<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Regulation on Sakura Sky: Cloud, Data, Security</title><link>https://www.sakurasky.com/tags/regulation/</link><description>Recent content in Regulation on Sakura Sky: Cloud, Data, Security</description><generator>Hugo</generator><language>en-US</language><copyright>Sakura Sky</copyright><lastBuildDate>Tue, 26 May 2026 11:23:18 +0200</lastBuildDate><atom:link href="https://www.sakurasky.com/tags/regulation/index.xml" rel="self" type="application/rss+xml"/><item><title>The Regulatory Stack, Part 2: Why the Boardroom Should Be Funding the Verification Layer in 2026</title><link>https://www.sakurasky.com/blog/regulatory-stack-part-2/</link><pubDate>Thu, 21 May 2026 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/regulatory-stack-part-2/</guid><description>&lt;style>
 
.series-pull-quote {
 float: right;
 clear: both;
 width: 340px;
 margin-left: 2rem;
 margin-bottom: 1.5rem;
 border: 1px solid #e9ecef;
 border-radius: 6px;
 overflow: hidden;
 background-color: #ffffff;
 
 position: relative;
 z-index: 20;
}

 
@media (max-width: 768px) {
 .series-pull-quote {
 float: none;
 clear: both;
 width: 100%;
 margin-left: 0;
 }
}

.series-header {
 background-color: #f8f9fa;
 color: #6c757d;
 font-size: 0.65rem;
 font-weight: 700;
 letter-spacing: 0.05em;
 padding: 0.8rem 1.25rem;
 border-bottom: 1px solid #e9ecef;
}

.part-label {
 display: block;
 font-size: 0.6rem;
 color: #adb5bd;
 margin-bottom: 0.15rem;
 text-transform: uppercase;
}

.nav-link-text {
 font-size: 0.85rem;
 line-height: 1.4;
 color: #495057;
 text-decoration: none;
 
 position: relative;
 z-index: 21;
}

 
.active-part {
 border-left: 4px solid #000 !important;
 background-color: #ffffff !important;
}

.active-part .nav-link-text {
 font-size: 0.9rem;
 font-weight: 700;
 color: #212529;
 text-decoration: underline;
 text-underline-offset: 3px;
}

.locked-part .nav-link-text {
 color: #ced4da;
}

.list-group-item {
 border-bottom: 1px solid #f8f9fa;
 padding: 1rem 1.25rem !important;
}
&lt;/style>

&lt;aside class="series-pull-quote shadow-sm">
 &lt;div class="series-header">
 READ MORE IN THIS SERIES
 &lt;/div>
 &lt;div class="list-group list-group-flush">
 
 
 

 &lt;div class="list-group-item ">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;a href="https://www.sakurasky.com/blog/regulatory-stack-part-1/" class="nav-link-text">Part 1 - AISVS Has 14 Categories. GATE Has 16 Controls. Here Is the Map.&lt;/a>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item active-part ">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;a href="https://www.sakurasky.com/blog/regulatory-stack-part-2/" class="nav-link-text">Part 2 - Why the Boardroom Should Be Funding the Verification Layer in 2026&lt;/a>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 3 - How the EU AI Act Made Verification a Legal Question, Not a Best-Practice One&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 4 - Engineering Under the AI Act: Article 15 Cybersecurity in Practice&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 5 - The Cyber Resilience Act Closes the Last Loophole&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 
 

 &lt;div class="list-group-item locked-part">
 &lt;div class="d-flex justify-content-between align-items-center">
 &lt;div>
 
 &lt;span class="nav-link-text">Part 6 - Building Under the CRA: A Reference Architecture&lt;/span>
 
 &lt;/div>

 &lt;/div>
 &lt;/div>
 
 &lt;/div>
&lt;/aside>


&lt;p>The capital deployment decisions boards make this year will determine whether their autonomous AI systems are governable assets or existential liabilities by 2027. Here is the strategic case.&lt;/p></description></item><item><title>OWASP Just Drew a New Map, Read It Before Your Auditors Do</title><link>https://www.sakurasky.com/blog/owasp-strategic-plan-2026/</link><pubDate>Thu, 07 May 2026 00:00:00 -0400</pubDate><guid>https://www.sakurasky.com/blog/owasp-strategic-plan-2026/</guid><description>&lt;p>&lt;em>The Foundation&amp;rsquo;s new strategic plan is not a community update. It commits OWASP to setting the technical floor for AI security, secure-development competence, and EU compliance. Three things on it should already be on your roadmap.&lt;/em>&lt;/p></description></item></channel></rss>