Browse guides

Governance & Regulation articles

21
Governance & Regulation

AI Governance

AI governance is the answer to a small set of questions: who approves a use case, who reviews outputs, what data may go where, and who can stop it. It is mostly organisational design rather than technology. Under the EU AI Act, parts of it stop being optional. In practice: A register of AI use cases with an owner and a risk tier for each.

Governance & Regulation

AI Literacy

Article 4 requires providers and deployers to take measures ensuring a sufficient level of AI literacy among staff dealing with AI systems, taking account of their role, context, and the people affected. This is one of the few obligations that lands on essentially every organisation using AI at work, not just high-risk ones. There is no prescribed curriculum, so it is proportionate rather than box-ticking. In practice: Documented training so the team knows what the tool can do, where it fails, and when to escalate. ...

Governance & Regulation

AI Regulatory Sandbox

Article 3(55) defines a controlled framework set up by a competent authority, allowing providers to develop, train, validate and test an innovative system for a limited time under supervision, following an agreed sandbox plan. Each member state must provide access to one. It is aimed particularly at SMEs and start-ups. In practice: Testing a novel high-risk system with a national authority watching, before market entry. Plain-English summary of Article 3(55). The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

AI System (legal definition)

Article 3(1) defines an AI system as machine-based, designed to operate with varying levels of autonomy, possibly adaptive after deployment, which infers from its inputs how to generate outputs such as predictions, content, recommendations, or decisions that can influence environments. The definition is deliberately technology-neutral, and ‘infers’ is the operative word — it is what separates an AI system from ordinary software. The Commission issued guidelines in February 2025 to help draw that line. ...

Governance & Regulation

Biometric Categorisation

Article 3(40) defines it, excluding uses ancillary to another service and strictly necessary for technical reasons. Categorising people by sensitive or protected characteristics is a prohibited practice; other biometric categorisation generally falls in the high-risk tier. In practice: Inferring ethnicity or political affiliation from a face is prohibited. Plain-English summary of Article 3(40). The binding text is Regulation (EU) 2024/1689.

Governance & Regulation

CE Marking

CE marking is the familiar EU conformity mark extended to AI. Affixing it is a legal statement by the provider that the system meets the requirements and that the paperwork exists to prove it. It is a declaration, not a certificate someone hands you. In practice: The same principle that governs a kettle now applies to a CV screening system. Plain-English summary. The binding text is Regulation (EU) 2024/1689.

Governance & Regulation

Conformity Assessment

Conformity assessment is the compliance gate for high-risk systems, done either by the provider itself or through a notified body depending on the use case. It ends in a declaration of conformity, CE marking, and registration in the EU database. Substantial modification can require repeating it. In practice: A documented file showing the risk management, data governance, and testing behind the system. Plain-English summary. The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

Deployer

If your company uses an AI system at work, you are probably a deployer. Purely personal, non-professional use is excluded. Deployer duties are lighter than provider duties but real for high-risk systems: use it as instructed, assign competent human oversight, keep logs, and inform affected people. In practice: An HR team using a third-party CV screening tool is a deployer of a high-risk system. Plain-English summary of Article 3(4). The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

Downstream Provider

Downstream providers build products on top of another party’s GPAI model. The Act obliges the upstream model provider to supply the technical information downstream providers need to meet their own obligations. It is the mechanism that makes the value chain legible instead of a black box. In practice: Building and selling a legal assistant on top of someone else’s API. Plain-English summary of Article 3(68). The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

Emotion Recognition System

Article 3(39) defines it and Article 5 prohibits its use at work and in education, with narrow exceptions for medical and safety purposes. Elsewhere it is generally high-risk. The scientific basis for inferring emotion from faces or voice is contested, which is part of why the restriction is strict. In practice: Software claiming to score candidate enthusiasm from a video interview. Plain-English summary of Article 3(39) and Article 5. The binding text is Regulation (EU) 2024/1689. ...