Trend 3 · Testing is now evidence
Test records are legal artifacts.
What began with SOX and HIPAA has compounded. GDPR. State privacy laws. EU AI Act. SEC cyber-incident disclosure. Sectoral rules — IEC 62304, ISO 26262, financial services.
For AI-enabled products, governance adds a second stack: model documentation, evaluation disclosures, bias testing, model cards, post-deployment monitoring.
Threat
Testing evidence is discoverable. A poor testing record is a legal liability, not just a quality problem.
What to learn
Requirements traceability. Audit-grade test documentation. OWASP ASVS. AI-system evaluation standards. Privacy-testing practice.