The AI Liability Act was withdrawn — here's what applies now
The AI Liability Directive was withdrawn in October 2025. National law, the revised Product Liability Directive, and the AI Act's evidentiary role fill the gap.
Read more →Templates and guides to structure your data — clear ownership, catalog, quality — and then deploy AI safely on that foundation. Referenced article by article with the AI Act, GDPR, and DAMA-DMBOK, no jargon to translate.
You're not alone. These are the same 8 symptoms we see in most organizations — and each one has a clear path below.
No one knows who "owns" each dataset.
Every team has its own "truth" — and the numbers don't match.
No one knows who accessed which data, or when.
"Where does this data come from?" — and you improvise an answer.
You use AI without knowing which risk category you fall into.
No registry of which AI each team uses, or who approved it.
No one has defined what's allowed with customer data.
If the AESIA asks tomorrow, you have nothing to show.
The good news: every symptom has a concrete next step. Choose your starting point ↓
Two entry points into the same path — the one that leads to experimenting with AI knowing the foundation is already solid. Pick yours based on where you are now, and we'll guide you phase by phase.
Whichever path you choose, there's one thing you can't control: the calendar.
Article 50 transparency obligations have applied since August 2026. Annex III high-risk obligations were postponed by the Digital Omnibus and now take effect in December 2027 — real breathing room, not a reason to wait. Knowing whether your organization falls within scope, which systems to classify, and what documentation to prepare is the first step — and it doesn't depend on company size.
Select the relevant modules and get your maturity level, priority gaps, and a personalized roadmap.
The Regulation applies in phases. Find out what each milestone requires and when it takes effect for your organization.
Regulation (EU) 2024/1689 enters into force. Transition period begins.
CompletedThe most harmful AI uses are now prohibited, with narrow exceptions.
CompletedProviders of general-purpose AI models must meet specific obligations.
In progressAI-generated content, chatbots and deepfakes must be labeled as such. Annex III high-risk obligations, originally due this date, were postponed by the Digital Omnibus.
In forceHigh-risk AI systems (Annex III) must meet every requirement from this date — postponed from August 2026 by the Digital Omnibus.
Next milestoneAI embedded in safety-regulated products must meet high-risk requirements — postponed from August 2027 by the Digital Omnibus.
UpcomingAnswer 3 questions and we'll tell you exactly how much time you have and what you should do first.
This is what Regulation (EU) 2024/1689 itself says
Source: Regulation (EU) 2024/1689, Arts. 99 and 101. No template guarantees compliance on its own, but it's the first documented step an auditor or authority will ask to see.
Now you know how much time you have. Here's exactly what you need so you don't run out of it:
Instant download · VAT included · Referenced article by article with the AI Act
AI Act + Data Governance, in English and Spanish. Also available separately: AI Governance Pack (14 products) or Data Governance Pack (10 products).
Still unsure if the AI Act is enough on its own, or if you need to fit it with another framework? The three main options, compared on what matters most when choosing.
| Dimension | ISO 42001 | NIST AI RMF | AI Act |
|---|---|---|---|
| Type | International standard | Voluntary framework | Binding EU regulation |
| Certifiable | Yes | No | — N/A |
| Geographic scope | Global | Global (U.S. origin) | European Union |
| Mandatory | Voluntary | Voluntary | Mandatory |
| Main focus | Management and audit system | Operational risk management | Regulatory compliance |
| Maturity required | Mid-high | Any level | Varies by system risk |
| Implementation cost | Mid-high | Low-mid | Variable (fines up to 7% of turnover) |
| Relationship with the AI Act | Convergent — can help demonstrate conformity | Complementary — operational guidance | — |
| Best for | Demonstrating maturity to clients and regulators | Implementing internal risk practices | Legal compliance in the EU |
The most common combination at mid-to-high maturity organizations: NIST AI RMF as internal operational guidance + ISO 42001 as the certification reference + the AI Act as the legal compliance framework.
Regulatory updates, stage-based recommendations, and quick access to the assessment.
The AI Liability Directive was withdrawn in October 2025. National law, the revised Product Liability Directive, and the AI Act's evidentiary role fill the gap.
Read more →Article 50 took full effect on August 2, 2026. What it requires in practice, and what to check this week — including for organizations outside the EU.
Read more →Definition, roles, a 6-phase implementation plan, tools in 2026, and why the AI Act makes Data Governance non-optional.
Read more →Salaries, most in-demand roles, and company maturity across Spain and LatAm — anonymous, with results shared with participants and published on the blog for the whole community.
Take the survey (2 min) →The latest published on Data Governance and AI Governance, sorted by date.
The AI Liability Directive was withdrawn in October 2025. National law, the revised Product Liability Directive, and the AI Act's evidentiary role fill the gap.
Article 50 took full effect on August 2, 2026. What it requires in practice, and what to check this week — including for organizations outside the EU.
Definition, roles, a 6-phase implementation plan, tools in 2026, and why the AI Act makes Data Governance non-optional.
Why most Data Governance projects fail when they start directly with policies, with no business or data strategy behind them.
Complete 4-phase roadmap from diagnosis to scaling, based on DAMA-DMBOK v2 and aligned with the AI Act and GDPR.
The controls required by the standard, explained one by one and ready to audit.
In-depth analysis on the AI Act, frameworks, and data governance.
The 7 fundamental data quality KPIs, how to set thresholds with the business, and how to build a dashboard someone with authority actually checks weekly.
Leer →Completeness, accuracy, consistency, timeliness, validity, and uniqueness: what each one measures and real cases that illustrate the impact when it fails.
Leer →Data quality dimensions, how to implement rules as code, tools in 2026, and what the AI Act requires of training data quality.
Leer →What a Data or AI Governance role truly needs isn't Python or advanced SQL. It's judgment, negotiation, systems thinking, and regulatory understanding.
Leer →What an AI agent doing a Data Governance Specialist's job really costs. Real numbers, and where AI amplifies rather than replaces.
Leer →What each Data Governance role does, what profile it needs, and the minimum structure for governance to work and comply with the AI Act.
Leer →The essential concepts of the AI Act, Data Governance, and ISO 42001, explained clearly.