Theses on infrastructure,
regulation, and digital truth.
Strategic analysis of AI governance, cryptographic evidence, and European regulatory frameworks, for legal, compliance, and executive management teams.
Which version is currently in effect? And who approved it?
In any audit of an ISO management system, two questions always come up: Which revision is currently in effect, and who approved it? All too often, the answer begins with a search for paperwork.
What portion of your code was written by AI? The question is no longer a technical one.
Code assistants on every team, dozens of branches, and a repository that no one knows in its entirety. For technical management, it’s a control issue. For Legal, it’s a matter of authorship and licensing. For the auditor, it’s a matter of evidence.
Which version of your model is in production, and who approved it?
Your data team knows which version is the winning one. What an audit asks is something else: who decided to put it into production, what controls were in place, and exactly which files were running on the day of the incident.
His agent is already taking action. Can he show what he was capable of?
AI agents no longer just respond: they query systems, select tools, and move data. The auditor’s question will be simple: What could that agent do, with what permissions, and who approved it?
The AI Governance Market Is Growing at an Annual Rate of 67.5%: What This Means for Your Company
The AI governance platform market is growing at an annual rate of 67.5%. This is not an optimistic projection—it is the result of four forces that are already at work: the EU AI Act already in effect, publicly reported AI incidents, insurers changing their terms and conditions, and a risk that is dynamic, not static. The window of competitive advantage exists right now.
We are finalists for the 2026 Innovacat Awards
V-PROOF® is one of the 12 finalists in the Osona Jove category of the 2026 Innovacat Awards. On October 6, we will present the jury in Manlleu with a sealed presentation that they can verify themselves using a QR code.
Your code already has a history. Strategic Provenance turns that history into evidence.
Who understands your code, how much of it was written by AI, and what changed in each version. V-PROOF turns your repository into verifiable evidence for CIOs and auditors.
AI Systems Inventory: A Practical Guide to Compliance | V-PROOF
Most organizations that launch an AI governance program encounter the same problem: they don’t know exactly which AI systems they’re using. They don’t have a centralized, up-to-date view. Without an inventory, there is no governance—and without governance, there is no compliance with the EU AI Act or ISO 42001.
Why Your GRC Tool Isn't Enough to Govern AI—and What Is
GRC tools document risks, policies, and controls. Governing AI also requires evaluating each system and providing evidence that a third party can verify. This adds a layer of AI governance with verifiable evidence.
The AI seatbelt. And what Volvo understood before anyone else.
In 1959, Nils Bohlin invented something that no one had asked for. Volvo patented it and then gave the patent away—not to make money, but to ensure that trust in the car would become a universal standard. Today, we’re at that same juncture with AI. The problem isn’t technological; it’s one of evidence.
Why the evidentiary infrastructure is not a dat governance —and why that difference matters.
The AI governance market is growing rapidly. And with it comes confusion that has real-world consequences. Every week, new platforms emerge promising “immutable records” and “compliance by design.” They all use the same vocabulary. But not all of them solve the same problem.
Governance as Code: The End of Document-Based Controls and the Beginning of Executable Guardrails
What is Governance as Code, why GRC is not enough to govern AI, and how V-PROOF implements real-time, executable guardrails for AI-generated assets.
August 2, 2026: What Changes Today for Organizations Using High-Risk AI
The General Data Protection Regulation ( EU AI Act ) takes effect today for high-risk AI systems. This is not a transition period—it marks the start of the period during which authorities can investigate, request documentation, and impose fines of up to 3% of global revenue. Many organizations that have spent months preparing for compliance will face the same problem: their current records do not provide the verifiable evidence required by the Regulation.
AI Governance: 30 Key Questions, 8 Regulatory Frameworks, 1 Layer of Evidence
All AI governance frameworks—POPIA, ISO 42001, ISO 27001, ISO 27701, EU AI Act, NIST AI RMF, PCI DSS, and HIPAA—define the “what.” None of them certifies the “how” or the “when.” This matrix cross-references the 30 critical governance questions against the 8 global standards and adds the missing layer: cryptographic evidence that can be verified by any European auditor. Declarative compliance vs. verifiable compliance.
The first requirement of the AI regulation is not technical. #ARTICLE 50 AI ACT
The primary requirement of the EU AI Act is not technical. Article 50 took effect on August 2, 2025, and requires any operator using AI to clearly indicate when a machine is on the other end. Comprehensive analysis including the legal framework, timeline, and penalties: up to €15 million or 3% of global revenue.
The train carrying the foundational models has already left. Europe has another one.
The race for artificial intelligence cannot be won with computing power alone. Europe isn’t competing in that league—and it shouldn’t even try. It competes in another: verifiable trust, legal sovereignty, and the ability to turn regulation into strategic infrastructure. Opinion piece by Gil Blancafort, founder of the V-PROOF Protocol, published in Expansión (July 2026).
The First AI Governance Magic Quadrant: What Gartner Measures and Where the Verifiable Evidence Stands
In June 2026, Gartner published its first Magic Quadrant for AI Governance Platforms. Thirteen vendors were evaluated. None of them operate in the same space as V-PROOF.
La Vanguardia highlights the "black box" of AI: V-Proof Protocol in the Business Special
Noncompliance can cost up to €35 million or 7% of global revenue. *La Vanguardia* has published a feature on the V-Proof Protocol: the Barcelona-based infrastructure that turns human oversight of AI into verifiable evidence, ahead of the General Data Protection Regulation ( EU AI Act ), which takes effect on August 2, 2026.
EU CRA: Code Traceability and Vulnerability Management as Law
EU Cyber Resilience Act: Cybersecurity Requirements for Software Products and How to Comply with Them
How V-PROOF Helps with DORA Compliance in the Financial Sector
The DORA Regulation will be fully in effect as of January 2025. Articles 9, 10, 11, and 17 require verifiable ICT records. V-PROOF generates these using timestamp blockchain from the outset.
