17 篇文章 · technology
ML-DSA and SLH-DSA are standardised. The harder question for regulated organisations is what happens to the integrity proofs you created before them.
On 21 September, the remaining FIPS 140-2 certificates move to historical status. The immediate impact is procurement.
After an incident, the question isn't whether the model behaved oddly. It's whether you can prove what it was actually trained on in the first place.
Both frameworks tell you to govern your AI data. Neither tells you how to prove, independently, that you actually did.
A model card tells you what a team says about a model. It doesn't prove any of it. Regulators are starting to notice the difference.
Every vendor claims their data is AI-ready. Here is a definition that holds up when a regulator, not a sales deck, asks the question.
Poisoning doesn't look like an attack. It looks like data. That's what makes it effective, and hard to catch after the fact.
Standard audit logs can be modified. Cryptographic audit trails cannot. Here is the difference, and why it matters for compliance.
Ransomware announces itself. Data tampering does not. And that invisibility is exactly what makes it the more serious threat.
关于数据完整性、合规与连续性的实用、可审计指南--发布即送达。