All terms

Regulation & Policy

AI compliance

Also known as: AI regulatory compliance

AI compliance is the work of making sure AI systems meet the laws, regulations, standards and internal policies that apply to them. It spans data protection, transparency, risk classification, documentation, human oversight and record keeping across the life of a system. In practice it combines legal interpretation, engineering controls and ongoing evidence gathering.

What it is

AI compliance covers obligations from instruments such as the EU AI Act, data protection law including the UK GDPR, sector rules in finance or health, and voluntary standards like ISO/IEC 42001 and the NIST AI Risk Management Framework. It applies to systems you build and to third party models and tools you deploy. The output is usually an inventory, a risk classification for each use case, and documented controls with evidence.

Why it matters

Non compliance can stall launches, trigger legal exposure and lose enterprise deals where buyers demand assurance before signing. For marketing and discovery work it also touches disclosure of AI generated content, consent for personal data used in personalisation, and honesty in claims about automated systems. Getting this right early is far cheaper than retrofitting controls after a product is live.

How it works

Teams start with an inventory of AI use cases, classify each by risk and applicable rules, then assign owners and controls such as data minimisation, human review, logging, evaluation and incident handling. Documentation is maintained as a living record, including data sources, model versions, testing results and decisions, so it can be produced for auditors or customers. Reviews are repeated when models, vendors or use cases change, because compliance status is not static.

When it applies

It applies from the moment an AI use case is proposed, and especially when it touches personal data, decisions about individuals, regulated sectors, or markets with specific AI legislation.

Examples

  • A marketing team documents lawful basis and consent for using customer data in an AI personalisation model.
  • A bank classifies an AI credit support tool as higher risk and adds mandatory human review plus decision logging.
  • A SaaS vendor completes an AI questionnaire and supplies model documentation as part of an enterprise security review.

How it is measured

  • Share of AI use cases inventoried and risk classified
  • Percentage of systems with complete, current documentation and named owners
  • Median time to close compliance findings or remediation actions
  • Number of failed customer assurance reviews or regulatory queries per period

Related terms in Regulation & Policy

Primary research · August 2026

How ChatGPT Shortlists Software Brands

An audit across 10 categories and 60 buying questions. I recorded what ChatGPT reads, throws away and links to when a buyer asks it which software to buy, and what that decides.

60
Questions asked
10
Software markets
2,680
Results read
367
Links shown
Free35 pages · PDF · 536 KBDiscovery Digest every Friday

Free download

Get the full report

35 pages · PDF · 536 KB. Enter your details and it downloads straight away.

How ChatGPT Shortlists Software Brands downloads straight away. No spam, unsubscribe anytime.