AI Regulation & Governance
The Policy Layer Has Arrived
For most of AI's history, governance was voluntary — company policies, voluntary commitments, and industry best practices. That era has ended, but unevenly. The EU AI Act is in force, with general-purpose AI obligations already applying and high-risk obligations phasing in now. The US has moved the opposite direction federally — the 2023 Executive Order on AI was rescinded in January 2025 — leaving a growing patchwork of state laws to fill the gap. China, UK, Canada, and Brazil have active legislative or regulatory processes underway. Anyone building or deploying AI commercially today operates within a regulatory environment — whether they know it or not.
- EU AI Act: risk-based tiering — entered into force August 2024; GPAI model obligations have applied since August 2025; high-risk obligations phasing in through 2026–2027 — the world's first comprehensive AI law
- US: the 2023 Executive Order on AI was rescinded in January 2025 — federal policy has taken a deregulation turn, while a growing patchwork of state laws (e.g. the Colorado AI Act) fills the gap and NIST AI RMF remains the voluntary anchor
- UK: pro-innovation principles-based approach — sector regulators apply existing powers to AI rather than a horizontal law
- China: generative AI regulations (2023) requiring security assessments and content controls before deployment
- The common thread: every major jurisdiction is moving from voluntary to binding — the question is when, not whether
EU AI Act: What It Requires and Who It Affects
The EU AI Act creates a risk-based tiering system for AI systems. The tier your product lands in determines your compliance obligations. Understanding the tiers — not just that the Act exists — is what allows you to assess your exposure accurately.
- Unacceptable risk (banned): social scoring by governments, real-time biometric surveillance in public spaces, AI that exploits psychological vulnerabilities
- High-risk: AI used in employment decisions, credit scoring, essential services access, law enforcement, medical devices, education — requires conformity assessment, human oversight, audit trail, documentation
- Limited risk: chatbots, recommendation systems — transparency obligations (disclose it's AI)
- Minimal risk: spam filters, AI-assisted games — no specific obligations beyond general law
- Timeline: the Act entered into force August 2024; prohibited practices have been banned since February 2025; GPAI obligations applied August 2025; high-risk rules phase in through 2026–2027; penalties up to €35M or 7% global revenue
Compliance as Competitive Advantage
The instinctive reaction to AI regulation is to treat it as a cost. Sophisticated organisations are treating it as a differentiator. Customers in regulated industries — financial services, healthcare, government — increasingly require AI vendors to demonstrate compliance before signing contracts. Being compliance-ready is a sales qualification, not just a legal requirement.
- The market signal: financial services buyers are increasingly asking for EU AI Act readiness in RFPs — before the deadlines
- What compliance-ready means: model cards, audit trails, human oversight mechanisms, risk tier assessments, and incident response procedures
- AI governance frameworks: NIST AI RMF (US), ISO/IEC 42001, and EU AI Act together form the compliance baseline serious buyers are referencing
- Vendor differentiation: vendors who can demonstrate documented human oversight, explainability, and bias auditing win in regulated-sector sales
- The governance gap: most organisations in scope have not started their compliance assessment — the first-mover advantage is real
Prefer slides, quizzes, and saved progress? Read this lesson in the library — free, no sign-up.