Back to blog

Why compliance-as-code will separate AI leaders from the rest

By Joe Zhou ยท

Here's the uncomfortable truth about AI in 2025

Less than 1% of organisations have fully operationalised responsible AI, as reported by the World Economic Forum. Meanwhile, only 41% of Americans are currently willing to trust AI, reflecting continued low confidence in commercial and government entities according to the latest KPMG research.

This isn't a legal problem. It's an engineering problem.

And legal teams can't solve engineering problems.

Why compliance-as-code is the only way forward

I've been working with Australian CTOs navigating the EU AI Act, and here's what I've learned: the startups that win aren't the ones hiring compliance consultants to write documents.

They're the ones treating compliance like they treat security as code, in the pipeline, from day one.

Think about it: We've been doing this with DevSecOps for years. We don't write security policies in Word docs and hope developers follow them. We enforce them in CI/CD pipelines with policy-as-code.

Security policies are now enforced as code, directly within CI/CD pipelines, as outlined by the Cloud Security Alliance. Meta's Automated Compliance Hardening tool uses LLMs to generate tests that catch code out of compliance before it enters production.

Why should AI compliance be any different?

The Bottom-Up revolution

The EU AI Act gives us something no compliance framework has given us before: technical requirements that map directly to code.

  • Risk classification? That's a function in your model registry.
  • Training data provenance? That's metadata in your data pipeline.
  • Bias detection? That's a test in your CI/CD.
  • Human oversight? That's an architectural pattern.
  • Automated logging? That's infrastructure.

JFrog is treating AI models the same as software artifacts, introducing ML-BOMs (machine learning bills of materials) that track model provenance and dataset bias with digital signatures at every stage.

This is what compliance-as-code looks like for AI.

Why this matters for technical leaders

CTOs: You can't outsource this to Legal.

  • Your lawyers can interpret the regulation, but they can't:
  • Architect your logging infrastructure
  • Design your model registry
  • Build your evaluation pipelines
  • Implement your human-in-the-loop patterns
  • Create your automated documentation systems

This is infrastructure work. This is platform engineering. This is DevOps.

When AI agents start writing code, treating prompts as code artifacts becomes essential, LLMOps is simply DevSecOps for a new kind of actor.

The Shift-Left approach to AI compliance

We learned this lesson with security: catching vulnerabilities in production is 100x more expensive than catching them in development. The same is true for AI compliance.

The concept of "fix-left" ensures issues caught early can be resolved early without creating bottlenecks or requiring deep security expertise from every engineer.

Your compliance architecture should:

In your IDE:

  • Real-time feedback on compliance violations as you code
  • Auto-suggestions for compliant implementations
  • Pre-commit hooks that block non-compliant models

In your CI/CD:

  • Automated conformity checks on every merge
  • Policy-as-code enforcement (OPA, Gatekeeper, Conftest)
  • Fail the build if documentation is incomplete
  • Block deployment if bias thresholds are exceeded

In your infrastructure:

  • Immutable audit logs (6-month retention minimum)
  • Automated incident detection and reporting
  • Drift detection for model behavior
  • Continuous monitoring dashboards

Policy as code allows for automated enforcement and real-time validation, ensuring applications meet security and regulatory standards without extra manual effort.

The Playbook: Start small, think big

If you're a CTO or engineering leader, here's where to start:

Week 1: Treat one model as production-critical

  • Add it to your model registry
  • Document its training data sources
  • Set up basic logging
  • Create a one-pager on how it works

Week 2: Add compliance checks to CI/CD

  • Block deployments without documentation
  • Require bias assessment before production
  • Enforce logging standards
  • Add automated tests for compliance requirements

Week 4: Make it self-service

  • Create templates for compliant model deployment
  • Build internal tooling that makes compliance the easy path
  • Document the patterns so other teams can copy them

Month 2: Scale horizontally

  • Every new model follows the same pattern
  • Compliance becomes part of your "definition of done"
  • Engineers understand the "why" not just the "what"

This is how you build from the bottom up. Start with engineering, not legal.

The competitive advantage nobody's talking about

Here's what changed in 2025: 85% of consumers want laws to combat AI-generated misinformation, and 72% say more regulation is needed in the KPMG report.

Your customers want governance. They want transparency. They want accountability.

Compliance-as-code gives you:

  • Faster deployment: no manual reviews blocking releases
  • Lower risk: catch issues before production
  • Better trust: demonstrate compliance programmatically
  • Cheaper scaling: automate what others do manually

The startups that figure this out will move faster AND be more trusted.

The bottom line

The EU AI Act isn't about lawyers writing policies.

It's about engineers building systems that are transparent, auditable, and trustworthy by design.

Compliance-as-code isn't optional. It's the only way to build AI at scale that people actually trust.

Are you building compliance into your architecture, or hoping your documentation will save you?

Ready to build this?

We are building compliance-as-code systems for AI companies navigating the EU AI Act and implementing ISO/IEC 42001 AI management systems. Not frameworks in slide decks but actual architecture that ships.

Here's how we start: Book a 30-minute technical review ->

Bring your current architecture. I'll show you:

  • Where the gaps are for EU AI Act compliance
  • What you can automate vs. what needs human oversight
  • A realistic 90-day plan
  • Specific tools/approaches for your stack

This is a technical conversation, not a sales pitch. If there's a fit, we can talk about working together. If not, you'll leave with a clearer picture of what you need to build.