

Failures that defined the category

July 2025CI/CD agent

Replit production deletion

An AI coding agent deleted a production database during an active code freeze, records for 1,206 executives and 1,196+ companies, then produced misleading status messages and initially claimed rollback was impossible.

Why it matters: policy stated, nothing enforced. The case for system-level gates.

CVE-2025-32711 · CVSS 9.3Enterprise copilot

EchoLeak zero-click exfiltration

The first real-world zero-click prompt-injection exfiltration from Microsoft 365 Copilot, data exfiltrated with no user action and little conventional forensic trace. CyberArk's research on MCP tool-poisoning extends the same attack surface.

Why it matters: agent attacks bypass tooling built for human-driven threats. The case for session telemetry tied to the agent.

July 2025Algorithmic trading

SEBI vs. Jane Street

₹4,843.57 crore (~US$565–580M) impounded over alleged algorithmic index manipulation on Bank Nifty/Nifty expiry days, the marquee signal that regulators expect trigger-level forensic reconstruction of algorithmic behavior.

Why it matters: forensic reconstruction is now the regulatory baseline for autonomous systems.

2024 · BCCRT 149Customer-facing AI

Moffatt v. Air Canada

A tribunal held the airline liable for its chatbot's misstatements, finding it makes no difference whether information comes from a static page or a chatbot. The institution answers for what its AI tells customers.

Why it matters: AI output is corporate speech. The case for evidence behind every customer-facing answer.

The frameworks, decoded for operators

RBI FREE-AI (India)

7 sutras, 6 pillars, 26 recommendations. Inventories, incident reporting, audit processes, board-approved policies, annual-report disclosures, and accountability regardless of autonomy.

Issued Aug 13, 2025 · Read more →

DPDP Act + Rules (India)

72-hour breach reporting, SDF audits, DPIAs, and fairness assessments, phased rollout with core obligations binding May 2027, penalties to ₹250 crore.

Rules notified Nov 14, 2025 · Read more →

SEBI algo framework (India)

Algo IDs, kill switches, full execution logging, broker-as-principal accountability, fully mandatory since April 1, 2026, with deployer liability proposed for AI/ML in markets.

Circular Feb 4, 2025 · Read more →

IRDAI (India)

Explainability for claims and pricing decisions, India-only record storage, CISO independence, quarterly risk-committee cadence, CERT-In and DPDP alignment.

2025 regulations & guidelines · Read more →

SR 11-7 & the 2026 MRM revision (US)

Inventory completeness remains the top examination finding. The April 2026 interagency revision excludes generative/agentic AI from MRM scope, leaving it under general governance expectations, with an agentic-AI RFI signaled.

OCC · Fed · FDIC · Read more →

CFPB / ECOA (US)

Specific adverse-action reasons are mandatory, no advanced-technology exception. Complex credit models face proxy-discrimination scrutiny.

Winter Supervisory Highlights, Jan 2025 · Read more →

State AI laws (US)

Colorado, Texas TRAIGA, California SB 53, Illinois, Connecticut. Preemption unsettled, build to the strictest standard.

CO · TX · CA · IL · CT · Read more →

EU AI Act (Europe)

The world's first comprehensive AI law. Risk-based classification, conformity assessments, GPAI obligations, and penalties up to €35M or 7% of global turnover.

Regulation (EU) 2024/1689 · Read more →

DORA (Europe)

Digital Operational Resilience Act for financial services. ICT risk management, incident reporting within 4 hours, resilience testing, and third-party vendor oversight.

Applicable since Jan 17, 2025 · Read more →

GDPR & AI (Europe)

Automated decision-making under Article 22, right to explanation, DPIAs for AI, and penalties up to €20M or 4% of global turnover. The data protection baseline for every AI system touching EU residents.

Regulation (EU) 2016/679 · Read more →

ISO/IEC 42001

The certifiable AI management-system standard, and the common language between your governance program and your auditors. Nexovern evidence maps to its operational clauses.

AI management systems · Read more →

View all frameworks → Want the deep-dive briefing for your jurisdiction and role? We prepare persona-specific regulatory briefings for demo participants.

Get the briefing for your desk.

Tell us your role, industry, and jurisdiction, we'll bring the relevant regulatory mapping to a demo.