The starting point of any governance program is a complete inventory: which AI systems and features are in use – developed in-house, procured as a service or embedded as a feature in standard software – and which business units use them for what? Each use case is then classified along the risk categories of the AI Act: prohibited practices (Art. 5, applicable since 2 February 2025), high-risk systems (Art. 6 in conjunction with Annex III), systems subject to transparency obligations (Art. 50) and minimal-risk systems. Relevant for planning: Regulation (EU) 2026/1744 (the "Digital Omnibus", in force since 27 July 2026) has postponed the application of the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (systems embedded in products under Annex I). The classification determines the depth of controls, the scope of documentation and the approval paths – and must be repeated whenever a use case changes substantially.
AI Compliance & Governance
How to build an AI governance program in a structured way – from the AI inventory through risk classification and AI literacy to lifecycle controls along the AI Act, ISO/IEC 42001, the NIST AI RMF and BSI AIC4.
Hardly any organization introduces just a single AI system these days – the typical picture is a growing portfolio of AI features in standard software, use cases built on generative models and a handful of in-house developments. Regulation (EU) 2024/1689 (the AI Act) sets a staggered framework for this: the AI literacy obligation and the bans on certain practices have applied since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025, and the transparency obligations of Art. 50 apply from 2 August 2026; following the "Digital Omnibus" Regulation (EU) 2026/1744, the high-risk obligations follow in stages from 2 December 2027. AI governance is the answer to this mix: a program that systematically records AI use, classifies each use case by risk and steers it across the entire lifecycle. This overview page puts the building blocks into context – for details on ISO/IEC 42001, the transparency obligations under Art. 50 and the NIST AI frameworks, see the respective deep dives in this knowledge base.
The AI Act's staggered roadmap
Tap a milestone for details.
AI literacy & bans
The AI literacy obligation (Art. 4) and the bans on certain practices (Art. 5) have applied since this date.
General-purpose AI models
The obligations for providers of general-purpose AI models have applied since this date.
Transparency obligations (Art. 50)
The transparency obligations of Art. 50 of the AI Act apply from this date.
High-risk obligations (Annex III)
Following the “Digital Omnibus” Regulation (EU) 2026/1744 (in force since 27 July 2026), the high-risk obligations for Annex III systems apply from this date.
Embedded systems (Annex I)
For high-risk systems embedded in products under Annex I, the obligations apply from this later date.
The Essentials at a Glance
Six topic blocks — tap to expand.
Standards map
Four building blocks that complement rather than compete — pick a tab.
- As law, the AI Act sets the binding framework for AI use.
- In a governance program it forms the level of legal obligation.
- ISO/IEC 42001:2023 is the first certifiable standard for AI management systems (AIMS).
- It describes the organizational implementation — following the same management-system logic as ISO/IEC 27001.
- The NIST AI RMF (AI RMF 1.0, 2023) is a voluntary framework for managing the risks of individual AI systems.
- It is complemented by the generative AI profile NIST AI 600-1 (2024).
- BSI AIC4 (2021), an extension of the C5 catalogue, addresses the auditability of AI cloud services.
- In a governance program it serves as an assurance instrument for suppliers.
Standards & Sources
The content on this page is based on the following publicly available guides and studies.
Verordnung (EU) 2024/1689 (KI-Verordnung / AI Act)
Risk-based legal framework with staggered application; relevant here: Art. 4 (AI literacy), Art. 5 (prohibitions), Art. 6/Annex III (high risk), Art. 27 (fundamental rights impact assessment), Art. 50 (transparency).
Verordnung (EU) 2026/1744 („Digital Omnibus on AI“)
In force since 27 July 2026; postpones the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) and softens the AI literacy obligation of Art. 4 into an obligation to promote AI literacy.
ISO/IEC 42001:2023 – Information technology – Artificial intelligence – Management system
First certifiable standard for AI management systems (AIMS); complemented by ISO/IEC 42005:2025 as guidance for AI impact assessments.
Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1
Voluntary framework built around the four functions Govern, Map, Measure, Manage; complemented for generative AI by the profile NIST AI 600-1 (2024).
AI Cloud Service Compliance Criteria Catalogue (AIC4)
Auditable criteria for AI cloud services across the entire lifecycle (including robustness, data quality, explainability, bias) as an extension of the C5 catalogue.
Orientierungshilfe „Künstliche Intelligenz und Datenschutz“ (Version 1.0)
Data protection requirements for AI applications including DPIAs; complemented by the DSK guidance on technical and organizational measures for the development and operation of AI systems (June 2025).
Related Services
Where does your AI governance program stand?
In a no-obligation initial consultation, we jointly assess which building blocks – from the AI inventory to ISO/IEC 42001 readiness – should take priority in your organization.