TOPIC · AI COMPLIANCE

AI compliance: obligations, evidence and audit readiness

AI compliance is the practice of showing that each use of artificial intelligence meets the internal, contractual and regulatory obligations that apply to it — with evidence that can be produced when asked. It differs from AI governance in emphasis: governance organises decisions, compliance proves them.

Obligations come from more than regulation

Teams often wait for a law and miss the obligations already in force.

  • Data protection law wherever personal data is processed.
  • Contractual clauses with customers, suppliers and model providers.
  • Sector rules — financial, health, public procurement, advertising.
  • Internal policy, ethics commitments and public statements.
  • Standards adopted voluntarily, such as ISO/IEC 42001.

Evidence is the part that fails

Most programmes can describe their controls and cannot produce evidence that those controls operated. Evidence needs a date, an owner and a link to the specific use — otherwise it is a policy document, not proof.

Audit readiness, tested internally

Pick one AI use at random and try to produce, in under an hour: its purpose, the data it touches, the obligations that apply, the risk assessment, the controls, the evidence and the decision that authorised it. Whatever you cannot produce is your backlog.

Frequently asked questions

Is AI compliance the same as AI governance?

They overlap. Governance sets roles, criteria and decisions; compliance demonstrates that obligations are met, with evidence.

Where do we start with no budget?

With the inventory of uses and their purposes. Almost every obligation is assessed per use, so nothing else can be scoped before that exists.