Guide · 9 min read · Updated 2026-06-16

AI Governance & EU AI Act Compliance: A Practical Guide

The EU AI Act is the European Union's regulation on artificial intelligence. It is the first comprehensive AI law anywhere in the world, and it is already shaping how organisations design, deploy, and govern AI systems globally.

The Act classifies AI systems by risk level, bans certain uses outright, and imposes transparency and compliance obligations on providers and deployers. It takes a risk-based approach similar to data protection law (GDPR), but with more specific technical requirements.

This guide covers the key provisions, risk categories, compliance obligations, and how AI governance platforms can help you stay compliant.

What is AI governance?

AI governance is the framework of policies, processes, and oversight mechanisms that ensure AI systems are developed and used responsibly, ethically, and in compliance with applicable regulations. It covers the entire lifecycle of an AI system, from design and data collection through deployment, monitoring, and decommissioning.

At its core, AI governance addresses three questions: who is responsible for AI decisions, how are risks managed, and how is transparency maintained for affected stakeholders. It draws from information security frameworks like ISO 27001 but adds specific considerations for AI: bias and fairness, explainability, data provenance, model drift, and human oversight.

For organisations, a mature AI governance program typically includes: an AI policy approved by leadership, a risk assessment process for all AI systems, designated roles (such as a Chief AI Officer or AI governance committee), ongoing monitoring and audit procedures, and clear incident response protocols for AI-related failures.

What is the EU AI Act?

What is the EU AI Act?

The EU AI Act is a regulation passed by the European Parliament that establishes a legal framework for the development, deployment, and use of artificial intelligence within the European Union. It applies to providers and deployers of AI systems, regardless of where they are located, if their output is used in the EU.

The regulation was formally adopted in 2024 and entered into force in August 2024. Most provisions apply from August 2026, with prohibitions on unacceptable-risk AI applying from February 2025.

The Act covers a broad range of AI systems - from chatbots and recommendation engines to biometric identification and critical infrastructure AI. It does not apply to military and defence purposes, and personal non-commercial use is generally exempt.

The risk-based approach

The risk-based approach

The AI Act uses a four-tier risk classification system. This is the core architecture of the regulation, and it determines what obligations apply to each AI system.

The four tiers are: Unacceptable Risk (banned), High Risk (strict obligations), Limited Risk (transparency obligations), and Minimal Risk (no obligations, voluntary codes of conduct encouraged).

This tiered approach means that most AI applications face no new requirements, while the highest-risk systems face the most stringent rules. The goal is to protect citizens while allowing innovation to flourish.

Unacceptable Risk: Banned AI Systems

These are AI systems considered too dangerous for any use in the EU. The ban includes: social scoring systems by governments (similar to what China has been criticised for), real-time remote biometric identification in publicly accessible spaces for law enforcement (with narrow exceptions for targeted searches for missing persons, prevention of specific terrorist threats, or prosecution of serious crimes), emotion recognition in workplaces and educational institutions, untargeted scraping of facial images for facial recognition databases, and predictive policing based solely on profiling individuals or assessing personality traits.

The social scoring ban is particularly significant because it targets a specific use case of AI that governments have used to rate citizens. The emotion recognition ban reflects concerns about the scientific validity and potential for abuse of emotion recognition technology.

High Risk: Strict Obligations

High Risk: Strict Obligations

High-risk AI systems face the most substantial compliance requirements. These include AI used in: critical infrastructure (transport, energy, water, gas), education and vocational training (grading, admission, personalised learning), employment (candidate screening, task allocation, performance evaluation), essential private and public services (credit scoring, emergency dispatch, routing), law enforcement (risk assessment of individuals, evidence evaluation), migration and border control (verifying authenticity of travel documents, processing asylum applications), and the administration of justice (analyzing facts and evidence, researching case law).

High-risk AI systems must meet requirements for: risk management systems, data quality and governance, technical documentation, transparency and provision of information to deployers, human oversight, accuracy, cybersecurity and robustness, and post-market monitoring. Providers must also conduct conformity assessments before placing systems on the market.

Limited Risk: Transparency Obligations

AI systems with limited risk face transparency obligations. The main category is AI systems that interact with humans, such as chatbots, customer service bots, and emotion recognition systems used outside of workplaces and schools.

The key requirement is that users must be informed that they are interacting with an AI system. This allows users to make informed decisions and exercise their autonomy. Deep fake content (AI-generated or manipulated audio, video, or image content) must also be clearly labelled as artificially manipulated.

This is a relatively light touch - the main obligation is disclosure, not technical compliance.

Minimal Risk: Free Use

The vast majority of AI systems fall into this category. Examples include AI-enabled video games, spam filters, and most recommendation systems. These systems face no obligations under the AI Act.

The Act encourages voluntary codes of conduct for minimal-risk AI, and providers can choose to voluntarily comply with the high-risk requirements for their systems.

This category is designed to leave room for innovation while focusing regulatory attention where it is most needed.

Key AI governance frameworks

Beyond the EU AI Act, several frameworks and standards shape how organisations approach AI governance. Understanding these helps build a comprehensive programme that works across jurisdictions.

The NIST AI Risk Management Framework (AI RMF) is a US-developed framework that provides a structured approach to managing AI risks. It covers four functions: Map (understand your AI context), Measure (assess risks), Manage (prioritise and address risks), and Govern (establish oversight and accountability). The AI RMF is voluntary and focuses on trustworthiness rather than compliance, making it a practical complement to regulatory requirements.

ISO 42001 is the AI management system standard for organisations that develop, provide, or use AI systems. It follows the same management-system rhythm as ISO 27001, making it familiar to organisations already certified under that standard. ISO 42001 requires organisations to establish an AI policy, conduct AI risk assessments, implement controls, and demonstrate continual improvement. Our ISO 42001 hub turns that structure into practical requirement and control-area pages.

Together, the EU AI Act (regulatory), NIST AI RMF (practical risk management), and ISO 42001 (management system certification) form a layered approach to AI governance. Organisations can use the NIST RMF to identify and manage risks, ISO 42001 to structure their management system, and the EU AI Act as the regulatory baseline for systems affecting EU citizens.

Obligations by role

The AI Act assigns different obligations depending on your role in the AI supply chain. The main roles are: Provider (develops or places an AI system on the market), Deployer (uses an AI system under their authority), Distributor (makes an AI system available without changing its intended purpose), Importer (brings an AI system from outside the EU into the EU), and Product Manufacturer (integrates AI into a product and places it on the market).

Providers bear the heaviest burden: they must establish a risk management system, ensure data quality, create technical documentation, implement transparency measures, enable human oversight, and conduct conformity assessments. Deployers must use the system according to instructions, monitor operation, ensure human oversight, keep logs, inform affected persons, and conduct fundamental rights impact assessments for high-risk systems.

What compliance looks like in practice

What compliance looks like in practice

For organisations deploying high-risk AI systems, compliance involves several concrete steps. First, you need to determine whether your AI system is classified as high-risk under the Act. This requires understanding the intended purpose and the context of use.

Next, you need to establish processes for risk management, data governance, and documentation. This often means creating or updating existing governance frameworks to include AI-specific requirements. Many organisations are finding that their existing ISO 27001 or SOC 2 programs provide a strong foundation for AI governance.

Third, you need to implement monitoring and reporting mechanisms. This includes logging system outputs, tracking incidents, and conducting regular audits. AI governance platforms can automate much of this work by providing structured frameworks, continuous monitoring, and evidence collection.

Finally, you need to ensure ongoing compliance as the regulation evolves. The EU AI Act is still being implemented, and detailed technical standards are still being developed by the European Committee for Standardisation (CEN, CENELEC, and ETSI).

How AI governance platforms help

Several compliance automation platforms are adding AI governance capabilities to their existing offerings. These platforms can help with: mapping AI systems to regulatory requirements, collecting and maintaining evidence of compliance, monitoring AI systems for drift or incidents, generating documentation and reports, and managing the lifecycle of AI governance policies.

The same platforms that help with ISO 27001, SOC 2, and PCI DSS compliance are increasingly adding AI-specific modules. This makes sense because AI governance shares many requirements with traditional information security governance: risk assessment, documentation, evidence collection, and continuous monitoring.

When evaluating AI governance capabilities, look for platforms that offer: automated evidence collection for AI-specific controls, integration with your existing cloud and identity systems, support for multiple regulatory frameworks (not just the AI Act), and a user-friendly interface that non-technical team members can use.

Global impact and extraterritorial reach

The EU AI Act has significant global impact because of its extraterritorial scope. Any organisation that places AI systems in the EU market or whose AI system output is used in the EU must comply, regardless of where the organisation is located.

This is similar to how GDPR created a global standard for data protection. Many organisations are adopting EU AI Act compliance as their global standard, even for operations outside the EU, because it is simpler to maintain one compliance programme than multiple different ones.

Other jurisdictions are watching closely. The UK has taken a pro-innovation, sector-specific approach rather than a comprehensive law. The US has issued executive orders and guidance but no comprehensive federal AI law. Brazil, Canada, Japan, and Singapore are all developing their own AI governance frameworks, many of which draw inspiration from the EU AI Act.

Getting started with AI governance

If your organisation uses AI systems, here are the practical steps to begin your AI governance journey. First, create an inventory of all AI systems your organisation develops or uses. This includes everything from chatbots and recommendation engines to machine learning models used for decision-making.

Second, classify each system by risk level under the AI Act. Most will be minimal or limited risk, but a few may be high risk. For high-risk systems, begin preparing for compliance immediately.

Third, establish or update your AI governance framework. This should cover: AI use policies, risk assessment procedures, documentation standards, monitoring and reporting processes, and incident response procedures.

Fourth, consider using an AI governance platform to automate the ongoing work. The same platforms that handle your ISO 27001 and SOC 2 compliance can often handle AI governance as well, giving you a unified compliance programme.

Finally, stay informed. The EU AI Act is still being implemented, and technical standards, guidance documents, and regulatory decisions are evolving. Subscribe to updates from the European Commission and the new AI Office that will oversee implementation.

AI compliance playbooks

Understanding the EU AI Act is the first step, but implementing an AI governance program requires practical, hands-on guidance. Our AI compliance playbooks provide step-by-step instructions for running ISO 27001 and PCI DSS with AI, each with copy-paste skill files and markdown templates.

These playbooks cover controls, policies, evidence collection, audits, risk management, vendor assessments, and incident response. They are designed to be used immediately, not just read.

AI compliance playbooks

Step-by-step guides for running ISO 27001 and PCI DSS with AI, each with copy-paste skill files and templates.

Automate your AI governance

Automated, continuous compliance with deep integrations.

FAQ

When does the EU AI Act come into force?
The Act entered into force in August 2024. Prohibitions on unacceptable-risk AI apply from February 2025. Most other provisions, including high-risk requirements, apply from August 2026. Some provisions for general-purpose AI models apply from February 2025 and February 2026.
Does the EU AI Act apply outside the EU?
Yes. The Act applies to providers and deployers of AI systems regardless of their location if the output of the AI system is used in the EU. This extraterritorial scope is similar to GDPR.
What are the penalties for non-compliance?
Penalties are substantial. Violations of the bans on unacceptable-risk AI can result in fines of up to EUR 35 million or 7% of global annual turnover. Violations of other provisions can result in fines of up to EUR 15 million or 3% of global annual turnover.
How does the EU AI Act relate to ISO 27001?
The two regulations are complementary. ISO 27001 provides a framework for information security management, while the AI Act imposes specific requirements on AI systems. Many AI Act requirements - risk management, documentation, monitoring - align closely with ISO 27001 controls. Organisations with ISO 27001 certification are often well-positioned for AI Act compliance.
What is a general-purpose AI model under the Act?
General-purpose AI models are AI systems that display general capability and can competently perform a wide range of distinct tasks, regardless of how they were placed on the market. The Act imposes specific transparency and documentation requirements on providers of general-purpose AI models, with additional requirements for models with systemic risk.
Do I need to comply if I just use AI tools as a customer?
If you are a deployer (user) of an AI system, you have obligations under the Act, particularly for high-risk systems. These include using the system according to the provider's instructions, ensuring human oversight, monitoring operation, and keeping logs. The obligations are lighter than those on providers, but they still exist.
// Signal, not noise

AI governance, in your inbox

Practical steps for navigating the EU AI Act. No spam.