AI Governance & Compliance

What AI governance means.

AI governance is the set of structures, rules and responsibilities that determine how an organisation makes decisions about its AI systems. Compliance is one part of governance — the part that concerns legal obligations. This page walks through the evidence on the governance gap, what governance covers, what the EU AI Act requires, how governance operates in practice, and the questions an organisation should be able to answer.

Governance lifecycle — an explanatory model, not an official framework
SYSTEM
What system
are we talking about?
→
PURPOSE
What is it
supposed to do?
→
OWNER
Who is
responsible?
→
RULES &
CONTROLS
What policies,
boundaries apply?
→
EVIDENCE
How do we know
it works as intended?
→
REVIEW
When and how
do we revisit?

This lifecycle is a way of thinking about governance, not a certification standard. It says: before you can govern an AI system, you need to know it exists and what it is meant to do. Only then can you assign responsibility, set rules, collect evidence and schedule review. Skipping early steps — for example, setting rules for systems whose purpose has never been clearly defined — produces governance that looks complete on paper but does not connect to how the system actually operates.

Governance

How does the organisation make, document and review decisions about AI systems?

Compliance

Does the system meet the legal and regulatory obligations that apply to it?

Governance and compliance support each other. Good governance makes compliance easier because the relevant information — which systems exist, what they do, who owns them, how they are controlled — is already available. Compliance alone, without governance, tends to become a document-production exercise: the required paperwork exists, but the organisation does not have a reliable way to know whether it reflects reality. This page looks at both dimensions, separately and together.

Governance Gap

What does the data say about the gap between AI use and AI governance?

Multiple surveys across different geographies and populations report a consistent pattern: organisations are adopting AI faster than they are building the governance structures to manage it. The gap is not hypothetical — it appears in data from consulting firms, industry associations and academic research.

74% / 21%

of organisations say AI governance is important, but only 21% have mature governance in place.

Deloitte's 2024 "State of AI Governance" report, based on a survey of organisations across multiple industries, found that 74% of respondents rated AI governance as important or very important to their organisation. However, only 21% reported having mature governance structures in operation. The gap between recognising the need and having functioning governance is the central finding of the report.

This is a survey of organisational self-assessment, not an audit. Organisations may overestimate or underestimate their own maturity. The 74% figure measures stated importance, not verified action. The 21% figure measures self-reported maturity against criteria defined by the survey.

SURVEY · DELOITTE · GLOBAL · 2024 Deloitte — State of AI Governance
47% Partial governance

Organisations that reported having some AI governance measures in place, but acknowledged they were incomplete or inconsistently applied.

40% No or ad-hoc governance

Organisations that reported having little to no formal AI governance, relying instead on ad-hoc decisions or individual manager discretion.

A KPMG study conducted with the University of Melbourne examined AI governance maturity across organisations in multiple sectors. The research found that nearly half of organisations had some governance measures in place but considered them incomplete, while two in five had little to no formal governance. Only a minority reported mature, comprehensive governance. The study highlighted that many organisations treat governance as a compliance checklist rather than an operational capability — policies exist, but they are not embedded in how AI systems are actually built, deployed and reviewed.

RESEARCH · KPMG / UNIVERSITY OF MELBOURNE · 2024
8% Comprehensive governance

German companies that reported having a comprehensive, organisation-wide AI governance framework in place.

43% No governance at all

German companies that reported having no formal AI governance measures whatsoever.

Bitkom, Germany's digital industry association, surveyed companies across sectors about their AI governance readiness. The results showed a striking gap: fewer than one in ten had comprehensive governance, while more than four in ten had none at all. The remaining respondents fell somewhere in between — partial measures, pilot programmes or governance limited to specific departments. The Bitkom data is especially relevant for organisations operating in Germany, where the EU AI Act applies directly.

SURVEY · BITKOM · GERMANY · 2024

Having a policy is not the same as having governance.

EY's research on AI governance found a recurring pattern: organisations that had published an AI policy or an ethics statement often believed their governance was complete. But when researchers looked at whether those policies were connected to operational controls — system inventories, role assignments, approval processes, review cycles — the connection was often absent. The policy existed. The governance did not.

This distinction matters because a policy that is not linked to specific systems, specific owners and specific controls is a statement of intent, not a governance structure. It may influence behaviour. It does not, by itself, provide assurance that AI systems are operating within defined boundaries. EY's finding is consistent with other governance research: the gap between documented policy and operational practice is one of the most common failure modes in AI governance.

RESEARCH · EY · GLOBAL · 2024
Research note

The surveys cited in this section use different methodologies, different populations and different definitions of "governance maturity." They should not be combined into a single composite number. What they share is a consistent pattern: across different countries, industries and survey designs, the gap between AI adoption and AI governance is large and persistent. For a fuller discussion of how to read these figures, see the Research Notes section at the end of this page.

What Governance Covers

Six dimensions of AI governance.

AI governance is not a single activity. It is a set of related questions that span the full lifecycle of an AI system — from knowing it exists to reviewing whether it should continue. The six dimensions below describe what governance needs to cover for each AI system an organisation uses or builds.

01 — System

What is the system?

An organisation cannot govern what it does not know about. The first governance question is an inventory question: which AI systems exist, where do they run, who provides them, and how are they classified? This includes systems the organisation builds, systems it buys, systems embedded in tools that were not purchased as "AI" and systems employees use on their own initiative.

02 — Purpose

What is the system meant to do?

Purpose determines which rules apply and which risks are relevant. A system that recommends products carries different governance requirements from one that assesses creditworthiness or scans job applications. Purpose must be documented clearly enough that someone reviewing the system a year later can understand what it was intended to do and under which assumptions.

03 — Owner

Who is responsible?

Every AI system needs a named owner who is accountable for its governance. The owner may not be the person who built or deployed the system. Their role is to ensure that the governance questions are asked and answered, that documentation is maintained, and that the system is reviewed on a defined schedule. Without a named owner, governance remains an organisational aspiration rather than an assigned responsibility.

04 — Data & Access

What does the system use, and who can reach it?

This dimension covers the data the system was trained on, the data it processes in operation, and the access controls around both. It also covers who can modify the system — its configuration, its training data, its prompts, its connected tools. Access governance is as important as data governance because a system that is well-documented but can be changed by anyone without review is not governed.

05 — Decisions & Actions

What does the system decide or do?

Governance needs to address what the system can decide autonomously, what it can recommend, what actions it can take, and what requires human approval. The distinction matters because the governance of a system that drafts text for human review is different from the governance of a system that can send communications, modify records or trigger transactions without human involvement.

06 — Change & Review

When and how is the system reviewed?

Governance is not a one-time assessment. Models are updated, data changes, tools are added, use cases evolve. The governance structure needs to define: how often the system is reviewed, what triggers an out-of-cycle review, who conducts it, and what happens when the review finds something that needs to change. A system that was low-risk when first deployed may not stay low-risk if its use, its data or its capabilities change.

These dimensions are interconnected, not sequential.

A change in purpose (dimension 02) may affect which rules apply. A change in data access (dimension 04) may affect the system's risk classification. A change in ownership (dimension 03) may affect how reviews are conducted. Governance structures need to recognise these connections, not treat each dimension as an independent checklist item.

AI Act & Compliance

What does the EU AI Act require?

The EU AI Act (Regulation 2024/1689) is the first comprehensive AI regulation in a major jurisdiction. It creates a risk-based framework with obligations that vary by the role an organisation plays and the classification of the AI system. This section covers the key concepts, the implementation timeline and the relationship with existing regulation.

Provider and Deployer are two different roles.

The AI Act distinguishes between the organisation that develops an AI system (provider) and the organisation that uses it in a professional context (deployer). A single organisation can be both — building some AI systems and using others. The obligations differ by role.

Providers carry the primary obligations for high-risk AI systems: conformity assessment, technical documentation, risk management, quality management, and registration in the EU database. Deployers carry operational obligations: ensuring human oversight is in place, monitoring the system's operation, keeping records, and informing affected people when the system is used. Both roles carry AI literacy obligations under Article 4.

Timeline as of August 2026 — reflecting the current implementation schedule

The AI Act phases in over several years.

1 August 2024 AI Act entered into force. The Act became EU law, starting the countdown for the phased obligations.
2 February 2025 AI Literacy (Article 4) — obligation took effect. Organisations must ensure that staff who operate or use AI systems have a sufficient level of AI literacy. Prohibitions on unacceptable-risk AI practices also took effect on this date.
2 August 2025 General-Purpose AI (GPAI) rules took effect, including transparency obligations for GPAI model providers. Penalties regime became applicable. Member States were required to have notified the Commission of their national competent authorities.
2 August 2026 High-Risk AI (Annex III) — obligations for high-risk AI systems listed in Annex III took effect. This includes systems used in education, employment, essential services, law enforcement, migration and administration of justice. The Commission published the high-risk AI system definition and supporting guidelines.
2 August 2027 High-Risk AI (Annex I) — obligations for high-risk AI systems that are safety components of products covered by EU harmonisation legislation (machinery, toys, medical devices, etc.) took effect.

The phased timeline means that different obligations become applicable at different dates. An organisation using an Annex III high-risk AI system had obligations from August 2026. An organisation using a system classified as high-risk only under Annex I had until August 2027. AI literacy obligations have been in effect since February 2025. Organisations should determine which obligations apply to them based on the specific systems they provide or deploy, not on a general impression of when "the AI Act applies."

AI Literacy (Article 4) is a standing obligation.

Article 4 requires providers and deployers to ensure that staff who operate or use AI systems have a sufficient level of AI literacy. "Sufficient" is context-dependent — it takes into account the person's technical knowledge, experience, education and training, and the context in which the AI system is used. A person using a consumer-grade chatbot needs a different level of literacy from someone operating a high-risk AI system in a clinical setting.

Article 4 is not a one-time training requirement. It is a standing obligation: as systems change, as staff change roles, and as the organisation's AI use evolves, the literacy obligation continues. The European Commission has published guidance through the AI Act Service Desk on what constitutes sufficient AI literacy for different contexts.

EU AI Act — Article 4

Transparency (Article 50) applies to specific use cases.

Article 50 requires that people are informed when they are interacting with an AI system (such as a chatbot), when an AI system generates or manipulates content (such as deepfakes), and when an AI system is used for emotion recognition or biometric categorisation. The transparency obligation is not a general "explain everything" requirement — it applies to specific interactions and specific types of content.

For deployers of AI systems that interact directly with people, the practical question is: does the person know they are interacting with AI, and if not, should they? The answer to the second question is determined by the use case, not by personal preference. Some interactions — customer service chatbots, AI-generated content published as news — carry an obligation to disclose. Others — an AI-assisted spelling checker in a word processor — generally do not.

EU AI Act — Article 50

High-risk AI classification depends on the system's purpose.

The AI Act defines two routes to high-risk classification. Annex I covers AI systems that are safety components of products already regulated under EU harmonisation legislation — medical devices, machinery, toys, lifts, radio equipment and others. Annex III covers AI systems used in specific domains: biometrics (under certain conditions), critical infrastructure, education and vocational training, employment and worker management, access to essential services (credit, insurance, public benefits), law enforcement, migration and border control, and administration of justice and democratic processes.

Not every AI system in these domains is automatically high-risk. The Act uses a significance test: the system must be intended to be used as a safety component, or its output must be intended to substantially influence a decision. A system that performs a purely ancillary or preparatory function in one of these domains is not necessarily high-risk. The European Commission has published guidelines to help organisations determine whether their specific systems fall within the high-risk classification.

The AI Act and the GDPR are separate instruments that can both apply.

The AI Act and the General Data Protection Regulation (GDPR) are distinct legal instruments with different scopes. The GDPR governs the processing of personal data. The AI Act governs the placing on the market and use of AI systems. A single AI system can be subject to both — for example, an AI system used in employment decisions may be high-risk under the AI Act and also process personal data under the GDPR.

The two instruments interact in several ways. The AI Act requires that high-risk AI systems using personal data for training, validation or testing comply with GDPR requirements for those activities. The AI Act's transparency obligations (Article 50) operate alongside the GDPR's transparency requirements (Articles 13 and 14), not instead of them. And the GDPR's provisions on automated decision-making (Article 22) remain fully applicable — the AI Act does not modify or replace them.

Compliance with one does not automatically mean compliance with the other. An organisation that has a lawful basis for processing personal data under the GDPR still needs to meet the AI Act's requirements for the specific AI system. An organisation that meets the AI Act's technical documentation requirements still needs to comply with the GDPR's data protection principles. The two frameworks are complementary, not interchangeable.

This page is not legal advice.

The information in this section describes the structure and general requirements of the EU AI Act for educational purposes. It does not constitute legal advice about whether a specific AI system is subject to specific obligations. Organisations should consult qualified legal counsel for compliance assessments. The official source for the EU AI Act is Regulation (EU) 2024/1689, published in the Official Journal of the European Union. The European Commission's AI Act Service Desk provides guidance on implementation.

Governance in Practice

How does governance operate day to day?

Governance is not a document. It is a set of operating practices that connect policy to action. This section describes what governance looks like when it is working — the ongoing chain of activities that turn "we should have governance" into "we know what our AI systems are doing, who is responsible and whether they are operating as intended."

Explanatory model — not a prescriptive framework

The operating governance chain

IDENTIFY

Know what AI systems exist.

ASSIGN

Name the owner.

CLASSIFY

Determine the risk and regulatory category.

CONTROL

Apply rules, boundaries and approvals.

RECORD

Keep evidence the controls are working.

REVIEW

Revisit on schedule and on trigger.

This is not a one-time sequence. It is a loop. A review may lead to reclassification, which may lead to new controls, which generate new evidence, which feeds the next review. The chain works only when each step is connected to the next. A system inventory that is not connected to ownership assignments is a list, not governance. A risk classification that is not connected to controls is an assessment, not governance. Controls that are not connected to evidence collection are instructions, not governance.

The NIST AI RMF is a voluntary framework — not law.

The NIST AI Risk Management Framework (AI RMF 1.0, published January 2023) is a voluntary guidance document developed by the U.S. National Institute of Standards and Technology. It is not a regulation and carries no legal obligation in any jurisdiction. It is mentioned here because it is widely referenced in AI governance discussions and because its core functions — Govern, Map, Measure, Manage — provide a useful structure for thinking about AI risk management, whether or not an organisation is subject to the EU AI Act.

The NIST AI RMF and the EU AI Act are fundamentally different instruments. The AI RMF is voluntary guidance — an organisation can adopt it, adapt it or ignore it. The EU AI Act is binding law — an organisation that falls within its scope must comply. The AI RMF's concepts (govern, map, measure, manage) can support compliance with the AI Act, but using the AI RMF does not, by itself, satisfy any AI Act obligation. The distinction between voluntary guidance and legal requirement is essential to accurate governance discussions.

Governance needs infrastructure, not only rules.

The governance gap described in Section 2 exists in part because organisations publish policies without building the infrastructure to make them operational. A policy that says "AI systems must be documented" requires a place where documentation lives, a process for creating it, a person responsible for maintaining it and a schedule for reviewing it. Without that infrastructure, the policy is a statement of intent.

The infrastructure does not need to be elaborate. For a small organisation with a handful of AI systems, a shared document that lists the systems, their purposes, their owners and their review dates may be sufficient. For a large organisation with hundreds of systems across multiple departments, the infrastructure needs to scale accordingly. The principle is the same: governance infrastructure is the mechanism through which policy becomes practice. Without it, the gap between "we have a policy" and "we know what is happening" remains.

Governance is proportional, not absolute.

The level of governance should reflect the level of risk. A system that drafts internal meeting notes needs different governance from a system that makes decisions about access to services. Governance that treats every AI system as if it were high-risk is wasteful. Governance that treats every AI system as if it were low-risk is negligent. The skill is in matching the governance to the system — and having a process for revisiting that match when the system or its use changes.

Company Self-Check

What should a company be able to answer?

An organisation does not need every employee to understand every detail of every AI governance framework. But for AI systems that affect customers, employees, business decisions or regulatory standing, some basic governance questions should have clear answers. This is not a compliance checklist or a maturity score — it is a set of questions that help identify where the governance picture is incomplete.

01 — Visibility

Do we know what AI systems we use?

Is there a current inventory of AI systems the organisation uses or builds?
This includes systems developed internally, systems purchased from vendors, AI features embedded in tools that were not bought as "AI," and tools employees use on their own initiative.
Is the inventory reviewed and updated on a defined schedule?
An inventory that was last updated 18 months ago may not reflect what the organisation is actually using today.
Does the inventory distinguish between different types of AI systems?
A classification that puts a customer-facing decision system and an internal spell-checker in the same category does not support useful governance.
02 — Ownership

Does every AI system have a named owner?

Is there a person or role accountable for the governance of each system?
The owner does not need to be the person who built or deployed the system. Their role is to ensure governance questions are asked, answered and maintained.
Do owners know they are owners?
Governance assignments that exist on an org chart but not in the awareness of the person assigned do not function as governance.
Is there a process for transferring ownership when roles change?
A system whose named owner left the organisation six months ago is unowned in practice, regardless of what the documentation says.
03 — Purpose & Impact

Is each system's purpose documented and classified?

Is the purpose of each AI system documented clearly enough to assess which rules apply?
"Improves customer experience" is not a purpose statement that supports governance. "Recommends products based on purchase history" is.
Has each system been assessed for its regulatory classification?
Under the EU AI Act, this means determining whether the system falls within Annex I, Annex III, limited-risk or minimal-risk categories — or is not covered by the Act at all.
Is the classification reviewed when the system's use, capabilities or data change?
A system that was classified as low-risk at deployment may not stay low-risk if its scope expands.
04 — Data & Access

What does each system use, and who can change it?

Is the data each system processes documented — training data, operational inputs, outputs?
Governance needs to know what information flows through the system, not only what the system is called.
Is personal data processing identified and linked to the GDPR record of processing activities?
A system that processes personal data should appear in the organisation's data protection documentation, not only in its AI inventory.
Who can modify the system — its configuration, its training data, its prompts, its connected tools?
Access governance is a governance dimension, not only a security one. A system that can be changed by anyone with the URL is not governed.
05 — People

Do the people who use and manage AI systems know enough?

Have staff who operate or use AI systems received appropriate AI literacy training?
This is an Article 4 obligation under the EU AI Act. The level of literacy should reflect the person's role and the systems they use.
Is there a way for staff to report concerns about an AI system?
Governance can only work when information flows up as well as down. If staff see something concerning and do not know where to report it, the governance structure has a blind spot.
Do procurement and legal teams know to flag AI systems in vendor contracts?
AI governance needs to reach procurement processes. A system purchased through a standard software contract may carry AI Act obligations that were not considered at the time of purchase.
06 — Rules

Are rules connected to systems?

Does the organisation have documented AI governance policies?
The question is not only whether policies exist, but whether they are specific enough to guide decisions about individual systems.
Are the policies connected to the system inventory?
A policy that says "high-risk AI systems must undergo conformity assessment" only works if someone can identify which systems are high-risk.
Are there defined approval processes for deploying new AI systems or changing existing ones?
Governance includes gates. Without them, every deployment is a governance decision made by the person who deployed it.
07 — Evidence

Can the organisation show that governance is working?

Is there documentation that shows each system's governance status at a point in time?
Governance that cannot be demonstrated is indistinguishable from governance that does not exist — at least from the perspective of an auditor, a regulator or a new person joining the team.
Are review decisions, classification changes and incident responses recorded?
The record is the evidence that governance was applied, not only described.
Can the organisation produce governance evidence without a last-minute scramble?
If producing governance documentation for a specific system requires weeks of searching, the governance infrastructure is not yet operational.
08 — Change

Does governance keep up with change?

Is there a defined review cycle for each system?
The review interval should reflect the system's risk level. A high-risk system reviewed once every two years may be under-reviewed. A low-risk system reviewed monthly may be over-reviewed.
What triggers an out-of-cycle review?
Model updates, data changes, new tools, expanded use cases, incidents, regulatory changes and organisational changes can all trigger a need for review. The triggers should be defined, not improvised each time.
When a review finds something that needs to change, who acts on it and by when?
A review that identifies issues but assigns no action and no deadline is documentation, not governance.
If many of these questions are difficult to answer, the governance picture is incomplete.

That does not automatically mean the organisation is non-compliant or that its AI systems are unsafe. It means that important properties of the AI systems the organisation uses — what they are, who owns them, how they are classified, what rules apply, what evidence exists and how they are reviewed — are not yet fully documented or operational. The purpose of this self-check is to make those gaps visible enough that the organisation can decide what to address and in which order.

How to Read the Data

How to read the numbers on this page.

The research on this page comes from different sources using different methods. Some survey security and technology leaders. Some survey general business populations. Some conduct academic research on governance maturity. The evidence is useful because the methods illuminate different parts of the same subject. The figures should not be mixed as if they were all measuring the same population with the same definition of governance.

Survey data is not the same as audit data.

The Deloitte, Bitkom and EY figures come from surveys in which organisations self-assess their governance maturity. Self-assessment can overestimate maturity (organisations believe their governance is more complete than it is) or underestimate it (organisations with higher standards rate themselves more critically). Survey data tells us what organisations report about themselves. It does not tell us what an independent audit would find.

Different surveys use different definitions of "governance."

One survey may define governance maturity in terms of documented policies. Another may define it in terms of operational controls, review cycles and evidence collection. A third may define it in terms of board-level oversight. The 74% in one survey and the 8% in another are not measuring the same thing with different results — they are measuring different things. Comparing them directly as if they were on the same scale is misleading.

Geography and industry composition affect the numbers.

The Bitkom survey covers German companies and reflects the regulatory context of the EU. The Deloitte survey covers a global population and includes organisations in jurisdictions where AI regulation is less developed. Differences between survey results partly reflect real differences in governance maturity and partly reflect differences in who was asked and what regulatory environment they operate in.

Policies and governance are not the same thing — and surveys do not always distinguish them.

EY's finding that organisations confuse having a policy with having governance is itself a methodological caution. If survey respondents answer "yes, we have AI governance" because they have published an AI ethics statement, the survey may overstate governance maturity relative to a definition that requires operational controls. Readers should check what a survey counted as "governance" before comparing its results with another survey that may have used a different definition.

The EU AI Act is binding law; the NIST AI RMF is voluntary guidance.

These are fundamentally different categories of instrument. The AI Act creates legal obligations for organisations that fall within its scope. The NIST AI RMF provides a framework that organisations can choose to adopt, adapt or ignore. Both are referenced in governance discussions, but they operate on different planes. Using the NIST AI RMF may help an organisation structure its thinking about AI risk. It does not satisfy any obligation under the AI Act. Conflating the two — treating voluntary guidance as if it were law, or treating law as if it were optional — is one of the most common inaccuracies in AI governance writing.

Governance maturity is not a single number.

An organisation may have excellent visibility into its AI systems but weak review processes. It may have strong policies but no owner assignments. It may have comprehensive documentation for internally built systems but no governance over AI features in purchased tools. A single maturity score — "47% of organisations have partial governance" — is a summary that hides variation across dimensions. The self-check section of this page asks questions across eight dimensions precisely because governance is not one thing that can be captured in a single figure.

Sources & Further Reading

Source policy

For important factual claims, this page prioritises:

  1. Original research and survey data with published methodology
  2. Official legal texts (EU AI Act, GDPR)
  3. European Commission and AI Office publications
  4. National and international standards bodies (NIST, CEN/CENELEC, ISO)
  5. Industry association surveys with transparent methodology

Statistics should show the year, geography and study population where that information is available. Voluntary frameworks should be distinguished from legal obligations. A source should never be used to support a stronger claim than it actually measured.

Governance gap — survey data

SURVEY · GLOBAL · 2024

Deloitte — State of Ethics & Trust in Technology: AI Governance

Survey examining organisational AI governance maturity across industries. Reports 74% of organisations rate AI governance as important; 21% report mature governance in place. Used for: governance gap headline figures in Section 2.

Original source
RESEARCH · AUSTRALIA / GLOBAL · 2024

KPMG / University of Melbourne — AI Governance Maturity Study

Academic and industry research on AI governance maturity across sectors. Reports 47% with partial governance and 40% with none or ad-hoc. Used for: governance maturity distribution in Section 2.

SURVEY · GERMANY · 2024

Bitkom — AI Governance in German Companies

Survey of German companies on AI governance readiness. Reports 8% with comprehensive governance and 43% with none. Used for: Germany-specific governance gap data in Section 2.

RESEARCH · GLOBAL · 2024

EY — AI Governance: From Policy to Practice

Research on the gap between AI policy publication and operational governance. Identifies the pattern of organisations equating having a policy with having governance. Used for: policy vs governance distinction in Section 2.

EU AI Act — official sources

LEGISLATION · EU · 2024

Regulation (EU) 2024/1689 — The EU AI Act

Full text of the AI Act as published in the Official Journal of the European Union. The definitive legal source for all AI Act obligations. Used for: all AI Act content in Section 4.

EUR-Lex — Official text
OFFICIAL GUIDANCE · EU · 2025–2026

European Commission — AI Act Service Desk

Official Commission portal providing guidance, timelines, FAQs and implementation support for the AI Act. Covers classification guidance, compliance steps and the phased implementation schedule. Used for: implementation timeline, high-risk classification guidance and Article 4 interpretation in Section 4.

AI Act Service Desk
REFERENCE · EU · ONGOING

EU AI Act — Annotated Reference (artificialintelligenceact.eu)

Independent annotated version of the AI Act with article-by-article commentary, annex references and cross-references to related legislation. Used for: article-level references in Section 4.

artificialintelligenceact.eu
LEGISLATION · EU · 2016

Regulation (EU) 2016/679 — General Data Protection Regulation (GDPR)

The EU's data protection regulation. Referenced in the AI Act in relation to personal data processing for AI systems. Used for: AI Act & GDPR relationship discussion in Section 4.

EUR-Lex — Official text

Governance frameworks and further reading

VOLUNTARY FRAMEWORK · US · 2023

NIST AI Risk Management Framework (AI RMF 1.0)

Voluntary guidance developed by the U.S. National Institute of Standards and Technology. Organised around four core functions: Govern, Map, Measure, Manage. Not a legal obligation in any jurisdiction. Used for: governance framework reference in Section 5.

NIST AI RMF
STANDARD · INTERNATIONAL · 2023

ISO/IEC 42001:2023 — AI Management System

International standard for establishing, implementing, maintaining and improving an AI management system. Provides a certifiable framework for AI governance. Referenced in this page as a relevant standard for organisations seeking structured governance approaches.