Browse guides

Governance & Regulation articles

21
Governance & Regulation

EU AI Act

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in phases: prohibited practices from February 2025, general-purpose AI model obligations from August 2025, and the bulk of the framework from August 2026. It sorts systems into unacceptable, high, limited, and minimal risk, with obligations scaling accordingly. It reaches non-EU providers whose output is used in the EU. In practice: A US SaaS company selling into the EU is in scope regardless of where it is incorporated. ...

Governance & Regulation

General-Purpose AI Model

Article 3(63) covers models trained at scale, typically with self-supervision, that are broadly capable and integrable downstream. Models used purely for research or pre-market prototyping are excluded. GPAI providers carry documentation, copyright-policy, and training-data-summary obligations, with heavier duties where the model is deemed to carry systemic risk. In practice: A general text model sold via API and embedded into a thousand different products. Plain-English summary of Article 3(63). The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

High-Risk AI System

High-risk covers AI used as a safety component of a regulated product, plus the Annex III list: biometrics, critical infrastructure, education, employment, essential services, law enforcement, migration, and justice. High-risk is not banned; it is regulated. Obligations include risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness, and conformity assessment. In practice: Software that scores job applicants or grades exams sits in Annex III. Plain-English summary. The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

Human Oversight

Article 14 requires high-risk systems to be designed so that natural persons can oversee them effectively — including understanding capacity and limits, watching for automation bias, interpreting output, deciding not to use it, and intervening or halting operation. Oversight must be designed into the system, not asserted in a policy. In practice: A visible stop control and a reviewer who is empowered and trained to use it. Plain-English summary of Article 14. The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

ISO/IEC 42001

ISO/IEC 42001 specifies requirements for establishing and improving an AI management system, in the same family as ISO 27001 for security. Being certifiable is the point: it gives procurement teams something to ask for. It complements rather than replaces the EU AI Act, which certification alone does not satisfy. In practice: An enterprise RFP asking whether your AI management system is certified.

Governance & Regulation

NIST AI Risk Management Framework

Published by NIST in January 2023, the AI RMF is guidance rather than law, and it is sector-agnostic. Its four functions give teams a structure for identifying context, measuring risk, and acting on it. It has become the de facto reference for AI governance programmes, including at companies with no US obligations, because it is practical and free. In practice: Using Govern-Map-Measure-Manage as the skeleton of an internal AI policy. ...

Governance & Regulation

Post-Market Monitoring

Article 3(25) and Article 72 require providers to collect and review experience from deployed systems so problems trigger corrective action rather than accumulating. It closes the loop that shipping usually leaves open, and it pairs with serious-incident reporting duties. In practice: A documented plan for collecting field performance data and acting on it. Plain-English summary. The binding text is Regulation (EU) 2024/1689.

Governance & Regulation

Prohibited AI Practice

Article 5 bans a defined list, including manipulative techniques that materially distort behaviour and cause harm, exploitation of vulnerabilities, social scoring by or on behalf of public authorities, untargeted scraping of facial images to build recognition databases, and emotion inference in workplaces and schools — with narrow carve-outs. These apply regardless of risk assessment: there is no compliance route. In practice: Emotion recognition on employees during work is prohibited, not merely high-risk. ...

Governance & Regulation

Provider

Provider is the role carrying the heaviest obligations. It is defined by what you do, not what you build: put your own brand on someone else’s model and you can become the provider of that system. Substantially modifying a high-risk system can also transfer provider status to you. In practice: White-labelling a third-party model as ‘YourCo AI’ can make you the provider. Plain-English summary of Article 3(3). The binding text is Regulation (EU) 2024/1689. ...

Governance & Regulation

Systemic Risk

Article 3(65) ties systemic risk to GPAI models whose capabilities match or exceed the current state of the art and whose reach could significantly affect the Union market. Designation brings extra duties: adversarial testing, incident reporting, cybersecurity, and evaluation. It is the Act’s answer to frontier models. In practice: A model crossing the compute threshold triggers additional obligations for its provider. Plain-English summary of Article 3(65). The binding text is Regulation (EU) 2024/1689. ...