<?xml version="1.0" encoding="utf-8"?><feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en"><generator uri="https://jekyllrb.com/" version="3.10.0">Jekyll</generator><link href="https://amritesh-sec.github.io/ai-governance/feed.xml" rel="self" type="application/atom+xml" /><link href="https://amritesh-sec.github.io/ai-governance/" rel="alternate" type="text/html" hreflang="en" /><updated>2026-06-30T13:06:08+01:00</updated><id>https://amritesh-sec.github.io/ai-governance/feed.xml</id><title type="html">AI Governance | Amritesh</title><subtitle>AI governance research covering EU AI Act compliance, NIST AI Risk Management Framework, AI policy development, and board-level AI risk reporting by Amritesh. United States, United Kingdom, and European Union focus.</subtitle><author><name>Amritesh</name></author><entry><title type="html">The EU AI Act: A Practical Compliance Guide for 2026</title><link href="https://amritesh-sec.github.io/ai-governance/2026/05/eu-ai-act-practical-compliance-guide/" rel="alternate" type="text/html" title="The EU AI Act: A Practical Compliance Guide for 2026" /><published>2026-05-12T00:00:00+01:00</published><updated>2026-05-12T00:00:00+01:00</updated><id>https://amritesh-sec.github.io/ai-governance/2026/05/eu-ai-act-practical-compliance-guide</id><content type="html" xml:base="https://amritesh-sec.github.io/ai-governance/2026/05/eu-ai-act-practical-compliance-guide/"><![CDATA[<p>The EU AI Act is the world’s first comprehensive AI regulation — and it does not only apply to companies headquartered in Europe. Any organisation whose AI system output is used by people in the EU falls within scope, regardless of where the company is based. For US and UK organisations with European customers, this is not optional reading.</p>

<p>This guide translates the regulation into what actually matters for compliance teams, boards, and AI governance functions.</p>

<hr />

<h2 id="who-this-affects">Who This Affects</h2>

<p>The extraterritorial reach of the EU AI Act mirrors GDPR’s approach. You are in scope if:</p>

<ul>
  <li>You provide an AI system that is placed on the EU market</li>
  <li>Your AI system’s output is used within the EU, even if you have no EU presence</li>
  <li>You are a US or UK company with EU customers using your AI-powered product</li>
</ul>

<blockquote>
  <p>If your SaaS product has a single EU customer using an AI feature, you are likely in scope. This catches far more US and UK companies than most realise.</p>
</blockquote>

<hr />

<h2 id="the-risk-tier-structure">The Risk-Tier Structure</h2>

<p>The EU AI Act’s core mechanism is risk classification. Obligations scale with risk:</p>

<h3 id="unacceptable-risk--prohibited">Unacceptable Risk — Prohibited</h3>

<p>Certain AI practices are banned outright, including:</p>

<ul>
  <li>Social scoring by public authorities</li>
  <li>Real-time biometric identification in public spaces (with narrow exceptions)</li>
  <li>Manipulative AI exploiting vulnerabilities (age, disability)</li>
  <li>Emotion inference in workplaces and educational institutions (with limited exceptions)</li>
</ul>

<h3 id="high-risk--heavily-regulated">High Risk — Heavily Regulated</h3>

<p>This is where most enterprise compliance effort concentrates. High-risk categories include:</p>

<ul>
  <li>AI used in recruitment, employee evaluation, and HR decisions</li>
  <li>AI used in credit scoring and financial services eligibility</li>
  <li>AI used in critical infrastructure</li>
  <li>AI used in education (assessment, admission)</li>
  <li>AI used in law enforcement and migration</li>
</ul>

<p><strong>High-risk obligations include:</strong></p>

<ol>
  <li>Risk management system throughout the AI lifecycle</li>
  <li>Data governance — training data quality, bias testing</li>
  <li>Technical documentation and record-keeping</li>
  <li>Transparency to users</li>
  <li>Human oversight mechanisms</li>
  <li>Accuracy, robustness, and cybersecurity requirements</li>
  <li>Conformity assessment before market placement</li>
</ol>

<h3 id="limited-risk--transparency-obligations">Limited Risk — Transparency Obligations</h3>

<p>Chatbots, deepfakes, and emotion recognition systems require disclosure that users are interacting with AI or AI-generated content.</p>

<h3 id="minimal-risk--no-specific-obligations">Minimal Risk — No Specific Obligations</h3>

<p>The majority of AI applications (spam filters, AI in video games) fall here with no specific obligations beyond general product safety law.</p>

<h3 id="general-purpose-ai-gpai--special-category">General-Purpose AI (GPAI) — Special Category</h3>

<p>Foundation models and general-purpose AI systems have their own obligations, scaling further for models deemed to carry “systemic risk” based on compute thresholds.</p>

<hr />

<h2 id="compliance-timeline">Compliance Timeline</h2>

<table>
  <thead>
    <tr>
      <th>Date</th>
      <th>Obligation</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>February 2025</td>
      <td>Prohibited practices ban took effect</td>
    </tr>
    <tr>
      <td>August 2025</td>
      <td>GPAI obligations took effect</td>
    </tr>
    <tr>
      <td>August 2026</td>
      <td>High-risk system obligations take effect</td>
    </tr>
    <tr>
      <td>August 2027</td>
      <td>Extended deadline for certain embedded high-risk systems</td>
    </tr>
  </tbody>
</table>

<p>If you are reading this and have not yet begun a high-risk classification exercise, the August 2026 deadline is closer than it appears once you account for documentation and conformity assessment lead time.</p>

<hr />

<h2 id="eu-ai-act-vs-nist-ai-rmf--key-differences">EU AI Act vs NIST AI RMF — Key Differences</h2>

<p>US organisations often ask how their NIST AI RMF work translates to EU AI Act compliance. The honest answer: it helps, but does not replace it.</p>

<table>
  <thead>
    <tr>
      <th>Aspect</th>
      <th>EU AI Act</th>
      <th>NIST AI RMF</th>
    </tr>
  </thead>
  <tbody>
    <tr>
      <td>Nature</td>
      <td>Mandatory law</td>
      <td>Voluntary framework</td>
    </tr>
    <tr>
      <td>Enforcement</td>
      <td>Fines up to €35M or 7% global turnover</td>
      <td>None (reputational/contractual only)</td>
    </tr>
    <tr>
      <td>Structure</td>
      <td>Risk-tiered prohibitions and obligations</td>
      <td>Four functions: Govern, Map, Measure, Manage</td>
    </tr>
    <tr>
      <td>Scope</td>
      <td>EU market impact, extraterritorial</td>
      <td>Primarily US-focused, increasingly cited internationally</td>
    </tr>
    <tr>
      <td>Certification</td>
      <td>Conformity assessment required for high-risk</td>
      <td>No formal certification</td>
    </tr>
  </tbody>
</table>

<p><strong>Practical implication:</strong> Organisations using NIST AI RMF as their governance foundation have strong process maturity that maps well onto EU AI Act risk management requirements — but legal compliance still requires EU AI Act-specific documentation, conformity assessment, and CE marking for high-risk systems.</p>

<hr />

<h2 id="what-boards-should-be-asking-now">What Boards Should Be Asking Now</h2>

<p>For board members and executives overseeing AI governance, the right questions are:</p>

<ol>
  <li><strong>Do we know our AI system inventory?</strong> Most organisations cannot answer this completely.</li>
  <li><strong>Have we classified each system by risk tier?</strong> This drives everything downstream.</li>
  <li><strong>Who owns AI governance internally?</strong> Without clear ownership, compliance gaps emerge silently.</li>
  <li><strong>What is our August 2026 readiness for high-risk systems?</strong></li>
  <li><strong>Do our vendor contracts address AI Act compliance obligations?</strong></li>
</ol>

<hr />

<h2 id="a-practical-first-step--ai-system-inventory">A Practical First Step — AI System Inventory</h2>

<p>Before any compliance programme can function, organisations need a complete inventory:</p>

<div class="language-plaintext highlighter-rouge"><div class="highlight"><pre class="highlight"><code>For each AI system, document:
- Business purpose and deployment context
- Risk tier classification (and rationale)
- Data sources used for training/operation
- Human oversight mechanisms in place
- Vendor/third-party AI components
- Current documentation status
</code></pre></div></div>

<p>This inventory becomes the foundation for risk registers, board reporting, and conformity assessment preparation.</p>

<hr />

<h2 id="official-resources">Official Resources</h2>

<ul>
  <li><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689">EU AI Act — Official Text</a></li>
  <li><a href="https://digital-strategy.ec.europa.eu/en/policies/ai-act-implementation">European Commission — AI Act Implementation</a></li>
  <li><a href="https://www.nist.gov/itl/ai-risk-management-framework">NIST AI Risk Management Framework 1.0</a></li>
  <li><a href="https://www.iso.org/standard/81230.html">ISO/IEC 42001:2023</a></li>
</ul>

<hr />

<h2 id="conclusion">Conclusion</h2>

<p>The EU AI Act represents a fundamental shift — AI governance is no longer a voluntary best practice for organisations with EU exposure; it is enforceable law with significant penalties. Organisations that begin systematic risk classification now will face August 2026 with confidence. Those that wait face a documentation and conformity assessment timeline that does not compress easily.</p>

<p>The next article in this series covers <strong>building an AI governance committee structure</strong> — who should sit on it, what authority it needs, and how it reports to the board.</p>

<hr />

<p><em>Questions or corrections on this analysis? <a href="https://amritesh-sec.github.io/contact/">Get in touch</a>.</em></p>]]></content><author><name>Amritesh</name></author><category term="ai-governance" /><category term="EU-AI-Act" /><category term="compliance" /><category term="risk-tiers" /><category term="governance" /><category term="NIST-AI-RMF" /><summary type="html"><![CDATA[A practical guide to EU AI Act compliance — risk tiers, obligations by tier, timeline, and how it compares to NIST AI RMF for organisations operating across the US, UK, and EU.]]></summary></entry></feed>