<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Verillian writing</title>
    <link>https://verillian.ai/blog/</link>
    <atom:link href="https://verillian.ai/blog/feed.xml" rel="self" type="application/rss+xml"/>
    <description>Plain-language writing on AI governance on the device, AI audit trails, shadow AI, and compliance for regulated institutions.</description>
    <language>en-us</language>
    <item>
      <title>Agentic AI governance: control the action, not the prompt</title>
      <link>https://verillian.ai/blog/governing-agentic-ai/</link>
      <guid isPermaLink="true">https://verillian.ai/blog/governing-agentic-ai/</guid>
      <pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate>
      <description>Agents act on their own at machine speed. Why agentic AI governance must move to the action boundary, and why the signed record is the only witness.</description>
    </item>
    <item>
      <title>An AI acceptable use policy is not enforcement</title>
      <link>https://verillian.ai/blog/ai-acceptable-use-policy-enforcement/</link>
      <guid isPermaLink="true">https://verillian.ai/blog/ai-acceptable-use-policy-enforcement/</guid>
      <pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate>
      <description>Most institutions have an AI acceptable use policy. Few can show it held. AI policy enforcement means decisions at execution, plus a record that proves it.</description>
    </item>
    <item>
      <title>CJIS compliance and AI: what the CJIS Security Policy requires before staff use AI tools</title>
      <link>https://verillian.ai/blog/cjis-and-ai/</link>
      <guid isPermaLink="true">https://verillian.ai/blog/cjis-and-ai/</guid>
      <pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate>
      <description>What the CJIS Security Policy requires before CJI touches an AI tool, what auditors will ask, and what a defensible record looks like.</description>
    </item>
    <item>
      <title>Is ChatGPT HIPAA compliant? What healthcare teams need to know</title>
      <link>https://verillian.ai/blog/is-chatgpt-hipaa-compliant/</link>
      <guid isPermaLink="true">https://verillian.ai/blog/is-chatgpt-hipaa-compliant/</guid>
      <pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate>
      <description>No AI tool is HIPAA certified, because no such certification exists. What a business associate agreement covers, what it does not, and how PHI stays governed.</description>
    </item>
    <item>
      <title>What is an AI audit trail, and what makes one trustworthy</title>
      <link>https://verillian.ai/blog/what-is-an-ai-audit-trail/</link>
      <guid isPermaLink="true">https://verillian.ai/blog/what-is-an-ai-audit-trail/</guid>
      <pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate>
      <description>An AI audit trail records who used which AI tool, what was sent and returned, when, and whether policy held. What separates evidence from a text file of logs.</description>
    </item>
    <item>
      <title>What is shadow AI? A plain guide for regulated institutions</title>
      <link>https://verillian.ai/blog/what-is-shadow-ai/</link>
      <guid isPermaLink="true">https://verillian.ai/blog/what-is-shadow-ai/</guid>
      <pubDate>Sat, 04 Jul 2026 12:00:00 GMT</pubDate>
      <description>Shadow AI is the AI in use that no one approved and no one can see. Why it grows, why bans fail, and how shadow AI detection leads to one enforced policy.</description>
    </item>
  </channel>
</rss>
