GDPR and AI: Six Tiers of Authority, and What Each One Can Carry

Last Updated : September 24, 2026
Share Article

Table of Contents

An Italian decision of 3 July 2026 did something no other enforcement decision in Europe has done. Fining Character Technologies 158,000 euro, the Garante listed in mitigation that the company had told users in the European Economic Area about post-training of its language models and let them object in advance, and recorded why that counted:

conformemente alle raccomandazioni espresse dall’EDPB nel parere n. 28/24

GDPR authority over AI has that shape throughout: an EDPB opinion that binds no controller anywhere was used to reduce a fine. The GDPR governs AI systems through a stack of instruments with wildly different legal weight, and most published guidance flattens the stack, quoting a draft guideline, an advisory opinion and an annulled fine in the same paragraph as though each carried the same force.

The General Data Protection Regulation’s authority on AI sorts into six tiers, heaviest first, and what follows sets out what each tier can and cannot support in a document a supervisory authority will read.

Tier one: the Court of Justice has construed Articles 22 and 15 for automated decisions, and those constructions bind

Only one part of GDPR and AI has been decided by a court whose rulings bind every Member State. The decided law concerns decisions taken about people, not models trained on them.

GDPR Article 22(1) got its construction in Case C-634/21 SCHUFA Holding, First Chamber, 7 December 2023:

the automated establishment, by a credit information agency, of a probability value based on personal data relating to a person and concerning his or her ability to meet payment commitments in the future constitutes ‘automated individual decision-making’ within the meaning of that provision, where a third party, to which that probability value is transmitted, draws strongly on that probability value to establish, implement or terminate a contractual relationship with that person

Read the condition, because commentary routinely drops it. Scoring becomes an Article 22 decision through the downstream use, where a recipient draws strongly on the value. A score computed and ignored is not caught. A score computed and relied on is.

Case C-203/22 Dun & Bradstreet Austria, 27 February 2025, then fixes the content of the explanation. The facts are small enough to remember: an Austrian mobile operator refused a contract worth ten euro a month on an automated credit assessment. The Court held that a data subject may require the controller to explain, as meaningful information about the logic involved under Article 15(1)(h), “the procedure and principles actually applied in order to use, by automated means, the personal data concerning that person with a view to obtaining a specific result.” Its own press release states the limit that most summaries invert:

the mere communication of an algorithm does not constitute a sufficiently concise and intelligible explanation

Handing over model architecture, weights or source code fails the test. What the Court pointed to instead is counterfactual: tell the data subject how far a variation in the input data would have changed the result. Where the controller says the explanation would expose a trade secret, it must give the disputed material to the supervisory authority or court to balance, and a national rule that excludes access as a matter of course is precluded.

The GDPR’s tested layer is short, and the shortness is the point. Two judgments, both about decisions taken on people, neither about whether a model contains personal data. Anyone telling you the CJEU has ruled on AI training is describing something that has not happened.

Tier two: binding text that no authority has yet applied to a model

GDPR text binds whether or not anyone has tested it against a model. Four GDPR provisions and five AI Act provisions carry full legal force on AI systems today, and almost none of them has been construed in an AI context.

ProvisionWhat it requiresTested against a model?
GDPR Article 6(1)A lawful basis for every processing operation, training includedNo
GDPR Article 17Erasure on the grounds listedNo
GDPR Article 30A record of processing activitiesNo
GDPR Article 35A DPIA where processing is likely to result in high riskUnder inquiry, no decision
AI Act Article 2(7)Data protection law applies to personal data processed in connection with the AI ActNot needed, declaratory
AI Act Article 10(2)(b)Training set governance covering data origin and, for personal data, the original purpose of collectionNo
AI Act Article 10(5)Special category processing for bias detection, under six cumulative conditionsNo
AI Act Article 26(9)Deployers use Article 13 provider information in their Article 35 DPIANo
AI Act Article 27(4)A fundamental rights impact assessment complements a DPIANo

Two of these repay reading in full, because the usual summaries get them backwards.

Article 2(7) and recital 10 preserve both the rules and the regulators

The GDPR is left alone by the AI Act twice over, and the two statements do different work. Article 2(7) preserves the instruments:

Union law on the protection of personal data, privacy and the confidentiality of communications applies to personal data processed in connection with the rights and obligations laid down in this Regulation.

Its next sentence adds that the AI Act “shall not affect Regulation (EU) 2016/679 or (EU) 2018/1725, or Directive 2002/58/EC or (EU) 2016/680, without prejudice to Article 10(5) and Article 59 of this Regulation.” Two carve-outs, both named: bias detection, and regulatory sandboxes.

Recital 10 preserves something the operative text does not spell out:

This Regulation does not seek to affect the application of existing Union law governing the processing of personal data, including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments.

Powers, not only rules. A national market surveillance authority under the AI Act does not inherit, absorb or displace the data protection authority. Two regulators, two mandates, one system, and a firm can be examined by both over the same deployment.

Article 2(8) exempts the activity of training, not the record of it

GDPR commentary repeats a claim here that needs correcting, including a version of it published on this site before today. Article 2(8) removes research, testing and development activity from the AI Act until a system is placed on the market or put into service, with one carve-back in the same paragraph: “Testing in real world conditions shall not be covered by that exclusion.”

GDPR coverage of training does not imply AI Act absence, and reading Article 2(8) as “training is outside the AI Act” is wrong. The AI Act reaches training retrospectively, through obligations that attach at market entry and look backwards at how the data was assembled. Article 10(2) subjects training, validation and testing data sets to data governance practices covering, at point (b), “data collection processes and the origin of data, and in the case of personal data, the original purpose of the data collection.” Article 53(1)(d) requires a provider of a general-purpose AI model to “draw up and make publicly available a sufficiently detailed summary about the content used for training.”

The GDPR governs training alone while training happens, which is the accurate statement and a narrower one, and the AI Act imposes no live obligation at that stage. Once the model or system reaches the market, the AI Act audits the same training through documentation duties, which means the lawful basis recorded under the GDPR in 2026 becomes the evidence an AI Act conformity file rests on later. Article 10(2)(b) is the hinge, and it is almost never cited.

Tier three: three fines stand, and one of them was reduced for following an opinion

GDPR enforcement that has completed carries real weight, though a first-instance national fine binds nobody beyond its addressee.

AuthorityTargetDecisionAmountStatus
Autoriteit Persoonsgegevens (NL)Clearview AI16 May 2024, announced 3 Sep 202430,500,000 euroFinal, uncontested
Garante (Italy)Luka Inc., Replika10 April 20255,000,000 euroNo appeal reported
Garante (Italy)Character Technologies3 July 2026158,000 euroNo appeal reported

The largest GDPR fine in this tier belongs to Clearview, and it is also the most final. The Dutch authority records that “Clearview has not objected to this decision and is therefore unable to appeal against the fine,” which is a rarer status than it sounds. Note what it is about: biometric search, not a generative model.

The Character Technologies decision is the one to read in full, and its operative part is worth quoting precisely because two separate summaries of it in circulation get the articles wrong. The Garante declared unlawful conduct:

per la violazione degli artt. 5, par. 2; 12, par. 1; 13, parr. 1 e 2; 14, parr. 1 e 2; 24, par. 1; 25, par. 2; 27, par. 1 e 35, par. 1, del Regolamento

Eight provisions, and no others. Article 27(1) for designating an EU representative late, Article 35(1) for a late DPIA, Article 25(2) and 24(1) for the absence of working age verification, and Article 14 for failing to explain pre-training of the language model to people whose data was involved. Compliance was ordered within 120 days, and publication of the decision was added as an accessory sanction because a generative AI service had been offered to the public “in carenza delle dovute salvaguardie.”

Then the mitigation, which is where this decision earns its place at the top of this page. Among the factors reducing the fine, the Garante counted the information given to EEA users about post-training of the underlying models together with an advance right to object, expressly “conformemente alle raccomandazioni espresse dall’EDPB nel parere n. 28/24.” No European authority had previously applied Opinion 28/2024 in an enforcement decision. The first application ran in the controller’s favour. Following advisory guidance is worth money, and now there is a decision that proves it.

One open matter belongs here rather than in the table. When the Garante fined Luka, it simultaneously opened an autonomous investigation into Replika’s generative model across its whole lifecycle, including the development and training phases of the language model. No outcome has been published. Whenever it lands, it will be the first European decision squarely on the lawfulness of training.

Tier four: an annulled fine and four open inquiries settle nothing at all

The most cited GDPR enforcement action in this field no longer exists, and a surprising amount of guidance has not caught up.

On 18 March 2026 the Tribunale Ordinario di Roma, single judge, annulled the Garante’s 15 million euro sanction against OpenAI in case R.G. 4785/2025:

in accoglimento del ricorso, annulla il provvedimento n. 755 emesso dal Garante per la protezione dei dati personali in data 2 novembre 2024

The ground was competence. OpenAI launched ChatGPT with no establishment in the European Economic Area, OpenAI Ireland was recognised as the single establishment on 15 February 2024, after the Garante had opened proceedings and before it decided, and the court held that recognition triggered the one-stop-shop in Articles 55 and 56 and moved competence to the Irish authority. Costs were offset because the outcome rested on “la pregiudiziale incompetenza dell’autorità resistente,” and every other ground was declared absorbed. No court has said whether training ChatGPT on European personal data was lawful. No appeal has been publicly reported.

Set the annulment beside the Character Technologies decision and a pattern appears that is worth stating as interpretation rather than law. Character Technologies is a United States company with no main establishment in the Union, so no lead authority existed, no transfer was possible, and the Garante acted directly. An AI provider with a recognised EU main establishment answers to one authority and gets the procedural shelter of the cooperation mechanism. A provider without one is exposed to every concerned authority separately. Where to establish is therefore a supervisory exposure decision, taken years before anyone opens a file.

The open matters, none of which has produced a decision:

AuthorityTargetOpenedScope
Irish DPCGoogle Ireland, PaLM 212 Sep 2024Whether an Article 35 DPIA was required before development processing. Nothing wider
Irish DPCX Internet Unlimited, Grok training11 Apr 2025Lawfulness and transparency. The DPC named no article numbers
Irish DPCX Internet Unlimited, Grok imagery17 Feb 2026Articles 5, 6, 25 and 35
GaranteDeepSeek30 Jan 2025Urgent limitation of processing. No fine, no final decision

Stated carefully, because the careless version invites an easy rebuttal: as at September 2026 the Irish Data Protection Commission has issued no decision and no fine in any inquiry concerning an AI model or AI system. The DPC has fined for other things in the same period, including 530 million euro against TikTok over international transfers in April 2025, which is sometimes loosely filed under AI and is not.

One more negative worth keeping straight. The DPC statement of 21 May 2025 on Meta AI training is a supervisory engagement, not a decision. Meta agreed to notification, objection forms and filtering. The DPC determined no legal basis, and reporting that says Meta’s legitimate interest was approved is describing something that did not happen.

Tier five: EDPB opinions steer supervisory authorities and now carry evidential value

The GDPR consistency mechanism produced Opinion 28/2024, adopted 17 December 2024 under Article 64(2) on a request from the Irish authority, which is advisory and binds no controller. Addressed to supervisory authorities rather than to companies, and as the Character Technologies decision shows, following it is now demonstrably worth something.

Its central holding on anonymity, at paragraph 43:

for an AI model to be considered anonymous, using reasonable means, both (i) the likelihood of direct (including probabilistic) extraction of personal data regarding individuals whose personal data were used to train the model; as well as (ii) the likelihood of obtaining, intentionally or not, such personal data from queries, should be insignificant for any data subject

Two words carry the weight. Insignificant, not remote or unlikely. And for any data subject, not averaged across a training corpus.

GDPR lawful basis gets three cumulative conditions at paragraph 66, each to be assessed and documented: a legitimate interest pursued, necessity, and a balancing test. Paragraph 68 adds that the interest must be lawful, clearly and precisely articulated, and real and present rather than speculative. Paragraph 65 records the consequence most programmes forget, that reliance on legitimate interest brings the Article 21 right to object with it.

Paragraph 105(c) is the sentence that changed procurement language across the industry:

Excluding collection from websites (or sections of websites) which clearly object to web scraping and the reuse of their content for the purpose of building AI training databases (for example, by respecting robots.txt or ai.txt files or any other recognised mechanism to express exclusion from automated crawling or scraping).

GDPR lawfulness does not turn on robots.txt. Respecting it is a mitigation that improves a balancing test, no provision of the Regulation makes it an obligation, and pages presenting it as a legal requirement are wrong in a way that will not survive contact with a regulator.

Paragraph 134 closes the escape route that a claim of anonymity appears to open:

the EDPB emphasises that a mere assertion of anonymity of the model is not enough to exempt it from the application of the GDPR

Tier six: four EDPB instruments that everyone quotes are still drafts

GDPR authority drops sharply at this tier, and the drop is usually invisible in published commentary.

InstrumentAdoptedStatus today
Guidelines 1/2024, legitimate interest8 Oct 2024Consultation version. No final text after 23 months
Guidelines 01/2025, pseudonymisation16 Jan 2025Consultation version. Consultation closed Mar 2025
Guidelines 02/2026, anonymisation7 Jul 2026Version 1.0. Consultation open to 30 Oct 2026
Guidelines 03/2026, web scraping for generative AI7 Jul 2026Version 1.0. Consultation open to 30 Oct 2026

Guidelines 02/2026 matters most and is least written about, because it reworks the test an anonymity claim has to pass. The criteria are named No Record Isolation, No Linkage and No Inference. The first is a renaming rather than a new idea: paragraph 55 provides that the criterion is met if the data does not contain a unique combination of attribute values relating to a single individual, with singling out surviving as the underlying concept.

Paragraph 82 applies the third criterion to models directly:

This would, in particular, be the case for AI models or synthetic data. Specific inferences can be made by querying (or, in the case of AI models, prompting) the given data with additional information to elicit new information about a particular individual. Where such an inference is also meaningful, this would be a violation of the No Inference criterion.

A GDPR anonymity claim can be defeated by prompting alone. Paragraph 77 treats extraction attacks against supposedly anonymous AI models as a form of de-aggregation, and paragraphs 92 and 93 note that developments in AI, and agentic AI in particular, will keep reducing the time and cost of running such attacks. The test therefore tightens on its own as attack tooling improves, which means an anonymity assessment has a shelf life.

Guidelines 03/2026 carries a scope limit stated plainly in its executive summary: the guidelines “are limited to web scraping done by private entities.” Public sector scraping and data obtained by other routes fall outside it.

The GDPR would gain a new Article 88c, sitting further down this same tier. The Digital Omnibus, COM(2025) 837 final of 19 November 2025, would provide that processing in the context of developing and operating an AI system “may be pursued for legitimate interests within the meaning of Article 6(1)(f) of Regulation (EU) 2016/679, where appropriate,” with safeguards and an unconditional right to object.

Joint Opinion 2/2026 of the EDPB and EDPS, adopted 10 February 2026, declines it at paragraph 39: the Board had already confirmed the point in Opinion 28/2024, so “it is not necessary to add a specific provision to the GDPR on this point,” and the proposed wording “does not bring any legal clarification following Opinion 28/2024.” Paragraph 41 adds that “where appropriate” in the draft would “decrease rather than increase legal certainty.”

Their resistance is targeted. The two authorities support simplification and accept a derogation for incidental and residual processing of special categories during AI development. Where they refuse to move is the proposed narrowing of the definition of personal data, which paragraph 21 urges co-legislators “to not adopt.” Compliance planning aimed at the Omnibus should be aimed at that fight, not at Article 88c.

Off the ladder: two national authorities contradict each other and neither binds you

GDPR positions published by national authorities can carry no formal weight at all and still be quoted as though they settled something.

Hamburg’s supervisory authority issued a discussion paper on large language models, self-described as a Debattenimpuls, carrying no printed date on its face although it is attributed to July 2024. Its first thesis is absolute:

Die bloße Speicherung eines LLMs stellt keine Verarbeitung im Sinne des Art. 4 Nr. 2 DSGVO dar. Denn in LLMs werden keine personenbezogenen Daten gespeichert.

GDPR rights cannot attach to a model on that reading, and unlawful training does not taint later deployment. France’s CNIL, finalising its recommendations on the development of AI systems on 22 July 2025, states the opposite: the GDPR “often applies to AI models trained on personal data due to their memorisation capabilities.” The CNIL is building PANAME with ANSSI, the iPoP research programme and PEReN, a software library to assess whether a model processes personal data, a project that presupposes models can hold it.

Neither position binds a controller in the other’s jurisdiction, and neither binds anyone outside it. Hamburg has not withdrawn or updated its paper, and has not publicly reconciled it with Opinion 28/2024, which contemplates that a model may fail to be anonymous. A controller operating across both markets has no published reconciliation to rely on and must take a position of its own.

The GDPR erasure question sits in the same void. Article 17 gives a right to erasure, and no court or supervisory authority in the Union has published a decision on what that right reaches once data has been used to fit parameters. Three arguments circulate: delete the source record and exclude it from future training runs while leaving the deployed model alone; treat the right as unenforceable against models; or rely on anonymity so that the GDPR does not reach the model at all. Guidelines 02/2026 makes the third harder, because the anonymity claim it rests on now has to survive the No Inference criterion against prompting. None of the three is an answer. Choosing one and writing down why is the only defensible move available.

Citing the ladder in a document a regulator will read

GDPR claims in a compliance file should carry the weight of their tier and no more. Overstating a draft is how a well-intentioned assessment turns into an admission.

Where the claim comes fromHow to phrase itWhat it will not support
CJEU judgment“The Court has held that…”Anything about training or model composition
GDPR or AI Act text“Article X requires…”A claim that anyone has applied it to a model
A national fine that stands“The Garante found, on these facts, that…”A general rule binding in other Member States
An annulled or open matter“Not decided”Any proposition whatever
An EDPB opinion“The EDPB considers… and we have followed it”A legal basis in itself
A draft guideline“Draft guidance, in consultation until 30 October 2026”A settled standard
A national authority’s discussion paper“One authority’s published view, contested”A position in another jurisdiction

GDPR evidence comes down to six artefacts in practice, each mapping to a tier above. An anonymity evaluation run against the three criteria in Guidelines 02/2026, including an extraction test and a prompting test, dated, because the standard tightens over time. A three-step legitimate interest assessment naming the collection criteria and the exclusions actually applied, with the Article 21 objection route live. A written position on what an erasure request reaches, covering source data, future training runs and the deployed model. An Article 30 record entry that states, for any special category data used in bias testing, why the processing was strictly necessary and why other data would not serve, which is what Article 10(5)(f) of the AI Act demands. An Article 35 DPIA that the Article 27 fundamental rights assessment can complement rather than duplicate. And an establishment map with a working Article 27 representative record, because the Rome judgment and the Character Technologies decision both turned on it.

Govern365.ai holds the mapping from a provision to the artefact that proves it, with the authority tier attached, so a compliance file records that an anonymity evaluation answers a draft guideline while a DPIA answers a binding article, and a reviewer can see at a glance which claims would survive challenge. One record usually serves several regimes: the same model file supports a GDPR Article 30 entry, an AI system inventory and an AI Act classification, and one vendor assessment answers both Article 28 processor diligence and AI Act deployer duties. Our AI compliance evidence guide sets out the artefact types across regimes, third-party AI risk management covers the vendor layer, and foundation model vendor risk questions covers what sits beneath it.

The GDPR and the AI Act are constantly conflated, so a note on scope belongs here. Our page at /blogs/eu-ai-act-vs-gdpr compares them side by side: risk tiers, penalties, supervisory architecture. The page you are reading takes the GDPR on its own terms and asks what actually binds an AI system today, and the answer is less than most guidance implies and sits in different places.

Three things worth doing before the consultation closes on 30 October 2026. Re-date every anonymity claim you hold about a deployed model and re-run it against the No Inference criterion with a prompting test. Audit your own published material for the Garante’s OpenAI fine cited as live law, since it was annulled in March 2026. And read the Character Technologies decision, because it is the only place where following EDPB guidance has demonstrably reduced a penalty, which makes it the best argument available for funding the work.

Frequently asked questions

Has any court ruled on whether training AI on personal data is lawful under the GDPR?

No. The Court of Justice has ruled on automated decision-making in C-634/21 SCHUFA and on the explanation standard in C-203/22 Dun & Bradstreet, both about decisions taken on people rather than about training. The one national fine that reached a court, the Garante’s against OpenAI, was annulled on 18 March 2026 for lack of competence, with the substantive grounds declared absorbed and never examined.

Is a trained AI model personal data under the GDPR?

The GDPR does not settle it, and two national authorities take opposite views. Hamburg says a model stores no personal data. The CNIL says the GDPR often applies because of memorisation. EDPB Opinion 28/2024 paragraph 43 says a model is anonymous only where the likelihood of extraction and the likelihood of obtaining personal data from queries are both insignificant for any data subject, and paragraph 134 adds that a mere assertion of anonymity is not enough.

Does the GDPR or the AI Act cover AI training?

The GDPR and the AI Act both reach it, at different moments. Article 2(8) of the AI Act excludes research, testing and development activity until a system is placed on the market or put into service, except testing in real world conditions, so the GDPR governs training while it happens. The AI Act then reaches back: Article 10(2)(b) requires training set governance covering the origin of data and, for personal data, the original purpose of collection, and Article 53(1)(d) requires a public summary of training content for general-purpose models.

What legal basis applies to training an AI model on personal data?

The GDPR most often supplies Article 6(1)(f) legitimate interest. EDPB Opinion 28/2024 paragraph 66 requires three cumulative conditions to be assessed and documented, and paragraph 65 records that reliance on legitimate interest brings the Article 21 right to object. Special category data additionally requires an Article 9(2) exception. Proposed Article 88c of the Digital Omnibus would restate the position in the GDPR itself, and the EDPB and EDPS say it adds nothing.

Does the GDPR make robots.txt compliance a condition of lawful AI training?

No. Opinion 28/2024 paragraph 105(c) lists respect for robots.txt or ai.txt as one of the measures that can improve the outcome of the balancing test. Respecting it is a mitigation, not a legal basis, and the GDPR creates no such obligation.

Does the GDPR require you to delete or retrain a model after an erasure request?

The GDPR gives no answer that any authority or court in the Union has published. Practice splits between deleting source data and excluding it from future training runs, and relying on anonymity so the GDPR does not reach the model. Guidelines 02/2026 makes the second route harder by treating prompting as an inference technique that can defeat anonymity. Record which position you took and the reasoning behind it.

Was the Garante’s fine against OpenAI upheld?

No. The Tribunale Ordinario di Roma annulled the 15 million euro sanction on 18 March 2026 in R.G. 4785/2025, on the ground that recognition of OpenAI Ireland as the single establishment on 15 February 2024 moved competence to the Irish authority under Articles 55 and 56. No appeal has been publicly reported.

Has any regulator applied EDPB Opinion 28/2024 in an enforcement decision?

Yes, once, and in the controller’s favour. In its decision of 3 July 2026 against Character Technologies, the Garante treated information given to EEA users about post-training of the underlying models, with an advance right to object, as a mitigating factor, expressly because it conformed to the recommendations in Opinion 28/2024.

Can a DPIA and a fundamental rights impact assessment be one document?

The GDPR assessment and the AI Act assessment stay separate and interlock. Article 27(4) of the AI Act provides that where an obligation is already met through an Article 35 DPIA, the fundamental rights impact assessment complements that assessment. Article 26(9) requires deployers of high-risk systems to use the provider’s Article 13 information when carrying out the DPIA.

Are the EDPB guidelines on anonymisation and web scraping binding?

No. Guidelines 02/2026 and 03/2026 were adopted on 7 July 2026 as version 1.0 for public consultation, open until 30 October 2026. Guidelines 1/2024 on legitimate interest and Guidelines 01/2025 on pseudonymisation remain consultation versions as well. All four are advisory even when final.

Which authority regulates an AI system, the data protection authority or the AI Act market surveillance authority?

The GDPR supervisory authority and the AI Act market surveillance authority both do, over different questions. Recital 10 of the AI Act states that the Regulation does not seek to affect existing data protection law “including the tasks and powers of the independent supervisory authorities competent to monitor compliance with those instruments.” The AI Act creates no transfer of data protection competence

Stay ahead of the curve

Join 5,000+ industry leaders who receive our weekly briefing on AI governance and secure enterprise collaboration.

About the Author

Dr Faiz Rasool

Director at the Global AI Certification Council (GAICC) and PM Training School

Globally certified instructor in ISO/IEC, PMI®, TOGAF®, and Scrum.org disciplines with hands-on experience in ISO/IEC 42001 AI governance across the US, EU, and Asia-Pacific.

Summarize with AI

AI-Powered Data Governance Platform

Secure, Govern, and Collaborate on Sensitive Data—All Within Microsoft 365

Further Reading

Related Insights

model-risk-management

Model Risk Management After SR 26-2, One Word at a Time

Supervisory guidance is a text before it is a framework, and the text changed on

Read More →
ai-policies-incident-response

AI Incident Reporting Duties, Sorted by the Date They Bind You

Almost everything written about AI incident reporting assumes Article 73 of the EU AI Act

Read More →
ai-policies-acceptable-use

Grading Every Clause in an AI Acceptable Use Policy

Open any AI acceptable use policy and the clauses look alike, set in the same

Read More →

Summarize with AI

Transforming AI Risks into Strategic Assets.

Request a Personalized Demo

Our governance experts will walk you through the platform and help you map out your ISO 42001 or EU AI Act roadmap.