Book an Appointment

AI Compliance & Governance

How to build an AI governance program in a structured way – from the AI inventory through risk classification and AI literacy to lifecycle controls along the AI Act, ISO/IEC 42001, the NIST AI RMF and BSI AIC4.

Last updated: July 2026 · Valeri Milke, ISO 27001 & ISO 42001 Lead Auditor

2025AI literacy obligation and bans on certain practices have applied since 2 February 2025
2027High-risk obligations (Annex III) follow from 2 December 2027 under the “Digital Omnibus”
42001ISO/IEC 42001:2023 — first certifiable standard for AI management systems (AIMS)
4functions structure the NIST AI RMF: Govern, Map, Measure, Manage

Hardly any organization introduces just a single AI system these days – the typical picture is a growing portfolio of AI features in standard software, use cases built on generative models and a handful of in-house developments. Regulation (EU) 2024/1689 (the AI Act) sets a staggered framework for this: the AI literacy obligation and the bans on certain practices have applied since 2 February 2025, the obligations for providers of general-purpose AI models since 2 August 2025, and the transparency obligations of Art. 50 apply from 2 August 2026; following the "Digital Omnibus" Regulation (EU) 2026/1744, the high-risk obligations follow in stages from 2 December 2027. AI governance is the answer to this mix: a program that systematically records AI use, classifies each use case by risk and steers it across the entire lifecycle. This overview page puts the building blocks into context – for details on ISO/IEC 42001, the transparency obligations under Art. 50 and the NIST AI frameworks, see the respective deep dives in this knowledge base.

The AI Act's staggered roadmap

Tap a milestone for details.

The Essentials at a Glance

Six topic blocks — tap to expand.

Standards map

Four building blocks that complement rather than compete — pick a tab.

Law
  • As law, the AI Act sets the binding framework for AI use.
  • In a governance program it forms the level of legal obligation.
LawBinding frameworkObligation

Standards & Sources

The content on this page is based on the following publicly available guides and studies.

Amtsblatt der EU / EUR-Lex · 2024

Verordnung (EU) 2024/1689 (KI-Verordnung / AI Act)

Risk-based legal framework with staggered application; relevant here: Art. 4 (AI literacy), Art. 5 (prohibitions), Art. 6/Annex III (high risk), Art. 27 (fundamental rights impact assessment), Art. 50 (transparency).

Amtsblatt der EU / EUR-Lex · 2026

Verordnung (EU) 2026/1744 („Digital Omnibus on AI“)

In force since 27 July 2026; postpones the high-risk obligations to 2 December 2027 (Annex III) and 2 August 2028 (Annex I) and softens the AI literacy obligation of Art. 4 into an obligation to promote AI literacy.

ISO/IEC · 2023

ISO/IEC 42001:2023 – Information technology – Artificial intelligence – Management system

First certifiable standard for AI management systems (AIMS); complemented by ISO/IEC 42005:2025 as guidance for AI impact assessments.

NIST · 2023

Artificial Intelligence Risk Management Framework (AI RMF 1.0), NIST AI 100-1

Voluntary framework built around the four functions Govern, Map, Measure, Manage; complemented for generative AI by the profile NIST AI 600-1 (2024).

BSI · 2021

AI Cloud Service Compliance Criteria Catalogue (AIC4)

Auditable criteria for AI cloud services across the entire lifecycle (including robustness, data quality, explainability, bias) as an extension of the C5 catalogue.

Datenschutzkonferenz (DSK) · 2024

Orientierungshilfe „Künstliche Intelligenz und Datenschutz“ (Version 1.0)

Data protection requirements for AI applications including DPIAs; complemented by the DSK guidance on technical and organizational measures for the development and operation of AI systems (June 2025).

Where does your AI governance program stand?

In a no-obligation initial consultation, we jointly assess which building blocks – from the AI inventory to ISO/IEC 42001 readiness – should take priority in your organization.