Home / Resources
The incident library and the regulatory map.
The fastest way to understand app + OS correlated security is through the failures that demanded it and the frameworks that now require it. Start here.
Failures that defined the category
Replit production deletion
An AI coding agent deleted a production database during an active code freeze, records for 1,206 executives and 1,196+ companies, then produced misleading status messages and initially claimed rollback was impossible.
Why it matters: policy stated, nothing enforced. The case for system-level gates.
EchoLeak zero-click exfiltration
The first real-world zero-click prompt-injection exfiltration from Microsoft 365 Copilot, data exfiltrated with no user action and little conventional forensic trace. CyberArk's research on MCP tool-poisoning extends the same attack surface.
Why it matters: agent attacks bypass tooling built for human-driven threats. The case for session telemetry tied to the agent.
SEBI vs. Jane Street
₹4,843.57 crore (~US$565–580M) impounded over alleged algorithmic index manipulation on Bank Nifty/Nifty expiry days, the marquee signal that regulators expect trigger-level forensic reconstruction of algorithmic behavior.
Why it matters: forensic reconstruction is now the regulatory baseline for autonomous systems.
Moffatt v. Air Canada
A tribunal held the airline liable for its chatbot's misstatements, finding it makes no difference whether information comes from a static page or a chatbot. The institution answers for what its AI tells customers.
Why it matters: AI output is corporate speech. The case for evidence behind every customer-facing answer.
The frameworks, decoded for operators
RBI FREE-AI (India)
7 sutras, 6 pillars, 26 recommendations. Inventories, incident reporting, audit processes, board-approved policies, annual-report disclosures, and accountability regardless of autonomy.
Issued Aug 13, 2025 · Read more →
DPDP Act + Rules (India)
72-hour breach reporting, SDF audits, DPIAs, and fairness assessments, phased rollout with core obligations binding May 2027, penalties to ₹250 crore.
Rules notified Nov 14, 2025 · Read more →
SEBI algo framework (India)
Algo IDs, kill switches, full execution logging, broker-as-principal accountability, fully mandatory since April 1, 2026, with deployer liability proposed for AI/ML in markets.
Circular Feb 4, 2025 · Read more →
IRDAI (India)
Explainability for claims and pricing decisions, India-only record storage, CISO independence, quarterly risk-committee cadence, CERT-In and DPDP alignment.
2025 regulations & guidelines · Read more →
SR 11-7 & the 2026 MRM revision (US)
Inventory completeness remains the top examination finding. The April 2026 interagency revision excludes generative/agentic AI from MRM scope, leaving it under general governance expectations, with an agentic-AI RFI signaled.
OCC · Fed · FDIC · Read more →
CFPB / ECOA (US)
Specific adverse-action reasons are mandatory, no advanced-technology exception. Complex credit models face proxy-discrimination scrutiny.
Winter Supervisory Highlights, Jan 2025 · Read more →
State AI laws (US)
Colorado, Texas TRAIGA, California SB 53, Illinois, Connecticut. Preemption unsettled, build to the strictest standard.
CO · TX · CA · IL · CT · Read more →
EU AI Act (Europe)
The world's first comprehensive AI law. Risk-based classification, conformity assessments, GPAI obligations, and penalties up to €35M or 7% of global turnover.
Regulation (EU) 2024/1689 · Read more →
DORA (Europe)
Digital Operational Resilience Act for financial services. ICT risk management, incident reporting within 4 hours, resilience testing, and third-party vendor oversight.
Applicable since Jan 17, 2025 · Read more →
GDPR & AI (Europe)
Automated decision-making under Article 22, right to explanation, DPIAs for AI, and penalties up to €20M or 4% of global turnover. The data protection baseline for every AI system touching EU residents.
Regulation (EU) 2016/679 · Read more →
ISO/IEC 42001
The certifiable AI management-system standard, and the common language between your governance program and your auditors. Nexovern evidence maps to its operational clauses.
AI management systems · Read more →
View all frameworks → Want the deep-dive briefing for your jurisdiction and role? We prepare persona-specific regulatory briefings for demo participants.
Get the briefing for your desk.
Tell us your role, industry, and jurisdiction, we'll bring the relevant regulatory mapping to a demo.
