Skip to content
2 guided paths · 6 phases each

Comply with the AI Act and build your Data Governance
the foundation before you experiment with AI.

Templates and guides referenced article by article with the AI Act, GDPR, and DAMA-DMBOK — the preparation your company needs before scaling AI experimentation, no jargon to translate.

Data Governance · AI Governance Global Free assessment · Templates from €19
+200 assessments
completed
24 resources ready
to download
Art. 10 AI Act referenced
in every resource
🆓 Assessment
always free
Start assessment →

Does any of this sound familiar?

You're not alone. These are the same 8 symptoms we see in most organizations — and each one has a clear path below.

If this happens with your data…

No one knows who "owns" each dataset.

Every team has its own "truth" — and the numbers don't match.

No one knows who accessed which data, or when.

"Where does this data come from?" — and you improvise an answer.

If this happens with your AI…

You use AI without knowing which risk category you fall into.

No registry of which AI each team uses, or who approved it.

No one has defined what's allowed with customer data.

If the AESIA asks tomorrow, you have nothing to show.

The good news: every symptom has a concrete next step. Choose your starting point ↓

Prepare your foundation: Data Governance and AI Governance

Two entry points into the same path — the one that leads to experimenting with AI knowing the foundation is already solid. Pick yours based on where you are now, and we'll guide you phase by phase.

Where to start? If you don't yet have roles or structure around your data, start with Data Governance — it's the foundation Art. 10 of the AI Act requires, and the one that supports any serious AI experimentation later. If you already use AI day to day and need to comply with the AI Act, go straight to AI Governance.
See both paths in detail →

Whichever path you choose, there's one thing you can't control: the calendar.

August 2026 · Deadlines in force

The AI Act is already binding.
Do you know what applies to you?

Annex III obligations take effect in August 2026. Knowing whether your organization falls within scope, which systems to classify, and what documentation to prepare is the first step — and it doesn't depend on company size.

Classify AI systems Unacceptable, high, limited, or minimal risk per Annex III
Document and keep evidence Art. 10-11: data, technical documentation, and usage records
Meet the right deadlines Art. 5: Feb 2025 · GPAI: Aug 2025 · Annex III: Aug 2026
View all deadlines →
/// Free assessment · 5–12 min

Is your company
ready?

Select the relevant modules and get your maturity level, priority gaps, and a personalized roadmap.

AI Act Data Governance NIS2 RGPD ISO 42001
Start now →
🆓 Free Instant results +200 assessments

AI Act Key Dates

The Regulation applies in phases. Find out what each milestone requires and when it takes effect for your organization.

August 2024

AI Act enters into force

Regulation (EU) 2024/1689 enters into force. Transition period begins.

24-month periodMost obligations
Completed
February 2025

Prohibition of unacceptable practices

The most harmful AI uses are now prohibited, with narrow exceptions.

Subliminal manipulationSocial scoringReal-time biometrics
Completed
August 2025

Obligations for general-purpose AI models (GPAI)

Providers of general-purpose AI models must meet specific obligations.

TransparencyTechnical documentationSystemic risk: extra rules
In progress
August 2026

Full obligations for high-risk systems (Annex III)

High-risk AI systems (Annex III) must meet every requirement from this date.

Risk managementData quality · Art. 10Tech docs · Art. 11Registration · Art. 49Human oversight
Next milestone
December 2027

Annex I high-risk systems (regulated sectors)

AI embedded in safety-regulated products must meet high-risk requirements.

MachineryMedical devicesVehicles
Upcoming

Calculate your real deadline

Answer 3 questions and we'll tell you exactly how much time you have and what you should do first.

Does your organization use or deploy AI systems?

This is what Regulation (EU) 2024/1689 itself says

Maximum fine for violating Art. 5 prohibitions
Price of the Complete Pack: 24 products
€35M · 7%
€599
of annual global turnover, whichever is higher
one-time payment · no subscription

Source: Regulation (EU) 2024/1689, Arts. 99 and 101. No template guarantees compliance on its own, but it's the first documented step an auditor or authority will ask to see.

Now you know how much time you have. Here's exactly what you need so you don't run out of it:

Choose what you need

Instant download · VAT included · Referenced article by article with the AI Act

€19–69 per product 24 products
FULL PACK · 24 PRODUCTS Save ~€417

The entire catalog in a single download

AI Act + Data Governance, in English and Spanish. Also available separately: AI Governance Pack (14 products) or Data Governance Pack (10 products).

€599 €1,016 · VAT included · one-time payment
See all 3 packs → Instant download
No subscription · Pay by card, PayPal, Apple Pay, or Google Pay
AI Governance Pack
14 products · AI Act only
€349 See →
Data Governance Pack
10 products · Data Governance only
€349 See →

ISO 42001 vs NIST AI RMF vs AI Act

Still unsure if the AI Act is enough on its own, or if you need to fit it with another framework? The three main options, compared on what matters most when choosing.

Dimension ISO 42001 NIST AI RMF AI Act
Type International standard Voluntary framework Binding EU regulation
Certifiable Yes No — N/A
Geographic scope Global Global (U.S. origin) European Union
Mandatory Voluntary Voluntary Mandatory
Main focus Management and audit system Operational risk management Regulatory compliance
Maturity required Mid-high Any level Varies by system risk
Implementation cost Mid-high Low-mid Variable (fines up to 7% of turnover)
Relationship with the AI Act Convergent — can help demonstrate conformity Complementary — operational guidance —
Best for Demonstrating maturity to clients and regulators Implementing internal risk practices Legal compliance in the EU

The most common combination at mid-to-high maturity organizations: NIST AI RMF as internal operational guidance + ISO 42001 as the certification reference + the AI Act as the legal compliance framework.

Read the full analysis →

Once you've decided, here's how to keep the momentum

Regulatory updates, stage-based recommendations, and quick access to the assessment.

Jun 2026 AI Act

The European Commission publishes the first guidelines on high-risk AI systems in HR

The guidelines clarify which candidate selection and evaluation systems fall under Annex III and what documentation companies must prepare before August 2026.

Leer más →
Jun 2026 AEPD

Spain's AEPD updates its generative AI guidance with new criteria for autonomous agents

The second version includes requirements on action logging, human intervention, and data minimization in AI agent chains.

Leer más →
Jun 2026 ISO 42001

CEN-CENELEC advances on harmonized standards that will create a presumption of AI Act conformity

European standards bodies are working on ISO/IEC standards that will let certified companies presume conformity without additional assessment.

Leer más →
View all articles →

Latest Articles

In-depth analysis on the AI Act, frameworks, and data governance.

How to Measure Data Quality: KPIs, Thresholds and Dashboards

The 7 fundamental data quality KPIs, how to set thresholds with the business, and how to build a dashboard someone with authority actually checks weekly.

Leer →

The 6 Dimensions of Data Quality, Explained With Real Cases

Completeness, accuracy, consistency, timeliness, validity, and uniqueness: what each one measures and real cases that illustrate the impact when it fails.

Leer →

Data Quality Management: What It Is, How to Measure It and Why the AI Act Cares

Data quality dimensions, how to implement rules as code, tools in 2026, and what the AI Act requires of training data quality.

Leer →

Key Skills in Data and AI Governance: Beyond the Technical

What a Data or AI Governance role truly needs isn't Python or advanced SQL. It's judgment, negotiation, systems thinking, and regulatory understanding.

Leer →

Is AI Cheaper Than an Employee? The Real Answer for Data Professionals

What an AI agent doing a Data Governance Specialist's job really costs. Real numbers, and where AI amplifies rather than replaces.

Leer →

Roles and Responsibilities of a Data Governance Team: The Minimum Structure for the AI Act

What each Data Governance role does, what profile it needs, and the minimum structure for governance to work and comply with the AI Act.

Leer →
View all articles →

Key AI Governance Terms

The essential concepts of the AI Act, Data Governance, and ISO 42001, explained clearly.