<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>Regulus — Where Google ADK ends, regulated builds begin</title><description>Regulus is the open-source EU + UK compliance plane for Google ADK. 8 BasePlugin controls, 6 service extensions, 10 regulation profiles, 6 governance frameworks, 4 GRC adapters — drop into Vertex AI Agent Engine in 60 seconds. Java 21, ADK 1.2, MIT.</description><link>https://regulus.neullabs.com/</link><language>en-us</language><generator>Astro</generator><item><title>Annex III high-risk: five questions that decide whether your agent is in scope</title><link>https://regulus.neullabs.com/blog/annex-iii-high-risk-classification-five-questions/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/annex-iii-high-risk-classification-five-questions/</guid><description>Most agentic AI workflows in production end up high-risk under Annex III. Here are the five concrete questions to ask of your agent — answer yes to any, and the EU AI Act&apos;s Article 9 obligations bind.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>eu-ai-act</category><category>annex-iii</category><category>high-risk</category><category>classification</category><category>scope</category></item><item><title>FCA Consumer Duty (GC23/2) outcomes monitoring for AI-driven decisioning</title><link>https://regulus.neullabs.com/blog/fca-consumer-duty-outcomes-monitoring-for-ai-decisioning/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/fca-consumer-duty-outcomes-monitoring-for-ai-decisioning/</guid><description>Consumer Duty PRIN 12 demands outcomes monitoring on a cross-cutting basis. For AI agents making retail-customer decisions, this means runtime evidence tagged to the four Duty outcomes.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>fca</category><category>consumer-duty</category><category>prin-12</category><category>outcomes-monitoring</category><category>gc23-2</category></item><item><title>GDPR Article 5(1)(b) purpose limitation in agentic AI: from PDF to runtime</title><link>https://regulus.neullabs.com/blog/gdpr-article-5-purpose-limitation-from-pdf-to-runtime/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/gdpr-article-5-purpose-limitation-from-pdf-to-runtime/</guid><description>GDPR purpose limitation is a runtime check, not a contract clause. Here&apos;s how to enforce it at the agent&apos;s tool dispatch with a Principal claim and a BeforeToolCallback decision.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>gdpr</category><category>article-5</category><category>purpose-limitation</category><category>runtime</category><category>principal</category></item><item><title>EU AI Act Article 9 in code: how to evidence risk management for ADK agents</title><link>https://regulus.neullabs.com/blog/eu-ai-act-article-9-evidence-for-adk-agents/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/eu-ai-act-article-9-evidence-for-adk-agents/</guid><description>Article 9 risk management isn&apos;t a PDF — it&apos;s a continuous runtime obligation. Here&apos;s how to evidence it for a Google ADK agent, mapped to specific BasePlugin callbacks and audit envelope fields.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>eu-ai-act</category><category>article-9</category><category>adk</category><category>risk-management</category><category>audit</category><category>gpai</category></item><item><title>GPAI Code of Practice (2 August 2026): what enforcement actually looks like</title><link>https://regulus.neullabs.com/blog/gpai-code-of-practice-2-august-2026/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/gpai-code-of-practice-2-august-2026/</guid><description>The GPAI Code of Practice deadline is 2 August 2026. From that date the AI Office can request evidence from any GPAI-derived agent in the EU. What that means in practice for deployers building on ADK.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>eu-ai-act</category><category>gpai</category><category>ai-office</category><category>code-of-practice</category><category>enforcement</category></item><item><title>Google ADK plugin SPI deep-dive: BeforeAgentCallback to AfterToolCallback</title><link>https://regulus.neullabs.com/blog/google-adk-plugin-spi-deep-dive/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/google-adk-plugin-spi-deep-dive/</guid><description>Walking through Google ADK&apos;s plugin SPI from BeforeAgentCallback through AfterToolCallback with worked examples. Where to attach policy, where to attach privacy, where to attach the audit envelope.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>google-adk</category><category>plugin-spi</category><category>baseplugin</category><category>callbacks</category><category>java</category></item><item><title>Hash-chained audit trails for ADK agents: SHA-256 + RFC 9421 in ~200 lines of Java</title><link>https://regulus.neullabs.com/blog/hash-chained-audit-trails-for-adk-agents/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/hash-chained-audit-trails-for-adk-agents/</guid><description>How to build a tamper-evident audit chain for an ADK agent. SHA-256 over the previous event&apos;s hash, offline verification, retention policies. Plus where RFC 9421 fits for cross-org agent calls.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>audit</category><category>hash-chain</category><category>sha-256</category><category>rfc-9421</category><category>integrity</category><category>java</category></item><item><title>Is your LLM agent a &apos;model&apos; under PRA SS1/23? The five tests that decide it</title><link>https://regulus.neullabs.com/blog/is-your-llm-agent-a-model-under-pra-ss1-23/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/is-your-llm-agent-a-model-under-pra-ss1-23/</guid><description>PRA SS1/23&apos;s Principle 1 defines a model in broad terms. Five concrete tests applied to a typical LLM-powered agent — the answer is yes in every case. What that means operationally.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>pra-ss1-23</category><category>model-risk</category><category>mrm</category><category>uk-banking</category><category>ss1-23</category></item><item><title>NHS DSPT + agentic AI: mapping the 10 data security standards to runtime controls</title><link>https://regulus.neullabs.com/blog/nhs-dspt-and-agentic-ai-10-standards-to-runtime-controls/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/nhs-dspt-and-agentic-ai-10-standards-to-runtime-controls/</guid><description>The NHS DSPT&apos;s 10 standards are the gating compliance asset for AI in NHS settings. Here&apos;s the runtime-controls map — which Regulus plugin delivers evidence for each NDG standard.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>nhs-dspt</category><category>healthcare</category><category>ndg</category><category>ai-in-healthcare</category><category>ehr</category></item><item><title>Vertex AI Agent Engine compliance gaps and how to close them without forking the runtime</title><link>https://regulus.neullabs.com/blog/vertex-ai-agent-engine-compliance-gaps/</link><guid isPermaLink="true">https://regulus.neullabs.com/blog/vertex-ai-agent-engine-compliance-gaps/</guid><description>Vertex AI is the runtime; Org Policy + VPC-SC + Assured Workloads is the data plane. The agent&apos;s decision plane has no default story. Where the gaps are and how to close them via the ADK plugin SPI.</description><pubDate>Mon, 01 Jun 2026 00:00:00 GMT</pubDate><category>vertex-ai</category><category>agent-engine</category><category>gcp</category><category>control-plane</category><category>decision-plane</category></item></channel></rss>