Newsletter
Compliance Engineering
AI governance for the agent era, delivered. Every new entry in the AI Agent Incident Register: a real AI-agent failure, analysed legally. What happened, who was liable across the chain, and the governance that would have prevented it. By Michael K. Onyekwere, CIPP/E.
Compliance Engineering
The AI Agent Incident Register, delivered. Each new entry analysed legally. By Michael K. Onyekwere, CIPP/E.
Free. Unsubscribe anytime. No spam.
What you get
Every Register entry, analysed legally
Each issue is a documented AI-agent incident worked through by a lawyer: the facts, the legal duty engaged, who bears liability across the chain (model provider, orchestrator, tool vendor, deployer), and the governance that would have prevented it.
Mapped to the frameworks you already run
Every entry maps to GDPR, the EU AI Act, OWASP, and NIST, so the analysis slots into the compliance work you already do rather than sitting beside it.
A stable source you can cite
Every entry has a permanent, numbered home in the AI Agent Incident Register. The newsletter delivers it; the citation stays on the canonical entry URL.
Sent as the work is done
You get each new entry as it publishes, not a fixed marketing cadence. When an incident is worth analysing, it lands in your inbox with the analysis attached.
Who it's for
- In-house and enterprise counsel assessing AI-agent liability
- DPOs and compliance leads governing AI and agent deployments
- Founders and engineers shipping AI agents into the UK or EU
- Insurers, vendors, and regulators tracking how agents fail and who pays
- Anyone who wants the law on AI agents from someone who runs them
About Michael
CIPP/E certified data protection professional. 10+ years across Royal Bank of Scotland, Fidelity, TMF Group, and UnitedHealth, doing financial services and corporate compliance at enterprise scale.
Common law qualified lawyer (LLB, LLM). Works at the intersection of AI governance and the law: how AI agents fail, who is liable, and what governance holds. Author of the AI Agent Incident Register, and the operator of a real governed agent system while writing about it.
What I write here is the work, on the cadence of the work, for people who care about both shipping AI and not getting fined.
Read more about Michael →Free download
Or get the AI API Compliance Checklist first
If you want a concrete artifact before subscribing, take the AI API Compliance Checklist. OpenAI / Anthropic DPA setup, zero-retention config, the documentation pack procurement reviewers will accept. Free.
Built for engineers implementing AI and the founders or compliance leads responsible for signing it off.
- ·DPA setup steps for OpenAI and Anthropic API accounts
- ·Zero-retention configuration: when it applies, what it changes, how to evidence it
- ·Retention and logging questions to answer before launch
- ·Audit documentation pack a procurement reviewer will accept
Your email is used to deliver the PDF and (if you opt in) the newsletter. No spam. Privacy policy.