Skip to main content

22 posts tagged with "Audit Logging"

Tamper-evident, hash-chained records of AI actions

View All Tags

AML/BSA and AI Agents: The Travel Rule, Transaction Monitoring, and SAR Filing

· 4 min read
David Sanker
Lawyer, Legal Knowledge Engineer & UAPK Inventor | Patent EP 25 000 056.9 | ORCID 0009-0004-9636-3910

The Bank Secrecy Act has been around since 1970. FinCEN's expectations for AI-assisted transaction monitoring are not new — the 2021 guidance on AML program effectiveness explicitly called out model risk management and audit trail requirements for automated transaction monitoring systems.

If your AI agent initiates, approves, routes, or monitors financial transactions, AML/BSA requirements apply. There's no AI carve-out.

HIPAA and AI Agents: PHI, Minimum Necessary, and Approval Gates

· 4 min read
David Sanker
Lawyer, Legal Knowledge Engineer & UAPK Inventor | Patent EP 25 000 056.9 | ORCID 0009-0004-9636-3910

HIPAA was written in 1996. AI agents weren't part of the threat model. But the obligations translate directly: any AI agent that accesses, uses, or discloses Protected Health Information (PHI) is subject to the same rules as any other HIPAA-covered entity or business associate.

That means the clinical documentation AI, the patient communication bot, the diagnostic support tool, the prior authorization agent — all of them need HIPAA controls built in at the infrastructure level, not just the application level.