<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Ansvar AI Blog</title>
    <link>https://ansvar.eu/blog</link>
    <atom:link href="https://ansvar.eu/blog/feed.xml" rel="self" type="application/rss+xml" />
    <description>Field notes on auditable AI for legal, compliance, and security work.</description>
    <language>en</language>
    <lastBuildDate>Thu, 09 Jul 2026 09:00:00 GMT</lastBuildDate>
    <item>
      <title>Stop letting threat models die in a wiki: make STRIDE output double as compliance evidence</title>
      <link>https://ansvar.eu/blog/threat-model-to-compliance-evidence</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/threat-model-to-compliance-evidence</guid>
      <pubDate>Thu, 09 Jul 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>A threat model and a NIS2/DORA/ISO gap analysis describe the same system. Map each threat to the measure it satisfies, with article-level citations.</description>
      <category>threat-modeling</category>
      <category>nis2</category>
      <category>dora</category>
      <category>compliance</category>
      <category>mcp</category>
    </item>
    <item>
      <title>EU AI Act: your obligations depend on your role, not your tech stack</title>
      <link>https://ansvar.eu/blog/eu-ai-act-obligations-by-role</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/eu-ai-act-obligations-by-role</guid>
      <pubDate>Mon, 06 Jul 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>Provider, deployer, importer, distributor, GPAI provider — each EU AI Act role carries its own obligations. The role test, article references, and live dates.</description>
      <category>eu-ai-act</category>
      <category>compliance</category>
      <category>ai-governance</category>
      <category>regulatory-intelligence</category>
      <category>mcp</category>
    </item>
    <item>
      <title>Why RAG over a document dump fails regulated work</title>
      <link>https://ansvar.eu/blog/cited-answers-vs-rag-for-regulated-work</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/cited-answers-vs-rag-for-regulated-work</guid>
      <pubDate>Thu, 02 Jul 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>RAG citations are decorative — no provenance contract links chunk to answer. Regulated work needs typed corpus tools, deterministic validation, and refusal.</description>
      <category>rag</category>
      <category>citations</category>
      <category>compliance</category>
      <category>mcp</category>
      <category>legal-tech</category>
    </item>
    <item>
      <title>Swedish law as an MCP server: how SFS statutes become a queryable corpus</title>
      <link>https://ansvar.eu/blog/swedish-law-as-an-mcp-server</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/swedish-law-as-an-mcp-server</guid>
      <pubDate>Mon, 29 Jun 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>6,041 Swedish statutes from Riksdagen, segmented to section level and served as an MCP — query by SFS number, chapter, and paragraf, every result cited.</description>
      <category>swedish-law</category>
      <category>mcp</category>
      <category>legal-data</category>
      <category>citations</category>
      <category>compliance</category>
    </item>
    <item>
      <title>What you can and can&apos;t automate in a DPIA</title>
      <link>https://ansvar.eu/blog/automating-the-dpia-evidence-trail</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/automating-the-dpia-evidence-trail</guid>
      <pubDate>Thu, 25 Jun 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>A GDPR Article 35 DPIA has an automatable core and a judgment core. AI assembles the cited evidence trail; the DPO signs necessity and proportionality.</description>
      <category>gdpr</category>
      <category>dpia</category>
      <category>privacy</category>
      <category>compliance-automation</category>
      <category>mcp</category>
    </item>
    <item>
      <title>Working through DORA Article 28: third-party obligations, the contract checklist, and what the auditor asks for</title>
      <link>https://ansvar.eu/blog/dora-article-28-third-party-mapping</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/dora-article-28-third-party-mapping</guid>
      <pubDate>Mon, 22 Jun 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>DORA Article 28 sets the third-party obligations; the contract clauses live in Article 30. Each subsection mapped to ISO 27001 and SCF controls.</description>
      <category>dora</category>
      <category>third-party-risk</category>
      <category>iso-27001</category>
      <category>compliance</category>
      <category>mcp</category>
    </item>
    <item>
      <title>NIS2 vs ISO 27001: a clause-by-clause working mapping (and where ISO stops short)</title>
      <link>https://ansvar.eu/blog/nis2-vs-iso-27001-clause-mapping</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/nis2-vs-iso-27001-clause-mapping</guid>
      <pubDate>Thu, 18 Jun 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>Every NIS2 Article 21(2) measure mapped to ISO 27001:2022 Annex A — and the three real gaps: reporting clock, management liability, supply chain depth.</description>
      <category>nis2</category>
      <category>iso-27001</category>
      <category>compliance</category>
      <category>regulatory-intelligence</category>
      <category>mcp</category>
    </item>
    <item>
      <title>What an MCP gateway is, and why compliance work needs one</title>
      <link>https://ansvar.eu/blog/what-is-an-mcp-gateway-for-compliance</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/what-is-an-mcp-gateway-for-compliance</guid>
      <pubDate>Mon, 15 Jun 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>Chat and RAG hallucinate regulatory citations. An MCP gateway adds routing, fan-out, tier auth, and deterministic citation validation — and when you need one.</description>
      <category>mcp</category>
      <category>compliance</category>
      <category>mcp-gateway</category>
      <category>citations</category>
      <category>regulatory-intelligence</category>
    </item>
    <item>
      <title>Effective risk: turning the LLM-era CVE firehose into a triage queue you can actually work</title>
      <link>https://ansvar.eu/blog/effective-risk-cve-noise-llm-era</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/effective-risk-cve-noise-llm-era</guid>
      <pubDate>Mon, 25 May 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>AI tooling files more CVEs than any analyst can read. Effective-risk rescoring deterministically scores CVE × asset × controls, citing every score change.</description>
      <category>vulnerability-management</category>
      <category>cvss</category>
      <category>risk-scoring</category>
      <category>mcp</category>
      <category>ai-security</category>
    </item>
    <item>
      <title>How we threat-model AI systems: STRIDE meets MCP</title>
      <link>https://ansvar.eu/blog/how-we-threat-model-ai-with-mcp</link>
      <guid isPermaLink="true">https://ansvar.eu/blog/how-we-threat-model-ai-with-mcp</guid>
      <pubDate>Wed, 20 May 2026 09:00:00 GMT</pubDate>
      <author>team@ansvar.eu (Jeffrey von Rotz)</author>
      <description>STRIDE was built for 1999 monoliths. How we adapted it for agentic systems and shipped it as a workflow your own AI client runs through the Ansvar gateway.</description>
      <category>threat-modeling</category>
      <category>ai-security</category>
      <category>mcp</category>
      <category>linddun</category>
      <category>tara</category>
    </item>
  </channel>
</rss>
