Articles, reports & whitepapers
Engineering-focused writing from the RuleMesh team. Regulatory explainers, technical whitepapers, and protocol proposals for teams implementing compliance.
The New Economics of Audit Evidence
Audit sampling exists because auditor attention is expensive. As that stops being true, evidence has to come from the running system rather than a folder assembled before fieldwork.
Trust as a control: lessons from the Revolut impersonation case
A request from a genuine government email address, customer passports in reply, and the GDPR and DORA obligations that were already written for exactly this situation.
Automated decision-making: the EU regulatory position and lessons from Uber’s driver deactivations
What Uber’s automated driver deactivations can teach product and engineering teams about translating regulation into requirements before a system is built.
The AI Act Deadline Just Moved 16 Months. Three Obligations Didn’t.
The Digital Omnibus delays high-risk AI to December 2027 — but transparency, watermarking, and two new prohibitions still apply in 2026, mapped by actor role.
We Proposed a New Web Standard So Systems Can Prove Compliance to Each Other
HCAP — the HTTP Compliance Authorization Protocol. A draft specification submitted to the IETF to move compliance verification out of email and into the HTTP layer.
GDPR Is Not 99 Articles. It Is 7 Engineering Problems.
A practical framework for prioritising GDPR compliance — based on what the regulation actually requires from your systems.
You Are Outside the EU. The GDPR Still Applies to You.
GDPR Article 27 — EU Representation for Non-EU Controllers and Processors.
Sending EU Data Outside Europe? Here Is What the GDPR Requires.
Under GDPR Chapter V, the transfer of personal data to a third country requires specific safeguards.
Agent-Agnostic Compliance: How Three AI Models Interpret Identical Regulatory Data via MCP
A technical study demonstrating that structured MCP data drives consistent compliance outcomes across Claude, Gemini, and GPT.
AI Agents Don't Earn Trust. Their Compliance Infrastructure Does.
What the CSA's Agentic Trust Framework says — and why the regulatory data layer, not the model, is where trust is actually earned.