Topics
Browse posts by category and tag — every topic we cover, with the latest pieces under each.
Tags
- #compliance 13
- #gdpr 11
- #data-anonymization 5
- #training-data 4
- #differential-privacy 3
- #eu-ai-act 3
- #llm 3
- #machine-learning 3
- #privacy-engineering 3
- #ai-governance 2
- #automated-decision-making 2
- #data-protection 2
- #edpb 2
- #pii 2
- #privacy 2
- #privacy-tools 2
- #ab-2013 1
- #admt 1
- #ai-assistants 1
- #ai-office 1
- #ai-security 1
- #article-22 1
- #article-50 1
- #ccpa 1
- #cjeu 1
- #cnil 1
- #colorado-ai-act 1
- #cppa 1
- #cpra 1
- #cross-border-transfers 1
- #data-retention 1
- #data-security 1
- #de-identification 1
- #disclosure 1
- #dpia 1
- #enforcement 1
- #federated-learning 1
- #foundation-models 1
- #gdpr-article-35 1
- #human-review 1
- #illinois 1
- #legitimate-interest 1
- #membership-inference 1
- #open-source 1
- #policy 1
- #privacy-enhancing-technologies 1
- #pseudonymization 1
- #regulator 1
- #right-to-erasure 1
- #risk-assessment 1
- #scc 1
- #schrems-ii 1
- #secure-aggregation 1
- #state-ai-law 1
- #synthetic-content 1
- #synthetic-data 1
- #test-data 1
- #traiga 1
- #transparency 1
Categories
policy 11 posts
- How Membership Inference Attacks Work, and Why They MatterMembership inference attacks reveal whether a person's record was in a model's training set. Here is the mechanism, the shadow-model method, and defenses.
- US State AI Laws 2026: Colorado, Texas, California, IllinoisThe US state AI laws shaping 2026: Colorado's stalled SB 24-205, Texas TRAIGA, California AB 2013, and Illinois HB 3773, with their effective dates.
- CCPA and CPRA ADMT Rules for LLM ProductsCalifornia's finalized ADMT rules add pre-use notice, opt-out, appeal, and risk-assessment duties to automated decisionmaking, catching many LLM products.
- Training Data Privacy: GDPR Data Subject RightsEDPB Opinion 28/2024 and CNIL guidance reshaped how GDPR applies to AI training data, from model anonymity to legitimate interest and erasure requests.
- AI Chat Assistant Privacy Risks: Training, Review, RetentionConsumer AI assistants increasingly default to using your conversations for training, human review and multi-year retention. Here is what actually changes.
- Cross-Border LLM Data Transfers: SCCs After Schrems IIMost LLM deployments cross borders. How Standard Contractual Clauses, post-Schrems II case law, and supplementary measures apply to model inference.
data-privacy 5 posts
- How Federated Learning Protects Privacy, and Where It StopsFederated learning keeps raw training data on-device, but model updates still leak records. What the architecture protects, and what closes the gap.
- Open Source Data Anonymization Tools ComparedARX, Presidio, Amnesia, PostgreSQL Anonymizer, Greenmask and sdcMicro compared by data type, the privacy model each enforces, and what each cannot do.
- Pseudonymization vs Anonymization Under GDPRAnonymized data leaves GDPR entirely, pseudonymized data does not. Where Recital 26, the CJEU SRB ruling and EDPB guidance put the line in practice.
- How to Anonymize Training Data: Methods and ComplianceHow to anonymize training data in practice: PII scrubbing, k-anonymity, differential privacy, synthetic data, and what GDPR actually requires.
- Best Data Anonymization Tools: Open Source vs EnterpriseA practitioner's guide to the best data anonymization tools 2026: ARX, Microsoft Presidio, Tonic.ai, and K2View, plus how to pick for your threat model.
Compliance 2 posts
- Best GDPR Compliance Tools for AI: A Practitioner's GuideWhich platforms handle GDPR's toughest AI obligations: DPIA automation, Article 22 oversight, ROPA management, and data discovery for AI systems.
- GDPR Compliance for Machine Learning Models: Practical GuideGDPR requirements for machine learning models, covering lawful bases, DPIAs, Article 22 rights, anonymization, erasure, and rectification.