Comply with the AI Act and build your Data Governance the foundation before you experiment with AI.
Templates and guides referenced article by article with the AI Act, GDPR, and DAMA-DMBOK — the preparation your company needs before scaling AI experimentation, no jargon to translate.
You're not alone. These are the same 8 symptoms we see in most organizations — and each one has a clear path below.
If this happens with your data…
No one knows who "owns" each dataset.
Every team has its own "truth" — and the numbers don't match.
No one knows who accessed which data, or when.
"Where does this data come from?" — and you improvise an answer.
If this happens with your AI…
You use AI without knowing which risk category you fall into.
No registry of which AI each team uses, or who approved it.
No one has defined what's allowed with customer data.
If the AESIA asks tomorrow, you have nothing to show.
The good news: every symptom has a concrete next step. Choose your starting point ↓
/// The foundation before you experiment with AI
Prepare your foundation: Data Governance and AI Governance
Two entry points into the same path — the one that leads to experimenting with AI knowing the foundation is already solid. Pick yours based on where you are now, and we'll guide you phase by phase.
Where to start? If you don't yet have roles or structure around your data, start with Data Governance — it's the foundation Art. 10 of the AI Act requires, and the one that supports any serious AI experimentation later. If you already use AI day to day and need to comply with the AI Act, go straight to AI Governance.
Whichever path you choose, there's one thing you can't control: the calendar.
August 2026 · Deadlines in force
The AI Act is already binding. Do you know what applies to you?
Annex III obligations take effect in August 2026. Knowing whether your organization falls within scope, which systems to classify, and what documentation to prepare is the first step — and it doesn't depend on company size.
Classify AI systemsUnacceptable, high, limited, or minimal risk per Annex III
Document and keep evidenceArt. 10-11: data, technical documentation, and usage records
Meet the right deadlinesArt. 5: Feb 2025 · GPAI: Aug 2025 · Annex III: Aug 2026
This is what Regulation (EU) 2024/1689 itself says
Maximum fine for violating Art. 5 prohibitions
Price of the Complete Pack: 24 products
€35M · 7%
€599
of annual global turnover, whichever is higher
one-time payment · no subscription
Source: Regulation (EU) 2024/1689, Arts. 99 and 101. No template guarantees compliance on its own, but it's the first documented step an auditor or authority will ask to see.
Now you know how much time you have. Here's exactly what you need so you don't run out of it:
/// Available Resources
Choose what you need
Instant download · VAT included · Referenced article by article with the AI Act
Still unsure if the AI Act is enough on its own, or if you need to fit it with another framework? The three main options, compared on what matters most when choosing.
Dimension
ISO 42001
NIST AI RMF
AI Act
Type
International standard
Voluntary framework
Binding EU regulation
Certifiable
Yes
No
— N/A
Geographic scope
Global
Global (U.S. origin)
European Union
Mandatory
Voluntary
Voluntary
Mandatory
Main focus
Management and audit system
Operational risk management
Regulatory compliance
Maturity required
Mid-high
Any level
Varies by system risk
Implementation cost
Mid-high
Low-mid
Variable (fines up to 7% of turnover)
Relationship with the AI Act
Convergent — can help demonstrate conformity
Complementary — operational guidance
—
Best for
Demonstrating maturity to clients and regulators
Implementing internal risk practices
Legal compliance in the EU
The most common combination at mid-to-high maturity organizations: NIST AI RMF as internal operational guidance + ISO 42001 as the certification reference + the AI Act as the legal compliance framework.
Once you've decided, here's how to keep the momentum
Regulatory updates, stage-based recommendations, and quick access to the assessment.
Jun 2026AI Act
The European Commission publishes the first guidelines on high-risk AI systems in HR
The guidelines clarify which candidate selection and evaluation systems fall under Annex III and what documentation companies must prepare before August 2026.
The essential concepts of the AI Act, Data Governance, and ISO 42001, explained clearly.
No terms found for that search.
Cookies:
We use technical cookies necessary for the website to function (Plausible Analytics, with no identifiable personal data) and third-party Google Fonts cookies (for loading typefaces). We do not use tracking or advertising cookies.
Cookie Policy