Open-source steward readiness before the CRA reporting date
A public-source review can help an open-source organisation assess CRA steward status, conditional reporting duties, and the evidence it still needs.
A public-source review can help an open-source organisation assess CRA steward status, conditional reporting duties, and the evidence it still needs.
Ansvar Gateway is listed in the CSA STAR Registry — a Level 1 CAIQ v4.0.3 self-assessment with all 261 answers published, including the No answers. How to read it.
The Model Context Protocol gets its largest revision on 28 July 2026 — stateless core, an extensions framework, tighter auth. Nothing breaks that day. Here is what changes and what we did ahead of it.
Every AI tool answers questions about your documents. Almost none can prove, months later, what the cited paragraph said. Why hash-anchored paragraph citations matter for counsel, DPOs, GRC teams, and procurement.
A citation that survives audit is a provision URI that resolves, text that matches, and a refusal when neither holds. Inside the cite-resolve-compare pipeline.
Claude Desktop, VS Code Copilot, Copilot Studio, and Cursor compared for compliance teams: OAuth MCP support, enterprise controls, data-training policies.
A threat model and a NIS2/DORA/ISO gap analysis describe the same system. Map each threat to the measure it satisfies, with article-level citations.
Provider, deployer, importer, distributor, GPAI provider — each EU AI Act role carries its own obligations. The role test, article references, and live dates.
RAG citations are decorative — no provenance contract links chunk to answer. Regulated work needs typed corpus tools, deterministic validation, and refusal.
6,041 Swedish statutes from Riksdagen, segmented to section level and served as an MCP — query by SFS number, chapter, and paragraf, every result cited.
DORA Article 28 sets the third-party obligations; the contract clauses live in Article 30. Each subsection mapped to ISO 27001 and SCF controls.
Every NIS2 Article 21(2) measure mapped to ISO 27001:2022 Annex A — and the three real gaps: reporting clock, management liability, supply chain depth.
Chat and RAG hallucinate regulatory citations. An MCP gateway adds routing, fan-out, tier auth, and deterministic citation validation — and when you need one.