<script data-pm-proxy="intercept"></script><?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Enterprise AI Governance]]></title><description><![CDATA[Practical and actionable insights for AI governance professionals. New posts delivered every fortnight.]]></description><link>https://oliverpatel.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!Q-G6!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1137200c-5be2-43bb-9655-1b38ebf29e0e_256x256.png</url><title>Enterprise AI Governance</title><link>https://oliverpatel.substack.com</link></image><generator>Substack</generator><lastBuildDate>Thu, 03 Sep 2026 17:14:32 GMT</lastBuildDate><atom:link href="/__u/oliverpatel.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Oliver Patel]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[oliverpatel@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[oliverpatel@substack.com]]></itunes:email><itunes:name><![CDATA[Oliver Patel]]></itunes:name></itunes:owner><itunes:author><![CDATA[Oliver Patel]]></itunes:author><googleplay:owner><![CDATA[oliverpatel@substack.com]]></googleplay:owner><googleplay:email><![CDATA[oliverpatel@substack.com]]></googleplay:email><googleplay:author><![CDATA[Oliver Patel]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[How China is governing agentic AI]]></title><description><![CDATA[Decision authority, agent identity, and risk classification | #49]]></description><link>https://oliverpatel.substack.com/p/how-china-is-governing-agentic-ai</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/how-china-is-governing-agentic-ai</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 30 Aug 2026 13:03:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!MDp1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!MDp1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!MDp1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4869276,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/213396036?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!MDp1!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1bbb59e-74a3-4364-bd3b-264efdcad26e_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br><em>China is quietly developing one of the world&#8217;s most sophisticated infrastructures for agentic AI governance. This article outlines what China&#8217;s agentic AI policy position is, how this could evolve into a framework of agentic AI regulations and standards, and what enterprise AI governance practitioners can learn from these developments.<br></em><br><strong><span>Disclaimer</span></strong><span>: </span><em><span>this article is not intended as legal advice and should not be read, interpreted, or relied on as such. It is for educational and informational purposes only. </span></em></p><p><span>On 8 May 2026, China published one of the world&#8217;s first agentic AI governance frameworks: the </span><em><a href="https://mp.weixin.qq.com/s/_b4zG-3_NH1CV7WpyLefgw"><span>Implementation Opinions on the Standardized Application and Innovative Development of Intelligent Agents</span></a><span> </span></em><span>(henceforth &#8216;Implementation Opinions on Agents&#8217;). </span></p><p><span>Although not legally binding, the Implementation Opinions on Agents, jointly released by the Cyberspace Administration of China (CAC), the National Development and Reform Commission (NDRC), and the Ministry of Industry and Information Technology (MIIT), provides a detailed and influential policy position on agentic AI governance. It reveals how China&#8217;s AI regulatory and standards framework will evolve to address agentic AI, whilst also providing useful guidance and inspiration for AI governance practitioners and enterprises in China and further afield.<br><br></span><strong><span>Credit</span></strong><span>: this article would not have been possible without the English language translation of the &#8216;Implementation Opinions on Agents&#8217;, published by Geopolitechs on 8 May 2026. Read the </span><a href="https://www.geopolitechs.org/p/chinas-first-policy-framework-for"><span>original article here</span></a><span>.</span></p><div><hr></div><p>My book, <em><strong><a href="https://aigovernancebook.com">Fundamentals of AI Governance</a></strong></em>, will be released soon. It features a comprehensive, visual guide to China AI Law and Policy and agentic AI governance. Pre-order today to secure a 25% discount.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><div><hr></div><p><span>The key thing to understand about AI governance in China is that innovation and regulation are not viewed as opposing forces. The government has long championed the importance of regulation and standards to promote responsible and trustworthy AI. Although the Chinese government often has different fundamental AI policy objectives to jurisdictions like the EU, there is consensus between these regulatory superpowers on the notion that innovation and governance go hand in hand. <br><br>For organisations operating in mainland China, there exists a comprehensive suite of AI-specific regulations and standards that impose mandatory requirements and shape best practice. These requirements have become embedded into everyday business practices. This has happened in parallel to notable technological progress in China&#8217;s AI ecosystem. The </span><a href="https://hai.stanford.edu/ai-index/2026-ai-index-report"><span>Stanford AI Index Report 2026</span></a><span>, for example, argued that the performance gap between Chinese and U.S. AI models &#8220;has effectively closed&#8221;. </span></p><h4><strong><br>China&#8217;s AI regulatory framework</strong></h4><div><hr></div><h4><span>China&#8217;s AI regulatory framework centres on the following binding instruments:</span></h4><ul><li><p><strong><a href="https://www.chinalawtranslate.com/en/human-like-ai/"><span>Provisional Measures on the Administration of Human-Like Interactive AI Services</span></a><span> </span></strong><span>(&#8216;Human-Like Interactive AI Measures&#8217;)</span></p><ul><li><p><strong><span>Purpose: </span></strong><span>governs AI services that are designed to interact with individuals and simulate human traits, with a focus on AI companionship and emotional dependence.</span></p></li><li><p><strong><span>Effective date:</span></strong><span> 15 July 2026</span></p></li></ul></li></ul><ul><li><p><strong><a href="https://www.chinalawtranslate.com/en/ai-labeling/"><span>Measures for Labelling of AI-Generated Synthetic Content</span></a><span> </span></strong><span>(&#8216;AI-Generated Content Labelling Measures&#8217;)</span></p><ul><li><p><strong><span>Purpose: </span></strong><span>mandates the use of &#8216;implicit&#8217; and &#8216;explicit&#8217; labels to promote transparency regarding AI-generated content (e.g., deepfakes).</span></p></li><li><p><strong><span>Effective date:</span></strong><span> 1 September 2025</span></p></li></ul></li></ul><ul><li><p><strong><a href="https://www.chinalawtranslate.com/en/generative-ai-interim/"><span>Interim Measures for the Management of Generative AI Services</span></a><span> </span></strong><span>(&#8216;Generative AI Services Measures&#8217;)</span></p><ul><li><p><strong><span>Purpose:</span></strong><span> imposes stringent requirements, including model evaluations and registration, for the development and release of public-facing generative AI services.</span></p></li><li><p><strong><span>Effective date:</span></strong><span> 15 August 2023</span></p></li></ul></li><li><p><strong><a href="https://www.chinalawtranslate.com/en/deep-synthesis/"><span>Provisions on the Administration of Deep Synthesis Internet Information Services </span></a></strong><span>(&#8216;Deep Synthesis Provisions&#8217;)</span></p><ul><li><p><strong><span>Purpose: </span></strong><span>governs the development and use of AI services to create and share synthetic content (e.g., image, audio, video, and text).</span></p></li><li><p><strong><span>Effective date:</span></strong><span> 10 January 2023</span></p></li></ul></li></ul><blockquote></blockquote><ul><li><p><strong><a href="https://www.chinalawtranslate.com/en/algorithms/"><span>Provisions on the Management of Algorithmic Recommendations in Internet Information Services</span></a><span> </span></strong><span>(&#8216;Algorithmic Recommendation Provisions&#8217;)</span></p><ul><li><p><strong><span>Purpose:</span></strong><span> regulates providers of online services that use AI to recommend, distribute, and share content to users in a targeted way, with a focus on social media, online news, and e-commerce platforms.</span></p></li><li><p><strong><span>Effective</span></strong><span> </span><strong><span>date:</span></strong><span> 1 March 2022</span></p></li></ul></li></ul><p><span>These instruments are &#8216;departmental regulations&#8217; rather than national laws. The foundational national laws that are relevant for AI include:</span></p><ul><li><p><span>Cybersecurity Law (updated in October 2025 to incorporate AI-related provisions)</span></p></li><li><p><span>Copyright Law</span></p></li><li><p><span>Data Security Law</span></p></li><li><p><span>Personal Information Protection Law</span></p></li><li><p><span>Law on the Progress of Science and Technology</span></p></li></ul><p><span>The prospect of a national AI law has been actively discussed in Chinese policy circles for several years. Such a law could merge and integrate the core requirements from the AI-specific regulations listed above, whilst imposing a horizontal and comprehensive framework for AI governance (akin to other national laws). The government has previously suggested such a law is on the cards. In 2026, the </span><a href="https://concordia-ai.com/research/state-of-ai-safety-in-china-2026/"><span>State Council&#8217;s legislative plan stated</span></a><span> China will &#8220;accelerate comprehensive legislation&#8221; on AI. To date, no concrete plans have been announced and no official draft AI law has been published.</span></p><h4><br>From traditional ML and generative AI to the agentic frontier</h4><div><hr></div><p><span>Traditional machine learning (ML), generative AI, and agentic AI represent the three core waves for enterprise AI. Analysis of China&#8217;s AI regulatory and policy framework highlights the way it has been at the forefront of anticipating and responding to this evolution of AI technology development. The widespread societal impact of traditional ML (i.e., AI recommending content) in shaping the information individuals consume, the way they are profiled and targeted, and how this can influence behaviour at scale was addressed with the Algorithmic Recommendation Provisions in 2022. Subsequent regulations, including the Generative AI Services Measures and the AI-Generated Content Labelling Measures, largely focused on generative AI (i.e., AI producing content). These generative AI-era regulations are designed to ensure that prohibited information sources are not used to train public-facing AI models or generated as output by those models, and that the public is not misled or deceived by AI-generated content. <br><br>China has been the most active jurisdiction worldwide in terms of the number of different AI-specific regulations it has enacted. A common thread is that these regulations focus on governing AI technologies and services that are available to the public, as well as AI-generated content that the public can access and share. Several of these regulations require algorithms and models that can impact public opinion or mobilise public action to be registered with the authorities. Although the government&#8217;s primary focus has been the impact of AI on the information ecosystem, it is now increasingly working on agentic AI security and governance.</span><br></p><h4>How will China govern agentic AI?</h4><div><hr></div><p><span>Since 2025, there has been increasing concern about the security and safety risks of agentic AI and how these can be managed. This concern ramped up with the release of OpenClaw, which was met with a flurry of official responses and warnings. A comprehensive report on agentic AI security was released by TC260, China&#8217;s cybersecurity standards committee, in March 2026. It highlighted 11 agentic AI threats and countermeasures (</span><a href="https://concordia-ai.com/wp-content/uploads/2026/07/State-of-AI-Safety-in-China-2026.pdf"><span>summarised here</span></a><span> by Concordia AI), from agent hijacking to tool abuse. Most of these threats are equivalent or similar to those highlighted by OWASP in its </span><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/"><span>Top 10 for Agentic Applications for 2026</span></a><span> framework.<br><br>In recent months, the focus on agentic AI governance has gained further momentum. The most significant development was in May 2026, when three central government departments jointly released the &#8216;Implementation Opinions on Agents&#8217;. Although not legally binding, the Opinions provide a detailed official position on China&#8217;s agentic AI governance and policy ambitions. They reveal how China&#8217;s AI regulatory framework will evolve to address agentic AI, emphasising the importance of technical standards, open-source frameworks, risk-based classification, and industry self-governance, whilst also providing useful inspiration for enterprise AI governance practitioners grappling with agentic AI, in China and beyond. <br><br>The Opinions advocate for developing decision authority rules to codify what agents can and cannot do, what type of human oversight is required, and how human-on-the-loop approaches can be supported with continuous monitoring and anomaly detection. The fundamental principles underpinning this governance approach are safety, controllability, reliability, and trustworthiness. These fundamental principles should be operationalised into baseline requirements that organisations adhere to across the agentic AI lifecycle.<br><br>The Opinions outline the contours of an agentic AI governance framework, whilst also championing the importance of agentic AI for economic development and highlighting priority use cases for agents across all major sectors. This follows naturally from the government&#8217;s &#8216;AI+ Plan&#8217;, </span><a href="https://merics.org/en/comment/chinas-ai-drive-aims-integration-across-sectors-wake-call-europe"><span>announced in 2025</span></a><span>, which imbued a sense of urgency by setting ambitious targets for widespread diffusion of AI systems and agents across Chinese society. The policy vision is for agents to become embedded in all parts of the economy, which includes embodiment in physical AI applications.</span></p><p><span>Here is a snapshot of five of the most interesting agentic AI use cases encouraged in the Opinions. Although there is no guarantee these use cases will be directly supported by the government, their inclusion highlights that officials think there are promising opportunities to explore: </span></p><ul><li><p><strong><span>Financial services: </span></strong><span>credit card fraud interception and anti-money laundering agents.</span></p></li><li><p><strong><span>Commercial services: </span></strong><span>embodied agents for cleaning, warehousing, and distribution to improve operational efficiency (e.g., in restaurants, hospitality, retail, and logistics).</span></p></li><li><p><strong><span>Education: </span></strong><span>agents for personalised learning, intelligent tutoring, and virtual teaching assistance.</span></p></li><li><p><strong><span>Public safety</span></strong><span>: embodied agents in disaster rescue and hazardous materials handling.</span></p></li><li><p><strong><span>Information services:</span></strong><span> agents for online content governance, including recommendation distribution and intelligent moderation, as well as emotional counselling.</span></p></li></ul><p><span>The Opinions recommend comprehensive risk mitigation strategies whilst also promoting priority agent use cases and innovation opportunities. This duality is distinctive to the Chinese approach. It illustrates, through the prism of agentic AI, that innovation and governance are not deemed mutually exclusive. Perhaps the sharpest example of this is the recommendation to explore the use of agents for &#8220;emotional counselling&#8221;, which was issued just weeks before the Human-Like Interactive AI Measures (which are designed to address the risks of such use cases) became effective.</span></p><h4><strong><br>Agentic AI standards</strong></h4><div><hr></div><p><span>The Opinions state that agentic AI development shall be &#8220;standardized and orderly&#8221;. Establishing a framework of agentic AI standards is positioned as a priority action area. To turn this vision into a reality, a host of agentic AI standards are currently under development. This is consistent with the approach taken to generative AI governance. There exists a comprehensive package of mandatory standards that facilitate compliance with the Generative AI Services Measures and AI-Generated Content Labelling Measures. These are highly detailed and prescriptive documents for organisations to follow, and a core part of the AI regulatory framework. </span></p><p><span>Concordia AI, a social enterprise that works on AI governance in China, notes that &#8216;agent safety&#8217; is a priority theme for AI standardisation in China. Its 2026 report on the &#8216;</span><a href="https://concordia-ai.com/research/state-of-ai-safety-in-china-2026/"><span>State of AI Safety in China</span></a><span>&#8217; highlights seven agentic AI standards under development, as well as an additional seven-part series: </span></p><ul><li><p><span>Basic Specification for Agent Safety (drafting announced January 2026)</span></p></li><li><p><span>General Security Requirements for AI Agent Applications (drafting announced April 2026)</span></p></li><li><p><span>General Technical Requirements for Agent Safety (drafting announced July 2025)</span></p></li><li><p><span>AI Agent Safety Protection Guide (drafting announced July 2025)</span></p></li><li><p><span>Agent Collaboration Safety Framework and Safety Requirements (drafting announced July 2025)</span></p></li><li><p><span>Technical Requirements for Agent Development Platform Safety (drafting announced November 2025)</span></p></li><li><p><span>Model Context Protocol (MCP) Application Safety Requirements (drafting announced September 2025)</span></p></li></ul><p><span>In June 2026, the National Standardization Administration of China (SAC) </span><a href="https://sesec.eu/2026/07/16/china-will-accelerate-agentic-ai-standardization/"><span>published seven guiding technical documents</span></a><span> under the &#8216;AI &#8211; Agent Interconnection&#8217; series. These documents, part of the evolving standards framework, address frontier issues including agent identity, multi-agent interaction, and tool invocation. </span></p><p><span>This means fourteen different agentic AI governance standards and technical documents are under development or published. Several of these could become mandatory standards in future.</span></p><h4><strong><br>Three key takeaways for AI governance practitioners</strong></h4><div><hr></div><p><span>For AI governance professionals building agentic AI frameworks, tracking these developments is prudent. Irrespective of whether compliance with China&#8217;s AI regulatory framework is of direct relevance, the agentic AI standards referenced above represent some of the most advanced policy and governance work on agentic AI risk management worldwide. The AI governance frameworks and regulations that most organisations align to, including the NIST AI RMF, ISO/IEC 42001, and the EU AI Act, do not cover agent-specific considerations in any detail. Therefore, organisations have little choice but to consult wider sources to inform their approach.</span></p><p><span>Here are the top three takeaways for practitioners grappling with agentic AI governance:<br><br></span><strong><span>1. Establish decision authority rules <br><br></span></strong><span>The Implementation Opinions on Agents emphasise the importance of clarifying &#8220;decision-making authority&#8221;, including boundaries and required permissions, for actions executed by agents. A high-level, three-tier framework is proposed:</span></p><ul><li><p><span>Decisions reserved exclusively for users (i.e., humans)</span></p></li><li><p><span>Decisions requiring user authorisation</span></p></li><li><p><span>Autonomous agent decisions</span></p></li></ul><p><span>As agentic AI capabilities improve rapidly, each enterprise should agree and codify internal decision governance and authority rules for agents, covering their highest priority domains. This includes defining where agents can act autonomously, where human review and approval is essential, what the thresholds for human intervention should be, and everything in between. Without such a framework, the technical controls and guardrails that bound and restrict agent action will lack a coherent policy foundation. It&#8217;s worth noting that the Chinese framework proposes that users should retain &#8220;ultimate decision-making authority over autonomous agent actions&#8221;. Human oversight is thus integral to agent governance. </span></p><p><strong><span>2. Prioritise agent identity and traceability<br><br></span></strong><span>Agent identity and traceability are core themes of China&#8217;s emerging framework of agentic AI standards and technical documents. These considerations are particularly pertinent for multi-agent systems, where agent behaviour, action, and impact are shaped by the myriad ways in which different agents interact, communicate, and coordinate. Oversight and governance of such systems is virtually impossible without each agent having a unique identity, with inputs/outputs and actions logged in a manner that is attributable to each agent. This is a prerequisite for most key aspects of agent governance, including operationalising human oversight and decision authority.<br><br></span><strong><span>3. Take a risk-based approach to agent governance</span></strong><span><br><br>Finally, the Opinions signal that the precise governance approach, including whether mandatory requirements will be imposed via new regulations, will depend on the level of risk. Sensitive sectors will likely be subject to new requirements, whereas &#8216;self-governance&#8217; (e.g., compliance self-assessment and internal evaluations) will be expected in lower-risk domains. </span></p><p><span>Agentic AI presents distinct risks, but the fundamental approach to AI governance need not change. Not all agents and agentic systems can or should be governed in the same way. Controls and risk management measures should be targeted and proportionate relative to risk. This means organisations should update risk classification and tiering frameworks to adequately incorporate agentic AI use cases.</span></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The EU AI Act amendments explained (Part 2)]]></title><description><![CDATA[Download my latest AI Act Cheat Sheet | #48]]></description><link>https://oliverpatel.substack.com/p/the-eu-ai-act-amendments-explained-8a5</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/the-eu-ai-act-amendments-explained-8a5</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Mon, 22 Jun 2026 17:46:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!75l6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!75l6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!75l6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5852142,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/203069067?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!75l6!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F00177784-6d8c-460b-9b71-7c4eca9de71b_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br>This article is Part 2 of a two-part series that explains the ways in which the EU AI Act will be amended. Last week, following months of trilogue negotiations, the European Parliament voted to approve the <a href="https://www.europarl.europa.eu/doceo/document/TA-10-2026-0198_EN.pdf">regulation to amend the EU AI Act</a>. This series analyses the ten most significant amendments that enterprises need to prepare for.</p><p><a href="/__u/oliverpatel.substack.com/p/the-eu-ai-act-amendments-explained">Part 1</a>, published last week, covered the timeline changes and postponements, the prohibited AI expansion, the softening of the AI literacy obligation, and the registration obligation. Part 2 covers the processing of sensitive personal data for bias mitigation, the expansion in scope of the AI Office&#8217;s regulatory powers, the extension of proportionality to small mid-cap (SMC) enterprises, and the changes for AI systems in scope of the Machinery Regulation and other EU product safety laws. This article also features a free, high-res <strong>EU AI Act Amendments Regulation Cheat Sheet</strong>, which you can download via the link below.</p><p>It is worth repeating that although the new amending regulation has not yet been formally adopted and entered into force, enterprises should already be reviewing and updating their AI governance and compliance approaches, as the three co-legislating EU institutions have reached a consensus on the substance of the amendments. Nonetheless, the core purpose, logic, and structure of the EU AI Act remain mostly intact. </p><div><hr></div><p>My book, <em><strong><a href="https://aigovernancebook.com">Fundamentals of AI Governance</a></strong></em>, will be released in September 2026. It features a comprehensive, visual guide to the EU AI Act, which will incorporate all of the amendments which are formally adopted. Pre-order today to secure a 25% discount.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Get the discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Get the discount</span></a></p><div><hr></div><p>For each of the ten most significant amendments, this series explains what the law says today, how this is changing, and the practical implications for enterprises. Items 1-5 were covered in <a href="/__u/oliverpatel.substack.com/p/the-eu-ai-act-amendments-explained">Part 1</a> and items 6-10 are covered in Part 2 (below). </p><p><strong>The 10 most significant EU AI Act amendments</strong></p><ol><li><p><strong>Expanding the list of prohibited AI practices to ban &#8220;nudifier apps&#8221;.</strong></p></li><li><p><strong>Timeline changes for high-risk AI system compliance.</strong></p></li><li><p><strong>Timeline changes for transparency-requiring AI system compliance.</strong></p></li><li><p><strong>Limiting registration in the EU public database for the &#8220;exempted&#8221; AI systems. </strong></p></li><li><p><strong>Softening of the AI literacy obligation.</strong></p></li><li><p><strong>Processing sensitive personal data for bias detection and correction.</strong></p></li><li><p><strong>Expanding the scope of the European AI Office&#8217;s regulatory powers.</strong></p></li><li><p><strong>Proportionality for small mid-cap (SMC) enterprises.</strong></p></li><li><p><strong>Addressing potential duplication for high-risk AI systems which are regulated by EU product safety laws listed in Annex I. </strong></p></li><li><p><strong>Addressing potential duplication for high-risk AI systems which are regulated by the EU Machinery Regulation</strong>.</p></li></ol><p><strong>Disclaimer:</strong> <em>this article is not legal advice and should not be used, relied on, or interpreted as such. Always consult a qualified legal professional. Furthermore, this article does not cover all amendments outlined in the amending regulation. Finally, these amendments have not yet been enacted as law and are not in force.</em></p><div><hr></div><p><em><strong>Download the pdf version (link below) for the highest resolution version :)</strong> </em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!sYEO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 424w, /__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 848w, /__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!sYEO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png" width="1456" height="1463" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1463,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1858335,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/203069067?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 424w, /__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 848w, /__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 1272w, /__u/substackcdn.com/image/fetch/$s_!sYEO!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b71c4da-53f0-4955-919f-26be0d5e6d80_5769x5795.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail" src="/__u/substackcdn.com/image/fetch/$s_!YUK0!,w_400,h_600,c_fill,f_auto,q_auto:best,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb1380af8-e44c-4505-a553-7cfd498be3f1_1316x1308.png"></image><div class="file-embed-details"><div class="file-embed-details-h1">EU AI Act Amendments Regulation Cheat Sheet (by Oliver Patel)</div><div class="file-embed-details-h2">281KB &#8729; PDF file</div></div><a class="file-embed-button wide" href="/__u/oliverpatel.substack.com/api/v1/file/0dacac97-1d21-415e-bb7a-4267fe780210.pdf"><span class="file-embed-button-text">Download</span></a></div><div class="file-embed-description">Download the high-res PDF cheat sheet for free. You can use this for any purpose, including commercially, but please provide appropriate attribution.</div><a class="file-embed-button narrow" href="/__u/oliverpatel.substack.com/api/v1/file/0dacac97-1d21-415e-bb7a-4267fe780210.pdf"><span class="file-embed-button-text">Download</span></a></div></div><h4><strong>6. Processing sensitive personal data for bias detection and correction</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong><span>The GDPR stipulates that the processing of &#8216;special categories&#8217; of personal data (henceforth sensitive personal data) is prohibited, apart from in limited circumstances. Sensitive personal data includes: </span></p><ul><li><p>Data revealing racial or ethnic origin</p></li><li><p>Data revealing political opinions</p></li><li><p>Data revealing religious or philosophical beliefs</p></li><li><p>Data revealing trade union membership</p></li><li><p>Genetic data</p></li><li><p>Biometric data (for the purpose of uniquely identifying a natural person)</p></li><li><p>Health data</p></li><li><p>Sex life or sexual orientation</p></li></ul><p><span>Article 9(2) of the GDPR outlines ten exceptions to this prohibition. These exceptions represent distinct scenarios where sensitive personal data can be processed. This includes, but is not limited to, when explicit consent has been obtained, when doing so is necessary to &#8220;protect the vital interests of the data subject&#8221; where they are &#8220;physically or legally incapable of giving consent&#8221; (e.g., in a medical emergency), or when the processing is necessary and proportionate for a &#8220;substantial public interest&#8221;.</span></p><p><span>The EU AI Act augments this by providing an additional legal basis for the processing of sensitive personal data. It does so because providers of high-risk AI systems are required to &#8220;detect, prevent, and mitigate possible biases&#8221; that are likely to affect the &#8220;health and safety&#8221; of individuals, have a &#8220;negative impact on fundamental rights&#8221;, or lead to unlawful discrimination. To enable this, </span>Article 10(5) of the EU AI Act stipulates that providers of high-risk AI systems <span>can process sensitive personal data for the purpose of &#8220;ensuring bias detection and correction&#8221; in relation to their high-risk AI systems. </span></p><p><span>However, it must be &#8220;</span><strong><span>strictly necessary</span></strong><span>&#8221; to use the sensitive personal data to achieve this purpose, and the bias detection and correction cannot be effectively achieved by other means. The EU AI Act outlines a range of additional mandatory safeguards which must be applied alongside all the safeguards already required by the GDPR. <br></span><br><strong>How is this changing?</strong></p><p>There are two key changes. Firstly, providers and deployers of AI systems and AI models which are <strong>not high-risk</strong> will also be permitted to process sensitive personal data when it is &#8220;strictly necessary&#8221; to ensure &#8220;bias detection and correction&#8221;. When doing so, they must apply the same safeguards referenced above. Secondly, <strong>deployers of high-risk AI systems</strong> will also be permitted to process sensitive personal data, under the same conditions as providers.</p><p>The substantive changes are therefore the expansion in scope of which organisations can process sensitive personal data for bias detection and correction (i.e., providers <em>and</em> deployers), as well as in relation to which AI archetypes (i.e., high-risk AI systems, <em>as well as</em> AI systems which are not high-risk and AI models). However, what is not changing are the types of biases this processing must be targeted at addressing, the &#8220;strictly necessary&#8221; condition, and the safeguards that must be applied for the processing to be lawful. <br><br><strong>Enterprise implications</strong></p><p>These changes are useful for enterprises which develop and deploy AI systems which are not high-risk, but which nonetheless support decisions or actions that directly impact individuals or groups and can therefore result in bias. They are also useful for deployers using high-risk AI systems, in domains like recruitment, education, and healthcare. However, the strict conditions and safeguards stipulated in both the EU AI Act and the GDPR ensure that there will continue to be a relatively high bar for when such processing (of sensitive personal data) is lawful. The notion of strict necessity, for example, is well established in EU case law, and it means that organisations must be prepared to demonstrate that they effectively had no other option but to process the data in order to mitigate the risk of bias.<br></p><h4><strong>7. Expanding the scope of the European AI Office&#8217;s regulatory powers</strong></h4><div><hr></div><p><strong>What is in law today?</strong></p><p><span>The EU AI Act has established a decentralised governance and enforcement regime for AI systems. The European AI Office, part of the European Commission, is responsible for overseeing and enforcing the provisions relating to general-purpose AI (GPAI) models (e.g., the frontier models released by the likes of OpenAI and Anthropic). The national market surveillance authorities (i.e., member state regulators) are responsible for overseeing and enforcing the provisions relating to AI systems (e.g., high-risk and transparency-requiring AI systems), as well as most other EU AI Act provisions. </span></p><p><span>Article 75(1) provides the AI Office with powers to monitor and supervise AI systems based on GPAI models. This only applies when the AI model and AI system are developed by the same provider. For example, ChatGPT is an AI system which is powered by AI models like GPT-5.5. OpenAI is the provider of both the AI model and the AI system. However, this regulatory power is not exclusively held by the AI Office. Member state regulators can also oversee and enforce EU AI Act provisions relating to these AI systems. This creates potential situations of overlapping competence and providers (like OpenAI) being investigated and enforced against by multiple regulators simultaneously.</span></p><p><strong>How is this changing?</strong></p><p>Considering that there are, in many cases, multiple designated regulators per member state, as well as an increasingly large number of AI systems based on GPAI models, governance and enforcement of the EU AI Act has the potential to get messy.</p><p>Confronting this challenge head on, the EU has opted to simplify the governance regime by granting the AI Office with &#8220;exclusive competence&#8221; to oversee and govern AI systems based on GPAI models, where both the AI system and the GPAI model are developed by the same provider (or by providers that are part of the same organisation or corporate group). This also applies where the deployer of the AI system is also the provider of that system (as well as the GPAI model(s) on which it is based). </p><p>However, there are several exceptions to the AI Office&#8217;s exclusive competence. These are:</p><ul><li><p>AI systems developed and used by EU institutions, agencies, and bodies.</p></li><li><p>AI systems which are safety components in the management and operation of critical infrastructure.</p></li><li><p>AI systems intended to be used in the administration of justice.</p></li><li><p>AI systems provided by law enforcement authorities, border management authorities, and (certain) financial institutions.</p></li><li><p>AI systems which are products, or safety components of products, covered by an EU product safety law listed in Annex I of the EU AI Act.</p></li></ul><p>In these scenarios, the AI Office will not have exclusive competence, and member state regulators will continue to have an important role to play.</p><p><strong>Enterprise implications</strong></p><p>For organisations that develop GPAI models and then integrate those models into AI systems which they both provide to other organisations and use themselves&#8212;like OpenAI and Anthropic&#8212;their interactions with EU regulators should become more streamlined. This is because the AI Office will serve as their key point of contact (e.g., for reporting serious incidents), and there will be a reduced likelihood of multiple regulators simultaneously investigating them or pursuing enforcement action in relation to the same issue. </p><p>However, these changes do not affect organisations that are merely deployers of AI systems which they did not develop&#8212;even if those AI systems and their GPAI models were developed by the same provider. Furthermore, certain AI systems may always be governed by both the AI Office and member state regulators, no matter their technical architecture and model composition. Therefore, these changes only directly affect a small number of organisations and are not particularly relevant for any enterprise which doesn&#8217;t develop GPAI models. <br></p><h4>8. <strong>Proportionality for small mid-cap (SMC) enterprises</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>The EU AI Act provides targeted flexibility and proportionality for micro, small, and medium-size enterprises (SMEs), including start-ups. For example, the compliance penalties which SMEs can be issued are capped as follows:</p><ul><li><p>Prohibited AI breaches: up to &#8364;35 million <em>or</em> 7% of total worldwide annual turnover for the preceding financial year (whichever is lower).</p></li></ul><ul><li><p>Most other provisions: up to &#8364;15 million <em>or</em> 3% of total worldwide annual turnover for the preceding financial year (whichever is lower).</p></li></ul><ul><li><p>Supplying incorrect, incomplete, or misleading information to regulators: up to &#8364;7.5 million <em>or</em> 1% of total worldwide annual turnover for the preceding financial year (whichever is lower).</p></li></ul><p><span>This is the inverse to the &#8220;whichever is higher&#8221; penalty logic that applies for all other businesses (i.e., those which are not SMEs). This means, for example, that even if 7% of an SME&#8217;s total annual turnover far exceeds &#8364;</span>35 million, it would not pay more than this larger amount if penalised for engaging in a prohibited AI practice. However, an organisation which is not an SME could pay a substantially higher penalty for an equivalent breach, perhaps in the hundreds of millions or billions of euros. </p><p><strong>How is this changing?</strong></p><p>The most significant change is to extend the proportionate, inverse penalty regime for SMEs to small mid-caps (SMCs) as well. This would significantly reduce the total potential penalty exposure of SMCs in certain circumstances, meaning that many more companies benefit from EU AI Act proportionality. </p><p>SMCs that are providers of high-risk AI systems would also be able to provide the required technical documentation in a simplified manner. Again, this is an extension of a proportionality mechanism already afforded to SMEs. </p><p>The other key change is to include the formal legal definitions of SME and SMC in the amending regulation. These are:</p><ul><li><p><strong>SME</strong>: an enterprise that employs fewer than 250 people and which has an annual turnover not exceeding &#8364;50 million, and/or an annual balance sheet total not exceeding &#8364;43 million.</p></li><li><p><strong>SMC</strong>: an enterprise, which is not an SME, that employs fewer than 750 people and which has an annual turnover not exceeding &#8364;150 million or an annual balance sheet total not exceeding &#8364;129 million.</p></li></ul><p><strong>Enterprise implications</strong></p><p><span data-color="rgb(55, 78, 93)" style="color: rgb(55, 78, 93);">The influence of the Draghi report can be detected in these amendments. The </span><a href="https://commission.europa.eu/document/download/97e481fd-2dc3-412d-be4c-f152a8232961_en?filename=The%20future%20of%20European%20competitiveness%20_%20A%20competitiveness%20strategy%20for%20Europe.pdf">&#8220;Draghi report&#8221; on The Future of European Competitiveness</a>, published in 2024,<span data-color="rgb(55, 78, 93)" style="color: rgb(55, 78, 93);">  argued that the EU&#8217;s complex digital regulatory environment impedes innovation and growth. It positioned &#8220;reducing the regulatory burden&#8221; as a core priority for transforming the EU&#8217;s economic prospects. By significantly lowering the potential regulatory penalties which both start-ups and scale-ups could face, the EU will be hoping to encourage a broader range of firms to take a proactive, innovative, and ambitious approach to AI adoption, to the benefit of European growth and competitiveness.</span></p><h4><strong><br>9. Addressing potential duplication for high-risk AI systems which are regulated by EU product safety laws listed in Annex I</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Broadly speaking, there are two categories of high-risk AI system under the EU AI Act:</p><ul><li><p>AI systems listed in Annex III; and</p></li><li><p>AI systems which are products, or safety components of products, regulated by an EU product safety law listed in Annex I.</p><ul><li><p>For these AI systems to be classified as high-risk, there must be an existing requirement (in the applicable product safety law) for the product, or the safety component of the product, to undergo a third-party conformity assessment.</p></li></ul></li></ul><p>For these &#8216;Annex I AI systems&#8217;, the most important consideration is the EU product safety law under which it is already regulated, and how this interacts with any new EU AI Act requirements. Annex I is split into two sections: Section A and Section B. Each section lists EU product safety laws. For AI systems regulated by an EU product safety law listed in Section A, the requirements of the EU AI Act directly apply, in addition to all existing requirements from the other law. However, for high-risk AI systems regulated by an EU product safety law listed in Section B, most EU AI Act requirements do not directly apply. Instead, the European Commission is supposed to &#8220;take into account&#8221; the EU AI Act&#8217;s high-risk AI system requirements when adopting future implementing acts that concern AI systems that are safety components (or products themselves) in these domains. </p><p>Section A includes laws that regulate machinery, medical devices, and radio equipment. Section B includes laws that regulate aviation, vehicles, and marine equipment.  </p><p><strong>How is this changing?</strong></p><p>The main concern has been potential overlap between the requirements stipulated in the existing product safety laws and the EU AI Act. Although there were already some mechanisms to address this (e.g., not requiring multiple conformity assessments), these are being expanded and strengthened. </p><p>Specifically, to reduce &#8220;compliance burdens&#8221; and address potential overlap, for high-risk AI systems listed in Annex I (Section A), the Commission will be able to limit the application of certain substantive high-risk AI system requirements, so that providers need not comply with them where an equivalent or higher safeguard already exists (in the applicable EU product safety law). </p><p>The Commission will do so by adopting delegated acts which outline which AI systems, product safety laws, and domains are impacted. It must do this by 2 August 2027. However, it will only be able to restrict the application and mandatory nature of specific requirements when the following two conditions apply:</p><ul><li><p>the EU product safety law (listed in Annex I (Section A)) has requirements or obligations that provide an <em>&#8220;equivalent or higher level of protection of health, safety or fundamental rights as the requirement or obligation concerned</em>"; and</p></li><li><p>limiting the requirements does not &#8220;<em>reduce the overall level of protection&#8221; </em>which the EU AI Act provides.</p></li></ul><p>Simply put, the Commission will have the power to determine that certain EU AI Act requirements do not have to be adhered to by providers of certain AI systems. However, it can only do so where the applicable product safety law already delivers an equivalent or higher level of protection for the specific requirement(s) in question, and where lifting that requirement does not weaken the overall level of protection the EU AI Act provides. </p><p><strong>Enterprise implications<br><br></strong>We do not yet know the precise significance of this change, as we do not know which high-risk AI systems, EU AI Act requirements, and EU product safety laws will be impacted&#8212;aside from AI systems regulated by the EU Machinery Regulation, which is being moved from Section A to Section B (see below). However, this could have a major impact on certain organisations, especially if they are providers of high-risk AI systems which the Commission deems to be covered by an existing product safety law which overlaps with EU AI Act requirements in a meaningful way. </p><p>Given the perceived and actual reduction in compliance workload, there will likely be intense industry lobbying over the coming months to persuade the Commission to relax certain EU AI Act restrictions, for certain sectors and AI systems, on this basis. However, this change is less significant than earlier proposals to move much of the Section A list into Section B, which would have drastically reduced the overall scope of the EU AI Act&#8217;s requirements across many industries. Finally, this change does not impact obligations for deployers of high-risk AI systems covered by Annex I (Section A).</p><h4><strong><br>10. Addressing potential duplication for high-risk AI systems which are regulated by the EU Machinery Regulation </strong></h4><div><hr></div><p><strong>What is in law today?</strong></p><p>As explained above, the <a href="https://eur-lex.europa.eu/eli/reg/2023/1230/oj/eng">EU Machinery Regulation</a> (Regulation (EU) 2023/1230) is currently listed in Section A of Annex I. This means that, today, high-risk AI systems which are products, or safety components of products, regulated by the Machinery Regulation are directly subject to the EU AI Act's high-risk AI system requirements, in addition to all requirements under the Machinery Regulation itself.<strong><br><br>How is this changing?</strong></p><p>The amending regulation moves the Machinery Regulation out of Section A and into Section B of Annex I. This is the only change to the structure and content of Annex I itself. Once moved to Section B, most substantive EU AI Act requirements for high-risk AI systems will no longer directly apply to any providers of AI systems which are regulated by the Machinery Regulation. Only a limited set of provisions will apply, none of which are particularly material or noteworthy, for providers, from a compliance perspective.<br><br><strong>Enterprise implications</strong></p><p>This is a meaningful simplification for providers of AI-enabled machinery, who will increasingly look to the Machinery Regulation, rather than the EU AI Act, as the primary source of their high-risk AI obligations and requirements. However, as per the amending regulation itself, this is a change in regulatory and compliance architecture to promote simplicity and avoid duplication, not deregulation. Indeed, it is important to note that AI systems covered by Annex I (Section B) are still classified as high-risk AI systems under the EU AI Act&#8212;and this includes AI-enabled machinery. The level of protection is intended to remain consistent. Providers should track how the Machinery Regulation, and associated artefacts, evolve to absorb these requirements, as that is where the key detail will now sit. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The EU AI Act amendments explained (Part 1)]]></title><description><![CDATA[MEPs vote to amend the EU AI Act | #47]]></description><link>https://oliverpatel.substack.com/p/the-eu-ai-act-amendments-explained</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/the-eu-ai-act-amendments-explained</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Thu, 18 Jun 2026 10:55:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!w36u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!w36u!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!w36u!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5336481,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/202539819?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!w36u!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5b919762-5474-480b-bbf2-b71217d25acd_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br><em>On Tuesday 16 June, the European Parliament voted in support of the regulation to amend the EU AI Act. The vote was decisive, with 423 MEPs in favour, 57 against, and 174 abstentions. The Parliament&#8217;s approval follows the provisional agreement, announced on 7 May, reached between the Council (EU member states) and the lead MEP negotiators. We now know (almost) exactly how the EU AI Act will be amended (unless there is a political earthquake). Although the new regulation has not yet been formally adopted and entered into force, it is a good time for enterprises to review their AI governance and compliance approaches, in light of the imminent changes.<br><br>This two-part series provides a comprehensive summary and explanation of the ten most significant EU AI Act amendments, drawing directly from the regulatory text recently approved by MEPs. The goal is to enable enterprise practitioners to prepare for and understand these changes. Part 2 (coming soon) will also feature a free EU AI Act Amendments Cheat Sheet visual.</em></p><p><strong>Background: </strong>In November 2025, the European Commission proposed various amendments to the EU AI Act, as part of its Digital Omnibus package. The stated purpose of this was to simplify and streamline key elements of the law, to reduce compliance burdens, support businesses, and boost European competitiveness. The trilogue negotiations that occurred over the past few months have resulted in the text of the regulation we can read and analyse today, which is now endorsed by all three EU institutions. Although the timeline changes and postponements are headline-grabbing, the core purpose, logic, and structure of the EU AI Act remain mostly intact. The EU is not walking away from comprehensive and stringent AI regulation.</p><p>The text still requires formal adoption and publication in the Official Journal of the EU before it enters into force. The substance, however, is now settled. Given the dependency on getting this done before the 2 August 2026 cut-off date, we can expect the EU to move quickly.</p><div><hr></div><p>I will be presenting on Agentic AI Governance and enterprise implementation at the <strong>Responsible AI Summit North America</strong> next week (on 23 and 24 June). Check out <a href="https://www.aidataanalytics.network/events-responsible-ai-summit-na">this page for more info</a> and reach out if you will be there!<br><br>My book, <em><strong><a href="https://aigovernancebook.com">Fundamentals of AI Governance</a></strong></em>, will be released in September. It features a comprehensive, visual guide to the EU AI Act, which will incorporate all of the amendments which are formally adopted. Pre-order today to secure a 25% discount.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><div><hr></div><p>For each of the ten most significant amendments I explain what the law says today, how this is changing, and the practical implications for enterprises. Items 1-5 are covered in Part 1 (this article) and items 6-10 are covered in Part 2. </p><p><strong>The 10 Most Significant EU AI Act Amendments</strong></p><ol><li><p><strong>Expanding the list of prohibited AI practices to ban &#8220;nudifier apps&#8221;.</strong></p></li><li><p><strong>Timeline changes for high-risk AI system compliance.</strong></p></li><li><p><strong>Timeline changes for transparency-requiring AI system compliance.</strong></p></li><li><p><strong>Limiting registration in the EU public database for the &#8220;exempted&#8221; AI systems. </strong></p></li><li><p><strong>Softening of the AI literacy obligation.</strong></p></li><li><p><strong>Processing sensitive personal data for bias detection and correction.</strong></p></li><li><p><strong>Expanding the scope of the European AI Office&#8217;s regulatory powers.</strong></p></li><li><p><strong>Proportionality for small mid-cap (SMC) enterprises.</strong></p></li><li><p><strong>Addressing potential duplication for high-risk AI systems regulated by the EU Machinery Regulation</strong>.</p></li><li><p><strong>Addressing potential duplication for AI systems which are regulated by other existing EU product safety laws.</strong></p></li></ol><p><strong>Disclaimer:</strong> <em>this article is not legal advice and should not be used, relied on, or interpreted as such. Always consult a qualified legal professional. Furthermore, this article does not cover all amendments outlined in the forthcoming regulation. Finally, these amendments have not yet been enacted as law. </em></p><h4><strong><br>1. Expanding the list of prohibited AI practices to ban &#8220;nudifier apps&#8221;</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 5 of the EU AI Act lists eight distinct prohibited AI practices. These provisions have been applicable since February 2025 and they carry the largest enforcement penalties under the AI Act, of up to 7% of global annual turnover for the most serious violations. The Commission&#8217;s original proposal in November 2025 did not feature any changes to the prohibited AI practices.<br><br><strong>How is this changing?</strong></p><p>A new category of prohibited AI practice is being added to Article 5 of the EU AI Act. Specifically, the <em>&#8220;placing on the market, the putting into service or the use of an AI system that generates or manipulates&#8221;</em> non-consensual intimate imagery or CSAM will be prohibited. This prohibition covers two broad scenarios:</p><ul><li><p>The intended purpose of the AI system is the generation or manipulation of non-consensual intimate imagery or CSAM.</p></li><li><p>The way the AI system has been developed, trained, and/or configured means that the generation or manipulation of non-consensual intimate imagery or CSAM is a <em>&#8220;reasonably foreseeable and reproducible outcome, without requiring significant technical modification, and the system does not have reasonable and adequate technical safety measures&#8221;</em> to prevent this.</p></li></ul><p>These two scenarios are most relevant for providers. However, deployers can also fall foul of this prohibition if they use an AI system to generate or manipulate non-consensual intimate imagery or CSAM. This can be done through use or misuse of a prohibited AI system, or potentially even through circumventing the preventive measures and guardrails in an AI system that is not prohibited.</p><p><strong>Enterprise implications</strong></p><p>This new prohibited AI practice will be applicable from 2 December 2026. The most practical implication is that providers of general-purpose AI (GPAI) systems will need to ensure that they implement robust, state-of-the-art guardrails and technical safeguards to mitigate these risks. According to the recital text, this can include:</p><ul><li><p>Data cleaning</p></li><li><p>Refusal training</p></li><li><p>Safe prompt design </p></li><li><p>Output controls</p></li><li><p>Runtime prompt guardrails</p></li><li><p>Content classification and filtering mechanisms</p></li><li><p>Usage restrictions</p></li><li><p>Abuse detection</p></li><li><p>Notice and action mechanisms<br></p></li></ul><h4><strong>2. Timeline changes for high-risk AI system compliance </strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>In law today, the applicable date for high-risk AI system compliance is <strong>2 August 2026</strong> for high-risk AI systems listed in Annex III (e.g., education, employment, and law enforcement) and <strong>2 August 2027</strong> for high-risk AI systems that are products, or safety components of products, regulated by an EU product safety law listed in Annex I. Some parts of the EU AI Act are already in force and applicable&#8212;this is not changing. For example, the provisions on prohibited AI practices, AI literacy, and GPAI models are applicable today. </p><p><strong>How is this changing?</strong></p><p>The EU has agreed to postpone the applicable date for high-risk AI system compliance. The new dates are <strong>2 December 2027</strong> for high-risk AI systems listed in Annex III and <strong>2 August 2028</strong> for high-risk AI systems covered by Annex I. These new dates will apply irrespective of the availability of harmonised standards and associated support tools. However, even though there is no new legal dependency, the regulatory text itself strongly emphasises the importance of the standards being ready and available.<br><strong><br>Enterprise implications</strong></p><p>The 16-month delay to the high-risk AI system compliance and enforcement date is arguably the most significant amendment for enterprises. It provides some breathing room and ensures that there will not be any investigation or enforcement action relating to high-risk AI system compliance until then. However, anyone who works in this field can appreciate that the time will fly by. Organisations would be unwise to use the delays as a reason to deprioritise.<br></p><h4>3. Timeline changes for transparency-requiring AI system compliance </h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 50 of the EU AI Act outlines the obligations for providers and deployers of transparency-requiring systems, covering topics like AI content labelling and disclosure. </p><p>Article 50(2) requires providers of AI systems that generate <em>&#8220;synthetic audio, image, video, or text content&#8221;</em> to ensure that their AI system outputs are <em>&#8220;marked in a machine-readable format and detectable as artificially generated or manipulated&#8221;</em>. This can be broadly referred to as the AI output detection and watermarking obligation. Currently, this specific obligation applies from <strong>2 August 2026</strong>, alongside all other Article 50 obligations. This compliance date applies to all AI systems, irrespective of whether they are placed on the market or put into service before or after 2 August 2026. </p><p><strong>How is this changing?</strong></p><p>The compliance date for the AI output detection and watermarking obligation is being postponed by 4 months, to <strong>2 December 2026</strong>. However, this postponement only applies to providers who have <em>&#8220;already placed their systems on the market before 2 August 2026&#8221;</em>, i.e., legacy AI systems that can generate this type of output. For AI systems placed on the market after 2 August 2026, they must be compliant from this date onwards.  </p><p><strong>Enterprise implications</strong></p><p>This is a shorter delay than was initially proposed by the Commission and Council, which both landed on 2 February 2027. It also solidifies the expectation that generative AI providers implement output detection and watermarking capabilities in all new AI systems. The recently published <strong><a href="https://digital-strategy.ec.europa.eu/en/policies/code-practice-ai-generated-content"><span>Code of Practice on Transparency of AI-Generated Content</span></a></strong><span> can support with this.</span></p><h4><strong><br>4. Limiting registration in the EU public database for the &#8220;exempted&#8221; AI systems. </strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Annex III of the EU AI Act lists eight categories of high-risk AI system, including law enforcement (#6), education and vocational training (#3), and employment, workers&#8217; management and access to self-employment (#5). </p><p>However, AI systems listed in Annex III are not high-risk if it can be demonstrated that they do not pose a significant risk of harm to health, safety, or fundamental rights. The parameters of this derogation are outlined in Article 6(3). One of these four conditions must apply for an Annex III AI system to be &#8220;exempt&#8221; from high-risk classification:</p><ul><li><p>The AI system is intended to perform a narrow procedural task.</p></li><li><p>The AI system is intended to improve the result of a previously completed human activity.</p></li><li><p>The AI system is intended to detect decision-making patterns or deviations from prior decision-making patterns and is not meant to replace or influence the previously completed human assessment, without proper human review</p></li><li><p>The AI system is intended to perform a preparatory task to an assessment relevant for an Annex III use case.</p></li></ul><p>Providers must register their Annex III high-risk AI systems in the EU&#8217;s public database for high-risk AI systems. This registration obligation <strong>also includes the &#8220;exempted&#8221; AI systems</strong> that the provider has concluded are not high-risk, via the derogation procedure outlined in Article 6(3). Therefore, if the provider follows the mandatory process of evaluating their AI system and documenting that it is not high-risk, they still need to register it.</p><p><strong>How is this changing?<br><br></strong>These &#8220;exempted&#8221; AI systems, which are considered not to be high-risk, will still need to be registered in the EU&#8217;s public database for high-risk AI systems. However, less information about these AI systems will need to be submitted as part of the registration. Specifically, the following information attributes will no longer need to be submitted:</p><ul><li><p>A short summary of the grounds on which the AI system is considered to be not-high-risk in application of the procedure under Article 6(3).</p></li><li><p>Any Member States in which the AI system has been placed on the market, put into service or made available in the Union.</p></li></ul><p>These are items 7 and 9 of Annex VIII (Section B) of the EU AI Act. Annex VIII outlines the information items that need to be registered for all high-risk AI systems and the &#8220;exempted&#8221; AI systems. The other items in Annex VIII (Section B) represent information which providers will have to submit about these &#8220;exempted&#8221; AI systems in the future.  </p><p><strong>Enterprise implications<br><br></strong>The EU is streamlining the content submission requirement without removing the registration obligation. This could be a tricky obligation to navigate for many enterprises. Although there is an element of simplification (as less information needs to be registered), the fundamental challenge remains: a large number of AI systems which are not high-risk will have to be registered. Any enterprise developing and deploying AI systems in one of the Annex III high-risk AI domains will have to evaluate, classify, track, and govern their AI systems, to keep on top of what needs to be registered and under which pathway. However, for everything that is registered, there will be less public transparency about why it is not considered high-risk.</p><h4><strong><br>5. Softening of the AI literacy obligation</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 4 of the EU AI Act obliges providers and deployers of AI systems to implement &#8220;AI literacy&#8221;. The AI literacy obligation has been applicable since February 2025. However, there are no direct enforcement penalties for non-compliance with it. <br><br>Specifically, Article 4 requires organisations to <em>&#8220;take measures <strong>to ensure, to their best extent, a sufficient level of AI literacy</strong> of their staff and other persons dealing with the operation and use of AI systems on their behalf&#8221;</em>. </p><p><strong>How is this changing?</strong></p><p>Here is the new text for Article 4(1):<strong><br><br></strong><em>&#8221;Providers and deployers of AI systems shall take measures <strong>to support the development of AI literacy</strong> of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. This obligation does not require providers or deployers to guarantee any specific level of AI literacy of any individual&#8221;.<br><br></em>The key difference is that organisations will no longer be obliged to take measures to &#8220;ensure&#8221; sufficient levels of AI literacy. Rather, they are obliged to &#8220;support the development&#8221; of AI literacy. Also, they will not be required to achieve a &#8220;sufficient level of AI literacy&#8221;. And it is clarified, with a new, additional clause, that organisations are not expected to guarantee the AI literacy level of a specific individual.<strong><br><br>Enterprise implications</strong></p><p>The change to the AI literacy provision seems fairly moderate on first reading, but it does represent a substantive softening of the legal obligation. Moving from &#8220;ensure&#8221; to &#8220;support&#8221; means that although organisations should still take meaningful steps to promote AI literacy, they are less likely to be held accountable for the lack of AI literacy in a particular individual and cannot be held to a measurable standard.</p><p>However, nothing in this change should be interpreted as a reason to abandon AI literacy and training which is focused on responsible AI. Furthermore, deployers must continue to assign human oversight of high-risk AI systems to staff with the &#8220;necessary competence, training and authority&#8221;&#8212;this separate provision is not changing. Moreover, actually complying with the EU AI Act in practice will not be possible without organisation-wide AI literacy.</p><p>Interestingly, both the Council and the Commission proposed removing the AI literacy obligation for providers and deployers. Ultimately, the Parliament stood its ground and the provision remains, albeit with a softer and more gentle flavour. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Banning AI is not an effective AI policy]]></title><description><![CDATA[Why prohibiting AI use backfires | #46]]></description><link>https://oliverpatel.substack.com/p/banning-ai-is-not-an-effective-ai</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/banning-ai-is-not-an-effective-ai</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Fri, 29 May 2026 17:42:10 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!oakI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!oakI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!oakI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5091339,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/199769083?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!oakI!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1bab1694-98d1-464d-93e3-11398b1734f8_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br><em>Some organisations still respond to AI with severe or disproportionate restrictions, up to and including outright bans on the use of AI. This article sets out five reasons why that approach backfires, from driving AI use into the shadows to discouraging high-value innovation. The core message is that the purpose of enterprise AI governance is not to stop people from using AI in order to mitigate risk, but to empower the workforce to use AI in a safe, responsible, and informed way.</em><br><br>If you value my work and want to read a comprehensive guide to enterprise AI governance and regulatory compliance, sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em>. It will be published in September 2026.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><p>Some organisations have implemented relatively cautious AI usage policies. At the more extreme end of the spectrum, this includes bans on the use of AI, either in general or in relation to specific activity areas. This was especially common in the earlier days of generative AI adoption, when there was less comfort and experience with the technology. Such restrictions have been more common in certain sectors, such as universities (e.g., bans on students using AI for coursework), law firms (e.g., bans on using AI to support client advisory work), and healthcare institutions (e.g., bans on using AI in patient-facing services). <br><br>Although wholesale AI bans are now less common, many organisations maintain highly restrictive AI policies. This can include only allowing the use of AI for certain use cases, requiring all AI use cases to be risk assessed via cumbersome processes, or only allowing employees to use one AI tool for their work. Anecdotally, it is often remarked that &#8220;we let our employees use Copilot, but that&#8217;s it&#8221;. Whilst the temptation for AI governance practitioners to implement similarly restrictive AI policies is understandable and well-intentioned, it is unlikely to work. </p><p>Here are five reasons why banning or significantly restricting the use of AI is not an effective AI policy. Each is explored in detail below: </p><ol><li><p><strong>The shadow AI risk</strong></p></li><li><p><strong>Policies must be conceptually sound and practically enforceable  </strong></p></li><li><p><strong>Workforce sentiment and engagement</strong></p></li><li><p><strong>Discouraging innovation and high-value use cases</strong></p></li><li><p><strong>The purpose of AI governance is to empower</strong><br></p></li></ol><h4><strong>1. The shadow AI risk</strong></h4><div><hr></div><p>Banning or significantly restricting the use of AI does not mean that employees will actually stop using AI. Just as the prohibition of alcohol in the U.S. in the 1920s did not stop people from purchasing and consuming alcohol, AI prohibitions do not stop AI use. Rather, it pushes it into the shadows. However, instead of a raucous Manhattan speakeasy bar, the &#8216;shadow&#8217; is the publicly available version of ChatGPT, Claude, or Gemini. This is because no matter what your policy says, people will still want and need to use AI in their work, and they will find ways to do so. <br><br>Shadow AI is one of the biggest challenges for enterprise AI governance and cybersecurity teams. Irrespective of your AI usage policy and its requirements, it is extremely difficult to deter and prevent the use of publicly available AI tools which are not approved. This shadow AI use poses a range of data and compliance risks. For example, it is challenging to protect any confidential data which is uploaded. Depending on the AI tool, such data may be shared with third parties or used to train publicly available AI models, increasing the risk of data leakage. It is also difficult to have meaningful oversight of potentially high-risk or regulated use cases and to ensure risks are effectively mitigated. Consider the law firm example provided above. Exposing client data via publicly available AI could be highly damaging. This is because it could breach the firm&#8217;s duty of confidentiality and, depending on the precise circumstances and AI tool used, risk waiving legal professional privilege. Therefore, whilst banning AI does not stop its use, it does mean you have less visibility and control. </p><p>It may seem counterintuitive, but one of the most effective AI governance &#8216;controls&#8217; is to provide your workforce with access to a wide range of cutting-edge AI tools, covering a multitude of capabilities and models. These AI tools should be complemented by proportionate and actionable usage policies, as well as clear guidance explaining which tools are available and approved for use, how to access them, and what their capabilities and limitations are. Finally, these tools should be configured with enterprise-grade guardrails and security controls, to protect your data and intellectual property. </p><p>The easier it is for employees to access and use approved and secure internal AI tools to solve their problems, the less incentivised they will be to use shadow AI, and the more visibility and control you will have. <strong><br></strong></p><h4><strong>2. Policies must be conceptually sound and practically enforceable  </strong></h4><div><hr></div><p>AI is a general-purpose technology which is increasingly being embedded in all software and devices that people use. When you use Google Maps, AI models help you navigate from A to B. When you order an Uber, AI models connect you with your driver. And when you use a search engine, AI models generate AI overviews for you to read. In this context, if you are going to ban or significantly restrict the use of AI, it will be challenging to define what the scope of the prohibition is and how it should be interpreted and complied with in practice. Consider a student that is told they cannot use AI as part of the essay-writing process. Does this also mean that when doing their research, they cannot read and factor in the AI overviews generated by the search engine? And why is this different from reading the content contained in the search results directly underneath, which are ranked and filtered by AI, and may also feature AI-generated content? As AI becomes ubiquitous, wholesale prohibitions are conceptually unsound and difficult to justify, implement, and enforce. <br><br>However, this does not mean that you should not restrict certain types of AI or data use. It is important to articulate and codify what your prohibited AI practices are, to ensure regulatory compliance and to uphold ethical standards. Also, certain types of data use may be inappropriate in certain AI tools, contexts, or jurisdictions. For example, AI overviews are not generated by Google in response to every search query, and are deliberately disabled in certain circumstances (e.g., certain queries during election campaigns due to the risks of AI-generated misinformation). Also, there are many reasons why universities will want to prohibit students from using AI to generate essays and submitting them as if they were their own work. However, this is more targeted and practical to enforce against than &#8220;do not use AI at all for your coursework&#8221;. <br><br>When you do implement an AI-related prohibition or restriction, it should be tightly defined, well-scoped, and supported by a rationale grounded in commercial, legal, or ethical considerations. If you do not take this approach, you risk your AI policies being perceived as disconnected from reality or even illegitimate. Furthermore, there will be lower levels of compliance and highly uneven or limited enforcement. All of this would have damaging implications for the credibility and effectiveness of the AI governance function. <br></p><h4>3. Workforce sentiment and engagement</h4><div><hr></div><p>It is not groundbreaking to claim that AI poses challenges for the workforce and for young people in particular. There is widespread concern and fear about what AI means for the future of work. This is leading to increased recognition of the importance of AI literacy and upskilling. Employees and students alike recognise that developing and honing AI skills, knowledge, and experience is one of the best things they can do for their career. If your organisation is perceived as actively blocking or undermining this&#8212;via overly restrictive AI usage policies or by failing to provide advanced AI tools for general use&#8212;then this is bound to have a negative impact. Merely saying &#8220;we let our employees use Copilot&#8221; and restricting everything else is no longer going to cut it. Such a rigid approach could also lead to difficulties in attracting and retaining talent.<br><br>Students, for example, may feel that they are not being adequately prepared for their future career if their university discourages them from using AI. A doctor may feel they are letting patients down by not leveraging the latest tech. And knowledge workers may feel that their long-term career aspirations are being undermined by an excessively cautious employer which is failing to keep up with the pace of technological change. This sentiment will be particularly acute amongst technical employees working in engineering, data science, and IT roles, as well as AI enthusiasts that want to vibe code prototypes and take advantage of all that agentic AI has to offer. Negative workforce sentiment and engagement is therefore a likely unintended consequence of banning or significantly restricting AI use. Do not underestimate the impact of sending the wrong message at the wrong time. </p><h4><strong><br>4. Discouraging innovation and high-value use cases</strong></h4><div><hr></div><p>This negative impact on employee engagement is likely to be exacerbated by broader opportunity costs relating to value generation. Although the precise level of impact is impossible to predict or quantify, it is highly likely that any organisation that takes an overly cautious approach will miss out on the efficiency, productivity, and innovation benefits that AI brings and the value that this can generate. This potential &#8220;loss&#8221; could be transformative or moderate, and will occur even with widespread shadow AI use. The precise scale of the opportunity cost depends on many factors. However, even in the best case scenario, over time, an organisation which is overly restrictive and discourages the use of AI will struggle to keep pace with competitors that take a more permissive and pro-innovation approach. </p><p>Simply put, by discouraging the use of AI, you will miss out on the use cases and innovations that could have positively transformed your business and its position in the market. Therefore, in one fell swoop you may be creating a disgruntled workforce and a less innovative and competitive organisation. <br><br>For those employees that circumvent the rules and leverage shadow AI, this activity is far less likely to result in impactful AI use cases and innovative ways of working that can be reused at scale across different teams and functions. If individuals and teams are knowingly breaching policies, they are more likely to keep quiet and perhaps only use AI for their personal productivity. In such an environment, an organisation will miss out on the benefits of employees exchanging and sharing information, best practice, and learnings about their AI use cases. Such knowledge exchange is valuable for promoting a culture of experimentation, innovation, and AI fluency, all of which is integral to successful AI adoption at scale. </p><h4><strong><br>5. The purpose of AI governance is to empower</strong></h4><div><hr></div><p>Ultimately, the purpose of enterprise AI governance is not to discourage, deter, or stop people from using AI. Wholesale prohibition is not an effective way of mitigating risk. Such an approach is characterised by a lack of nuance on a profoundly complex issue. Enterprise AI governance must be aligned with the broader strategic objectives of the organisation. Therefore, its aim should be to encourage and enable safe and responsible AI adoption. This can be done by implementing proportionate guardrails that promote governance by design and embedding a culture of openness and informed risk-taking. AI usage policies can support this by providing actionable dos and don&#8217;ts, making it clear which AI tools are approved for use, promoting a culture of experimentation and innovation, and clarifying which types of activities are prohibited, higher-risk, or subject to additional governance.<br><br>More broadly, forward-thinking organisations are thinking deeply about the role of the human in the AI era and making efforts to ensure their policies and guidance are empowering and ahead of the curve. </p><p>For example, many universities are no longer telling students to not use AI. Rather, they are highlighting, with actionable frameworks, guidelines, and case studies, the types of AI use that are appropriate, inappropriate, and borderline for different types of activities. This may differ from module to module and assignment to assignment. More broadly, they are educating students on why an informed and intentional approach to AI use matters for preserving academic integrity&#8212;and why academic integrity itself is important. They are teaching students how to use AI in a manner that advances critical thinking, and why the fastest route is not always the best route. Just telling a student to not use AI does not tell them why there is value in deepening their own expertise through structured engagement with primary literature, as well as what long-term benefits they may attain from refining their own thinking through independent writing. However, they are also teaching students how AI can be used to augment and accelerate various aspects of the research, writing, review, and editing processes, in a manner that does not undermine any of the aforementioned objectives.<br><br>By empowering your organisation with access to cutting-edge AI tools and capabilities, reinforcing this with high-quality AI literacy training, and encouraging your workforce to use AI to solve problems they face, you can achieve a transformative level of organisational AI fluency. Rather than telling people to not use AI, make it easy for everyone to understand what safe, responsible, and compliant AI use entails. And, if necessary, clarify where there are specific prohibitions or restrictions and why these exist. This is what effective and balanced AI governance looks like in practice.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[UPDATED! The Ultimate Agentic AI Governance Resource Guide]]></title><description><![CDATA[80+ resources to master agentic AI governance | Edition #45]]></description><link>https://oliverpatel.substack.com/p/updated-the-ultimate-agentic-ai-governance</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/updated-the-ultimate-agentic-ai-governance</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Fri, 24 Apr 2026 15:43:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aGkb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!aGkb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!aGkb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5743237,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/194690824?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!aGkb!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2897a2aa-3729-47bf-ba8d-1fb8cbd52bd7_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong>.</em></p><p>Apologies for the brief hiatus over the past couple of weeks. I&#8217;ve been hard at work finishing my book, <em><strong>Fundamentals of AI Governance</strong></em>, which I&#8217;m writing in my spare time alongside a rather busy day job. It will be published on 7 September 2026 and I can&#8217;t wait to share it with the community! Until then, I will post updates on Enterprise AI Governance every two weeks. You can pre-order the book here, to secure a 25% discount:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><p>This week&#8217;s newsletter presents the updated definitive agentic AI governance resource guide. This article (best viewed on browser) collates 80+ authoritative resources. Most of these resources have been published in the past 18 months and are grouped into 9 categories:</p><p>1&#65039;&#8419; Agentic AI: technology foundations and capabilities<br>2&#65039;&#8419; How enterprises are developing and deploying AI agents<br>3&#65039;&#8419; Agentic AI risks and challenges<br>4&#65039;&#8419; Risk mitigation and safeguards (security and safety)<br>5&#65039;&#8419; Agentic AI evaluations and observability<br>6&#65039;&#8419; Human oversight, accountability, and liability<br>7&#65039;&#8419; Agentic AI governance frameworks<br>8&#65039;&#8419; How EU law governs agentic AI: EU AI Act and GDPR<br>9&#65039;&#8419; AI provider guidance and agentic AI usage policies<br><br>This is a substantial update to my original resource guide, published in February 2026. I've added dozens of new resources, reflecting an exceptionally active period for agentic AI governance. This includes landmark outputs from the OECD, NIST, UK AISI, Spanish DPA, European Commission, and Dutch DPA, alongside major new academic and industry contributions&#8212;particularly on agentic AI and the EU AI Act. I've also introduced a new category&#8212;AI provider guidance and agentic AI usage policies&#8212;to capture the wave of usage policies and guidance that companies like Anthropic, OpenAI, Microsoft, and Google have published. </p><p>Whether you are working on the frontline of enterprise AI governance, advising clients in a legal or consulting capacity, or building, deploying, and using agentic AI systems, this resource guide enables you to keep track of and understand this rapidly evolving field. </p><div><hr></div><h4><strong>The Ultimate Agentic AI Governance Resource Guide</strong></h4><p><em>80+ resources to master agentic AI governance</em></p><div><hr></div><h4>1) Agentic AI: technology foundations and capabilities</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://www.oecd.org/en/publications/the-agentic-ai-landscape-and-its-conceptual-foundations_396cf758-en.html">The agentic AI landscape and its conceptual foundations</a></strong> - <em>OECD, (2026)</em></p></li><li><p><strong><a href="https://hai.stanford.edu/assets/files/ai_index_report_2026_chapter_2_technical.pdf">Technical Performance (Chapter 2)</a></strong> - <em>Stanford AI Index Report, (2026)</em></p></li></ul><p><em>Featured in previous resource guide</em></p><ul><li><p><strong><a href="https://www.ibm.com/think/ai-agents#605511093">The 2026 Guide to AI Agents</a></strong> - <em>IBM (2026)</em></p></li><li><p><strong><a href="https://cdn.openai.com/business-guides-and-resources/a-practical-guide-to-building-agents.pdf#:~:text=This%20guide%20is%20designed%20for,into%20practical%20and%20actionable%20best">A practical guide to building agents</a></strong> - <em>OpenAI (2025)</em></p></li><li><p><strong><a href="https://www.anthropic.com/engineering/building-effective-agents">Building Effective AI Agents</a></strong><a href="https://www.anthropic.com/engineering/building-effective-agents"> </a>- <em>Anthropic (2024)</em></p></li><li><p><strong><a href="https://huyenchip.com/2025/01/07/agents.html">Agents</a></strong> - <em>Chip Huyen (2025)</em></p></li><li><p><strong><a href="https://www.adalovelaceinstitute.org/policy-briefing/ai-assistants/">Delegation Nation: Advanced AI Assistants and why they matter</a></strong> - <em>Harry Farmer and Julia Smakman, Ada Lovelace Institute (2025)</em></p></li><li><p><strong><a href="https://www.preprints.org/manuscript/202512.2119">Large Language Model Agents: A Comprehensive Survey on Architectures, Capabilities, and Applications</a></strong> - Yiming Lei et al., (2025)</p></li><li><p><strong><a href="https://openreview.net/forum?id=WE_vluYUL-X">ReAct: Synergizing Reasoning and Acting in Language Models</a></strong> - <em>Shunyu Yao et al., (2023)</em> </p></li><li><p><strong><a href="https://arxiv.org/abs/2302.04761">Toolformer: Language Models Can Teach Themselves to Use Tools</a></strong> - <em>Timo Schick et al., (2023)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2201.11903">Chain-of-Thought Prompting Elicits Reasoning in Large Language Models</a> - </strong><em>Jason Wei et al., (2022)</em></p></li><li><p><strong><a href="https://modelcontextprotocol.io/docs/getting-started/intro">What is the Model Context Protocol (MCP)?</a></strong> <em>(2025)</em></p></li><li><p><strong><a href="https://cloud.google.com/discover/what-is-model-context-protocol">What is the MCP and how does it work?</a></strong> - <em>Google (2025)</em></p></li><li><p><strong><a href="https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/">Announcing the Agent2Agent Protocol (A2A): A new era  of Agent Interoperability</a></strong> - <em>Google (2025)</em></p></li></ul><div><hr></div><h4>2) How enterprises are developing and deploying AI agents</h4><p><em>Featured in previous resource guide</em></p><ul><li><p><strong><a href="/__u/cdn.sanity.io/files/4zrzovbb/website/cd77281ebc251e6b860543d8943ede8d06c4ef50.pdf">The 2026 State of AI Agents Report: How enterprises are building and deploying AI in production</a></strong> - <em>Anthropic (2026)</em></p></li><li><p><strong><a href="https://resources.anthropic.com/hubfs/2026%20Agentic%20Coding%20Trends%20Report.pdf?hsLang=en">2026 Agentic Coding Trends Report</a></strong> - <em>Anthropic (2026)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2512.04123">Measuring Agents in Production</a> </strong>- <em>Melissa Z. Pan et al. (2025)</em></p></li><li><p><strong><a href="https://www.langchain.com/state-of-agent-engineering">State of Agent Engineering</a></strong><a href="https://www.langchain.com/state-of-agent-engineering"> </a>- <em>LangChain (2026)</em></p></li><li><p><strong><a href="https://www.mckinsey.com/~/media/mckinsey/business%20functions/quantumblack/our%20insights/the%20state%20of%20ai/november%202025/the-state-of-ai-2025-agents-innovation_cmyk-v1.pdf">The state of AI in 2025: Agents, innovation, and transformation</a></strong> - <em>Alex Singla et al., McKinsey QuantumBlack (2025)</em></p></li><li><p><strong><a href="https://www.aisi.gov.uk/frontier-ai-trends-report/pdf">Frontier AI Trends Report</a></strong><a href="https://www.aisi.gov.uk/frontier-ai-trends-report/pdf"> </a>- <em>UK AI Security Institute (2025)</em></p></li></ul><div><hr></div><h4>3) Agentic AI risks and challenges</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://ico.org.uk/about-the-ico/research-reports-impact-and-evaluation/research-and-reports/technology-and-innovation/tech-horizons-and-ico-tech-futures/ico-tech-futures-agentic-ai/">Tech Futures: Agentic AI and Data Protection</a> </strong>- <em>UK Information Commissioner&#8217;s Office, (2026)</em></p></li><li><p><strong><a href="https://internationalaisafetyreport.org/publication/international-ai-safety-report-2026">International AI Safety Report 2026</a></strong> - <em>Yoshua Bengio et al., Department for Science, Innovation and Technology, (2026)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2510.26328">Agent Skills Enable a New Class of Realistic and Trivially Simple Prompt Injections</a></strong> - <em>David Schmotz, Sahar Abdelnabi, and Maksym Andriushchenko, (2025)</em></p></li></ul><p><em>Featured in previous resource guide</em></p><ul><li><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications for 2026</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/">Agentic AI - Threats and Mitigations</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/">Multi-Agentic system Threat Modelling Guide v1.0</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/initial-reflections-on-agentic-ai">Initial reflections on agentic AI governance</a></strong><a href="/__u/oliverpatel.substack.com/p/initial-reflections-on-agentic-ai"> </a>- <em>Oliver Patel, Enterprise AI Governance (2025)</em></p></li><li><p><strong><a href="https://domino.ai/blog/agentic-ai-risks-and-challenges-enterprises-must-tackle">Agentic AI risks and challenges enterprises must tackle</a></strong> - <em>Domino Data Lab (2025)</em></p></li></ul><div><hr></div><h4>4) Risk mitigation and safeguards (security and safety)</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://arxiv.org/pdf/2602.17753">The 2025 AI Agent Index: Documenting Technical and Safety Features of Deployed Agentic AI Systems</a> </strong>- <em>Leon Staufer et al., (2025)</em></p></li><li><p><strong><a href="https://www.saif.google/focus-on-agents">Secure AI Framework (SAIF) 2.0: Focus on Agents</a></strong> - <em>Google, (2025)</em></p></li></ul><p><em>Featured in previous resource guide </em></p><ul><li><p><strong><a href="https://openai.com/index/practices-for-governing-agentic-ai-systems/">Practices for Governing Agentic AI Systems</a></strong> - <em>Yonadav Shavit et al., OpenAI (2023)</em></p></li><li><p><strong><a href="https://www.governance.ai/research-paper/infrastructure-for-ai-agents">Infrastructure for AI Agents</a></strong> - <em>Alan Chan et al., Centre for the Governance of AI (2025)</em></p></li><li><p><strong><a href="https://www.centeraipolicy.org/work/ai-agents-governing-autonomy-in-the-digital-age">AI Agents: Governing Autonomy in the Digital Age</a></strong> - <em>Joe Kwon, Center for AI Policy (2025)</em></p></li><li><p><strong><a href="https://isomer-user-content.by.gov.sg/36/703ff9fe-9db1-4e09-98c2-89e3d7007ef0/Draft%20Addendum%20on%20Securing%20Agentic%20AI%20%5bFor%20Public%20Consultation%5d.pdf">Securing Agentic AI: An Addendum to the Guidelines and Companion Guide on Securing AI Systems</a></strong> - Cyber Security Agency of Singapore (2025)</p></li><li><p><strong><a href="https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/deploying-agentic-ai-with-safety-and-security-a-playbook-for-technology-leaders">Deploying agentic AI with safety and security: A playbook for technology leaders</a></strong> - <em>McKinsey (2025)</em></p></li><li><p><strong><a href="https://isomer-user-content.by.gov.sg/36/fbe74dcd-3905-4d62-96db-483f29a3ecfb/securing-agentic-ai-discussion.pdf">Securing Agentic AI: A Discussion Paper</a> - </strong><em>Cyber Security Agency of Singapore and Far.AI (2025)</em></p></li><li><p><strong><a href="https://research.google/pubs/an-introduction-to-googles-approach-for-secure-ai-agents/">Google&#8217;s Approach for Secure AI Agents</a> </strong>- <em>Christoph Kern and Kara Olive, Google (2025)</em></p></li><li><p><strong><a href="https://ai.meta.com/blog/practical-ai-agent-security/">Agents Rule of Two: A Practical Approach to AI Agent Security</a></strong><a href="https://ai.meta.com/blog/practical-ai-agent-security/"> </a>- <em>Meta (2025)</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ul><div><hr></div><h4>5) Agentic AI evaluations and observability</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://arxiv.org/pdf/2602.20021">Agents of Chaos</a></strong> - <em>Natalie Shapira et al., (2026)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2602.10453">The Landscape of Prompt Injection Threats in LLM Agents: From Taxonomy to Analysis</a> </strong>- <em>Peiran Wang et al., (2026)</em></p></li><li><p><strong><a href="https://spectrum.ieee.org/ai-agents-safety">AI Agents Break Rules Under Everyday Pressure</a></strong> - <em>Matthew Hutson, IEEE Spectrum, (2025)</em></p></li></ul><p><em>Featured in previous resource guide</em></p><ul><li><p><strong><a href="https://www.nist.gov/news-events/news/2025/01/technical-blog-strengthening-ai-agent-hijacking-evaluations">Strengthening AI Agent Hijacking Evaluations</a></strong> - <em>U.S. AI Safety Institute (2025)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2504.05259">How to Evaluate Control Measures for LLM Agents? A Trajectory from Today to Superintelligence</a></strong> - <em>Tomek Korbak et al., UK AI Security Institute (2025)</em></p></li><li><p><strong><a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">Demystifying evals for AI agents</a></strong> - <em>Anthropic (2026)</em></p></li><li><p><strong><a href="https://partnershiponai.org/wp-content/uploads/2025/09/agents-real-time-failure-detection.pdf?vgo_ee=zBAC1la9zQyJHSnpG6BgMHYqtA2DVnJIxaZdlyzMse4LqANZiVSdqdBDKQ%3D%3D%3AUuOdAvb8Al76ab6ZrhxDyj0LJ66FZeBh">Prioritizing Real-Time Failure Detection in AI Agents</a></strong> - <em>Madhulika Srikumar et al., Partnership on AI (2025)</em></p></li><li><p><strong><a href="https://azure.microsoft.com/en-us/blog/agent-factory-top-5-agent-observability-best-practices-for-reliable-ai/">Agent Factory: Top 5 agent observability best practices for reliable AI</a></strong> -  Yina Arenas, Microsoft (2025)</p></li></ul><div><hr></div><h4>6) Human oversight, accountability, and liability</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://www.cliffordchance.com/content/dam/cliffordchance/briefings/2026/02/agentic-ai-theliability-gap-your-contracts-may-not-cover.pdf">Agentic AI: The liability gap your contracts may not cover</a></strong> - <em>Clifford Chance, (2026)</em></p></li><li><p><strong><a href="https://arxiv.org/pdf/2602.11865">Intelligent AI Delegation</a></strong> - <em>Nenad Tomasev et al., Google DeepMind, (2026)</em></p></li><li><p><strong><a href="https://arxiv.org/pdf/2506.12469">Levels of Autonomy for AI Agents</a> </strong>- <em>K. J. Kevin Feng et al., (2025)</em></p></li></ul><p><em>Featured in previous resource guide </em></p><ul><li><p><strong><a href="https://arxiv.org/abs/2501.07913">Governing AI Agents</a></strong> - <em>Noam Kolt (2025)</em></p></li><li><p><strong><a href="https://www2.eecs.berkeley.edu/Pubs/TechRpts/2021/EECS-2021-207.html">The Principal-Agent Alignment Problem in AI</a></strong> - <em>Dylan Hadfield-Menell, UC Berkley (2021)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2510.09090">AI and Human Oversight: A Risk-Based Framework for Alignment</a> - </strong><em>Laxmiraju Kandikatla and Branislav Radeljic (2025)</em></p></li><li><p><strong><a href="https://www.adalovelaceinstitute.org/wp-content/uploads/pdfs/32617/the-dilemmas-of-delegation.pdf">The dilemmas of delegation: an analysis of policy challenges posed by Advanced AI Assistants and natural-language AI agents</a></strong> - <em>Harry Farmer, Ada Lovelace Institute (2025)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2502.02649">Fully Autonomous AI Agents Should Not be Developed</a></strong> - <em>Margaret Mitchell et al., Hugging Face (2025)</em></p></li><li><p><strong><a href="https://www.permit.io/blog/human-in-the-loop-for-ai-agents-best-practices-frameworks-use-cases-and-demo">Human-in-the-Loop for AI Agents: Best Practices, Frameworks, Use Cases, and Demo</a></strong> - <em>Gabriel L. Manor, Permit.io (2025)</em></p></li></ul><div><hr></div><h4>7) Agentic AI governance frameworks</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6567199">Scalable Runtime Governance for Agentic AI in Financial Services</a></strong> - <em>Lukasz Szpruch et al., (2026)</em></p></li></ul><p><em>Featured in previous resource guide</em></p><ul><li><p><strong><a href="https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf">Model AI Governance Framework for Agentic AI</a></strong> - <em>Singapore Infocomm Media Development Authority (2026)</em></p></li><li><p><strong><a href="https://www.weforum.org/publications/ai-agents-in-action-foundations-for-evaluation-and-governance/">AI Agents in Action: Foundations for Evaluation and Governance</a> </strong><em>- World Economic Forum (2025)</em></p></li><li><p><strong><a href="https://www.iaps.ai/research/ai-agent-governance">AI Agent Governance: A Field Guide</a></strong> <em>- Jam Kraprayoon, Institute for AI Policy and Strategy (2025)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2504.21848">Characterising AI Agents for Alignment and Governance</a></strong> - <em>Atoosa Kasirzadeh &amp; Iason Gabriel (2025)</em></p></li><li><p><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance-1-0/">The State of Agentic AI Security and Governance</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="https://www.adalovelaceinstitute.org/policy-briefing/the-regulation-of-delegation/">The regulation of delegation: Are AI advisers, agents and companions regulated in the UK?</a></strong> <em>- Julia Smakman, Ada Lovelace Institute (2025)</em></p></li><li><p><strong><a href="https://awo.cdn.ngo/media/documents/Final_Report_-_AWO_Analaysis_of_AAA_Harms_-_September_2025.pdf">Effective legal protections from harms caused by advanced AI assistants</a></strong> - <em>Lucie Audibert &amp; Alex Lawrence-Archer, AWO Agency (2025)</em></p></li></ul><div><hr></div><h4>8) How EU law governs agentic AI: EU AI Act and GDPR</h4><p><em>New resources</em></p><ul><li><p><strong><a href="https://arxiv.org/pdf/2604.04604">AI Agents Under EU Law: A Compliance Architecture for AI Providers</a></strong> - <em>Luca Nannini et al., (2026)</em></p></li><li><p><strong><a href="https://ai-act-service-desk.ec.europa.eu/en/faq">How are AI agents addressed within the AI Act?</a></strong> - <em>European Commission FAQs, (2026)</em></p></li><li><p><strong><a href="https://www.aepd.es/en/guides/agentic-artificial-intelligence.pdf">Agentic AI from the Perspective of Data Protection</a></strong> - <em>Spanish Data Protection Agency, (2026)</em></p></li><li><p><strong><a href="https://papers.ssrn.com/sol3/papers.cfm?abstract_id=6462658">Regulating AI Agents</a></strong> - <em>Kathrin Gardhouse, Amin Oueslati, and Noam Kolt, (2026)</em></p></li><li><p><strong><a href="https://storage.ghost.io/c/44/95/449506ca-034e-480f-9725-fcde08ef1cc1/content/files/2025/04/Human-Oversight-under-Article-14-of-the-EU-AI-Act.pdf">Human Oversight under Article 14 of the EU AI Act</a> </strong>- <em>Melanie Fink, (2026)</em></p></li><li><p><strong><a href="https://www.autoriteitpersoonsgegevens.nl/en/current/ap-warns-of-major-security-risks-with-ai-agents-like-openclaw">Autoriteit Persoonsgegevens (AP) warns of major security risks with AI agents like OpenClaw</a></strong> - <em>Dutch Data Protection Authority, (2026)</em></p></li></ul><p><em>Featured in previous resource guide</em></p><ul><li><p><strong><a href="https://thefuturesociety.org/wp-content/uploads/2023/04/Report-Ahead-of-the-Curve-Governing-AI-Agents-Under-the-EU-AI-Act-4-June-2025.pdf">Ahead of the Curve: Governing AI Agents Under the EU AI Act</a> </strong>- <em>Amin Oueslati and Robin Staes-Polet (2025)</em></p></li><li><p><strong><a href="https://www.europeanlawblog.eu/pub/dq249o3c/release/1">Agentic Tool Sovereignty</a></strong> - <em>Lloyd Jones, European Law Blog (2025)</em></p></li><li><p><strong><a href="https://iapp.org/news/a/engineering-gdpr-compliance-in-the-age-of-agentic-ai">Engineering GDPR compliance in the age of agentic AI </a></strong>- <em>Keivan Navaie, IAPP (2025)</em></p></li><li><p><strong><a href="https://fpf.org/wp-content/uploads/2025/04/Minding-Mindful-Machines_-AI-Agents-and-Data-Protection-Considerations.pdf">Minding Mindful Machines: AI Agents and Data Protection Considerations</a> -</strong> <em>Daniel Berrick, Future of Privacy Forum (2025)</em></p><div><hr></div></li></ul><h4>9) AI Provider Guidance and Agentic AI Usage Policies </h4><p><em>New resources</em></p><p><strong>Anthropic</strong></p><ul><li><p><strong><a href="https://www.anthropic.com/legal/aup">Anthropic Usage Policy</a></strong> (with dedicated agentic AI provisions) (2025)</p></li><li><p><strong><a href="https://support.claude.com/en/articles/12005017-using-agents-according-to-our-usage-policy">Using Agents According to Our Usage Policy</a></strong> <em>(2026)</em></p></li><li><p><strong><a href="https://support.claude.com/en/articles/13364135-use-claude-cowork-safely">Use Claude Cowork Safely</a></strong> <em>(2026)</em></p></li></ul><p><strong>OpenAI</strong></p><ul><li><p><strong><a href="https://openai.com/en-GB/policies/usage-policies/">OpenAI Usage Policies</a> </strong><em>(2025)</em></p></li><li><p><strong><a href="https://openai.com/policies/using-chatgpt-agent-in-line-with-our-policies/">Using ChatGPT agent in line with our policies</a></strong><a href="https://openai.com/policies/using-chatgpt-agent-in-line-with-our-policies/"> </a><em>(2025)</em></p></li><li><p><a href="https://developers.openai.com/codex/agent-approvals-security"> </a><strong><a href="https://developers.openai.com/codex/agent-approvals-security">Agent approvals &amp; security (Codex)</a></strong> <em>(2026)</em></p></li></ul><p><strong>Microsoft</strong></p><ul><li><p><strong><a href="https://learn.microsoft.com/en-us/microsoft-copilot-studio/system-service-card-copilot-studio">Microsoft Copilot Studio Application Card</a></strong> <em>(2026)</em></p></li><li><p><strong><a href="https://learn.microsoft.com/en-us/microsoft-copilot-studio/responsible-ai-overview">Responsible AI FAQs for Copilot Studio</a></strong> <em>(2026)</em></p></li><li><p><strong><a href="https://learn.microsoft.com/en-us/microsoft-copilot-studio/guidance/maturity-model-security-governance">Agentic AI Adoption Maturity Model: AI Governance and Security Pillar</a></strong> <em>(2026)</em></p></li></ul><p><strong>Google</strong></p><ul><li><p><strong><a href="https://ai.google.dev/gemini-api/terms">Gemini API Additional Terms of Service</a></strong> <em>(2026)</em></p></li></ul><div><hr></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[EU AI Act Amendments Cheat Sheet]]></title><description><![CDATA[Free and comprehensive visual mapping of the negotiating positions | #44]]></description><link>https://oliverpatel.substack.com/p/eu-ai-act-amendments-cheat-sheet</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/eu-ai-act-amendments-cheat-sheet</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 29 Mar 2026 21:43:40 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ihCP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!ihCP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!ihCP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6132726,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/192542530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!ihCP!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc19def76-3ac4-442b-a5f3-df9546a547f7_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.</p><p>This week I'm releasing a new Cheat Sheet which maps and compares the negotiating positions of the European Commission, Council of the EU, and European Parliament on AI Act amendments&#8212;across eight key domains. It takes 180+ pages of legislative complexity and distils it into one graphic. You can download it for free below (it&#8217;s much better viewed on a large screen as a high-res pdf).<br><br>If you value my work and want to read a comprehensive, visual guide to enterprise AI governance implementation&#8212;with over 150 original cheat sheets like this&#8212;sign up to pre-order my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026), for a 25% discount.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><p>Frequent readers of <em>Enterprise AI Governance</em> will recall that this newsletter has covered the EU AI Act amendment process in detail. Understanding and adhering to the AI Act is integral for AI governance practitioners and the organisations they support, given the uniquely comprehensive and stringent nature of this law, as well as its extraterritorial scope and cross-sectoral coverage.</p><p>As if AI governance was not hard enough already, practitioners now find themselves in the unenviable position of having to track and make sense of a raft of proposed amendments to this fiendishly complex law. Given that the AI Act only entered into force in August 2024 and is not yet fully applicable, the fact that substantive amendments are already being advanced is telling. It signals both the challenges of moving as early to regulate AI as the EU did&#8212;something which governments like the UK warned about&#8212;as well as the increasing pressure within the EU to make life easier for businesses.<br><br>Although, perhaps every AI governance practitioner can empathise with the EU, to a certain extent. Having to constantly adapt is a familiar feeling and a defining challenge of this field, given the relentless pace at which the AI technology and risk landscape is evolving, coupled with the increasing emphasis corporate leaders are placing on the importance of AI for their organisation&#8217;s future success. <br><br>Last week was a significant milestone for the AI Act amendment process. The European Parliament formally adopted its position on AI Act simplification, with MEPs voting to adopt a set of proposed amendments on 26 March 2026. The margin of approval was decisive: 569 votes in favour, 45 against, and 23 abstentions. <br><br>Following months of work behind the scenes, we now have the official negotiating positions for each of the three co-legislating institutions. The trilogue negotiations can now begin. The clock is ticking to August 2026, when the high-risk AI compliance date is due to kick in.<br><br>Each of these documents outline the respective institutions&#8217; position for how the AI Act should be amended (via a new regulation):</p><ul><li><p><strong><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:52025PC0836">European Commission position</a></strong> (published 19 November 2025)</p></li><li><p><strong><a href="https://data.consilium.europa.eu/doc/document/ST-7322-2026-INIT/en/pdf">Council of the EU (member states) position</a></strong> (13 March 2026)</p></li><li><p><strong><a href="https://www.europarl.europa.eu/doceo/document/TA-10-2026-0098_EN.pdf">European Parliament position</a></strong> (26 March 2026)</p></li></ul><p>My intention in covering this process has been to support readers with some of the analytical heavy lifting, by breaking down the complexity of these developments in a digestible way. Indeed, there are now over 180 pages of dense legislative text to wade through, in addition to 144-page AI Act itself. </p><p>Previous editions of <em>Enterprise AI Governance</em> have already covered:</p><ul><li><p><strong><a href="/__u/oliverpatel.substack.com/p/whats-next-for-eu-ai-act-simplification">Why the EU is amending the flagship digital laws</a></strong><a href="/__u/oliverpatel.substack.com/p/whats-next-for-eu-ai-act-simplification">, like the AI Act, and the impact of the Draghi report </a></p></li><li><p><a href="/__u/oliverpatel.substack.com/p/how-could-the-eu-ai-act-change">A deep-dive on the </a><strong><a href="/__u/oliverpatel.substack.com/p/how-could-the-eu-ai-act-change">European Commission&#8217;s proposal</a></strong><a href="/__u/oliverpatel.substack.com/p/how-could-the-eu-ai-act-change"> for AI Act amendments</a> </p></li><li><p><a href="/__u/oliverpatel.substack.com/p/eu-member-states-agree-to-amend-the">A comparative analysis of the </a><strong><a href="/__u/oliverpatel.substack.com/p/eu-member-states-agree-to-amend-the">Commission and Council positions</a></strong></p></li></ul><p>The key contribution of this week&#8217;s edition is an original Cheat Sheet, exclusively available for free download below, which compares and contrasts the negotiating positions of the Commission, Council, and Parliament&#8212;mapped against what is in law today. Although I will not do a detailed write-up of the European Parliament&#8217;s position, the visual highlights the key aspects. </p><p>Of note, both the Council and the Parliament have somewhat curtailed some of the more ambitious simplification measures proposed by the Commission (e.g., on sensitive data processing and registration of &#8220;exempted&#8221; AI systems), and have (broadly speaking) aligned on a new prohibited AI practice. Also, the Parliament is ostensibly more supportive than the Council and Commission of retaining a broad and explicit AI literacy obligation. Crucially, all three institutions are converging on 2 December 2027 as the applicable date for the high-risk AI systems listed in Annex III. Such a delay will give enterprises 16 additional months to get compliant.<br><strong><br></strong><em><strong>This visual is much better viewed on a large screen as a downloaded pdf :)</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!pf83!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 424w, /__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 848w, /__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!pf83!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png" width="1456" height="1341" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1341,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1884113,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/192542530?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 424w, /__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 848w, /__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!pf83!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faec7451d-14c5-429d-97cf-7b54aff7444b_5728x5275.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail-default" src="/__u/substackcdn.com/image/fetch/$s_!0Cy0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack.com%2Fimg%2Fattachment_icon.svg"></image><div class="file-embed-details"><div class="file-embed-details-h1">EU AI Act Amendments Cheat Sheet (by Oliver Patel)</div><div class="file-embed-details-h2">365KB &#8729; PDF file</div></div><a class="file-embed-button wide" href="/__u/oliverpatel.substack.com/api/v1/file/d3ee3ee4-f979-4d24-a2fe-b88759b79f5a.pdf"><span class="file-embed-button-text">Download</span></a></div><div class="file-embed-description">Download the high-res pdf here</div><a class="file-embed-button narrow" href="/__u/oliverpatel.substack.com/api/v1/file/d3ee3ee4-f979-4d24-a2fe-b88759b79f5a.pdf"><span class="file-embed-button-text">Download</span></a></div></div><p><strong>Disclaimer:</strong> <em>nothing in this article or Cheat Sheet constitutes legal advice and this content should not be used, relied on, or interpreted as such. It is for educational purposes only. Always consult a qualified legal professional for your specific compliance or legal needs.</em> </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[EU member states agree to amend the AI Act]]></title><description><![CDATA[Status update on the EU AI Act amendment process | #43]]></description><link>https://oliverpatel.substack.com/p/eu-member-states-agree-to-amend-the</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/eu-member-states-agree-to-amend-the</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Fri, 20 Mar 2026 12:11:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tvEy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!tvEy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!tvEy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5346313,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/191565299?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!tvEy!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F05eeee59-0844-463c-b794-49eb8594f646_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br>On 19 November 2025, the European Commission proposed targeted amendments to the EU AI Act as part of its Digital Omnibus package. On 13 March 2026, the Council of the EU (i.e., the EU member state governments) agreed its negotiating position, broadly maintaining the Commission&#8217;s proposals whilst introducing several notable changes. Finally, on 18 March, the European Parliament&#8217;s Internal Market and Civil Liberties committees adopted their joint position by 101 votes to 9, with a plenary vote expected on 26 March. Trilogue negotiations between the three institutions will follow this vote.<br><br>This article analyses the eight most consequential proposed amendments, comparing and contrasting the positions of the Commission and the Council. For each, I explain what is in the law today, what the Commission is proposing, and what the Council is proposing. I have excluded the European Parliament&#8217;s position from this analysis, as it has not yet been formally approved by MEPs via the plenary vote.<br><br>If you value my work and want to read a comprehensive guide to the EU AI Act and enterprise AI governance, sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><p>The key AI Act changes this article analyses are: </p><ol><li><p><strong>Expanding the list of prohibited AI practices.</strong></p></li><li><p><strong>Timeline changes for high-risk AI system compliance.</strong></p></li><li><p><strong>Timeline changes for transparency-requiring AI system compliance.</strong></p></li><li><p><strong>Limiting registration in the EU public database for high-risk AI systems.</strong></p></li><li><p><strong>Softening of the AI literacy obligation.</strong></p></li><li><p><strong>Processing sensitive personal data for bias mitigation.</strong></p></li><li><p><strong>Expanding the scope of the European AI Office&#8217;s regulatory powers.</strong></p></li><li><p><strong>Proportionality for small mid-cap (SMC) enterprises.</strong></p></li></ol><p>Before diving in, three caveats are needed. First, this article presents the positions of two of the three co-legislating EU institutions&#8212;neither of which represents the final text. Second, the upcoming trilogue negotiations may result in significant changes. Third, and critically, the existing AI Act remains fully in force. Unless and until these amendments are formally adopted, the current obligations and timelines apply, including the 2 August 2026 applicable date for high-risk AI system compliance.<br><br>Here are the key documents this article is based on:</p><ul><li><p><a href="https://eur-lex.europa.eu/legal-content/EN/TXT/PDF/?uri=CELEX:52025PC0836">European Commission AI Act amendments and negotiating position</a> (November 2025)</p></li><li><p><a href="https://data.consilium.europa.eu/doc/document/ST-7322-2026-INIT/en/pdf">Council of the EU AI Act amendments and negotiating position</a> (March 2026)</p></li><li><p><a href="https://www.europarl.europa.eu/news/en/press-room/20260316IPR38219/meps-support-postponement-of-certain-rules-on-artificial-intelligence">European Parliament Committee position and vote details</a> (March 2026)</p></li><li><p><a href="https://eur-lex.europa.eu/eli/reg/2024/1689/oj/eng">Original text of EU AI Ac</a></p></li></ul><p><strong>Scope:</strong> <em>this article focuses on the eight EU AI Act changes that are most consequential for enterprises implementing AI governance. It does not cover all EU AI Act changes, nor the proposed amendments to the GDPR or other EU digital legislation.</em> <br><br><strong>Disclaimer:</strong> <em>this article is not legal advice and should not be used, relied on, or interpreted as such. Always consult a qualified legal professional.<br></em></p><h4><strong>1. Expanding the list of prohibited AI practices</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 5 of the EU AI Act lists eight distinct prohibited AI practices. These provisions have been applicable since February 2025 and they carry the largest enforcement penalties under the AI Act, of up to 7% of global annual turnover for the most serious violations. <br><br><strong>What is the European Commission&#8217;s position<br><br></strong>The Commission did not propose amendments or additions to the prohibited AI practices outlined in Article 5.  <br><br><strong>What is the Council&#8217;s position?<br><br></strong>The most significant amendment proposed by the Council is to add two new prohibited AI practices to Article 5 of the AI Act. Under this proposal, AI systems capable of &#8220;generating, manipulating or reproducing&#8221; non-consensual intimate imagery (and similar content) would be prohibited, as well as AI systems capable of  &#8220;generating, manipulating or reproducing&#8221; CSAM. These prohibitions cover the following scenarios:</p><ul><li><p>The intended purpose of the AI system is to generate, manipulate or reproduce non-consensual intimate imagery or CSAM.</p></li></ul><ul><li><p>It is a &#8220;reasonably foreseeable&#8221; reproducible outcome that the AI system could be used in this way<sub>,</sub> without requiring significant technical modification, due to the way the AI system has been developed and its functionality. Furthermore, the safety measures and guardrails are not effectively able to prevent this type of use.</p></li></ul><p>The second point is significant, as it puts the onus on AI system providers to ensure that the safety features and guardrails they develop and configure are sufficiently robust to prevent this type of malicious and harmful use. The Council provides the following as examples of effective safety features and guardrails:</p><ul><li><p>Refusal training</p></li></ul><ul><li><p>Data cleaning</p></li></ul><ul><li><p>Output controls</p></li></ul><ul><li><p>Content classification and filtering</p></li></ul><ul><li><p>Usage restrictions</p></li></ul><ul><li><p>Abuse detection</p></li></ul><ul><li><p>Notice action and corrective measures <br></p></li></ul><h4><strong>2. Timeline changes for high-risk AI system compliance </strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>From 2 August 2026, unless there is a change in the law, providers and deployers must adhere to the obligations and requirements for high-risk AI systems. However, this applicable date only applies to high-risk AI systems listed in Annex III (e.g., education, employment, law enforcement etc.) that are placed on the market or put into service from 2 August 2026 onwards. Annex III high-risk AI systems that predate this are only subject to these EU AI Act obligations and requirements if there is a significant change in the AI system&#8217;s design or intended purpose. For high-risk AI systems that are products, or safety components of products, regulated by the EU product safety laws listed in Annex I, the applicable date is 2 August 2027. <br><br><strong>What is the European Commission&#8217;s position<br><br></strong>The Commission&#8217;s position is to link the availability of standards with the applicable date for high-risk AI system compliance. To do this, two options are proposed. </p><p><strong>Scenario 1. </strong>If harmonised standards and associated support tools for high-risk AI system compliance are finalised and approved by the Commission, then the applicable compliance date should be six months after this approval (for high-risk AI systems listed in Annex III) and 12 months after this approval (for product safety-related high-risk AI systems covered by Annex I). </p><p><strong>Scenario 2.</strong> If harmonised standards and associated support tools for high-risk AI system compliance are not finalised or approved by the Commission in a given timeframe (i.e., before the dates below), then the applicable compliance dates should be 2 December 2027 (for high-risk AI systems listed in Annex III) and 2 August 2028 (for product safety-related high-risk AI systems covered by Annex I). These effectively serve as backstop dates.<br><br><strong>What is the Council&#8217;s position?<br><br></strong>The Council&#8217;s position is more straightforward. Its proposal is that the applicable date for high-risk AI system compliance should be 2 December 2027 (for high-risk AI systems listed in Annex III) and 2 August 2028 (for product safety-related high-risk AI systems covered by Annex I). These dates would apply irrespective of the availability of harmonised standards and associated support tools.  <br></p><h4>3. Timeline changes for transparency-requiring AI system compliance </h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 50(2) requires providers of AI systems that generate &#8220;synthetic audio, image, video, or text content&#8221; to ensure that their AI system outputs are &#8220;marked in a machine-readable format and detectable as artificially generated or manipulated&#8221;. Currently, this specific obligation applies from <strong>2 August 2026</strong>. This compliance date applies to all AI systems, irrespective of whether they are placed on the market or put into service before or after 2 August 2026. <br><br><strong>What is the European Commission&#8217;s position?</strong></p><p>The Commission proposes to postpone the applicable date for this specific transparency obligation to <strong>2 February 2027</strong> for providers of AI systems that have been placed on the market before 2 August 2026. This proposed six-month postponement only applies to obligation stipulated in Article 50(2) and not the other transparency obligations outlined in Article 50. <br><br><strong>What is the Council&#8217;s position?</strong></p><p>The Council&#8217;s position is the same as the Commission&#8217;s. No changes were proposed to the Commission&#8217;s original proposal.  </p><h4><strong><br>4. Limiting registration in the EU public database for high-risk AI systems</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Annex III of the EU AI Act lists eight categories of high-risk AI system, including law enforcement (#6), education and vocational training (#3), and employment, workers&#8217; management and access to self-employment (#5). </p><p>However, AI systems listed in Annex III are not considered high-risk if it is demonstrated that they do not pose significant risk of harm to health, safety, or fundamental rights. For example, if the AI system does not materially influence decisions or is only used for a narrow procedural task, the provider is entitled to demonstrate, based on a documented assessment, that it is not a high-risk AI system. The parameters of this derogation are outlined in Article 6(3). This derogation procedure only applies to AI systems listed in Annex III. <br> <br>Providers must register high-risk AI systems listed in Annex III in the EU public database for high-risk AI systems. This registration obligation <strong>also includes</strong> &#8220;exempted&#8221; AI systems that the provider has concluded are not high-risk via the derogation procedure outlined in Article 6(3). <br><br><strong>What is European Commission&#8217;s position?</strong> <br> <br>The Commission proposes to limit the scope of this registration obligation so that it no longer applies to AI systems that providers have concluded are not high-risk via the Article 6(3) derogation procedure. Simply put, where a provider has assessed and documented that an AI system used in an Annex III domain is not high-risk, the provider would not have to register that AI system in the EU public database.<br> <br><strong>What is the Council&#8217;s position?</strong> <br> <br>The Council is proposing a more moderate amendment. Rather than completely removing the registration obligation for these exempted AI systems, registration would still be mandatory. However, less information would be required to be submitted as part of the registration. Annex VIII of the EU AI Act lists 9 information attributes that must be registered in relation to these exempted AI systems. The Council&#8217;s position is to remove 2 out of 9 attributes:</p><ul><li><p>The summary of why the AI system is not high-risk.</p></li></ul><ul><li><p>The EU member states in which the AI system is placed on the market, put into service, or made available.</p></li></ul><p>The purpose of this is to make the registration process more simplified and streamlined in these scenarios, whilst retaining the transparency and accountability registration provides. </p><h4><strong><br>5. Softening of the AI literacy obligation</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 4 of the EU AI Act obliges providers and deployers of AI systems to implement &#8220;AI literacy&#8221;. Specifically, Article 4 requires organisations to ensure that &#8220;staff and other persons dealing with the operation and use of AI systems&#8221; have a &#8220;sufficient level of AI literacy&#8221;. The AI literacy obligation has been applicable since February 2025. However, there are no enforcement penalties for non-compliance with it. <br> <br><strong>What is the European Commission&#8217;s position?</strong> <br> <br>The Commission proposes to remove the obligation for providers and deployers to implement AI literacy. Rather than providers and deployers being legally obliged to ensure their staff operating and using AI systems have sufficient levels of AI literacy, the Commission and member states will be required to foster and encourage AI literacy. <br> <br><strong>What is the Council&#8217;s position?</strong> <br> <br>The Council&#8217;s position is largely aligned with the Commission&#8217;s. There would no longer be a broad and widely applicable AI literacy obligation for providers and deployers of AI systems. Rather, the Commission and member states will be obliged to encourage AI literacy across the EU.</p><p>However, the Council&#8217;s proposal is to clarify, in Article 4, that providers and deployers of high-risk AI systems have specific AI literacy and training-related obligations, stipulated or implied in different parts of the EU AI Act. For example, deployers must assign human oversight (of high-risk AI systems) to individuals with the &#8220;necessary competence, training and authority&#8221;. Also, as part of the provider&#8217;s quality management framework, roles and responsibilities must be assigned to management and other staff, and these individuals must be adequately trained and competent to fulfil these responsibilities. <br> <br>Nonetheless, this clarification does not introduce substantive new AI literacy or training-related obligations for organisations. It merely reinforces what is already required for high-risk AI system compliance. </p><h4><strong><br>6. Processing sensitive personal data for bias mitigation </strong></h4><div><hr></div><p><strong>What is in law today?</strong> <br> <br>The GDPR stipulates that the processing of &#8220;special categories&#8221; of personal data (i.e., sensitive personal data) is prohibited, apart from in limited circumstances. Sensitive personal data includes:</p><ul><li><p>Racial or ethnic origin</p></li></ul><ul><li><p>Political opinions</p></li></ul><ul><li><p>Religious or philosophical beliefs</p></li></ul><ul><li><p>Trade union membership</p></li></ul><ul><li><p>Genetic data</p></li></ul><ul><li><p>Biometric data for the purpose of uniquely identifying a natural person</p></li></ul><ul><li><p>Health data</p></li></ul><ul><li><p>Sex life or sexual orientation</p></li></ul><p>Sensitive data can only be processed in limited circumstances, where a specific GDPR Article 9(2) exception applies. This includes, but is not limited to, where explicit consent has been obtained or where processing the data is necessary to &#8220;protect the vital interests of the data subject&#8221; where they are &#8220;physically or legally incapable of giving consent&#8221;. <br> <br>Article 10(5) of the AI Act provides another way in which sensitive personal data can be processed. It stipulates that providers of high-risk AI systems can process sensitive personal data for the purpose of &#8220;ensuring bias detection and correction&#8221; in relation to their high-risk AI systems. However, it must be &#8220;strictly necessary&#8221; to use the sensitive personal data in this way, and the bias detection and correction cannot be effectively achieved by other means. These conditions create a high practical bar for providers. Furthermore, this exception is subject to additional strict conditions, such as implementing robust safeguards relating to data transfer, reuse, and deletion. <br> <br><strong>What is the European Commission&#8217;s position?</strong></p><p>The Commission&#8217;s proposal is to broaden the scope of when organisations can process sensitive personal data for bias detection and correction. Rather than limiting this exclusively to providers of high-risk AI systems, it is expanded to providers and deployers of other AI systems and AI models, including deployers of high-risk AI systems. The rationale for this is because harmful biases could also arise from the use of AI in other contexts.  <br> <br>This means that sensitive personal data could be lawfully processed for bias detection and correction in a much broader range of circumstances and by a wider range of organisations. For this reason, the proposal is to move this provision from Article 10 to Article 4a of the AI Act, as it applies more broadly than to just high-risk AI systems.  <br> <br>Additionally, rather than this type of data processing only being permitted when it is &#8220;strictly necessary&#8221;, sensitive data could be processed when it is merely &#8220;necessary&#8221; (to ensure bias detection and correction). This subtle change lowers the bar for when organisations can use sensitive personal data in this way.  <br> <br><strong>What is the Council&#8217;s position?</strong></p><p>The Council largely agrees with broadening the scope&#8212;beyond providers of high-risk AI systems&#8212;for when sensitive personal data could be processed for bias detection and correction. This means that providers and deployers of other AI systems, including deployers of high-risk AI systems, would be permitted to process sensitive personal data for this bias detection and correction. However, the Council&#8217;s proposed changes are more limited than the Commission&#8217;s, in two important ways:</p><ul><li><p>Processing sensitive personal data would still have to be <strong>&#8220;strictly necessary&#8221;</strong> for ensuring bias detection and correction.</p></li></ul><ul><li><p>Providers and deployers of other AI systems and deployers of high-risk AI systems would only be permitted to do so to address<strong> specific types of biases</strong> impacting health, safety, fundamental rights, or discrimination.</p></li></ul><p>Therefore, although a wider range of organisations could process sensitive personal data for bias detection and correction in a broader range of circumstances than what the AI Act currently allows for, it would nonetheless be more limited than what the Commission is proposing.<strong><br></strong></p><h4><strong>7. Expanding the scope of the European AI Office&#8217;s regulatory powers</strong></h4><div><hr></div><p><strong>What is in law today?</strong> <br> <br>The AI Act enforcement architecture for AI systems is decentralised. </p><p>The AI Office, which is part of the European Commission, is responsible for overseeing and enforcing the provisions on general-purpose AI (GPAI) models. At the member state level, the national market surveillance authorities (there are typically several per member state) are responsible for overseeing and enforcing the provisions on AI systems (e.g., high-risk and transparency-requiring AI systems), as well as most other AI Act provisions.  <br> <br>Article 75(1) provides the AI Office with powers to monitor and supervise AI systems based on GPAI models. This applies when the AI model and AI system are developed by the same provider. However, this is not an exclusive power. National market surveillance authorities can also oversee and enforce applicable provisions relating to these AI systems. This creates potential situations of overlapping competence and providers being regulated by multiple regulators simultaneously.  <br> <br><strong>What is the European Commission&#8217;s position?</strong> <br> <br>The Commission proposes to &#8220;centralise oversight over a large number of AI systems built on general-purpose AI models&#8221; when the same provider develops both the GPAI model and the AI system. <br> <br>The proposed amendments to Article 75 would render the AI Office as the sole body responsible for monitoring and supervising compliance of AI systems that leverage GPAI models. However, this would only apply when the GPAI model and the AI system are developed and placed on the market or put into service by the same provider. In such scenarios, the AI Office would be <strong>&#8220;exclusively competent&#8221;</strong>, which means that the market surveillance authorities in the respective EU member states would no longer have a supervisory role. The AI Office would also have &#8220;all the powers of a market surveillance authority&#8221;. In a nutshell, the key change to Article 75 is the shift from shared to exclusive competence. <br> <br>This change primarily affects high-risk AI systems listed in Annex III and transparency-requiring AI systems regulated by Article 50 (where such AI systems leverage general-purpose AI models). It does not apply to high-risk AI systems covered by an EU product safety law listed in Annex I. <br> <br><strong>What is the Council&#8217;s position?</strong> <br> <br>Whilst the Council broadly aligns with the Commission&#8217;s proposals, it has introduced specific exceptions to this expansion in scope of the AI Office&#8217;s regulatory powers.  <br> <br>Under the Council&#8217;s proposal, the AI Office would be &#8220;exclusively competent&#8221; for the supervision and enforcement of AI Act provisions for AI systems based on GPAI models where the AI model and AI system are developed by the same provider&#8212; which includes different entities in the same corporate group (a subtle change to the Commission&#8217;s position). However, the exceptions to this AI Office exclusive competence are:</p><ul><li><p>Product safety-related high-risk AI systems covered by Annex I.</p></li></ul><ul><li><p>AI systems used for critical infrastructure management and operation (Annex III, point 2).</p></li></ul><ul><li><p>AI systems provided by law enforcement authorities and border management authorities.</p></li></ul><ul><li><p>AI systems provided by certain financial institutions.</p></li></ul><ul><li><p>AI systems used for the administration of justice and democratic processes (Annex III, point 8).</p></li></ul><p>This proposal means that, for the above exceptions, the AI Office would not have exclusive competence. The Council is signalling that these areas (i.e., critical infrastructure, law enforcement, border management, financial services etc.) should be the domain of member state regulators, not the European Commission.</p><h4><strong><br>8. Proportionality for small mid-cap (SMC) enterprises</strong></h4><div><hr></div><p>The AI Act provides an element of flexibility and proportionality for micro, small, and medium-size enterprises (SMEs), including start-ups. For example, the compliance penalties which SMEs can face are capped as follows:</p><ul><li><p>35 million EUR or 7% of total worldwide annual turnover (whichever is lower).</p></li></ul><ul><li><p>15 million EUR or 3% of total worldwide annual turnover (whichever is lower).</p></li></ul><ul><li><p>7.5 million EUR or 1% of total worldwide annual turnover (whichever is lower).</p></li></ul><p>This contrasts with the &#8220;whichever is higher&#8221; penalty logic that applies for all other businesses (i.e., those which are not SMEs). <br> <br><strong>What is the European Commission&#8217;s position?</strong> <br> <br>The first proposed change is to include legal definitions of SME and small mid-cap enterprise (SMC) to the AI Act. These are:</p><ul><li><p><strong>SME</strong>: an enterprise which employs fewer than 250 people and which has an annual turnover not exceeding 50 million EUR, and/or an annual balance sheet total not exceeding 43 million EUR.</p></li></ul><ul><li><p><strong>SMC</strong>: an enterprise which employs fewer than 750 people and which has an annual turnover not exceeding 150m EUR or an annual balance sheet total not exceeding 129m EUR.</p></li></ul><p>The second and more significant proposed change is to extend the proportionate, inverse penalty regime for SMEs to SMCs also. This would significantly reduce the total potential penalty exposure of SMCs (i.e., many more companies) in certain circumstances. SMCs that are providers of high-risk AI systems would also be able to provide the required technical documentation in a simplified manner. <br> <br><strong>What is the Council&#8217;s position?</strong> <br> <br>The Council has adopted the same position as the European Commission. This means that penalties for SMCs would also be capped at the lower amount, just as they are for SMEs today. <br><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Risk Assessments in Practice: Top 12 Templates and Toolkits ]]></title><description><![CDATA[Essential resources for AI risk management | #42]]></description><link>https://oliverpatel.substack.com/p/ai-risk-assessments-in-practice-top</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/ai-risk-assessments-in-practice-top</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Wed, 04 Mar 2026 19:23:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!v1rA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!v1rA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!v1rA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5971945,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/189588398?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!v1rA!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F877af68d-611b-44c8-8fa5-d5009e0d7609_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance.<br><br></em>AI risk assessments are one of the most important, challenging, and contentious activities in enterprise AI governance. Designing effective assessments from scratch is difficult, especially as the regulatory and technology landscape keeps changing. What your risk assessment consists of, and what type of AI-related initiatives are in scope of it, requires constant refinement and adaptation. </p><p>This week&#8217;s edition of Enterprise AI Governance spotlights 12 practical resources&#8212;from governments, regulators, standards bodies, and leading companies&#8212;that AI governance, compliance, and security teams can use to design, evaluate, and strengthen their AI risk assessment processes and frameworks. </p><p>If you haven&#8217;t done so already, consider signing up to pre-order my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em><strong>.</strong> It&#8217;s a comprehensive, visual guide to enterprise AI governance implementation, with dedicated chapters on the EU AI Act, AI risks and mitigations, and agentic AI governance. It also includes my AI risk assessment template. Pre-order here for a 25% discount:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure your 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure your 25% discount</span></a></p><h4><strong><br>12 Practical Resources for AI Risk Assessments</strong></h4><div><hr></div><p><em>AI risk assessment templates and checklists</em></p><ol><li><p><strong><a href="https://file.go.gov.sg/aivtf-pdf.pdf">AI Verify Testing Framework for Traditional and Generative AI</a></strong> (IMDA and Singapore AI Verify Foundation)</p></li><li><p><strong><a href="https://www.digital.gov.au/ai/impact-assessment-tool">AI Impact Assessment Tool and Supporting Guidance</a> </strong>(Australian Government)</p></li><li><p><strong><a href="https://msblogs.thesourcemediaassets.com/sites/5/2022/06/Microsoft-RAI-Impact-Assessment-Template.pdf">Microsoft Responsible AI Impact Assessment Template</a></strong> (Microsoft)</p></li><li><p><strong><a href="https://www.iso.org/obp/ui/en/#iso:std:iso-iec:42005:ed-1:v1:en">ISO/IEC 42005 &#8212; AI System Impact Assessment</a> </strong>(ISO/IEC Standard)</p></li></ol><p><em>EU AI Act and GDPR-specific resources</em></p><ol start="5"><li><p><strong><a href="https://aesia.digital.gob.es/storage/media/05-risk-management-guideline.pdf">Risk Management - EU AI Act Guidelines, Part 5</a> </strong>(The Spanish Agency for the Supervision of AI)</p></li><li><p><strong><a href="https://fpf.org/wp-content/uploads/2025/04/OT-comformity-assessment-under-the-eu-ai-act-WP-1.pdf">Conformity Assessments under the EU AI Act: A step-by step guide</a></strong> (Future of Privacy Forum and OneTrust)</p></li><li><p><strong><a href="https://www.edps.europa.eu/system/files/2025-11/2025-11-11_ai_risks_management_guidance_en.pdf">Guidance for Risk Management of AI Systems</a> </strong>(European Data Protection Supervisor)</p></li></ol><p><em>AI security risks </em></p><ol start="8"><li><p><strong>OWASP Top 10:</strong></p><ol><li><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">OWASP Top 10 for LLM Applications</a> </strong>(OWASP)</p></li><li><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications</a> </strong>(OWASP)</p></li></ol></li><li><p><strong><a href="https://saif.google/secure-ai-framework">Google SAIF - Secure AI Framework</a></strong> (including <strong><a href="https://saif.google/focus-on-agents">SAIF - 2.0 Secure Agents</a></strong>)</p></li></ol><p><em>For public authorities</em></p><ol start="10"><li><p><strong><a href="https://github.com/Testing-AI-Standards/cross-gov-ai-testing-framework/blob/main/framework.md">AI Testing and Assurance Framework for Public Sector</a> </strong>(UK Government)</p></li><li><p><strong><a href="https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html">Algorithmic Impact Assessment tool</a> </strong>(Government of Canada)</p></li><li><p><strong><a href="https://unicri.org/sites/default/files/2024-02/05_Risk%20Assesment_Questionnaire_Feb24.pdf">Responsible AI Innovation in Law Enforcement: Risk Assessment Questionnaire</a></strong> (Interpol and United Nations)  <br></p></li></ol><h4><strong>AI Risk Assessment Templates and Checklists</strong></h4><div><hr></div><p><strong>1. <a href="https://file.go.gov.sg/aivtf-pdf.pdf">AI Verify Testing Framework for Traditional and Generative AI</a></strong></p><p><strong>Publisher: </strong>Infocomm Media Development Authority (IMDA) and Singapore AI Verify Foundation </p><p><strong>Date:</strong> 2025</p><p><strong>Purpose: </strong>The AI Verify Testing Framework (AIVTF) is an extensive, practical resource that companies can use to assess and evaluate AI systems across the core dimensions of responsible AI. It outlines key steps that organisations should take for responsible AI system development and deployment.</p><p><strong>Features:</strong> The AIVTF is structured around 11 key principles (e.g., transparency, explainability, safety, and accountability) and it follows an evaluation questionnare format. For each principle, there are several specific outcomes organisations should aim to achieve and a series of practical steps for achieving them. Each of these steps can be integrated into AI risk assessments and mitigation and control plans. For example, under the &#8216;safety&#8217; principle, a key outcome to achieve is &#8216;carry out regular tests to evaluate for safety and possible harms (e.g., hallucination and general toxicity)&#8217;. This outcome is achieved by implementing the following (non-exhaustive) steps: </p><ul><li><p>Identify relevant and/or use-case appropriate benchmarks</p></li></ul><ul><li><p>Run benchmarking and red teaming</p></li></ul><ul><li><p>Testing to be performed at several checkpoints throughout the AI lifecycle</p></li></ul><ul><li><p>Where applicable, share results with relevant stakeholders</p></li></ul><p><strong>Key takeaways: </strong>This 118-page document is one of the most comprehensive and useful AI governance resources&#8212;and it is openly available for organisations to use. AI governance practitioners can use it to design, implement, evaluate, and strengthen their AI risk assessment questionnaires and AI lifecycle control frameworks. </p><div><hr></div><p><strong>2. <a href="https://www.digital.gov.au/ai/impact-assessment-tool">AI Impact Assessment Tool and Supporting Guidance</a></strong></p><p><strong>Publisher: </strong>Australian Government (Digital Transformation Agency)</p><p><strong>Date: </strong>December 2025</p><p><strong>Purpose: </strong>The AI Impact Assessment Tool is a comprehensive risk assessment template that is used by Australian Government departments. For certain AI use cases, it is mandatory for agencies to conduct AI impact assessments that align to this framework. This includes AI systems that the public will directly interact with or where the use of AI will materially influence administrative decisions that affect individuals.</p><p><strong>Features: </strong>The AI Impact Assessment Tool provides a structured template for assessing and scoring the risk of AI use cases, as well as mapping impacted stakeholders It is aligned to Australia&#8217;s AI Ethics Principles, is <a href="https://www.digital.gov.au/sites/default/files/documents/2025-12/Guidance%20for%20the%20AI%20impact%20assessment%20tool_0.pdf">supported by implementation guidance</a> (covering each question), and contains the following sections: </p><ul><li><p>Basic information</p></li><li><p>Purpose and expected benefits</p></li><li><p>Inherent risk assessment (e.g., unfair discrimination, harm, privacy, security etc.)</p></li><li><p>Fairness</p></li><li><p>Reliability and safety</p></li><li><p>Privacy protection and security</p></li><li><p>Transparency and explainability</p></li><li><p>Contestability</p></li><li><p>Human centred-values</p></li><li><p>Accountability</p></li></ul><p><strong>Key takeaways: </strong>Similar to Singapore, the Australian Government has also favoured soft law over AI-specific legislation, and has been proactive in publishing various guidelines and resources that organisations can use. This is a great example of a practical artefact that you can use to identify gaps and improvement opportunities for your internal AI risk assessment.</p><div><hr></div><p><strong>3. <a href="https://msblogs.thesourcemediaassets.com/sites/5/2022/06/Microsoft-RAI-Impact-Assessment-Template.pdf">Microsoft Responsible AI Impact Assessment Template</a></strong> </p><p><strong>Publisher: </strong>Microsoft</p><p><strong>Date: </strong>June 2022</p><p><strong>Purpose: </strong>Microsoft&#8217;s Responsible AI Impact Assessment Template provides a structured set of questions that AI governance teams can use to assess the impact and risks of an AI system. It is well-suited for higher-risk AI systems. The Template is accompanied by the <a href="https://msblogs.thesourcemediaassets.com/sites/5/2022/06/Microsoft-RAI-Impact-Assessment-Guide.pdf">Responsible AI Impact Assessment Guide</a>. These documents were released externally by Microsoft to provide transparency regarding internal responsible AI practices. However, it is inevitable that these internal processes have changed significantly since 2022. </p><p><strong>Features: </strong>The Responsible AI Impact Assessment Template consists of a set of technology-neutral risk assessment questions, grouped in the following sections:</p><ul><li><p>System information</p></li><li><p>Intended uses</p></li><li><p>Adverse impact</p></li><li><p>Data requirements</p></li><li><p>Summary of impact</p></li></ul><p><strong>Key takeaways: </strong>This resource is older than others on this list and is probably not sufficiently up-to-date to use as a standalone AI risk assessment framework in 2026.  However, it contains useful guidance for AI governance practitioners and is aligned to Microsoft&#8217;s Responsible AI Standard. Furthermore, it is part of a broader collection of <a href="https://www.microsoft.com/en-us/ai/tools-practices">Responsible AI Tools and Practices</a> released by Microsoft, which includes information about technical controls for data loss mitigation and AI content safety.</p><div><hr></div><p><strong>4. <a href="https://www.iso.org/obp/ui/en/#iso:std:iso-iec:42005:ed-1:v1:en">ISO/IEC 42005 &#8212; AI System Impact Assessment</a><br><br>Publisher: </strong>International Organisation for Standardisation (ISO) and International Electrotechnical Commission (IEC)</p><p><strong>Date: </strong>May 2025</p><p><strong>Purpose:</strong> ISO/IEC 42005 is an international standard that provides guidance for organisations conducting AI system impact assessments. The purpose of such assessments is to evaluate how AI may impact individuals, groups, or society throughout the AI system lifecycle.</p><p><strong>Features: </strong>The standard outlines a structured process covering: </p><ul><li><p>Timing of the AI system impact assessment</p></li><li><p>Scope</p></li><li><p>Allocation of responsibilities</p></li><li><p>Establishing thresholds for sensitive and restricted uses</p></li><li><p>Impact scales</p></li><li><p>Performing and analysing the AI system impact assessment</p></li><li><p>Approval and ongoing monitoring</p></li></ul><p>Annexes provide guidance on alignment with ISO/IEC 42001, the relationship with risk management under ISO/IEC 23894, and a taxonomy for analysing potential harms and benefits of AI systems.</p><p><strong>Key takeaways: </strong>This standard is complementary to ISO/IEC 42001 &#8212; AI Management System and is part of the same series of standards. It is also the first international standard dedicated to AI system impact assessments and it contains holistic guidance about every aspect of how to design, operate, and manage such processes. It is therefore a valuable resource for organisations that are conducting AI assessments, although it is behind a paywall.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><br><strong>EU AI Act and GDPR resources</strong></h4><div><hr></div><p><strong>5. <a href="https://aesia.digital.gob.es/storage/media/05-risk-management-guideline.pdf">Risk Management - EU AI Act Guide, Part 5</a></strong> </p><p><strong>Publisher: </strong>The Spanish Agency for the Supervision of AI (AESIA)</p><p><strong>Date: </strong>December 2025</p><p><strong>Purpose: </strong>This is one of 16 practical guides recently published by AESIA to support  EU AI Act compliance for high-risk AI systems. These resource guides, which are available in English, can be used by providers and deployers of high-risk AI systems. This Guide (Part 5), focuses on the risk management obligation for providers, outlined in Article 9 of the EU AI Act. </p><p><strong>Features:  </strong>The Risk Management Guide provides information on how providers can fulfil their obligation to implement a continuous and iterative risk management system for high-risk AI systems. This includes, but is not limited to, risk identification and analysis, risk evaluation, and risk management, mitigation, and elimination measures. The Guide is accompanied by an Excel checklist template with an illustrative risk management process that providers can leverage for different use cases. The broader collection of 16 guides covers key obligations including conformity assessments, quality management, human oversight, data governance, transparency, and accuracy, robustness, and cybersecurity.</p><p><strong>Key takeaways:</strong> This is the most comprehensive set of EU AI Act compliance guidance published by a national regulator to date. With harmonised standards still in development and the European Commission's guidelines on high-risk AI still being finalised, the AESIA guides serve as a valuable resource for organisations seeking practical, requirement-by-requirement implementation guidance. However, following such guidance does not guarantee compliance. </p><div><hr></div><p><strong>6. <a href="https://fpf.org/wp-content/uploads/2025/04/OT-comformity-assessment-under-the-eu-ai-act-WP-1.pdf">Conformity Assessments under the EU AI Act: A step-by step guide</a></strong></p><p><strong>Publisher: </strong>Future of Privacy Forum and OneTrust</p><p><strong>Date: </strong>April 2025.</p><p><strong>Purpose: </strong>This White Paper provides a step-by-step roadmap and detailed guidance for organisations to conduct and oversee conformity assessments under the EU AI Act. This is targeted primarily at providers of high-risk AI systems, as these organisations are obliged to ensure that the appropriate type of conformity assessment is performed, before their AI system is placed on the market or put into service.</p><p><strong>Features: </strong>The guide includes flowcharts and checklists for determining whether an AI system qualifies as high-risk, what type of high-risk AI system it is, what type of conformity assessment is required, and who is responsible for performing the required conformity assessment. It covers both internal conformity assessments (i.e., self-assessment) and third-party conformity assessments (i.e., those performed by notified bodies).</p><p><strong>Key takeaways: </strong>This resource is the most extensive and practical guidance available on conformity assessments under the EU AI Act. It is important to understand that the type of conformity assessment required&#8212;and who should perform it&#8212;depends on the type of high-risk AI system, as well as the availability of harmonised standards. See the flowchart below, which is provided in the guide, for more information (full credits to Future of Privacy Forum and OneTrust). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!GImt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 424w, /__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 848w, /__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!GImt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png" width="1408" height="644" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ca85da23-5c29-4226-98e3-62faf70233db_1408x644.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:644,&quot;width&quot;:1408,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:82894,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/189588398?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 424w, /__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 848w, /__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 1272w, /__u/substackcdn.com/image/fetch/$s_!GImt!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fca85da23-5c29-4226-98e3-62faf70233db_1408x644.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><p><strong>7. <a href="https://www.edps.europa.eu/system/files/2025-11/2025-11-11_ai_risks_management_guidance_en.pdf">Guidance for Risk Management of AI Systems</a></strong> </p><p><strong>Publisher</strong>: European Data Protection Supervisor (EDPS)</p><p><strong>Date: </strong>November 2025</p><p><strong>Purpose: </strong>This 55-page guidance document supports EU Institutions, Bodies, Offices and Agencies in identifying and mitigating data protection risks when developing and deploying AI systems. It is particularly relevant for scenarios where EU Institutions are data controllers. The EDPS is the data protection supervisory authority for the EU Institutions. This guidance is issued in this context of this EDPS role and not in the context of its role as an AI Act supervisory authority.</p><p><strong>Features: </strong>The guidance outlines the most significant AI-related risks associated with each of the main data protection principles, including:</p><ul><li><p>Fairness</p></li><li><p>Accuracy</p></li><li><p>Data minimisation</p></li><li><p>Security</p></li></ul><p>It also outlines risks relating to data subject rights, including in incomplete rectification or erasure and the challenge of machine unlearning.</p><p><strong>Key takeaways: </strong>This is one of the most useful resources for practitioners seeking to understand the data protection and privacy-related risks and challenges of AI development and deployment. Although it is primarily intended for EU institutions, it serves as a valuable reference for any organisation seeking a structured methodology for AI-related data protection risk assessment and management.</p><h4><strong><br>AI security risks</strong></h4><div><hr></div><p><strong>8. OWASP Top 10 (AI Threats and Mitigations)</strong></p><ul><li><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-llm-applications-2025/">OWASP Top 10 for LLM Applications</a> </strong>(OWASP)</p></li><li><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications</a> </strong>(OWASP)</p></li></ul><p><strong>Publisher: </strong>Open Worldwide Application Security Project<strong> </strong>(OWASP)</p><p><strong>Date: </strong>November 2024 (Top 10 for LLM Applications) and December 2025 (Top 10 for Agentic Applications)</p><p><strong>Purpose:</strong> These are two open-source, community driven resources that identify the top 10 most critical security risks and threats, as well as potential mitigations, for LLM applications and agentic AI applications respectively. They were developed collaboratively by many security researchers, practitioners, and AI experts.</p><p><strong>Features: </strong>The Top 10 for LLM Applications covers: </p><ul><li><p>Prompt injection</p></li><li><p>Sensitive information disclosure</p></li><li><p>Supply chain risks</p></li><li><p>Data and model poisoning,</p></li><li><p>Improper output handling</p></li><li><p>Excessive agency</p></li><li><p>System prompt leakage</p></li><li><p>Vector and embedding weaknesses</p></li><li><p>Misinformation</p></li><li><p>Unbounded consumption</p></li></ul><p>The Top 10 for Agentic Applications covers:</p><ul><li><p>Agent goal hijack</p></li><li><p>Tool misuse and exploitation</p></li><li><p>Identity and privilege abuse</p></li><li><p>Agentic supply chain vulnerabilities</p></li><li><p>Unexpected code execution</p></li><li><p>Memory and context poisoning</p></li><li><p>Insecure inter-agent communication</p></li><li><p>Cascading failures</p></li><li><p>Human-agent trust exploitation</p></li><li><p>Rogue agents</p></li></ul><p><strong>Key takeaways</strong>: Both resources adopt a compelling format. The top ten risks are presented, with each accompanied by an explanation, examples, and technical mitigations organisations can implement. Therefore, these are essential references for any organisation deploying LLMs or agentic AI applications at scale. These are security-focused lists, not comprehensive AI governance frameworks. However, the security-related controls should inform the broader AI risk assessment and control frameworks.</p><div><hr></div><p><strong>9. <a href="https://saif.google/secure-ai-framework">Google SAIF - Secure AI Framework</a></strong> (including <strong><a href="https://saif.google/focus-on-agents">SAIF - 2.0 Secure Agents</a></strong>)<br><br><strong>Publisher: </strong>Google</p><p><strong>Date: </strong>Published in 2023 and periodically updated since then.</p><p><strong>Purpose: </strong>Google&#8217;s Secure AI Framework (SAIF) is designed to enable organisations to manage the security-related risks of AI. It maps risks and controls across four layers of the AI system layers: data, infrastructure, model, and application.</p><p><strong>Core features: </strong>SAIF is built around six core elements: </p><ul><li><p>Expand strong security foundations to the AI ecosystem</p></li><li><p>Extend detection and response to bring AI into an organisation&#8217;s threat universe</p></li><li><p>Automate defences to keep pace with existing and new threats</p></li><li><p>Harmonise platform level controls to ensure consistent security</p><p>across the organisation</p></li><li><p>Adapt controls to adjust mitigations and create faster feedback loops for AI deployment</p></li><li><p>Contextualise AI system risks in surrounding business processes</p></li></ul><p>The Framework covers 15 AI security risk areas, including data poisoning, prompt injection, model exfiltration, model reverse engineering, and model evasion. For each risk, guidance is provided regarding how it emerges and is exposed in the AI lifecycle and what mitigations can be implemented.<br><br>Google recently published <strong>SAIF 2.0 Secure Agents</strong>, which focuses on agentic AI security and governance. Agent specific risk themes include rogue actions and sensitive data disclosure, with mitigations covering agent permissions, observability, and agent user control (e.g., human approval).</p><p><strong>Key takeaways: </strong>SAIF is a a useful high-level framework for integrating AI-specific security assessments and controls into existing programmes. Organisations can use SAIF alongside the OWASP Top 10 lists to build a more complete picture of AI security risks and controls.</p><h4><br>For public authorities</h4><div><hr></div><p><strong>10. <a href="https://github.com/Testing-AI-Standards/cross-gov-ai-testing-framework/blob/main/framework.md">AI Testing and Assurance Framework for Public Sector</a> </strong>(UK Government)<br><br><strong>Publisher:</strong> UK Government, Cross-Government Testing Community</p><p><strong>Date: </strong>Beta version published June 2025</p><p><strong>Purpose:</strong> A structured and technically rigorous approach to testing, evaluating, and assuring AI systems deployed in the UK public sector, covering every phase of the AI development lifecycle, from planning to ongoing monitoring.</p><p><strong>Core features: </strong>The framework identifies four core AI quality attributes, which should be the focus of testing and assurance activities:</p><ol><li><p>Safety and Ethics</p></li><li><p>Openness &amp; Trust</p></li><li><p>Performance &amp; Resilience</p></li><li><p>User &amp; Context Fit</p></li></ol><p>It distinguishes between testing (producing evidence), evaluation (interpreting evidence in context), and assurance (providing confidence the system is ready). It includes a modular strategy for selecting testing activities based on AI system type, use case, and risk level. It aligns with the <a href="https://www.gov.uk/government/publications/ai-playbook-for-the-uk-government/artificial-intelligence-playbook-for-the-uk-government-html">UK Government AI Playbook</a> and supports proportionate and risk-based assurance of impactful AI systems.</p><p><strong>Key takeaways: </strong> Although primarily for UK government, the testing-evaluation-assurance distinction is a useful framing that any organisation can adopt. This resource is part of the broader trend of the UK government producing practical, non-binding AI governance resources, rather than pursuing national AI legislation.  Departments are encouraged to adapt it for their specific context and any organisation could to the same. It is currently in beta, openly available, and accepts community contributions as a living tool.</p><div><hr></div><p><strong>11. <a href="https://www.canada.ca/en/government/system/digital-government/digital-government-innovations/responsible-use-ai/algorithmic-impact-assessment.html">Algorithmic Impact Assessment tool</a> </strong><br><br><strong>Publisher: </strong>Government of Canada</p><p><strong>Date: </strong>Published in 2019 and periodically updated since then.</p><p><strong>Purpose: </strong>The Algorithmic Impact Assessment (AIA) tool is a mandatory risk assessment tool supporting Canada's Directive on Automated Decision-Making. It is used by Canadian federal government departments to assess and evaluate automated decision systems, prior to use in specific contexts. It must be completed at the beginning of the design phase of a project and its outputs should guide the project thereafter.</p><p><strong>Core features: </strong>The AIA can be accessed as an online questionnaire with 65 risk questions and 41 mitigation questions. It classifies systems used for automating of administrative decisions into four impact levels:</p><ul><li><p>Level I: Little to no impact</p></li><li><p>Level II: Moderate impact</p></li><li><p>Level III: High impact</p></li><li><p>Level IV: Very high impact</p></li></ul><p>Each impact level corresponds to different requirements for human oversight, transparency, peer review, and monitoring. Completed assessments must be made publicly available.</p><p><strong>Key takeaways: </strong>The <a href="https://www.tbs-sct.canada.ca/pol/doc-eng.aspx?id=32592">Directive on Automated Decision-Making</a> that the AIA supports is one of the world's first AI-specific legally binding instruments. Although it applies solely to Canadian federal government use of automated decision systems, its open-access nature makes it a practical reference for any organisation designing AI risk assessments for high-risk use cases.</p><div><hr></div><p><strong>12. <a href="https://unicri.org/sites/default/files/2024-02/05_Risk%20Assesment_Questionnaire_Feb24.pdf">Responsible AI Innovation in Law Enforcement: Risk Assessment Questionnaire</a></strong> <br><br><strong>Publisher: </strong>Interpol and United Nations Interregional Crime and Justice Research Institute (UNICRI)</p><p><strong>Date: </strong>February 2024</p><p><strong>Purpose: </strong>This is a practical tool for law enforcement agencies to evaluate the risks of AI system deployment to individuals and communities. It is part of a series of resources within the broader Toolkit for Responsible AI Innovation in Law Enforcement.</p><p><strong>Core features: </strong>The questionnaire consists of 24 questions and aligns to five core principles: </p><ul><li><p>Lawfulness</p></li><li><p>Minimisation of harm</p></li><li><p>Human autonomy</p></li><li><p>Fairness</p></li><li><p>Good governance. </p></li></ul><p><strong>Key takeaways: </strong>This resource is designed to complement existing AI risk assessment artefacts and practices. Although designed for law enforcement entities, it provides a useful approach for structuring AI risk assessments in high-stakes contexts where AI systems can directly impact individuals&#8217; fundamental rights. </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[How deployers can become providers of high-risk AI systems]]></title><description><![CDATA[The EU AI Act risk you may be neglecting | #41]]></description><link>https://oliverpatel.substack.com/p/how-deployers-can-become-providers</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/how-deployers-can-become-providers</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 22 Feb 2026 22:20:28 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!_xeU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!_xeU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!_xeU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5273172,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/188837170?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_xeU!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc2dc7e3c-dcb0-45d5-8086-7a412556c5ba_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance</em>. <br><br><em>It is surprisingly easy for a deployer of an AI system to become the provider of a high-risk AI system under the EU AI Act. This article explains the three ways this can happen, why one of them is particularly difficult to detect and prevent, and what enterprises should do about it. In light of the widespread democratised access to general-purpose AI systems, this is one of the least discussed yet most consequential topics in enterprise AI governance today. The key takeaway is that when using AI systems for activities or use cases that overlap with the AI Act&#8217;s high-risk categories, it is advisable to use AI systems specifically designed, intended, and marketed for that purpose.<br><br></em><strong>Disclaimer:</strong> This article is for informational purposes only and does not constitute legal advice. Organisations should seek professional legal counsel for guidance on their specific circumstances and obligations under the EU AI Act.<em><br></em><br>If you haven&#8217;t done so already, consider signing up to pre-order my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em><strong>.</strong> It&#8217;s a comprehensive and practical guide to enterprise AI governance implementation, with a dedicated chapter on the EU AI Act. In the book, I break down every aspect of the law in 35+ visual cheat sheets. Pre-order at the link below for a 25% discount.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><h4><strong><br>What are &#8220;providers&#8221; and &#8220;deployers&#8221;?</strong></h4><div><hr></div><p>The concepts of &#8220;provider&#8221; and &#8220;deployer&#8221; are integral to the EU AI Act. </p><p>Simply put, providers are entities that develop AI systems&#8212;either for their own use or to make available for others to use&#8212;and deployers are entities that use AI systems developed and made available to them by providers. The legal definitions, supported by brief explanations, are provided below.<br><br><strong>Provider: </strong>&#8220;<em>a natural or legal person, public authority, agency or other body that <strong>develops an AI system or a general-purpose AI model </strong>or that has an AI system or a general-purpose AI model developed and <strong>places it on the market</strong> or <strong>puts the AI system into service under its own name or trademark</strong>, whether for payment or free of charge&#8221;.</em><br><br>An organisation can either be a provider of an AI system or a provider of a general-purpose AI (GPAI) model. However, they do not become a provider unless and until they place an AI system or GPAI model on the market or put an AI system into service. &#8220;<em>Putting into service&#8221;</em> means that the provider uses the AI system (e.g., for internal purposes) or directly supplies it to a deployer for first use.<br><br><strong>Deployer: </strong><em>&#8220;a natural or legal person, public authority, agency or other body using an AI system under its authority except where the AI system is used in the course of a personal non-professional activity&#8221;.</em><br><br>Deployers are typically organisations that use AI systems developed and made available to them by providers. An organisation can only be a deployer of an AI system; it cannot be a deployer of a GPAI model, as this scenario is not possible under the AI Act.<br> <br>Organisations routinely use GPAI models by integrating them into AI systems that they develop or by using externally provided AI systems powered by GPAI models (e.g., ChatGPT). In the former scenario, organisations typically become the &#8220;downstream provider&#8221; of an AI system. In the latter scenario, organisations typically become the deployer of an AI system. In neither scenario do they become the deployer of a GPAI model, despite the AI system being powered by a GPAI model. Indeed, the deployer never has any obligations which directly relate to the GPAI model itself. In such scenarios, deployer obligations only relate to the AI system which the GPAI model is part of.  <br><br>However, an organisation <em>can </em>become the provider of a GPAI model by making significant modifications to an existing GPAI model (e.g., by amending a pre-trained external GPAI model via fine-tuning or similar techniques). This scenario is beyond the scope of this article and was covered extensively in a <a href="/__u/oliverpatel.substack.com/p/downstream-modification-deployment">previous edition of Enterprise AI Governance</a>.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><strong><br>Why does the provider and deployer distinction matter?</strong></h4><div><hr></div><p>This article explains the scenarios in which a deployer of an AI system can become a provider of a high-risk AI system.</p><p>The key takeaway is that the obligations for providers and deployers are highly distinct in nature. The purpose of having these two separate roles is to appropriately and transparently allocate the key accountabilities, responsibilities, and liabilities to different entities. The allocation of these responsibilities directly relates to their respective relationship to the applicable AI system; it also has important implications for their relationship with each other. <br><br>Therefore, it is crucial for organisations to understand, as early as possible, whether they are a provider or a deployer (or both), and to take steps to adhere to the applicable obligations.</p><p>Furthermore, it is reasonable to argue that the obligations and requirements for providers of high-risk AI systems are more extensive and onerous than the corresponding deployer obligations. Therefore, not realising that you are a provider could pose significant regulatory and legal risk. <br><br>With respect to AI systems, the compliance obligations for providers and deployers only kick in for high-risk AI systems (see Article 6 and Annexes I and III) and transparency-requiring AI systems (see Article 50). An AI system can be high-risk, transparency-requiring, both, or neither. If it is neither, then it is not directly regulated by the AI Act (at least not with respect to the obligations for providers and deployers).<br><br>The precise compliance obligations and requirements that apply will always depend on the type of AI system. For example, there are baseline obligations and requirements for providers of high-risk AI systems covered by Annex I (Section A) and high-risk AI systems listed Annex III. However, there are also important differences depending on the type of high-risk AI system. For example, a third-party conformity assessment is required for some high-risk AI systems, whereas only an internal conformity assessment is required for others.<br><br>The same point can also be made for deployers. There are baseline obligations for deployers of high-risk AI systems, as well as obligations that only apply for deployers of specific types of high-risk AI systems (e.g., the obligation to conduct a fundamental rights impact assessment). <br><br>Although the scope of what is a high-risk AI system is relatively narrow&#8212;at least when considering the broad spectrum of enterprise AI use cases&#8212;many AI systems will be caught by the Article 50 transparency obligations. These obligations also differ, depending on both whether you are a provider or a deployer of a transparency-requiring AI system, as well as the exact type of AI system.<br><br>Although it is beyond the scope of this article to outline in detail the obligations for providers and deployers of AI systems, the key point is that they are highly distinct in nature and vary depending on the type of AI system.</p><h4><br><strong>How can deployers become providers of high-risk AI systems? </strong></h4><div><hr></div><p>Despite these important differences, it is surprisingly easy for a deployer of an AI system to become the provider of a high-risk AI system. This is one of the least discussed yet most consequential topics in AI governance today.<br><br>Article 25(1) of the AI Act outlines the three main ways in which an entity that is a deployer of an AI system can become the provider of a high-risk AI system. In each of these three scenarios, the deployer would become the provider of a high-risk AI system and <em>&#8220;therefore assume all the relevant obligations&#8221; </em>(i.e., all the obligations for a provider of that type of high-risk AI system).<br><br><em><strong>The 3 ways in which deployers can become providers of high-risk AI systems</strong></em><br><br><strong>1. The deployer puts its name or trademark on a high-risk AI system that has already been placed on the market or put into service. </strong><br><br>In this scenario, the deployer becomes the provider of the high-risk AI system, unless the agreement with the original provider stipulates otherwise. <br><br><strong>2. The deployer makes a &#8216;substantial modification&#8217; to a high-risk AI system that has already been placed on the market or put into service, and it remains a high-risk AI system.</strong><br><br>Understanding this scenario requires unpacking the meaning of &#8220;substantial modification&#8221;. This concept is defined as:</p><p><em>&#8220;a change to an AI system after its placing on the market or putting into service which is not foreseen or planned in the initial conformity assessment carried out by the provider and as a result of which the compliance of the AI system with the requirements set out in Chapter III, Section 2 is affected or results in a modification to the intended purpose for which the AI system has been assessed&#8221;.</em><br><br>Simply put, if the deployer changes a high-risk AI system in a manner that alters the intended purpose determined and communicated by the original provider, or in a manner that means it is no longer compliant with the applicable requirements for that type of high-risk AI system, then that deployer could become the provider of a <em>new </em>high-risk AI system. <br><br><strong>3. The deployer modifies the &#8216;intended purpose&#8217; of an AI system, including a general-purpose AI system, which has not been classified as high-risk and has already been placed on the market or put into service in such a way that the AI system becomes a high-risk AI system.</strong><br><br>In this scenario, the deployer would have to modify the intended purpose of an AI system that is not high-risk in a manner that results in it becoming a high-risk AI system. <br><br>&#8220;Intended purpose&#8221; is defined as: <em>&#8220;the use for which an AI system is intended by the provider, as specified in the information supplied by the provider in the instructions for use, promotional or sales materials and statements, as well as in the technical documentation&#8221;. </em></p><p>However, it is important to note that the AI Act does not explain exactly how the concept of &#8220;modify&#8221; should be interpreted in this context. For example, we do not know exactly how much active intervention is required for a &#8220;modification&#8221; to occur or whether mere usage of an AI system could equate to modification of it.<strong><br></strong><br>Nonetheless, in this scenario, the deployer would also become the provider of a <em>new </em>high-risk AI system.</p><p>Indeed, in all three scenarios, the original provider would no longer be the provider of the new AI system, which itself would, as explained above, have a new provider (i.e., the organisation that went from being a deployer to being a provider).</p><h4><br><strong>Could you become the provider of a high-risk AI system by merely using a general-purpose AI system?</strong></h4><div><hr></div><p><em>The caveat to the below analysis is that the European Commission was due to publish guidelines on high-risk AI systems in February 2026, but these guidelines are delayed. The Commission is also due to publish guidelines on the concept of &#8220;substantial modification&#8221;. At present, we have little indication as to how this aspect of the AI Act will be interpreted and enforced by the regulators. Once published, these guidelines will bring greater clarity to this knotty topic. This analysis is therefore based primarily on interpretation of the text in the AI Act itself.</em><br><br>Scenario 3 is arguably the most important for organisations to consider, as it is ostensibly surprisingly easy to do and could be quite difficult to detect and prevent. <br><br>With Scenarios 1 and 2, the organisation is perhaps more likely to know they are doing something which could make them a provider of a high-risk AI system. However, with Scenario 3, it is easy to anticipate ways in which this could happen inadvertently and/or without the organisation realising or appreciating.  <br><br>In most enterprises, employees have democratised access to general-purpose AI systems (GPAI systems) that are usually provided by external organisations. This ranges from mainstream generative AI chatbots to no- and low-code AI agent builder platforms. Such GPAI systems can be used for all aspects of enterprise work. And across large swathes of the corporate world, employees are being strongly encouraged to adopt AI as much as possible. <br><br>A key point to note is that these GPAI systems increasingly enable customisation and modification. For example, even non-technical users can connect knowledge sources, set system prompts, adjust &#8216;temperature&#8217;, or build bespoke features. Therefore, although Scenario 3 requires the deployer to &#8220;modify&#8221; the AI system&#8217;s intended purpose, it does not require a &#8220;substantial modification&#8221;, and there are various more subtle types of modification which are easy to implement and could potentially be captured by this somewhat nebulous term. <br><br>In many cases, the &#8216;intended purpose&#8217; of these GPAI systems will not cover the AI Act&#8217;s high-risk AI system categories. Sometimes, a GPAI system provider may even explicitly prohibit certain categories of high-risk AI usage. <br><br>This is not hypothetical. Below are some brief excerpts from GPAI provider terms of use:<br><br><strong><a href="https://ai.google.dev/gemini-api/terms">Gemini API Additional Terms of Service</a></strong> (Google): &#8220;<em>You may not use the Services in clinical practice, to provide medical advice, or in any manner that is overseen by or requires clearance or approval from a medical device regulatory agency&#8221;.</em><br><br><strong><a href="https://learn.microsoft.com/en-us/legal/ai-code-of-conduct?view=foundry-classic">Microsoft Enterprise AI Services Code of Conduct</a></strong><a href="https://learn.microsoft.com/en-us/legal/ai-code-of-conduct?view=foundry-classic">:</a><em> &#8220;Customers must not use the services [...] to make decisions or take actions without appropriate human oversight as part of an application that may have a consequential impact on any individual&#8217;s legal position, financial position, life opportunities, employment opportunities, or human rights, or may result in physical or psychological harm to an individual&#8221;.<br><br></em>It is also worth noting that where a provider has clearly specified that its AI system should not be used as a (particular type of) high-risk AI system&#8212;as the above terms indicate&#8212;Article 25(2) of the AI Act clarifies the original provider may have no obligation to closely cooperate with, or provide documentation to, the deployer that, in doing so, becomes a provider.<br><br>This means that if an employee or team in your organisation modifies&#8212;or potentially even just uses&#8212;a GPAI system in a manner that is both a) high-risk under the AI Act and b) not aligned with that GPAI system&#8217;s intended purpose, then your organisation is at risk of becoming both a <em><strong>deployer and a provider</strong></em> of a high-risk AI system&#8212;potentially without even realising it. This could happen inadvertently or unintentionally. <br><br>Consider the following example. A university admissions team uses a mainstream generative AI chatbot to upload, evaluate, and score submissions from prospective students. Depending on how regulators interpret the AI Act, this in itself could be considered &#8220;modification&#8221; and the university could become a provider of a high-risk AI system without even realising it.<br><br>Alternatively, perhaps the university creates relatively detailed system prompts and knowledge graphs, which it leverages alongside the GPAI system to optimise performance for this use case. In doing so, this could be interpreted as &#8220;modifying&#8221; the GPAI system, as this entails active intervention. However, the university may still not realise that in doing so it has become a provider.<br><br>If the chatbot (i.e., the GPAI system) was not intended to be used (by deployers) in this way, and this use is directly informing and impacting the admissions and decision-making process, then the university could potentially become both the provider and deployer of a high-risk AI system&#8212;even if its interventions or changes were minimal. As explained above, this entails significant and novel compliance obligations that require planning, investment, and capacity-building. <br><br><strong>The key takeaway is that when modifying, or even using, an AI system in a way that is directly related to, or overlaps with, one of the AI Act&#8217;s high-risk categories, it is advisable to use an AI system specifically designed, intended, and marketed for that purpose.</strong></p><p>This is important for both regulatory compliance and legal reasons, as well as for performance-related reasons. Such purpose-built and domain-specific AI systems&#8212;even if powered by GPAI models&#8212;are likely to be better suited for the use case, and using them will also provide you with greater legal clarity on your responsibilities and liabilities (as a deployer). <br><br>The logic underpinning this is that the EU deems it preferable for bespoke and tailor-made AI systems&#8212;designed, developed, and deployed according to required specifications&#8212;to be used for high-risk AI activities.<br><br>To put it even more simply, make sure your entire workforce is aware of what is a high-risk AI system under the AI Act, and implement both training and technical controls that decrease the likelihood of GPAI systems being used for high-risk AI use cases, apart from in scenarios where the provider confirms that this is part of the GPAI system&#8217;s intended purpose. <br><br>If you are a deployer that does not want to assume the legal responsibilities of a provider, incorporating such controls into your AI governance framework is essential.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[How to avoid AI compliance theatre]]></title><description><![CDATA[Policies versus guardrails is a false choice | #40]]></description><link>https://oliverpatel.substack.com/p/how-to-avoid-ai-compliance-theatre</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/how-to-avoid-ai-compliance-theatre</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 08 Feb 2026 18:51:15 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vnPs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!vnPs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!vnPs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4437097,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/187309557?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!vnPs!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F92524a5b-36f4-41ff-a99c-98a90814480a_4550x3275.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance</em>. Welcome to the 40th edition of this newsletter! In this edition, I dissect the &#8216;<em>AI policies versus guardrails</em>&#8217; debate and argue that pitting the two against each other is a false dichotomy. For AI governance to be effective, robust policies and technical guardrails need to work together and evolve in harmony.<br><br>If you haven&#8217;t done so already, consider signing up to pre-order my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em><strong>.</strong> It&#8217;s a comprehensive, visual guide to  enterprise AI governance implementation, with dedicated chapters on the EU AI Act, AI risks and mitigations, and agentic AI governance. Pre-order here for a 25% discount:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><h4><strong><br>The field of AI governance is evolving</strong></h4><div><hr></div><p>When I first noticed the flurry of new AI governance roles appearing in the corporate world in 2022, I immediately took interest. My fascination with the field of AI began during my postgraduate studies in Philosophy and Public Policy, where I focused on philosophy of mind, consciousness, and the ethical and societal implications of AI and emerging technologies. Since then, although I continued to cultivate this (formerly esoteric) set of interests, my career was primarily focused on privacy and data, as this is where much of the tech policy action was. </p><p>Fast forward to today and AI governance has quickly become a standalone profession, growing in both size and significance, and encompassing many distinct sub-fields and career pathways. Although the topic of AI ethics and governance is nothing new, it was only in the early 2020s that it evolved from being a relatively niche research and policy issue, to a sizeable professional field and capability across the corporate world&#8212;akin to established fields like privacy, cyber security, and data governance. </p><p>The more mainstream and important the field of AI governance becomes, the more divergent perspectives there are about what good looks like. And now more than ever, there is a robust and healthy debate about the best way organisations should approach AI governance.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><strong><br>The &#8216;policies versus guardrails&#8217; debate</strong></h4><div><hr></div><p>A major point of contention in 2026 is what I call the &#8216;<em>AI policies versus guardrails&#8217; </em>debate. This short essay outlines what this debate is, why I think pitting policies versus technical guardrails is a false dichotomy, and that traditional governance mechanisms&#8212;like policies and training&#8212;and engineered guardrails working in harmony is the only way to effectively govern AI.</p><p>My core argument is that the organisational culture and enabling environment fostered by AI governance leaders is just as important as the safety and security guardrails engineered into the AI systems and models that are the target of governance.<br><br>Having led enterprise AI governance at AstraZeneca for over three years now, whilst also delivering countless AI governance trainings for organisations and professional cohorts worldwide, I have had a front-row seat to watch the profession of AI governance mature into what it is today. In my view, although the current debates and challenges make perfect sense, it would be damaging for AI governance to split into fractured silos.<br><br>Over the past few years, there has undoubtedly been more focus across the enterprise AI governance world on codifying responsible AI principles, implementing policy and risk management frameworks, and working towards AI regulatory compliance, than there has been on engineering guardrails into AI systems, embedding policy-as-code, and building AI governance by design. </p><p>aI&#8217;ll be the first to admit that much of my work has focused on the former rather than the latter. However, as I have <a href="/__u/oliverpatel.substack.com/p/initial-reflections-on-agentic-ai">written about at length</a>, agentic AI takes the human out of the loop and poses fundamental challenges to legacy AI governance frameworks, which were not designed with such advanced and increasingly autonomous AI capabilities in mind. <br><br>So, what are the contours of the &#8216;<em>AI policies versus guardrails</em>&#8217;<em> </em>debate? And what is a viable path forward?</p><p>On one hand, many are increasingly dismissive about the policy and compliance aspects of AI governance work. I frequently read commentary along the lines of &#8220;<em>AI governance is just compliance theatre</em>&#8220; or &#8220;y<em>our policies are just PDFs and not real governance</em>&#8220;. The proposed solution invariably revolves around technological, engineering, and architectural controls and guardrails.</p><p>On the other hand, there are others who focus solely on AI regulatory compliance (e.g., EU AI Act) and standardisation (e.g., ISO 42001), and enabling mechanisms such as policy and process documentation, risk assessments, governance committees, and ethical principles&#8212;and providing training on all of the above. </p><h4><br>Why policies versus guardrails is a false dichotomy </h4><div><hr></div><p>Although both positions are well-intentioned, framing AI governance as a choice between policies and processes on one hand, and technical guardrails on the other, is a false dichotomy. In isolation, both are necessary but neither are sufficient for effective AI governance. It&#8217;s when you intentionally and seamlessly fuse both worlds together that AI governance starts to get real.</p><p>There is undoubtedly plenty of compliance theatre and performative governance to go around. Too often, for example, AI policy and compliance work does not adequately address how requirements can actually be implemented and operationalised in practice by technical teams working at the AI frontier, or where flexibility and proportionality should be afforded. And we are all drowning in a never-ending stream of AI frameworks and standards&#8212;many of which have high degrees of overlap. <br><br>However, this policy, compliance, and risk management work&#8212;and the AI literacy initiatives that support it&#8212;is valuable because it shapes how people think and behave, directly influencing how problems are solved, risks and trade-offs are weighed, and decisions are made.</p><p>Policies have an important signalling effect. Risk assessment processes and oversight and accountability structures moderate and temper risky behaviour, giving decision-makers pause for thought in high-stakes scenarios, and ensuring the buck stops with a specific, senior individual. And AI literacy and training promotes understanding of the limitations and risks of AI, which is crucial for ensuring responsible use of the technology.<br><br>Ultimately, <strong>AI governance is change management</strong>. </p><p>Rather than thinking of it solely as a control framework, think of it as a set of activities designed to shape and steer how people think and act. In this respect, the broader objective of AI governance is to foster an organisational culture and workforce that genuinely understands and prioritises responsible AI.<br><br>However, if AI governance goes no further than policies, frameworks, and training, its impact will remain limited. Governance by PDF is a genuine problem. </p><p>Instead, as a profession, we should strive for AI governance by design and by default. Technical guardrails&#8212;integrated into the AI models, systems, and platforms being developed and deployed&#8212;are integral for ensuring AI governance is automated, enforceable, and scalable.</p><p>For example, we will not meaningfully govern agentic AI without technical restrictions on the data agents can access, the tools they can use, and the actions they can execute. Runtime guardrails that keep semi-autonomous agentic AI systems in check and bound their autonomy are essential, especially as the human is taken out of the loop.<br><br>More broadly, although the days of reviewing and approving every AI-generated output are ending, agentic AI deployment and governance must be underpinned by orchestration and observability, facilitated at the platform level. This should entail technical assurance mechanisms and automated monitoring and flagging of deviations, drift, and incidents. <br><br>Simply put, as well as restricting and constraining what AI agents can do via policy-as-code mechanism, we need to be able to continuously monitor and track how they are behaving. In other words, we will be unable to govern agentic AI without AI.<br><br>Another instructive example is how to combat the prevalence and risk of shadow AI use. Merely publishing a strict policy and delivering training that tells people not to use unapproved AI tools is insufficient. Technical controls are required to mitigate the risk of data loss and flag suspicious activity. Moreover, employees need to have access to best-in-class AI capabilities internally, to reduce incentives to use unapproved public AI tools.</p><p>Nonetheless, dismissing AI policy-focused work as &#8220;compliance theatre&#8221; fails to acknowledge that technical guardrails depend on codified policy. It&#8217;s called &#8220;policy-as-code&#8221; for a reason. Technical guardrails have to be based on agreed policies and standards&#8212;rooted in organisational values, culture, business strategy, and risk appetite. Simply put, you need to know what guardrails to prioritise and why, before you build them. <br><br>This means that, sequentially, it makes sense that, historically, the AI governance profession has predominantly focused on codification of policies and standards. However, for the long-term impact of this to be meaningful, urgent focus is now required on how to operationalise and engineer these policies by design. These two things can be true simultaneously.</p><p>Consider this analogy. You don&#8217;t have the right to live in your property because of technical security systems and features (e.g., locks, cameras, and alarms). You have the right to live there because a piece of paper (i.e., your mortgage or rental agreement), backed up by a law, backed up by a fundamental principle, codified in a constitution says that you do. However, technical security systems play a crucial role in ensuring that you are safe in your home and that your right to live in peace and security is enforced and protected. And the physical safety of the property itself depends on building codes and standards&#8212;policies that directly influence the property&#8217;s structure and design.<br><br>For the most part, the interplay of these elements (norms, laws, policies, technical controls, safety features etc.) is well understood. Do you think of your mortgage agreement as mere &#8220;compliance theatre&#8221; or &#8220;just a PDF&#8221;?</p><p>AI governance is no different. Policies matter. Compliance matters. Risk assessments and committee reviews matter. But ensuring the key requirements from your policies and standards are engineered into your production AI models, systems, and platforms also matters&#8212;especially as AI becomes more advanced and harder for humans to control. <br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The Ultimate Agentic AI Governance Resource Guide]]></title><description><![CDATA[50+ resources to master agentic AI governance | Edition #39]]></description><link>https://oliverpatel.substack.com/p/the-ultimate-agentic-ai-governance</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/the-ultimate-agentic-ai-governance</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 01 Feb 2026 16:00:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hdWO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!hdWO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!hdWO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5905516,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/186496436?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!hdWO!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcf50d20-d5d7-481e-8946-65b3d9dc5659_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong>.</em></p><p>This week&#8217;s newsletter presents the definitive resource guide to agentic AI governance. This article (best viewed on browser) collates 50+ authoritative resources on agentic AI governance&#8212;mostly published in the past 18 months&#8212;grouped into 8 categories:<strong><br><br></strong>&#9989; Agentic AI: technology foundations and capabilities<br>&#9989; How enterprises are developing and deploying AI agents<br>&#9989; Agentic AI risks and challenges<br>&#9989; Risk mitigation strategies (security and safety)<br>&#9989; Agentic AI evaluations and observability<br>&#9989; Human oversight and accountability<br>&#9989; Agentic AI governance frameworks<br>&#9989; How EU law governs agentic AI: EU AI Act and GDPR<br><br>Whether you are working on the frontline of enterprise AI governance, advising clients in a legal or consulting capacity, or building, deploying, and using agentic AI systems, this resource guide enables you to keep track of and understand this rapidly evolving field. <br><br>There has been a brief hiatus of articles on Enterprise AI Governance, as I have been diving into this literature myself. </p><p>Agentic AI governance is one of the most important topics for practitioners this year, which is why I have taken some time out from posting to research and write a new long-read on <em><strong>Agentic AI Governance in 2026: A Guide for Practitioners</strong></em>. This free guide will soon be published on Enterprise AI Governance and shared with all subscribers.<br><br>In the meantime, if you haven&#8217;t done so already, consider pre-ordering my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em><strong>.</strong> It features a dedicated chapter on Agentic AI Governance, with actionable guidance and risk assessment templates for enterprise practitioners. Pre-order here for a 25% discount:</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order my book&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Pre-order my book</span></a></p><div><hr></div><h4><strong>The Ultimate Agentic AI Governance Resource Guide</strong></h4><p><em>50+ resources to master agentic AI governance</em></p><div><hr></div><h4>1) Agentic AI: technology foundations and capabilities</h4><ul><li><p><strong><a href="https://www.ibm.com/think/ai-agents#605511093">The 2026 Guide to AI Agents</a></strong> - <em>IBM (2026)</em></p></li><li><p><strong><a href="https://cdn.openai.com/business-guides-and-resources/a-practical-guide-to-building-agents.pdf#:~:text=This%20guide%20is%20designed%20for,into%20practical%20and%20actionable%20best">A practical guide to building agents</a></strong> - <em>OpenAI (2025)</em></p></li><li><p><strong><a href="https://www.anthropic.com/engineering/building-effective-agents">Building Effective AI Agents</a></strong><a href="https://www.anthropic.com/engineering/building-effective-agents"> </a>- <em>Anthropic (2024)</em></p></li><li><p><strong><a href="https://huyenchip.com/2025/01/07/agents.html">Agents</a></strong> - <em>Chip Huyen (2025)</em></p></li><li><p><strong><a href="https://www.adalovelaceinstitute.org/policy-briefing/ai-assistants/">Delegation Nation: Advanced AI Assistants and why they matter</a></strong> - <em>Harry Farmer and Julia Smakman, Ada Lovelace Institute (2025)</em></p></li><li><p><strong><a href="https://www.preprints.org/manuscript/202512.2119">Large Language Model Agents: A Comprehensive Survey on Architectures, Capabilities, and Applications</a></strong> - Yiming Lei et al., (2025)</p></li><li><p><strong><a href="https://openreview.net/forum?id=WE_vluYUL-X">ReAct: Synergizing Reasoning and Acting in Language Models</a></strong> - <em>Shunyu Yao et al., (2023)</em> </p></li><li><p><strong><a href="https://arxiv.org/abs/2302.04761">Toolformer: Language Models Can Teach Themselves to Use Tools</a></strong> - <em>Timo Schick et al., (2023)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2201.11903">Chain-of-Thought Prompting Elicits Reasoning in Large Language Models</a> - </strong><em>Jason Wei et al., (2022)</em></p></li><li><p><strong><a href="https://modelcontextprotocol.io/docs/getting-started/intro">What is the Model Context Protocol (MCP)?</a></strong> <em>(2025)</em></p></li><li><p><strong><a href="https://cloud.google.com/discover/what-is-model-context-protocol">What is the MCP and how does it work?</a></strong> - <em>Google (2025)</em></p></li><li><p><strong><a href="https://developers.googleblog.com/en/a2a-a-new-era-of-agent-interoperability/">Announcing the Agent2Agent Protocol (A2A): A new era  of Agent Interoperability</a></strong> - <em>Google (2025)</em></p></li></ul><div><hr></div><h4>2) How enterprises are developing and deploying AI agents</h4><ul><li><p><strong><a href="/__u/cdn.sanity.io/files/4zrzovbb/website/cd77281ebc251e6b860543d8943ede8d06c4ef50.pdf">The 2026 State of AI Agents Report: How enterprises are building and deploying AI in production</a></strong> - <em>Anthropic (2026)</em></p></li><li><p><strong><a href="https://resources.anthropic.com/hubfs/2026%20Agentic%20Coding%20Trends%20Report.pdf?hsLang=en">2026 Agentic Coding Trends Report</a></strong> - <em>Anthropic (2026)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2512.04123">Measuring Agents in Production</a> </strong>- <em>Melissa Z. Pan et al. (2025)</em></p></li><li><p><strong><a href="https://www.langchain.com/state-of-agent-engineering">State of Agent Engineering</a></strong><a href="https://www.langchain.com/state-of-agent-engineering"> </a>- <em>LangChain (2026)</em></p></li><li><p><strong><a href="https://www.mckinsey.com/~/media/mckinsey/business%20functions/quantumblack/our%20insights/the%20state%20of%20ai/november%202025/the-state-of-ai-2025-agents-innovation_cmyk-v1.pdf">The state of AI in 2025: Agents, innovation, and transformation</a></strong> - <em>Alex Singla et al., McKinsey QuantumBlack (2025)</em></p></li><li><p><strong><a href="https://www.aisi.gov.uk/frontier-ai-trends-report/pdf">Frontier AI Trends Report</a></strong><a href="https://www.aisi.gov.uk/frontier-ai-trends-report/pdf"> </a>- <em>UK AI Security Institute (2025)</em></p></li></ul><div><hr></div><h4>3) Agentic AI risks and challenges</h4><ul><li><p><strong><a href="https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/">OWASP Top 10 for Agentic Applications for 2026</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="https://genai.owasp.org/resource/agentic-ai-threats-and-mitigations/">Agentic AI - Threats and Mitigations</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="https://genai.owasp.org/resource/multi-agentic-system-threat-modeling-guide-v1-0/">Multi-Agentic system Threat Modelling Guide v1.0</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/initial-reflections-on-agentic-ai">Initial reflections on agentic AI governance</a></strong><a href="/__u/oliverpatel.substack.com/p/initial-reflections-on-agentic-ai"> </a>- <em>Oliver Patel, Enterprise AI Governance (2025)</em></p></li><li><p><strong><a href="https://domino.ai/blog/agentic-ai-risks-and-challenges-enterprises-must-tackle">Agentic AI risks and challenges enterprises must tackle</a></strong> - <em>Domino Data Lab (2025)</em></p></li></ul><div><hr></div><h4>4) Risk mitigation strategies (security and safety)</h4><ul><li><p><strong><a href="https://openai.com/index/practices-for-governing-agentic-ai-systems/">Practices for Governing Agentic AI Systems</a></strong> - <em>Yonadav Shavit et al., OpenAI (2023)</em></p></li><li><p><strong><a href="https://www.governance.ai/research-paper/infrastructure-for-ai-agents">Infrastructure for AI Agents</a></strong> - <em>Alan Chan et al., Centre for the Governance of AI (2025)</em></p></li><li><p><strong><a href="https://www.centeraipolicy.org/work/ai-agents-governing-autonomy-in-the-digital-age">AI Agents: Governing Autonomy in the Digital Age</a></strong> - <em>Joe Kwon, Center for AI Policy (2025)</em></p></li><li><p><strong><a href="https://isomer-user-content.by.gov.sg/36/703ff9fe-9db1-4e09-98c2-89e3d7007ef0/Draft%20Addendum%20on%20Securing%20Agentic%20AI%20%5bFor%20Public%20Consultation%5d.pdf">Securing Agentic AI: An Addendum to the Guidelines and Companion Guide on Securing AI Systems</a></strong> - Cyber Security Agency of Singapore (2025)</p></li><li><p><strong><a href="https://www.mckinsey.com/capabilities/risk-and-resilience/our-insights/deploying-agentic-ai-with-safety-and-security-a-playbook-for-technology-leaders">Deploying agentic AI with safety and security: A playbook for technology leaders</a></strong> - <em>McKinsey (2025)</em></p></li><li><p><strong><a href="https://isomer-user-content.by.gov.sg/36/fbe74dcd-3905-4d62-96db-483f29a3ecfb/securing-agentic-ai-discussion.pdf">Securing Agentic AI: A Discussion Paper</a> - </strong><em>Cyber Security Agency of Singapore and Far.AI (2025)</em></p></li><li><p><strong><a href="https://research.google/pubs/an-introduction-to-googles-approach-for-secure-ai-agents/">Google&#8217;s Approach for Secure AI Agents</a> </strong>- <em>Christoph Kern and Kara Olive, Google (2025)</em></p></li><li><p><strong><a href="https://ai.meta.com/blog/practical-ai-agent-security/">Agents Rule of Two: A Practical Approach to AI Agent Security</a></strong><a href="https://ai.meta.com/blog/practical-ai-agent-security/"> </a>- <em>Meta (2025)</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ul><div><hr></div><h4>5) Agentic AI evaluations and observability</h4><ul><li><p><strong><a href="https://www.nist.gov/news-events/news/2025/01/technical-blog-strengthening-ai-agent-hijacking-evaluations">Strengthening AI Agent Hijacking Evaluations</a></strong> - <em>U.S. AI Safety Institute (2025)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2504.05259">How to Evaluate Control Measures for LLM Agents? A Trajectory from Today to Superintelligence</a></strong> - <em>Tomek Korbak et al., UK AI Security Institute (2025)</em></p></li><li><p><strong><a href="https://www.anthropic.com/engineering/demystifying-evals-for-ai-agents">Demystifying evals for AI agents</a></strong> - <em>Anthropic (2026)</em></p></li><li><p><strong><a href="https://partnershiponai.org/wp-content/uploads/2025/09/agents-real-time-failure-detection.pdf?vgo_ee=zBAC1la9zQyJHSnpG6BgMHYqtA2DVnJIxaZdlyzMse4LqANZiVSdqdBDKQ%3D%3D%3AUuOdAvb8Al76ab6ZrhxDyj0LJ66FZeBh">Prioritizing Real-Time Failure Detection in AI Agents</a></strong> - <em>Madhulika Srikumar et al., Partnership on AI (2025)</em></p></li><li><p><strong><a href="https://azure.microsoft.com/en-us/blog/agent-factory-top-5-agent-observability-best-practices-for-reliable-ai/">Agent Factory: Top 5 agent observability best practices for reliable AI</a></strong> -  Yina Arenas, Microsoft (2025)</p></li></ul><div><hr></div><h4>6) Human oversight and accountability</h4><ul><li><p><strong><a href="https://arxiv.org/abs/2501.07913">Governing AI Agents</a></strong> - <em>Noam Kolt (2025)</em></p></li><li><p><strong><a href="https://www2.eecs.berkeley.edu/Pubs/TechRpts/2021/EECS-2021-207.html">The Principal-Agent Alignment Problem in AI</a></strong> - <em>Dylan Hadfield-Menell, UC Berkley (2021)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2510.09090">AI and Human Oversight: A Risk-Based Framework for Alignment</a> - </strong><em>Laxmiraju Kandikatla and Branislav Radeljic (2025)</em></p></li><li><p><strong><a href="https://www.adalovelaceinstitute.org/wp-content/uploads/pdfs/32617/the-dilemmas-of-delegation.pdf">The dilemmas of delegation: an analysis of policy challenges posed by Advanced AI Assistants and natural-language AI agents</a></strong> - <em>Harry Farmer, Ada Lovelace Institute (2025)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2502.02649">Fully Autonomous AI Agents Should Not be Developed</a></strong> - <em>Margaret Mitchell et al., Hugging Face (2025)</em></p></li><li><p><strong><a href="https://www.permit.io/blog/human-in-the-loop-for-ai-agents-best-practices-frameworks-use-cases-and-demo">Human-in-the-Loop for AI Agents: Best Practices, Frameworks, Use Cases, and Demo</a></strong> - <em>Gabriel L. Manor, Permit.io (2025)</em></p></li></ul><div><hr></div><h4>7) Agentic AI governance frameworks</h4><ul><li><p><strong><a href="https://www.imda.gov.sg/-/media/imda/files/about/emerging-tech-and-research/artificial-intelligence/mgf-for-agentic-ai.pdf">Model AI Governance Framework for Agentic AI</a></strong> - <em>Singapore Infocomm Media Development Authority (2026)</em></p></li><li><p><strong><a href="https://www.weforum.org/publications/ai-agents-in-action-foundations-for-evaluation-and-governance/">AI Agents in Action: Foundations for Evaluation and Governance</a> </strong><em>- World Economic Forum (2025)</em></p></li><li><p><strong><a href="https://www.iaps.ai/research/ai-agent-governance">AI Agent Governance: A Field Guide</a></strong> <em>- Jam Kraprayoon, Institute for AI Policy and Strategy (2025)</em></p></li><li><p><strong><a href="https://arxiv.org/abs/2504.21848">Characterising AI Agents for Alignment and Governance</a></strong> - <em>Atoosa Kasirzadeh &amp; Iason Gabriel (2025)</em></p></li><li><p><strong><a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance-1-0/">The State of Agentic AI Security and Governance</a></strong> - <em>OWASP (2025)</em></p></li><li><p><strong><a href="https://www.adalovelaceinstitute.org/policy-briefing/the-regulation-of-delegation/">The regulation of delegation: Are AI advisers, agents and companions regulated in the UK?</a></strong> <em>- Julia Smakman, Ada Lovelace Institute (2025)</em></p></li><li><p><strong><a href="https://awo.cdn.ngo/media/documents/Final_Report_-_AWO_Analaysis_of_AAA_Harms_-_September_2025.pdf">Effective legal protections from harms caused by advanced AI assistants</a></strong> - <em>Lucie Audibert &amp; Alex Lawrence-Archer, AWO Agency (2025)</em></p></li></ul><div><hr></div><h4>8) How EU law governs agentic AI: EU AI Act and GDPR</h4><ul><li><p><strong><a href="https://thefuturesociety.org/wp-content/uploads/2023/04/Report-Ahead-of-the-Curve-Governing-AI-Agents-Under-the-EU-AI-Act-4-June-2025.pdf">Ahead of the Curve: Governing AI Agents Under the EU AI Act</a> </strong>- <em>Amin Oueslati and Robin Staes-Polet (2025)</em></p></li><li><p><strong><a href="https://www.europeanlawblog.eu/pub/dq249o3c/release/1">Agentic Tool Sovereignty</a></strong> - <em>Lloyd Jones, European Law Blog (2025)</em></p></li><li><p><strong><a href="https://iapp.org/news/a/engineering-gdpr-compliance-in-the-age-of-agentic-ai">Engineering GDPR compliance in the age of agentic AI </a></strong>- <em>Keivan Navaie, IAPP (2025)</em></p></li><li><p><strong><a href="https://fpf.org/wp-content/uploads/2025/04/Minding-Mindful-Machines_-AI-Agents-and-Data-Protection-Considerations.pdf">Minding Mindful Machines: AI Agents and Data Protection Considerations</a> -</strong> <em>Daniel Berrick, Future of Privacy Forum (2025)</em></p><div><hr></div></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4></h4>]]></content:encoded></item><item><title><![CDATA[Emotion recognition and the EU AI Act ]]></title><description><![CDATA[Download the 4-step compliance checklist | #38]]></description><link>https://oliverpatel.substack.com/p/emotion-recognition-and-the-eu-ai</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/emotion-recognition-and-the-eu-ai</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Fri, 16 Jan 2026 16:54:41 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Qfw_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Qfw_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Qfw_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:7907349,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/184768366?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Qfw_!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F104e5fd4-dffa-483f-bc8a-a07c2fd24227_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><em><br>Emotion recognition is one of the least understood aspects of the EU AI Act. The prevalence of techniques like sentiment analysis across many industries, combined with the fact that AI-enabled emotion recognition is strictly prohibited in certain EU contexts whilst lawful elsewhere, makes it essential for enterprises to understand the nuances of this prohibition. This article outlines what is prohibited, what is high-risk, and what is not in scope&#8212;drawing on the AI Act and the <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act">European Commission's guidelines published</a> in February 2025.<br><br></em>This week&#8217;s newsletter covers:<br><br>&#9989; Understanding &#8216;emotion recognition&#8217; under the AI Act<br>&#9989; Emotion recognition: what is prohibited?<br>&#9989; Is it prohibited? 4-step compliance checklist visual (free download)<br>&#9989; Deep-dive on the 4 steps<br>&#9989; Emotion recognition: what is high-risk?<br>&#9989; Emotion recognition: what is not in scope?<em><br><br></em>Sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026). It provides a detailed, comprehensive, and visual overview of the EU AI Act, including dozens of flowcharts, checklists, and practical case studies.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure a 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure a 25% discount</span></a></p><h4><strong><br>Understanding &#8216;emotion recognition&#8217; under the AI Act</strong></h4><div><hr></div><p>Article 5 of the EU AI Act outlines 8 distinct prohibited AI practices. One of these prohibited AI practices concerns &#8216;emotion recognition&#8217;. Specifically, Article 5(1)(f) prohibits:<br><br><em>&#8220;the placing on the market, the putting into service for this specific purpose, or the use of AI systems to <strong>infer emotions of a natural person</strong> in the areas of <strong>workplace and education institutions</strong>, except where the use of the AI system is intended to be put in place or into the market for <strong>medical or safety reasons</strong>&#8221;.</em><br><br>The provisions relating to prohibited AI have been applicable since February 2025. This means that since then, it has been prohibited, under EU law, to use AI to infer emotions in the workplace or educational institutions. Regulatory authorities are empowered to investigate and pursue enforcement action in this area. However, we have not yet seen any major cases or actions.</p><p>Breaching the provisions on prohibited AI carries a maximum potential fine for companies of up to 7% of global annual turnover. This is the largest potential fine prescribed by the AI Act and greater than any potential fine under the GDPR.</p><p>Also, it is worth noting that the European Commission proposals to amend and simplify the AI Act, published in November 2025 and<a href="/__u/oliverpatel.substack.com/p/how-could-the-eu-ai-act-change"> covered extensively on this newsletter</a>, did not propose any changes directly impacting the prohibited AI practices or emotion recognition. Therefore, we can expect relative stability for this area of AI Act compliance.</p><p>Considering this, it is important for enterprises to understand exactly what is and what is not prohibited under the AI Act, to facilitate compliant practices and risk-based decision-making.</p><p>The prevalence of techniques like sentiment analysis across many industries, and the fact that AI-enabled emotion recognition is strictly prohibited in the EU whilst lawful in other jurisdictions, reinforces the importance of understanding the nuances of emotion recognition and the AI Act.</p><p>The analysis that follows outlines what is prohibited, what is high-risk, and what is not in scope.</p><h4><strong><br>Emotion recognition: what is prohibited?</strong></h4><div><hr></div><p>For the use of an AI system for emotion recognition to be prohibited, all four of these conditions must apply simultaneously:</p><ol><li><p><strong>The AI system is in scope of the EU AI Act.</strong></p></li><li><p><strong>The AI system processes and evaluates biometric data.</strong></p></li><li><p><strong>The AI system infers emotions.</strong></p></li><li><p><strong>The AI system is used in the workplace or an educational institution, without a valid exception for medical or safety reasons.</strong></p></li></ol><p>If one or more of these conditions does not apply, then it is most likely not a prohibited AI practice. The only caveat is unless that same AI system is somehow used for another prohibited AI practice (e.g., materially distorting behaviour and causing harm via deceptive, subliminal or manipulative techniques).</p><p>Each of these four conditions is equally important and warrant further explanation and analysis.<br><br><em>Check out my visual, 4-step check, which is elaborated on in the analysis below</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xbdF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 424w, /__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 848w, /__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xbdF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png" width="1044" height="1100" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1100,&quot;width&quot;:1044,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:492380,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/184768366?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 424w, /__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 848w, /__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 1272w, /__u/substackcdn.com/image/fetch/$s_!xbdF!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe2dfe657-a981-4f14-b050-ff9b7413a46d_1044x1100.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br><strong>1. The AI system is in scope of the EU AI Act.</strong><br><br>For an AI system to be in scope of the AI Act, it must be placed on the market, put into service, or used in the EU. Also, if the AI system outputs (e.g., recommendations, predictions, insights etc.) are used in the EU, then the AI system is in scope of the AI Act.</p><p>Crucially, this means that even if an AI system is not placed on the market, put into service, or used in the EU, it would still be in scope of the AI Act if the outputs of the AI system were used in the EU. This could happen, for example, by sharing AI system outputs to a team based in the EU, for processing, analysis, and decision-making. <br><br>The prohibited AI practices apply to all actors under the AI Act. This means that a provider could breach the law by placing a prohibited AI system on the market and a deployer could breach the law by using an AI system in a prohibited manner. <br><br>Therefore, the notion of scope (in this context) refers to both territorial scope, as well as what is done (if anything) with the AI system and/or its outputs.<br><br>Simply put, if an AI system is developed, made available, and used outside of the EU, and the outputs of that AI system are not transferred to or used in the EU, then it is not in scope of the AI Act and thus cannot be prohibited.</p><p><strong><br>2. The AI system processes and evaluates biometric data.</strong><br><br>Article 3(39) defines &#8220;emotion recognition system&#8221; as:<br><br><em>&#8220;an AI system for the purpose of identifying or inferring emotions or intentions of natural persons <strong>on the basis of their biometric data</strong>&#8221;</em></p><p>This means that emotion recognition&#8212;as defined by the AI Act&#8212; necessarily entails the processing and evaluation of biometric data. If an AI system is not processing biometric data and inferring emotions on that basis, then it is not an emotion recognition system.</p><p>Interestingly, some confusion has been caused by the fact that the text of the prohibition itself in Article 5(1)(f) (see above) does not refer to &#8216;emotion recognition system&#8217; or &#8216;biometric data&#8217;. It merely prohibits the use of AI to <em>&#8220;infer emotions [...] in the areas of workplace and education institutions&#8221;</em>.</p><p>However, in its guidelines, the European Commission acknowledged this discrepancy and clarified that, for consistency reasons, the prohibition should be linked to the legal definition and &#8216;emotion recognition system&#8217; and thereby limited to &#8220;inferences based on a person&#8217;s biometric data&#8221;. Furthermore, Recital 44 of the AI Act refers to &#8220;serious concerns&#8221; about using AI systems to infer emotions, due to &#8220;limited reliability&#8221;, specifically noting that:<br><br><em> &#8220;AI systems identifying or inferring emotions or intentions of natural persons <strong>on the basis of their biometric data</strong> may lead to discriminatory outcomes and can be intrusive to the rights and freedoms of the concerned persons&#8221;.</em><br><br>Therefore, if the AI system does not process and evaluate biometric data, and infer emotions on that basis, then it is not an emotion recognition system and is therefore not prohibited.<br><br>The notion of &#8220;biometric data&#8221; is defined in Article 3(34) of the AI Act:<br><br><em>&#8220;personal data resulting from specific technical processing relating to the physical, physiological or behavioural characteristics of a natural person, such as facial images or dactyloscopic data&#8221;.</em><br><br>This could include physiological biometric data such as fingerprints, iris patterns, and facial structure, or behavioural biometric data such as facial expressions, body language, or tone and pace of voice.<br><br>An important caveat to this section&#8217;s analysis is that the European Commission guidelines are not legally binding and it is theoretically possible that a member state regulator or a court could interpret the AI Act in a different way. However, considering the legal definition of &#8216;emotion recognition system&#8217;, the wording of Recital 44, and the European Commission guidelines, this would be somewhat surprising. <br><br><br><strong>3. The AI system infers emotions or intentions. </strong><br><br>Just because an AI system is evaluating biometric data does not necessarily mean it is inferring emotions. At the risk of stating the obvious, the AI system must infer emotions to be prohibited. <br><br>The AI Act does not provide a definition of &#8220;emotion&#8221;. However, Recital 18 provides a non-exhaustive list of emotions and intentions, for illustrative purposes:</p><ul><li><p>happiness, sadness, anger, surprise, disgust, embarrassment, excitement, shame, contempt, satisfaction, and amusement.</p></li></ul><p>The same recital also clarifies that <em>&#8220;physical states, such as pain or fatigue&#8221; </em>should not be considered as emotions or intentions. Also, the mere detection of physical expressions (e.g., whether someone is smiling) or presence (e.g., whether someone is in a meeting) does not constitute emotion inference. <br><br>The example provided in the AI Act is that using AI to detect the fatigue of professional pilots or drivers, for the purpose of preventing accidents, would not be prohibited.<br><br>However, the European Commission guidelines advise that the concept of emotions and intentions should be<em> &#8220;understood in a wide sense and not interpreted restrictively&#8221;</em>. Therefore, organisations should err on the side of caution when determining whether something is an emotion or not&#8212;especially if it is borderline.</p><p>Finally, given that AI systems that infer the intentions of individuals are also defined as emotion recognition systems, the European Commission guidelines clarifies that inferring intentions is also in scope of the prohibition. <br><br><br><strong>4. The AI system is used in the workplace or an educational institution, without a valid exception.</strong><br><br>Finally, the scope of the prohibition is limited to AI systems used in the workplace or an educational institution. <br><br>But not all uses of emotion recognition AI systems in the workplace and education are outright prohibited. The AI Act narrowly exempts AI systems used for inferring emotions for medical and safety purposes from the prohibition.</p><p>The European Commission guidelines clarify that the &#8220;notion of &#8216;workplace&#8217; should be interpreted broadly&#8221; and includes &#8220;any setting where work is performed&#8221;<em>. </em>It also covers recruitment and hiring processes and therefore not only employees.</p><p>Interestingly, the guidelines provide these two use cases as examples of AI practices that are not prohibited: </p><ul><li><p><em>&#8220;Using voice recognition systems by a call centre to track their customers emotions, such as anger or impatience, is not prohibited by Article 5(1)(f) AI Act (for example to help the employees cope with certain angry customers)&#8221;.</em></p></li><li><p><em>If only deployed for personal training purposes, emotion recognition systems are allowed if the results are not shared with HR responsible persons and cannot impact the assessment, promotion etc. of the person trained, provided that the prohibition is not circumvented and the use of the emotion recognition system does not have any impact on the work relationship.</em></p></li></ul><p>Although it feels counterintuitive, the thinking here is probably that such activities and usage patterns are not relevant for the power imbalances and asymmetries in workplace contexts, such as between employers and employees, self-employed workers, and job candidates.<br><br>Crucially, there are two exceptions to the prohibition of emotion recognition in the workplace and educational institutions:</p><ul><li><p>AI systems used for medical reasons.</p></li><li><p>AI systems used for safety reasons.</p></li></ul><p>This means that, if the use of the AI system for emotion recognition in a workplace context is for medical or safety reasons, then it may be permissible under the AI Act. However, these exceptions should be interpreted narrowly and there is a high bar to reach them.</p><p>With respect to medical reasons, the guidelines clarify that this would include approved medical devices, rather than the use of AI to analyse wellbeing more broadly. <br><br>With respect to &#8220;safety reasons&#8221;, the guidelines clarify that this should be interpreted as only applying to protection of life and health, not protection against other risks, like theft or fraud.</p><h4><br><strong>Emotion recognition: what is high-risk?</strong> </h4><div><hr></div><p>First, let&#8217;s recap on what makes an emotion recognition system prohibited:</p><ol><li><p>The AI system is in scope of the EU AI Act.</p></li><li><p>The AI system processes and evaluates biometric data.</p></li><li><p>The AI system infers emotions.</p></li><li><p>The AI system is used in the workplace or an educational institution, without a valid exception for medical or safety reasons.</p></li></ol><p>As explained above, if all four of these conditions apply simultaneously, then the AI system is most likely prohibited under the EU AI Act. However, if only conditions 1, 2, and 3 apply, then the AI system is most likely a high-risk AI system under the AI Act, rather than a prohibited AI practice.<br><br>This is because 1) it is in scope of the AI Act, 2) it evaluates biometric data, 3) it infers emotions, but 4) it is not used in a workplace or educational institution, or it is but there is a valid exception in place.<br><br>Simply put, if an AI system is used for emotion recognition in a manner that is not prohibited&#8212;such as in the workplace and educational institutions for medical or safety reasons, or outside of the workplace and educational institutions altogether&#8212;then it would be a high-risk AI system.<br><br>Or to put it even more simply, if an AI system used for emotion recognition is not prohibited, it is a high-risk AI system. <br><br>For this reason, Annex III(1)(c) of the AI Act includes <em>&#8220;AI systems intended to be used for emotion recognition&#8221; </em>in the list of high-risk AI systems.<br><br>In such scenarios, providers must adhere to the obligations and requirements for the high-risk AI system intended to be used for emotion recognition and deployers must also adhere to the applicable obligations for high-risk AI systems.</p><p>Finally, emotion recognition systems are also &#8216;transparency-requiring&#8217;. Article 50(3) of the AI Act stipulates that deployers of emotion recognition systems must inform impacted individuals about the use of the AI system. The only exception to this is for emotion recognition systems used in certain law enforcement contexts.</p><h4><strong><br>Emotion recognition: what is not in scope?</strong></h4><div><hr></div><p>Inferring emotion or sentiment merely on the basis of text (i.e., transcript data of what someone said) is not a prohibited AI practice. This was confirmed by the European Commission in its guidelines, which stated: <br><br><em>&#8220;An AI system inferring emotions from written text (content/sentiment analyses) to define the style or the tone of a certain article is not based on biometric data and therefore does not fall within the scope of the prohibition.&#8221;</em><br><br>Therefore, sentiment analysis, based purely on text transcripts, is not emotion recognition as it is not based on evaluation of biometric data. To further mitigate risk in such scenarios, it is prudent to ensure that text-based transcript data is not enriched with information describing an individual&#8217;s behaviour, physical appearance, or physiology.<br><br>However, just because text-based sentiment analysis is not emotion recognition and thus not prohibited in this context, does not mean it is always out of scope of the AI Act. It is theoretically possible for sentiment analysis to be part of a high-risk AI system or an alternative prohibited AI practice. For example, if sentiment analysis is embedded within a recruitment screening tool that evaluates candidates&#8217; written responses, the overall AI system would likely be classified as high-risk.</p><h4><strong><br>Key takeaways for enterprises</strong></h4><div><hr></div><p><strong>Interpret broadly at this stage. </strong>The law is new, enforcement is yet to materialise, and regulatory expectations are still forming. Until we see how regulators and courts apply these provisions in practice, a cautious and expansive interpretation is prudent. <br>For example, the European Commission guidelines advise that emotions and intentions should be <em>&#8220;understood in a wide sense and not interpreted restrictively&#8221;</em>. If an AI system evaluates traits closely linked to emotions, treat it as potentially in scope, or at the very least implement additional guardrails. </p><p><strong>Determine your global compliance strategy.</strong> Will you prohibit AI-enabled emotion recognition activities globally, or only in the EU? A global policy offers simplicity, standardisation, and a higher bar, whereas jurisdiction-specific policies potentially offer more flexibility and agility, albeit with greater compliance spill-over risk. If you do follow a jurisdiction-specific approach, robust controls and guardrails are required to ensure that any AI use cases that would be prohibited in the EU do not inadvertently impact EU-based individuals and that the corresponding AI system outputs are not shared with, or used by, anyone in the EU.</p><p><strong>Carefully assess AI applications that evaluate individuals.</strong> Any AI system that analyses individuals (e.g., employees or students)&#8212;and in particular that evaluates their performance or behaviour in interactions, role-plays, meetings, or interviews&#8212;warrants in-depth AI governance review. <br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[AI Governance in 2025: a year in review ]]></title><description><![CDATA[70+ defining milestones of 2025 | Edition #37]]></description><link>https://oliverpatel.substack.com/p/ai-governance-in-2025-a-year-in-review</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/ai-governance-in-2025-a-year-in-review</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sat, 03 Jan 2026 12:57:44 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!M6CQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!M6CQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!M6CQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6278066,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/183274504?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!M6CQ!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec538797-81b0-43ce-be51-df922cdf8978_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong>.<br><br></em>Happy new year! I hope that everyone who celebrates enjoyed a peaceful, relaxing, and pleasant festive season. 2026 is inevitably going to be a busy and intense year for AI governance professionals. But before looking ahead, we are going to look back on 2025, which was a landmark year for our field. </p><div><hr></div><p>This week&#8217;s newsletter provides a comprehensive review of AI law, policy, and governance in 2025. It features:</p><p>&#9989; 8 key themes that defined 2025<br>&#9989; Visual timeline: AI Governance in 2025 (free pdf download)<br>&#9989; The ultimate AI governance timeline: 70+ key milestones in 2025 (all hyperlinks provided)<br><br><strong>Note:</strong> <em>due to the length of this article, it is best viewed on your browser or the Substack app.<br><br></em>Sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026). It provides a detailed, comprehensive, and visual overview of Global AI Law and Policy, including U.S., China, and EU comparison charts, as well as practical strategies for cross-jurisdictional compliance.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Pre-order the book&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Pre-order the book</span></a></p><h3><br>8 key themes which defined 2025</h3><div><hr></div><ol><li><p><strong>EU AI Act compliance becomes a reality</strong>. 2025 was the year that EU AI Act compliance became a reality for many organisations worldwide. The first set of provisions, on prohibited AI practices and AI literacy, became applicable on 2 February 2025. And on 2 August 2025, the obligations for providers of general-purpose AI (GPAI) models became applicable. The <a href="/__u/oliverpatel.substack.com/p/eu-publishes-general-purpose-ai-code">GPAI Code of Practice</a> was approved just in time for this deadline, and the European Commission also published guidelines on prohibited AI practices, the AI system definition, and GPAI model provider obligations. However, <a href="/__u/oliverpatel.substack.com/p/how-could-the-eu-ai-act-change">as covered previously</a> in Enterprise AI Governance, there is now uncertainty regarding what the compliance deadline for high-risk AI systems will be, following the Commission&#8217;s proposal to delay the 2 August 2026 date, as part of the AI Act &#8220;simplification&#8221; changes. </p></li><li><p><strong>But the Brussels effect remains limited</strong>. The EU&#8217;s comprehensive, horizontal AI law remains an outlier. Despite the immense global policy focus on AI in recent years, other jurisdictions have not opted to follow the EU&#8217;s approach. Simply put, there is no other AI law globally that is comparable to the EU&#8217;s in terms of its comprehensiveness, stringency, and enforcement teeth. China has enacted several AI-specific regulations, but these are more narrowly focused on the way in which AI is used to recommend, amplify, and generate content and information. Japan and South Korea have also enacted more sweeping AI laws, but these are much lighter touch than the EU&#8217;s from a compliance perspective. Across major economies like the UK, Canada, Australia, Singapore, and India, no comprehensive AI law is on the horizon. And in the U.S., it&#8217;s a non-starter. </p></li><li><p><strong>Divergent approaches at the U.S. federal and state level. </strong>One of the first things President Trump did upon assuming office was to revoke President Biden&#8217;s landmark Executive Order on AI Safety. Since then, not only has the Trump administration pivoted away from the prior focus on AI governance and safety, it <a href="/__u/oliverpatel.substack.com/p/what-americas-ai-action-plan-means">has repeatedly stated</a> that its overriding AI policy objective is to strengthen U.S. leadership and dominance in AI, in order to seize the economic and national security advantages. Regulations that impede or restrict private sector AI activities&#8212;and the patchwork of hundreds of state AI laws&#8212;have been framed as a blocker to U.S. global AI dominance that could undermine U.S. competitiveness. Because of this, the Trump administration has attempted to deter and block U.S. states from passing and enforcing state level AI laws. However, its <a href="/__u/oliverpatel.substack.com/p/unpacking-the-10-year-moratorium">10-year moratorium</a> on state AI law enforcement was rejected by the Senate in July. A <a href="/__u/oliverpatel.substack.com/p/what-is-president-trumps-ai-policy">recent Executive Order</a> outlines plans to challenge state AI laws via litigation and funding restrictions instead. Despite this, meaningful <a href="https://prod.iapp.org/resources/article/us-state-ai-governance-legislation-tracker/">state AI laws</a> have been enacted across the U.S. in 2025, including in California, New York, and Texas.  </p></li><li><p><strong>Foundation models remain the target of AI regulations and standards.</strong> The most advanced frontier models continue to receive significant regulatory attention, with various laws and standards worldwide specifically focused on foundation models. For example, <a href="https://carnegieendowment.org/emissary/2025/10/california-sb-53-frontier-ai-law-what-it-does?lang=en">California&#8217;s Transparency in Frontier AI Act (SB53)</a> requires major AI developers to report certain safety incidents and to publish information about their frontier AI risk management frameworks. Similarly, <a href="https://natlawreview.com/article/new-yorks-raise-act-what-frontier-model-developers-need-know">New York&#8217;s RAISE Act requires</a> &#8220;frontier AI model&#8221; developers to implement mitigations to reduce the risk of &#8220;critical harm&#8221;. And the EU&#8217;s regime for GPAI model providers, and the accompanying GPAI Code of Practice, outlines detailed rules for model and training data transparency, copyright compliance, and systemic risk mitigation. Finally, the safety risks of foundation models with frontier capabilities remains a major focus of policy and research efforts, as evidenced by the inaugural <a href="https://internationalaisafetyreport.org/publication/international-ai-safety-report-2025">International AI Safety Report</a>, published in January. </p></li><li><p><strong>Increasing focus on how to implement labelling and marking of AI-generated content. </strong>Perhaps the most significant regulatory development in China was the <a href="https://www.chinalawtranslate.com/en/ai-labeling/">Measures for Labelling of AI-Generated Synthetic Content</a>, a regulation which took effect in September. The Measures require &#8220;implicit labels&#8221; for all AI-generated content (i.e., information embedded within file metadata to enable detectability of AI content), as well as &#8220;explicit labels&#8221;, such as text or audio notifications, for AI-generated content that might &#8220;confuse or mislead the public&#8221; (e.g., deepfake videos and AI-generated music). The Measures were accompanied by a mandatory national standard on AI Content Labelling Methods, which provides detailed requirements. Similarly, work is underway to develop the EU Code of Practice on marking and labelling of AI-generated content, with the first draft published in December. <a href="https://www.merriam-webster.com/wordplay/word-of-the-year">According to Merriam-Webster</a>, &#8220;slop&#8221; was the word of the year, which perhaps highlights the collective fatigue for low-quality, AI-generated content and the inreasing importance of transparency. </p></li><li><p><strong>Soft law, technical standards, and public-private sector collaboration prevail.</strong> The lack of comprehensive, EU AI Act-inspired laws does not mean there has been a lack of domestic AI policy activity. Many jurisdictions continue to prioritise soft law measures, such as producing guidelines and non-binding frameworks for organisations to leverage. For example, the UK Government published a <a href="https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice">Code of Practice on Cyber Security</a> and continues to support the growth of the AI Assurance sector. Similarly, Singapore&#8217;s regulators published guidelines on agentic AI security and launched a Global AI Assurance Pilot and Sandbox, to enable industry generative AI testing. Finally, China released version 2.0 of its non-binding <a href="https://www.cac.gov.cn/2025-09/15/c_1759653448369123.htm">AI Safety Governance Framework</a>. At the international level, industry and policy stakeholders worked together to produce various technical standards, such as the <a href="https://ieeexplore.ieee.org/document/11011522">IEEE 3119 Standard on AI Procurement</a> and the <a href="https://www.iso.org/standard/42005">ISO 42005 Standard on AI System Impact Assessment</a>. These efforts highlight that organisations have plenty of practical resources at their disposal which they can use to inform their AI governance work. </p></li><li><p><strong>Lots of discussion, but less tangible action on the international stage. </strong>Topics relating to AI policy and governance continued to receive significant airtime on the international stage. However, it is difficult to pinpoint major developments that go beyond well-intentioned discussion and dialogue. The AI Action Summit, hosted by France in February, was broader in focus than its 2023 and 2024 predecessor events, the AI Safety Summit and the AI Seoul Summit. Also, the UN establishing a Global Dialogue on AI Governance ensures a permanent home for such discussions. And China publishing its Global AI Governance Action Plan, and proposing a World AI Cooperation Organisation, highlights the leading role it seeks to play. Perhaps the most concrete development was the entry into force of the Council of Europe&#8217;s AI Treaty, which opened for signature in 2024. However, organisations hoping for greater regulatory convergence globally in 2026 are likely to be disappointed.</p></li><li><p><strong>The U.S.-China &#8220;AI race&#8221; and the shifting sands of AI export controls. </strong>The release of DeepSeek-R1 in January 2025 was a defining moment, as it highlighted the strength and disruptive potential of China&#8217;s AI ecosystem, despite the AI chip export controls already in place. DeepSeek, as well as Alibaba&#8217;s Qwen model family, demonstrate that China can innovate around hardware constraints through algorithmic efficiency, while reinforcing the Chinese government&#8217;s support for open-source AI as a strategic advantage. However, despite China&#8217;s strengths in AI talent, research, patents, and open-source AI, the U.S. retains significant leads in private investment, frontier model performance, and global diffusion. The U.S. export control regime continues to evolve. President Biden&#8217;s January 2025 Framework for AI Diffusion hardened AI chip export controls and expanded the regime to include model weights. President Trump rescinded it in May, calling it &#8220;burdensome&#8221;. In December, the <a href="https://www.cnbc.com/2025/12/08/trump-nvidia-h200-sales-china.html">Trump Administration permitted</a> Nvidia to export its H200 chips to China, in exchange for a 25% cut of the sales revenue. This pivot from strategic containment to transactional commerce represents a meaningful policy shift.<br><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ol><h3><br>Global AI Governance in 2025 (free pdf download)</h3><div><hr></div><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!H9J4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 424w, /__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 848w, /__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 1272w, /__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!H9J4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png" width="1456" height="3640" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1845214,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/183274504?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 424w, /__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 848w, /__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 1272w, /__u/substackcdn.com/image/fetch/$s_!H9J4!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0dcdc213-8e94-46a2-845f-4b787342af7c_2500x6250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div><hr></div><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail" src="/__u/substackcdn.com/image/fetch/$s_!cKVB!,w_400,h_600,c_fill,f_auto,q_auto:best,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbbccf3fc-2f76-4e9f-b469-778c69766bab_2500x6250.png"></image><div class="file-embed-details"><div class="file-embed-details-h1">Global AI Governance in 2025 (by Oliver Patel)</div><div class="file-embed-details-h2">399KB &#8729; PDF file</div></div><a class="file-embed-button wide" href="/__u/oliverpatel.substack.com/api/v1/file/e8c34174-0139-474c-91e1-1c8da54d3287.pdf"><span class="file-embed-button-text">Download</span></a></div><div class="file-embed-description">Download a high res pdf version of this Cheat Sheet, with hyperlinks to key sources. Can only be used or shared with attribution.</div><a class="file-embed-button narrow" href="/__u/oliverpatel.substack.com/api/v1/file/e8c34174-0139-474c-91e1-1c8da54d3287.pdf"><span class="file-embed-button-text">Download</span></a></div></div><p></p><h3><strong>The ultimate AI governance timeline: 70 key milestones in 2025</strong></h3><div><hr></div><p><strong>In scope:</strong> <em>AI-related policy, legislation, regulations, official guidance, international agreements and declarations, and technical standards shaping AI governance across major jurisdictions.</em> </p><p><strong>Not in scope:</strong> <em>Corporate policies, industry standards, AI model releases, technology developments, litigation, enforcement actions, and solely academic or civil society research and advocacy.</em></p><h4><strong>January</strong></h4><ul><li><p>&#127468;&#127463; UK Government publishes <a href="https://www.gov.uk/government/publications/ai-opportunities-action-plan/ai-opportunities-action-plan">AI Opportunities Action Plan</a>. </p></li><li><p>&#127482;&#127480; U.S. Department of Commerce publishes <a href="https://www.federalregister.gov/documents/2025/01/15/2025-00636/framework-for-artificial-intelligence-diffusion">Framework for AI Diffusion</a>, tightening AI export controls. </p></li><li><p>&#127472;&#127479; South Korea formally enacts the <a href="https://cset.georgetown.edu/publication/south-korea-ai-law-2025/">Framework Act on the Development of Artificial Intelligence and Establishment of Trust Foundation</a> (AI Basic Act).</p></li><li><p>&#127482;&#127480; President Trump signs <a href="https://www.whitehouse.gov/presidential-actions/2025/01/removing-barriers-to-american-leadership-in-artificial-intelligence/">Executive Order 14179: Removing Barriers to American Leadership in AI</a>, directing development of a new AI action plan.</p></li><li><p>&#127482;&#127480; President Trump revokes <a href="https://www.federalregister.gov/">Executive Order 14110</a> on AI safety, signed by President Biden in October 2023.</p></li><li><p>&#127760; The inaugural <a href="https://internationalaisafetyreport.org/publication/international-ai-safety-report-2025">International AI Safety Report</a> is published, led by Yoshua Bengio and authored by 100+ AI experts. </p></li><li><p>&#127468;&#127463; UK publishes <a href="https://www.gov.uk/government/publications/ai-cyber-security-code-of-practice">AI Cyber Security Code of Practice</a>. </p></li></ul><h4><strong>February</strong></h4><ul><li><p>&#127466;&#127482; EU AI Act provisions on <a href="https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai">AI literacy and prohibited AI</a> become applicable from 2 February, marking the first compliance deadline.</p></li><li><p>&#127475;&#127487; New Zealand Government publishes <a href="https://www.digital.govt.nz/assets/Standards-guidance/Technology-and-architecture/Generative-AI/Responsible-AI-Guidance-for-the-Public-Service-GenAI-Print.pdf">Responsible AI Guidance for the Public Service</a>, covering generative AI use.</p></li><li><p>&#127466;&#127482; European Commission publishes <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-prohibited-artificial-intelligence-ai-practices-defined-ai-act">guidelines on prohibited AI practices</a> under the EU AI Act.</p></li><li><p>&#127466;&#127482; European Commission publishes <a href="https://digital-strategy.ec.europa.eu/en/library/commission-publishes-guidelines-ai-system-definition-facilitate-first-ai-acts-rules-application">guidelines on AI system definition</a> to clarify scope of the EU AI Act.</p></li><li><p>&#127760; Statement on <a href="https://www.elysee.fr/en/emmanuel-macron/2025/02/11/statement-on-inclusive-and-sustainable-artificial-intelligence-for-people-and-the-planet">Inclusive and Sustainable AI for People and the Planet </a>signed by world leaders at the AI Action Summit in France.</p></li><li><p>&#127480;&#127468; Singapore launches <a href="https://aiverifyfoundation.sg/ai-assurance-pilot/">Global AI Assurance Pilot</a>, focused on technical generative AI testing.</p></li><li><p>&#127466;&#127482; European Commission <a href="https://iapp.org/news/a/european-commission-withdraws-ai-liability-directive-from-consideration">withdraws the AI Liability Directive</a> proposal.</p></li><li><p>&#127468;&#127463; UK AI Safety Institute <a href="https://www.gov.uk/government/news/tackling-ai-security-risks-to-unleash-growth-and-deliver-plan-for-change">becomes the AI Security Institute</a> and shifts focus.</p></li></ul><h4><strong>March</strong></h4><ul><li><p>&#127760; ASEAN publishes <a href="https://asean.org/book/asean-responsible-ai-roadmap-2025-2030/">Responsible AI Roadmap (2025-2030)</a>, setting regional AI governance priorities.</p></li><li><p>&#127482;&#127480; NIST publishes updated report on <a href="https://csrc.nist.gov/pubs/ai/100/2/e2025/final">Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations</a>.</p></li><li><p>&#127463;&#127479; Brazil&#8217;s <a href="https://www.lexology.com/library/detail.aspx?g=770c9e93-2750-41b5-86b1-a251a5d432cd">AI Bill (2338/2023) forwarded to Chamber of Deputies</a> following Senate approval.</p></li><li><p>&#127471;&#127477; Japan publishes updated <a href="https://www.lexology.com/library/detail.aspx?g=77336845-90f7-4d15-a921-65abec7eaca0">AI Guidelines for Business (Version 1.1)</a>.</p></li></ul><h4>April</h4><ul><li><p>&#127482;&#127480; OMB issues <a href="https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-22-Driving-Efficient-Acquisition-of-Artificial-Intelligence-in-Government.pdf">Memoranda on federal agency use</a> and acquisition of AI.</p></li><li><p>&#127466;&#127482; European Commission publishes <a href="https://digital-strategy.ec.europa.eu/en/library/ai-continent-action-plan">AI Continent Action Plan</a>. </p></li><li><p>&#127482;&#127480; President Trump signs <a href="https://www.federalregister.gov/documents/2025/04/28/2025-07368/advancing-artificial-intelligence-education-for-american-youth">Executive Order 14277: Advancing AI Education for American Youth</a>.</p></li></ul><h4>May </h4><ul><li><p>&#127760; <a href="https://www.scai.gov.sg/2025/scai2025-report/">Singapore Consensus on Global AI Safety Research Priorities</a> published following international summit.</p></li><li><p>&#127482;&#127480; <a href="https://www.bis.gov/press-release/department-commerce-announces-rescission-biden-era-artificial-intelligence-diffusion-rule-strengthens">Framework for AI Diffusion rescinded</a> by Trump Administration.</p></li><li><p>&#127464;&#127475; China State Council <a href="https://english.www.gov.cn/news/202505/14/content_WS68245503c6d0868f4e8f28ad.html">deprioritises Draft AI Law</a>, removing it from 2025 legislative plan.</p></li><li><p>&#127757; African Union officially declares the <a href="https://furtherafrica.com/2025/05/28/africa-declares-artificial-intelligence-strategy-a-priority-for-inclusive-development/">Africa AI Strategy</a> a top priority for the continent.</p></li><li><p>&#127482;&#127480; <a href="https://www.govinfo.gov/content/pkg/PLAW-119publ12/html/PLAW-119publ12.htm">TAKE IT DOWN Act</a> signed into U.S. federal law, criminalising non-consensual intimate imagery.</p></li><li><p>&#127482;&#127480; U.S. House of Representatives votes to pass <a href="/__u/oliverpatel.substack.com/p/unpacking-the-10-year-moratorium">10-year state AI law moratorium</a>. </p></li><li><p>&#127760;  <a href="https://www.iso.org/standard/42005">ISO/IEC 42005:2025</a> Standard on AI System Impact Assessment published.</p></li></ul><h4><strong>June</strong></h4><ul><li><p>&#127482;&#127480; Texas enacts <a href="https://www.dlapiper.com/en/insights/publications/2025/06/texas-adopts-the-responsible-ai-governance-act">Responsible AI Governance Act (HB 149)</a>, regulating AI use in the state.</p></li></ul><h4><strong>July </strong></h4><ul><li><p>&#127482;&#127480; U.S. Senate votes to <a href="/__u/oliverpatel.substack.com/p/unpacking-the-10-year-moratorium">reject 10-year state AI law moratorium</a>. </p></li><li><p>&#127760; <a href="https://www.iso.org/standard/42006#lifecycle">ISO/IEC 42006:2025</a> Standard published, outlining requirements for bodies providing audit and certification of AI management systems. </p></li><li><p>&#127480;&#127468; Singapore launches <a href="https://www.imda.gov.sg/resources/press-releases-factsheets-and-speeches/press-releases/2025/singapore-launches-new-tools-to-help-businesses-protect-data-and-deploy-ai-in-a-trusted-ecosystem">Global AI Assurance Sandbox</a>. </p></li><li><p>&#127475;&#127487; New Zealand Government publishes <a href="https://www.mbie.govt.nz/business-and-employment/business/support-for-business/responsible-ai-guidance-for-businesses">Responsible AI Guidance for Business</a>.</p></li><li><p>&#127466;&#127482; European Commission publishes <a href="https://digital-strategy.ec.europa.eu/en/library/guidelines-scope-obligations-providers-general-purpose-ai-models-under-ai-act">guidelines for providers of general-purpose AI models</a>.</p></li><li><p>&#127482;&#127480; White House releases <a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">America&#8217;s AI Action Plan</a>, outlining 90+ federal policy actions across three pillars.</p></li><li><p>&#127482;&#127480; President Trump signs <a href="https://www.whitehouse.gov/presidential-actions/2025/07/promoting-the-export-of-the-american-ai-technology-stack/">Executive Order 14320: Promoting the Export of the American AI Technology Stack</a>.</p></li><li><p>&#127482;&#127480; President Trump signs <a href="https://www.federalregister.gov/documents/2025/07/28/2025-14217/preventing-woke-ai-in-the-federal-government">Executive Order 14319: Preventing Woke AI in the Federal Government</a>.</p></li><li><p>&#127482;&#127480; President Trump signs <a href="https://www.whitehouse.gov/presidential-actions/2025/07/accelerating-federal-permitting-of-data-center-infrastructure/">Executive Order 14318: Accelerating Federal Permitting of Data Center Infrastructure</a>.</p></li><li><p>&#127466;&#127482; EU publishes <a href="https://digital-strategy.ec.europa.eu/en/library/explanatory-notice-and-template-public-summary-training-content-general-purpose-ai-models">General-Purpose AI Model Training Data Public Summary template</a>.</p></li><li><p>&#127464;&#127475; China proposes <a href="https://pandaily.com/china-proposes-world-ai-cooperation-organization-at-waic-2025">World AI Cooperation Organisation</a> at international forum.</p></li><li><p>&#127464;&#127475; China publishes <a href="https://www.mfa.gov.cn/eng/xw/zyxw/202507/t20250729_11679232.html">Global AI Governance Action Plan</a>.</p></li></ul><h4><strong>August </strong></h4><ul><li><p>&#127466;&#127482; EU formally approves <a href="https://digital-strategy.ec.europa.eu/en/policies/contents-code-gpai">General-Purpose AI Code of Practice</a>. </p></li><li><p>&#127466;&#127482; <a href="/__u/oliverpatel.substack.com/p/general-purpose-ai-model-compliance">Obligations for GPAI model providers</a> become applicable under the EU AI Act from 2 August.</p></li><li><p>&#127482;&#127480; Trump Administration negotiates deal with <a href="https://abcnews.go.com/Business/trump-administrations-deal-ai-chipmakers/story?id=124539684">Nvidia and AMD over China AI chip exports</a>.</p></li><li><p>&#127464;&#127475; China releases national <a href="https://english.www.gov.cn/policies/latestreleases/202508/27/content_WS68ae7976c6d0868f4e8f51a0.html">AI Plus Plan</a> to accelerate AI integration across industries.</p></li><li><p>&#127760; UN General Assembly adopts <a href="https://docs.un.org/en/A/RES/79/325">Resolution A/RES/79/325</a>, establishing the Global Dialogue on AI Governance and Independent International Scientific Panel on AI.</p></li></ul><h4><strong>September </strong></h4><ul><li><p>&#127464;&#127475; China&#8217;s <a href="https://www.chinalawtranslate.com/en/ai-labeling/">Measures for Labelling of AI-Generated Synthetic Content</a> take effect.</p></li><li><p>&#127464;&#127475; China&#8217;s mandatory national standard on <a href="https://www.geopolitechs.org/p/chinas-mandatory-national-standards">Labelling Method for Content Generated by AI (GB 45438-2025) </a>takes effect.</p></li><li><p>&#127471;&#127477; <a href="https://www.twobirds.com/en/insights/2025/japan/japans-new-ai-act-examining-an-innovationfirst-approach-against-the-eus-comprehensive-risk-framework">Japan AI Promotion Act</a> takes effect in full.</p></li><li><p>&#127468;&#127463; UK publishes <a href="https://www.gov.uk/government/publications/trusted-third-party-ai-assurance-roadmap/trusted-third-party-ai-assurance-roadmap">Trusted Third Party AI Assurance Roadmap</a>.</p></li><li><p>&#127464;&#127475; China releases <a href="https://www.cac.gov.cn/2025-09/15/c_1759653448369123.htm">AI Safety Governance Framework 2.0</a>.</p></li><li><p>&#127482;&#127480; California enacts <a href="https://www.cliffordchance.com/insights/resources/blogs/talking-tech/en/articles/2025/10/sb-53--california-sets-standards-for-ai-transparency.html">Transparency in Frontier Artificial Intelligence Act (SB53)</a>.</p></li><li><p>&#127482;&#127480; CAISI publishes <a href="https://www.nist.gov/news-events/news/2025/09/caisi-evaluation-deepseek-ai-models-finds-shortcomings-and-risks">Evaluation of DeepSeek AI Models</a>.</p></li></ul><h4>October </h4><ul><li><p>&#127480;&#127468; Singapore publishes <a href="https://isomer-user-content.by.gov.sg/36/703ff9fe-9db1-4e09-98c2-89e3d7007ef0/Draft%20Addendum%20on%20Securing%20Agentic%20AI%20%5bFor%20Public%20Consultation%5d.pdf">Draft Addendum on Securing Agentic AI</a>.</p></li></ul><h4><strong>November </strong></h4><ul><li><p>&#127760; <a href="https://www.coe.int/en/web/artificial-intelligence/the-framework-convention-on-artificial-intelligence">Council of Europe Framework Convention on AI</a> enters into force. </p></li><li><p>&#127464;&#127475; China updates <a href="https://techinsights.linklaters.com/post/102lrz5/chinas-2025-cybersecurity-law-amendments-enhanced-penalties-expanded-extraterr">National Cybersecurity Law</a> with AI-specific provisions.</p></li><li><p>&#127470;&#127475; India publishes <a href="https://static.pib.gov.in/WriteReadData/specificdocs/documents/2025/nov/doc2025115685601.pdf">AI Governance Guidelines</a>.</p></li><li><p>&#127466;&#127482; European Commission announces <a href="/__u/oliverpatel.substack.com/p/how-could-the-eu-ai-act-change">proposed changes to EU AI Act</a> as part of Digital Package simplification proposal.</p></li><li><p>&#127466;&#127482; EU AI Act <a href="https://digital-strategy.ec.europa.eu/en/news/commission-launches-whistleblower-tool-ai-act">whistleblower tool launched</a> by European Commission.</p></li><li><p>&#127462;&#127482; Australia establishes <a href="https://www.minister.industry.gov.au/ministers/charlton/media-releases/establishment-australian-ai-safety-institute">AI Safety Institute</a>.</p></li></ul><h4><strong>December</strong> </h4><ul><li><p>&#127462;&#127482; Australia publishes <a href="https://www.minister.industry.gov.au/ministers/timayres/media-releases/national-ai-plan-empowering-all-australians">National AI Plan</a>.</p></li><li><p>&#127482;&#127480; Trump Administration allows <a href="https://www.cnbc.com/2025/12/08/trump-nvidia-h200-sales-china.html">NVIDIA to export H200 AI chips to China</a>.</p></li><li><p>&#127462;&#127482; Australia passes <a href="https://www.esafety.gov.au/about-us/industry-regulation/social-media-age-restrictions">social media age restrictions law</a>, with AI verification implications.</p></li><li><p>&#127482;&#127480; President Trump signs <a href="https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/">Executive Order on Ensuring a National Policy Framework for AI</a>, establishing AI Litigation Task Force to challenge state AI laws.</p></li><li><p>&#127482;&#127480; OMB publishes Memorandum <a href="https://www.whitehouse.gov/wp-content/uploads/2025/12/M-26-04-Increasing-Public-Trust-in-Artificial-Intelligence-Through-Unbiased-AI-Principles-1.pdf">M-26-04: Increasing Public Trust in AI Through Unbiased AI Principles</a>.</p></li><li><p>&#127468;&#127463; UK publishes <a href="https://www.gov.uk/government/publications/copyright-and-artificial-intelligence-progress-report/copyright-and-artificial-intelligence-statement-of-progress-under-section-137-data-use-and-access-act">progress report on Copyright and AI consultation</a>.</p></li><li><p>&#127466;&#127482; European Commission publishes first draft of <a href="https://digital-strategy.ec.europa.eu/en/news/commission-publishes-first-draft-code-practice-marking-and-labelling-ai-generated-content">Code of Practice on marking and labelling of AI-generated content</a>.</p></li><li><p>&#127468;&#127463; UK AI Security Institute publishes <a href="https://www.aisi.gov.uk/frontier-ai-trends-report/pdf">Frontier AI Trends Report</a>.</p></li><li><p>&#127482;&#127480; New York enacts <a href="https://www.governor.ny.gov/news/governor-hochul-signs-nation-leading-legislation-require-ai-frameworks-ai-frontier-models">RAISE Act (S6953B/A6453B)</a> mandating transparency for frontier AI models. </p></li><li><p>&#127464;&#127475; China releases <a href="https://www.chinadaily.com.cn/a/202512/27/WS694fd34aa310d6866eb30c4f.html">draft regulations for AI-powered anthropomorphic interaction services</a>.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Top 10 Posts of 2025]]></title><description><![CDATA[Happy Holidays from Enterprise AI Governance! | #36]]></description><link>https://oliverpatel.substack.com/p/top-10-posts-of-2025</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/top-10-posts-of-2025</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Wed, 24 Dec 2025 13:55:02 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AD7Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!AD7Q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!AD7Q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6607933,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/182502199?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!AD7Q!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff1ac1c87-662d-4034-916b-be742a5e745c_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance.<br><br></em>As many of us wind down for the holiday season, I wanted to take a moment to thank you all for reading, supporting, and sharing my newsletter throughout 2025. <br><br>I also want to share some reflections from the year and the journey ahead, including the Top 10 Most Popular Posts of 2025 and what you can expect from me in 2026. <br><br>I greatly appreciate every single time this newsletter is opened, read, liked, and shared, as well as all of the insightful comments and responses I receive. We live in an age of information overload, exceptionally busy schedules, and unprecedented demands in our work and personal lives. Therefore, I do not take for granted the valuable time you spend engaging with my work. And I commit to doing all I can to ensure my content and resources remain truly valuable for your work next year.<br><br>It&#8217;s been just over 1 year since I launched Enterprise AI Governance, on 20 December 2024. I can confidently say that this turned out to be one of the best decisions I&#8217;ve made. <br><br>I am proud that we now have a community of 6,810 Enterprise AI Governance subscribers. This includes people from 135 countries and almost every continent&#8212;please forward this post to your friends and colleagues in Antarctica! The top five most represented countries are the U.S., UK, India, Germany, and Canada.<br><br>When I checked the stats today, I was also thrilled to see that the posts on Enterprise AI Governance have been viewed over 222,000 times in the past year. <br><br>To me, this highlights the importance of continuing and deepening this work in 2026. The ways in which AI is rapidly advancing, the increasingly democratised nature of this technology, its development and deployment in sensitive, real-world contexts&#8212;from healthcare to defence&#8212;and the practical ways in which individuals, organisations, governments, and societies can effectively manage risks and promote safe and ethical outcomes, are among the defining issues of our time.</p><p>Although it may not always feel like it, we remain at the very early stages of AI governance. The choices we make today will have important ripple effects on humanity for many years to come. <br><br>I started this newsletter for two simple reasons: to (re)cultivate my love for writing and to fill a gap in the market with practical guidance on AI governance implementation. </p><p>Before joining AstraZeneca, I&#8217;d spent my entire career writing. And I mean pre-ChatGPT writing, where you start with nothing but your mind, a blank page, and random Google searches! </p><p>After spending several years crafting papers in academia and government, I found myself in corporate leadership. In this environment, as many of you can relate, reading and writing longer-form content was suddenly no longer a core part of my work. This was something I missed and I didn&#8217;t want to lose a skill that I valued. Also, given that my shorter-form LinkedIn posts on AI governance were resonating, I thought it made sense to go deeper. </p><p>Doing so has provided me with several powerful benefits. The way in which producing longer-form content requires you to grapple with complexity, engage directly with primary sources, and formulate cogent arguments sharpens your mind in ways not many other activities can. This has enabled me to understand the challenges and dynamics of Enterprise AI Governance in a meaningful way, which has also connected me with many others at the forefront and on the frontline of this emerging field. </p><p>So far, I am proud to have published 36 editions of Enterprise AI Governance. Not quite once per week (sorry!), but not too far off either. As you will see from the list below, the most popular content is on the EU AI Act, agentic AI governance, and the practicalities of AI governance implementation, including AI literacy, AI procurement, and AI usage policies. <br><br>Next year, I will double down on these topics, by continuing to provide in-depth analysis on the EU AI Act (including how it may be amended) and global AI regulations, as well as the practicalities of how to implement AI governance in an organisational context, covering open-source AI, AI risk assessments, and accountability structures, and more.<br><br>I will also cover more technical topics, such as multi-agentic systems, explainability, hallucinations, model sycophancy, retrieval-augmented generation (RAG), knowledge graphs, and context engineering. Finally, I will provide an overview of the Top 10 AI Governance and Safety Papers in 2025. <br><br>This newsletter will remain unashamedly practical, with an emphasis on longer-form content and tangible resources that empower you to understand, implement, and master AI governance.</p><p>Of course, the thing I am most excited for in 2026 is the launch of my book, <em> <strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a>.</strong> </em>It will cover all of the topics covered in this newsletter and so much more, in a uniquely practical, visual, and comprehensive way. Given that Enterprise AI Governance is a free newsletter, signing up for my book is the best thing you can do to support my work. To secure a 25% discount during the pre-launch period, sign up at the link below.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure your 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure your 25% discount</span></a></p><h4><strong><br>Top 10 Most Popular Posts of 2025</strong></h4><div><hr></div><p>Here are the Top 10 Enterprise AI Governance Posts of 2025, ranked by total number of views:</p><ol><li><p><strong><a href="/__u/oliverpatel.substack.com/p/the-unofficial-aigp-resource-guide">The Unofficial AIGP Resource Guide</a>*</strong> (February 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/the-ultimate-eu-ai-act-resource-guide">The Ultimate EU AI Act Resource Guide</a>*</strong> (May 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/initial-reflections-on-agentic-ai">Initial Reflections on Agentic AI Governance</a></strong> (March 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/top-12-papers-on-agentic-ai-governance">Top 12 Papers on Agentic AI Governance (Part 1</a>)</strong> (June 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/the-ultimate-guide-to-ai-literacy">The Ultimate Guide to AI Literacy</a></strong> (March 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/whats-next-for-eu-ai-act-simplification">What&#8217;s next for EU AI Act &#8220;simplification&#8221;?</a></strong> (November 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/ai-usage-policy-playbook">AI Usage Policy Playbook</a></strong> (March 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/general-purpose-ai-model-compliance">General-Purpose AI Model Compliance Guide (Part 1)</a></strong> (August 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/eu-publishes-general-purpose-ai-code">EU Publishes General-Purpose AI Code of Practice</a> </strong>(July 2025)</p></li><li><p><strong><a href="/__u/oliverpatel.substack.com/p/the-ai-procurement-and-contracts">The AI Procurement and Contracts Toolkit: 10 Practical Resources</a> </strong>(October 2025)</p></li></ol><p>Given the popularity of these two resource guides, and the fact that they are now slightly out of date, I will publish updated versions in early 2026. </p><div class="file-embed-wrapper" data-component-name="FileToDOM"><div class="file-embed-container-reader"><div class="file-embed-container-top"><image class="file-embed-thumbnail" src="/__u/substackcdn.com/image/fetch/$s_!7_0e!,w_400,h_600,c_fill,f_auto,q_auto:best,fl_progressive:steep,g_auto/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F896f86d9-15a3-4175-a3e3-be93e390d4d8_2500x6250.png"></image><div class="file-embed-details"><div class="file-embed-details-h1">Top 10 Posts of 2025</div><div class="file-embed-details-h2">3.92MB &#8729; PDF file</div></div><a class="file-embed-button wide" href="/__u/oliverpatel.substack.com/api/v1/file/698738bc-efbc-48aa-a696-d45f8a17731a.pdf"><span class="file-embed-button-text">Download</span></a></div><div class="file-embed-description">Download the pdf, hyperlinked version here!</div><a class="file-embed-button narrow" href="/__u/oliverpatel.substack.com/api/v1/file/698738bc-efbc-48aa-a696-d45f8a17731a.pdf"><span class="file-embed-button-text">Download</span></a></div></div><p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!_2uS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 424w, /__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 848w, /__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!_2uS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png" width="1456" height="3640" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:3640,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3637628,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/182502199?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 424w, /__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 848w, /__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 1272w, /__u/substackcdn.com/image/fetch/$s_!_2uS!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb28d6fa9-c9c6-4287-a2f3-ff99afbbc3ae_2500x6250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4><br><strong>Meme of the Year</strong></h4><div><hr></div><p>To end on a light-hearted note, Homer Simpson was my most popular meme of 2025&#8212;and also my second most popular <a href="https://www.linkedin.com/feed/update/urn:li:activity:7283403525944926208/?updateEntityUrn=urn%3Ali%3Afs_updateV2%3A%28urn%3Ali%3Aactivity%3A7283403525944926208%2CFEED_DETAIL%2CEMPTY%2CDEFAULT%2Cfalse%29">LinkedIn post</a> (with over 166k views). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!xnor!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!xnor!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg" width="1008" height="1258" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/abb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1258,&quot;width&quot;:1008,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;diagram, engineering drawing&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="diagram, engineering drawing" title="diagram, engineering drawing" srcset="/__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 424w, /__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 848w, /__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 1272w, /__u/substackcdn.com/image/fetch/$s_!xnor!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fabb104e3-e17c-417c-949d-bf643927c8c0_1008x1258.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What is President Trump's AI policy?]]></title><description><![CDATA[Explaining the new AI Executive Order | #35]]></description><link>https://oliverpatel.substack.com/p/what-is-president-trumps-ai-policy</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/what-is-president-trumps-ai-policy</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 14 Dec 2025 20:53:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TFYP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!TFYP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!TFYP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/48300403-3f00-4183-a313-2475616b20e2_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5002981,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/181617696?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!TFYP!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F48300403-3f00-4183-a313-2475616b20e2_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br><em>On Thursday 11 December 2025, President Trump issued an Executive Order on Ensuring a National Policy Framework for AI. This represents the administration&#8217;s latest attempt at blocking and constraining how U.S. states regulate AI. This article summarises the new Executive Order, situates it in the wider context of Trump&#8217;s AI policy, assesses the challenges the administration faces in preempting state AI laws, and reflects on what companies should do next.<br><br></em>For a detailed, up-to-date, and visual guide to U.S. AI law and policy (covering the federal and state levels), as well as U.S, China, and EU comparison charts, sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Get a 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Get a 25% discount</span></a></p><h4><strong><br>What just happened?</strong></h4><div><hr></div><p>On 11 December 2025, President Trump issued a new Executive Order that attempts to block states from enforcing existing AI regulations and deter states from enacting new AI laws. <br><br>Just five months after the Senate rejected the proposed 10-year moratorium on state AI laws by 99 votes to 1, the administration is having another bite of the cherry&#8212;this time through litigation, funding restrictions, and federal preemption, potentially via new legislation. <br><br>However, it is important to note that the latest development is an Executive Order (i.e., a presidential directive), not legislation. Meaningfully preempting state laws in this way would require legislation, which requires approval from both the House of Representatives and the Senate. It does not appear that substantive political changes have occurred in the past few months to render this more likely than it was back in the summer. <br><br>Nonetheless, this latest Executive Order is a powerful signal of intent that highlights the administration is digging in on this particular issue, despite the large-scale opposition to the previous 10-year moratorium proposal. </p><p>Indeed, the administration has repeatedly stated that its AI policy objective is to &#8220;sustain and enhance America&#8217;s global AI dominance&#8221;. State AI laws have been in the firing line, as part of the wider focus on pursuing deregulation as a means to propel the U.S. as the world&#8217;s dominant AI power.</p><p>Preemption is a U.S. constitutional principle whereby federal law (i.e., law passed by Congress) takes precedence over state law when there are conflicts between the two. When a federal law &#8220;preempts&#8221; a state law, the state law is effectively nullified. However, the controversy regarding state AI law preemption is partly due to the fact that there is no comprehensive federal AI law. And the federal AI laws that are on the books cover narrower domains such as strengthening the U.S. AI industry, support and funding for AI research and infrastructure, and export controls. Where state AI laws focus on responsible AI topics like transparency or bias, there is arguably a lack of federal law to preempt these laws. <br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><strong>What is the new Executive Order on AI?</strong></h4><div><hr></div><p>President Trump signed the Executive Order: <em><a href="https://www.whitehouse.gov/presidential-actions/2025/12/eliminating-state-law-obstruction-of-national-artificial-intelligence-policy/">Ensuring a National Policy Framework for Artificial Intelligence</a></em> on Thursday 11 December 2025, </p><p>An Executive Order is a directive issued by the President to federal agencies and executive branch officials. It is issued by the President unilaterally, does not require Congressional approval and cannot, by itself, override state laws.</p><p>The core argument Trump presents in this Executive Order is that the patchwork of many state AI laws creates compliance burdens and administrative complexity that could undermine U.S. competitiveness. Having 50 different AI regulatory regimes, the Executive Order argues, &#8220;<em>makes compliance challenging, particularly for startups</em>&#8220;.</p><p>Colorado&#8217;s AI law&#8212;<a href="https://leg.colorado.gov/bills/sb24-205">Consumer Protections for AI</a> (SB24-205), effective date 30 June 2026&#8212;is singled out for criticism, with the Executive Order claiming that such laws tackling &#8220;algorithmic discrimination&#8221; may force AI models to produce false results in order to avoid differential treatment of protected groups.</p><p>The declared policy of the administration is to establish a &#8220;minimally burdensome national standard&#8221; for AI, as opposed to &#8220;50 discordant State ones&#8221;. To achieve this, the Executive Order directs a multi-pronged set of actions and broader strategy for the U.S. federal government to pursue:</p><ul><li><p>First, the Attorney General must establish an <strong>AI Litigation Task Force</strong> within 30 days (of the Executive Order), with the goal of challenging state AI laws in court. The focus will be on identifying state laws that are inconsistent with the U.S. AI policy of &#8220;sustaining and advancing U.S. global dominance in AI&#8221;. The grounds for legal challenge could include &#8220;unconstitutional regulation&#8221; of interstate commerce or preemption by existing federal regulations.</p></li><li><p>Second, the Secretary of Commerce, in consultation with other government leaders, must publish an <strong>evaluation of existing state AI laws</strong> within 90 days (of the Executive Order), identifying &#8220;onerous&#8221; laws that conflict with the U.S. AI policy objective mentioned above. This evaluation must focus on laws that &#8220;require AI models to alter truthful outputs&#8221; or that compel organisations to &#8220;disclose information in a manner that would violate the First Amendment&#8221;. This is significant, as it explicitly targets laws relating to AI transparency and bias mitigation, two core threads throughout many existing state AI laws.</p></li><li><p>Third, the Order imposes <strong>funding restrictions</strong> on states that are deemed to have &#8220;onerous AI laws&#8221;. States identified through the evaluation referenced above will be ineligible for certain categories of federal funding under the Broadband Equity Access and Deployment (BEAD) Program. U.S. government executive departments and agencies are also directed to assess whether they can condition discretionary grants on states agreeing not to enforce their existing AI laws and/or not enacting new AI laws. This could result in government agencies withholding certain types of grant funding from states.</p></li><li><p>Fourth, the Federal Communications Commission (FCC), the agency that regulates U.S. communications (e.g., broadcasting, internet, and telecommunications), must initiate work to determine whether to adopt a <strong>federal reporting and disclosure standard for AI models</strong> that would preempt conflicting state laws. It is important to note that the Executive Order requires the FCC to &#8220;initiate a proceeding&#8221;; it does not require the FCC to adopt such a standard for AI transparency. However, the implied thinking is that if there is a national standard, this could be argued to supersede state AI laws covering AI reporting and disclosure.</p></li><li><p>Fifth, the <strong>FTC must issue a policy statement </strong>explaining when state laws requiring the alteration of the &#8220;truthful outputs&#8221; are preempted by federal prohibitions on deceptive practices, which largely stem from the FTC Act that prohibits &#8220;unfair and deceptive practices&#8221;. Again, the implication is that such guidance would strengthen the case for existing federal laws superseding state AI laws in this domain too.</p></li><li><p>Finally, the administration will prepare a <strong>legislative proposal</strong> for a uniform federal AI framework that preempts state laws. However, the proposal would be narrow and would not seek to preempt state laws covering any of the following policy areas: </p><ul><li><p>child safety;</p></li><li><p>AI compute and data centre infrastructure;</p></li><li><p>state government procurement and use of AI; and</p></li><li><p>other topics to be determined.</p></li></ul></li></ul><p>This is significant as it highlights the policy areas which the administration deem to be legitimate domains of autonomous state AI lawmaking, even if the result is regulatory divergence within the U.S.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><br><strong>How did Trump attempt to block state AI laws previously?</strong></h4><div><hr></div><p>This latest Executive Order is not the administration&#8217;s first attempt to constrain state AI laws. Back in May 2025, the administration proposed adding a 10-year moratorium on state AI laws enforcement to Trump&#8217;s flagship domestic policy and taxation bill, the &#8216;One Big Beautiful Bill Act&#8217; (H.R.1).  <br><br>I covered the 10-year moratorium in detail in a previous edition of Enterprise AI Governance: <strong><a href="/__u/oliverpatel.substack.com/p/unpacking-the-10-year-moratorium">Unpacking the 10-year Moratorium on U.S. State AI Laws</a></strong>. Here is a summary of that article.</p><p>The proposed moratorium was designed to prevent U.S. states from being able to enforce &#8220;any law or regulation limiting, restricting, or otherwise regulating AI models, AI systems, or automated decision systems&#8221; for a period of 10 years. Although this would not technically have prevented states from introducing and passing new AI laws, the broad restriction on enforcement would have rendered doing so pointless.</p><p>This was an attempt by the federal government to preempt state AI laws by blocking states from enforcing laws they had already passed, as well as any new laws they might pass in the future. The stated goal was to halt the &#8220;proliferation of a complex and fragmented patchwork of state AI laws&#8221;, in support of AI innovation across the country.</p><p>The House of Representatives voted to pass the state AI law moratorium by a narrow margin, largely along party lines, with 215 in favour and 214 against. However, following this, the moratorium was decisively rejected. In July 2025, the Senate voted 99 to 1 to remove it from the bill. This followed a significant bipartisan campaign against the provision. A <a href="https://www.transparencycoalition.ai/news/bipartisan-lawmakers-from-50-states-tell-congress-dont-stop-us-from-acting-on-ai">June 2025 letter</a>, signed by 260 state lawmakers, stated that &#8220;states are laboratories of democracy accountable to their citizens and must maintain the flexibility to respond to new digital concerns&#8221;. Several Republican state governors also campaigned against the proposal.<br><br>The main reason the moratorium proved so controversial was not really about AI. The case (against it) centred on the philosophical objection to the federal government constraining states in this way, particularly given that there is no comprehensive federal AI law to take precedence. The argument was that the states&#8217; hands were being tied, without an alternative federal framework on the table. The fundamentals of the situation do not appear to have meaningfully changed in the months that have passed.</p><p>However, the December 2025 Executive Order represents a pivot in strategy. Rather than seeking blanket preemption through legislation&#8212;which requires Congressional approval&#8212;the administration is now pursuing litigation, agency action, and funding leverage. These approaches can be initiated by the executive branch alone. However, as noted above, the President&#8217;s legal authority to actually preempt state laws remains limited without legislation. The administration may also pursue new legislation, but this will likely face similar challenges in Congress.</p><h4><strong><br><br>What AI laws do states have and will Trump succeed in blocking them?</strong></h4><div><hr></div><p>In lieu of comprehensive federal AI law, dozens of U.S. states have enacted AI-related laws. 131 such laws were passed between 2016 and 2024, and over 700 AI-related bills were proposed in 2024 alone. The states with the most AI-related laws are California, Colorado, Maryland, Utah, and Virginia. California has been particularly active, enacting dozens of laws that regulate AI in different ways. These laws cover themes including fairness and accountability, transparency, data privacy, deepfakes, and government use of AI.</p><p>However, the administration faces an uphill task in its efforts to block the enforcement and enactment of these laws. Now that the moratorium has been rejected by the Senate due to concerns regarding preemption and the ways in which the federal government can constrain the states, it is fair to argue that subsequent federal legislative proposals will be met with similar levels of scrutiny and controversy.</p><h4><strong><br><br>What other AI policy actions has this administration taken?</strong></h4><div><hr></div><p>The new Executive Order sits within a broader pro-business and pro-innovation AI policy agenda. <br><br>Trump has pivoted away from the Biden administration&#8217;s AI governance and safety agenda. Promoting U.S. AI leadership&#8212;which has always been a core federal AI policy objective&#8212;now takes centre stage. One of the first actions taken by Trump at the start of this second term, in January 2025, was to revoke various Biden-era executive orders, including the flagship Executive Order on <em><a href="https://www.federalregister.gov/documents/2023/11/01/2023-24283/safe-secure-and-trustworthy-development-and-use-of-artificial-intelligence">Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence.</a></em></p><p>In July 2025, the administration published <em><a href="https://www.whitehouse.gov/wp-content/uploads/2025/07/Americas-AI-Action-Plan.pdf">Winning the Race: America&#8217;s AI Action Plan</a></em>, which outlines how the U.S. can achieve and maintain &#8220;unquestioned and unchallenged global technological dominance&#8221; in AI.</p><p>I also covered the administration&#8217;s AI Action Plan in a previous edition of Enterprise AI Governance: <strong><a href="/__u/oliverpatel.substack.com/p/what-americas-ai-action-plan-means">What America&#8217;s AI Action Plan Means for AI Governance</a></strong>. A summary of that explainer piece is provided below. <br><br>The AI Action Plan contains dozens of policy recommendations across three pillars:</p><ul><li><p>Pillar 1. Accelerate AI Innovation</p></li><li><p>Pillar 2. Build American AI Infrastructure</p></li><li><p>Pillar 3. Lead in International AI Diplomacy and Security</p></li></ul><p>Notably, under Pillar 1, the AI Action Plan recommended withholding funding for AI-related initiatives from states with &#8220;burdensome AI regulations&#8221;. This core idea has now been operationalised through the new Executive Order and its funding restrictions. Moreover, the rejection of the 10-year moratorium by the Senate did not extinguish the underlying policy objective; rather, it has been repackaged and is now pursued through alternative means.<br><br>The AI Action Plan is significant because it directly links AI regulations with the ability (or lack thereof) of companies to innovate at speed. Put simply, the Trump administration believes that AI should not be constrained by regulations and that doing so would impede the U.S. economic and security prospects in a damaging way.</p><p>Other recommended policy actions in the AI Action Plan included:</p><ul><li><p>Taking action to review and remove any existing Federal regulations that impede AI innovation.</p></li><li><p>Ensure the federal government only procures &#8220;unbiased&#8221; and &#8220;ideologically neutral&#8221; large language models.</p></li><li><p>Fast-track and streamline processes for data centre construction review, approval, and licensing.</p></li><li><p>Advocate for &#8220;pro-innovation&#8221; approaches to international AI governance, that reflect &#8220;American values&#8221; and shift away from &#8220;burdensome regulations&#8221;.</p></li></ul><p>Other notable AI policy measures pursued by this administration include Executive Orders on advancing AI education for American youth (April 2025), accelerating federal permitting for data centre infrastructure (July 2025), preventing &#8220;woke AI&#8221; in federal government procurement (July 2025), and promoting the export of the American AI technology stack (July 2025). The TAKE IT DOWN Act, which criminalises the publication of non-consensual intimate deepfakes, was signed into law in May 2025.</p><h4><strong><br>What should companies operating in the U.S. do now?</strong></h4><div><hr></div><p>If you think AI governance is not relevant for your organisation because the current administration is pro-AI and against restrictive AI regulation, you could be in for a rude awakening if things go wrong.</p><p>Deregulation does not mean that AI risks no longer apply to you or that you are not exposed. Indeed, the AI Action Plan itself highlights various AI-related risks that could slow innovation, including interpretability, robustness, and misalignment. Furthermore, all enterprises using generative AI at scale are exposed to a litany of (relatively novel) data-related risks. I outlined these in my article on the <strong><a href="/__u/oliverpatel.substack.com/p/the-protect-framework-managing-data">PROTECT Framework: Managing Data Risks in the AI Era</a></strong>.<br><br>The PROTECT Framework empowers you to understand, map, and mitigate the most pertinent data risks that are fuelled by widespread adoption of generative AI, covering themes such as public AI tool usage, rogue internal AI projects, opportunistic vendors, and compliance and copyright breaches. These risks cannot be mitigated without a robust approach to AI governance, which serves as a reminder that AI-specific regulatory compliance is not the sole driver for enterprise AI governance. <br><br>Moreover, even the White House&#8217;s Office of Management and Budget (OMB) describes effective AI governance as &#8220;key to accelerated innovation&#8221;. Indeed, the <a href="https://www.whitehouse.gov/wp-content/uploads/2025/02/M-25-21-Accelerating-Federal-Use-of-AI-through-Innovation-Governance-and-Public-Trust.pdf">AI governance framework</a> that OMB directs federal agencies to implement&#8212;covering AI development, deployment, procurement, and use&#8212;is robust. This suggests that although the U.S. government does not want there to be any regulatory measures getting in the way of U.S. companies&#8217; AI activities, it nonetheless recognises that a well-designed and proportionate AI governance framework is important for both risk mitigation and value generation, especially in sensitive domains.<br><br>For U.S. companies, the reality today is the same as it was yesterday. There still exists a complex patchwork of many state AI laws to contend with, as well as federal and state laws that meaningfully regulate or implicate AI in specific ways, such as privacy, copyright, employment, and consumer protection laws. Given the complexity of developing different internal AI governance frameworks for different jurisdictions, I always recommend having a company-wide AI governance framework that promotes and facilitates compliance, risk management, and AI-enablement across all the important jurisdictions you operate in.<br><br><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[How to Govern Externally Provided AI]]></title><description><![CDATA[From paperwork to dynamic oversight | #34]]></description><link>https://oliverpatel.substack.com/p/how-to-govern-externally-provided</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/how-to-govern-externally-provided</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 07 Dec 2025 19:03:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!EfVI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!EfVI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!EfVI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5055301,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/180973760?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!EfVI!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fba35a7-5e50-4c98-9743-9e8a0073aa82_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;<br><br>I&#8217;m Oliver Patel, author and creator of <strong>Enterprise AI Governance</strong>.<br><br><em>Your enterprise increasingly relies on AI products and foundation models developed by other companies. This article tackles two critical challenges for AI governance leaders: i) how to move from &#8216;paper-based&#8217; vendor due diligence to dynamic and continuous oversight, and ii) how to manage the novel risks of building AI systems with externally provided foundation models.<br><br></em>If you enjoy my work and want to read a comprehensive, step-by-step guide to enterprise AI governance, sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure your 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure your 25% discount</span></a></p><div><hr></div><p>Over the past few weeks, this newsletter has analysed some of the most pertinent challenges facing AI governance leaders in 2025.<br><br><a href="/__u/oliverpatel.substack.com/p/top-10-challenges-for-ai-governance">Part 1 explored challenges 1-3</a> (see below). It argued that the democratisation and widespread accessibility of AI is driving intense volume and velocity of AI use cases. This is contributing to an AI risk &#8216;vibe shift&#8217;, overwhelming AI governance functions, and necessitates updating the risk-based approach to AI governance. <br><br>We then took a mini detour for a deep dive on challenge 4&#8212;protecting confidential business data&#8212;in which I outlined the <a href="/__u/oliverpatel.substack.com/p/the-protect-framework-managing-data">PROTECT Framework for Managing Data Risks in the AI Era</a>. The purpose of the PROTECT Framework is to enable organisations to understand, map, and mitigate the most pertinent data risks that are fuelled by widespread adoption of generative AI.<br><br>Today&#8217;s article continues the series by analysing challenges 5 and 6, both of which are focused on the way in which enterprises leverage, and increasingly rely on, AI models, products, and services developed and provided by external organisations. It provides practical advice and guidance on how to conduct effective vendor due diligence and oversight, what AI procurement processes should entail, and notable challenges and risks to mitigate when using pre-trained foundation models to develop and deploy customised AI applications.<br><br>As a reminder, here are the top 10 challenges this series covers.<br><strong><br>Top 10 Challenges for AI Governance Leaders in 2025</strong></p><div><hr></div><ol><li><p><strong>The &#8216;democratisation dilemma&#8217;</strong>. <em>How to maintain robust oversight and promote compliance when the ability to develop, deploy, and use AI is democratised and widely accessible?</em></p></li><li><p><strong>Volume and velocity. </strong><em>How to keep up with the sheer volume and rapid pace of enterprise<strong> </strong>AI initiatives, whilst cutting through the noise and deploying finite resources and expertise on the highest value work?</em></p></li><li><p><strong>Refining the risk-based approach</strong>. <em>How to respond to the AI risk &#8216;vibe shift&#8217; and effectively target governance on the relatively small proportion of AI systems and use cases that could pose significant risks?</em></p></li><li><p><strong>Protecting confidential business data</strong>. <em>How to protect confidential business data when there is immense hunger to experiment with and use the latest AI applications that are released on the market?</em></p></li><li><p><strong>Ongoing vendor due diligence and oversight. </strong><em>How to move beyond &#8216;paper-based&#8217; vendor due diligence and apply continuous oversight on the performance, trustworthiness, and safety of externally provided AI applications?</em></p></li><li><p><strong>AI engineering: building with foundation models</strong>. <em>How to determine your rights, responsibilities, and liabilities&#8212;as well as the novel risks and tangible mitigations&#8212;when building AI systems with foundation models provided by external organisations?</em></p></li><li><p><strong>Open-source AI model oversight. </strong><em>How to effectively govern the widespread access and use of open-source AI models, to safeguard your organisation from legal, compliance, and cyber security risks, whilst promoting innovation?</em></p></li><li><p><strong>Embedding compliance by design. </strong><em>How to build AI systems that promote compliance by design and default, to make it seamless for your workforce to do the right thing?</em></p></li><li><p><em><strong>Agentic AI governance: taking the human out of the loop. </strong>How to promote responsible, meaningful, and empowered human oversight of AI, when the fundamental goal of agentic AI is to take the human out of the loop?</em></p></li><li><p><strong>Digital governance silos and inefficiencies. </strong><em>How to effectively streamline and integrate your disparate digital governance and risk management processes and capabilities, to improve the user experience and accelerate AI innovation, whilst also strengthening your compliance posture?<br></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ol><h4><strong>5. Ongoing Vendor Due Diligence and Oversight</strong></h4><div><hr></div><p><em>How to move beyond &#8216;paper-based&#8217; vendor due diligence and apply continuous oversight on the performance, trustworthiness, and safety of externally provided AI applications?</em><br><br>Modern enterprises are becoming heavily reliant on AI products, applications, and services developed and provided by external organisations. Core enterprise workflows and domains, including recruitment, learning and development, IT support, and financial analytics are powered by bespoke vendor AI solutions. Furthermore, virtually all legacy enterprise software is being enhanced and updated with novel AI features and capabilities.</p><p>For most organisations, it makes more sense to buy rather than build. However, this amplifies various AI risks, such as unauthorised use and sharing of confidential data,  liability exposure for AI performance issues and incidents, and copyright breaches. <br><br>For these reasons, AI vendor due diligence and oversight is an integral part of enterprise AI governance&#8212;but it is one of the hardest pillars to get right. This is because, fundamentally, organisations struggle to effectively monitor and control how well these externally provided AI applications work. <br><br>There are three core elements to the &#8216;paper-based&#8217; governance referred to above:<br><br>1. <strong>Vendor due diligence assessment process.</strong> This typically consists of a set of assessments and questions that must be completed by the vendor before they are onboarded, as well as documentation and assurances they must provide. <br><br>2. <strong>Contracts, clauses and templates. </strong>This refers to standardised contractual clauses that can be included in agreements with AI vendors, covering topics like service delivery, data use, regulatory compliance, indemnity protection, and allocation of responsibilities and liabilities. <br><br>3. <strong>AI policies, covering procurement and partnerships. </strong>Finally, enterprise AI policy foundations should outline the principles, requirements, and processes for AI procurement and partnerships. <br><br>The challenge is that these core elements are necessary, but not sufficient, for effective AI vendor oversight and risk management. In isolation, they can represent relatively blunt instruments that risk creating the impression of robust governance and risk management without significantly impacting outcomes or mitigating the most serious risks. <br><br>For example, pre-vendor onboarding due diligence covers a snapshot in time and does not enable dynamic response to future issues or concerns that may arise. This is especially problematic given the pace at which vendors are updating and evolving their applications, and the importance of monitoring performance, reliability, impacts, and incidents across a large organisation.</p><p><strong>Practical solutions</strong></p><ul><li><p><strong>Pre-deployment testing and PoCs:</strong> before onboarding new solutions and signing hefty contracts, enterprises should perform testing and evaluation of vendor AI solutions. This testing can focus on both performance (i.e., how well it works for various use cases) as well as safety (i.e., to what extent are guardrails effective). This can include undertaking proof-of-concept (PoC) engagements and leveraging sandbox-type environments. This provides an additional layer of confidence over solely paper-based assessment exercises. Simply put, the best way to determine how well an AI solution will work for your organisation is to rigorously test and evaluate it. </p></li><li><p><strong>Ongoing monitoring and evaluation: </strong>once externally provided AI solutions are deployed in production, they should be monitored and evaluated on an ongoing and dynamic basis. Enterprises should not merely rely on vendors&#8217; internal monitoring processes and the written assurances they provide pre-onboarding. This should be augmented with independent testing and monitoring&#8212;perhaps even involving third parties&#8212;optimised for their use cases. This approach is especially important for mission critical applications. This can be both quantitative (e.g., automated tracking of output accuracy) and qualitative (e.g., user feedback surveys and incident reports). Ideally, quantifiable performance metrics and thresholds (or baselines) should be contractually guaranteed, with robust response procedures in case of deviations or deficiencies.</p></li><li><p><strong>New AI features and capabilities: </strong>the pre-vendor onboarding due diligence, and the resulting contract that is signed, often fails to account for the myriad ways in which the product could be updated with new AI features or capabilities. Oftentimes, such new AI features or capabilities integrated into an existing product can materially change the risk level, compliance scope, or potential impact of the overall product. Therefore, mechanisms must be in place for formal assessment and evaluation of new AI features and capabilities that trigger certain risk-based criteria&#8212;even when the vendor and the product they provide is already approved and deployed in production.</p></li><li><p><strong>Shaping product implementation and roadmaps: </strong>the best way to be aware of product enhancements, including the integration of new AI features and capabilities that can amplify risk, is to maintain active and focused engagement with the vendor. Part of this should include working with the vendor to implement the product in a responsible way, taking advantage of all available guardrails, monitoring, and safety features&#8212;as well as the expertise they should have from countless prior deployments. More broadly, this is an underappreciated facet of enterprise AI governance. The more influence you have on the vendor and their products, the more effective you will be at managing and mitigating risks.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><br><strong>6. AI Engineering: Building with Foundation Models</strong></h4><div><hr></div><p><em>How to determine your rights, responsibilities, and liabilities&#8212;as well as the novel risks and tangible mitigations&#8212;when building AI systems with foundation models provided by external organisations?</em><br><br>The generative AI boom of the past few years has fundamentally reshaped the nature of enterprise AI. Almost all enterprises are now building AI applications with pre-trained foundation models. And it is becoming less common for organisations to independently train and develop AI models for deployment in production. <br><br>Chip Huyen characterises &#8220;AI engineering&#8221; as a new discipline, distinct from traditional machine learning engineering, that centres around building production applications (i.e., AI systems) using readily available foundation models developed and provided by external organisations, rather than training AI models from scratch. <br>Although AI and data science teams have always used external models, components, packages, toolkits, and libraries, AI engineering has quickly emerged as the dominant modality for enterprise AI development and deployment today. </p><p>This is true for both major enterprises and the vendors that serve them. For the latter, many of the vendor-provided AI products discussed above are ultimately software wrappers around advanced foundation models developed by AI labs. For the former, many of their internal AI use cases and AI systems leverage those same models, through services enabling foundation model consumption and use via APIs. <br><br>This challenges traditional AI governance frameworks and regulations, many of which were developed primarily during the traditional machine learning era. For example, the AI engineering modality disrupts the binary and outdated distinction between internal AI development of AI systems and procurement and use of externally provided AI solutions. Today, AI development is hybrid, as internal engineering teams build with external models. AI engineering also challenges the notion of AI systems designed and intended for a specific use case (or set of use cases), given the advanced, general-purpose capabilities of these frontier models. <br><br>Given that enterprises cannot rely solely on mainstream AI governance frameworks, standards, and regulations to surface and mitigate the myriad risks that building with foundation models entails, AI governance leaders need to do the heavy lifting themselves. Although there exists a broad spectrum of approaches and techniques for AI engineering&#8212;including prompt engineering, context management, retrieval augmented generation (RAG), and model fine-tuning&#8212;there are some shared risks and challenges that apply across the board.<br><br>Although this is not an exhaustive list, here are five of the most notable AI engineering challenges enterprises are currently grappling with:</p><ul><li><p><strong>EU AI Act obligations for general-purpose AI (GPAI) model providers</strong>: it is important for enterprises to verify that the GPAI model providers they work with are complying with their applicable obligations under the AI Act and adhering to the GPAI Code of Practice (if they are a signatory). The most important aspect of this is obtaining (and adhering to) the technical documentation (e.g., instructions for use, usage policy, training data summary etc.) provided by the GPAI model provider, prior to building an AI system which integrates that GPAI model. Furthermore, enterprises must also track scenarios where they are using extremely large amounts of compute for GPAI model modification (i.e., fine-tuning), as this can trigger GPAI model provider status if certain thresholds are breached. See this <a href="/__u/oliverpatel.substack.com/p/downstream-modification-deployment">previous newsletter article</a> for a deep dive on the topic.</p></li><li><p><strong>Jurisdictional access restrictions</strong>: there are various jurisdictions that restrict access to, and use of, certain types of AI models and services. This includes use case type restrictions that apply in specific scenarios, as well as broad restrictions that always apply. For example, <a href="/__u/oliverpatel.substack.com/p/ai-governance-in-china">China&#8217;s Generative AI Services law</a> restricts the types of AI models that can be integrated into &#8220;public-facing&#8221; AI applications, in order to prevent unauthorised information from being shared to the public. Also, various sanctions and export control regimes, such as the EU&#8217;s sanctions against Russia, restrict which AI models, services, and technologies can be provided or made available from one jurisdiction to another. </p></li></ul><ul><li><p><strong>Fragmentation of vendor terms and acceptable use policies: </strong>enterprises typically pay for access to various foundation model platforms, to enable on-demand consumption and use of a buffet of pre-trained foundation models. A key challenge is that different AI model providers have different terms of service and acceptable use policies, at both the platform level and the model level. For example, the overarching terms of service governing an organisation&#8217;s use of foundation model platforms provided by organisations like Google, Microsoft, and IBM will always differ, perhaps in important ways. And specific model providers, which enable access to their models for consumption via these platforms, have differing acceptable use policies and &#8220;pass through&#8221; terms that apply to the use of their foundation models. This becomes extremely complex to keep track of, especially for the average engineering team that simply wants to get on with their job. </p></li><li><p><strong>Black box opacity: </strong>it is widely accepted that explainability is difficult to achieve in the context of generative AI, in part due to the complexity and vastness of model architectures and the difficulties even the technical experts who developed those models have in understanding, interpreting, and explaining their outputs. This problem is amplified when using pre-trained, proprietary generative AI models, as you usually do not have access to the model weights and most likely have limited information about its training data sources. Therefore, it is virtually impossible to operationalise explainability in a meaningful way, which is a legal requirement or ethical imperative in certain scenarios.</p></li><li><p><strong>Compliance and reputational contagion: </strong>there is intense media and political scrutiny on every move made by the major AI companies. The more your organisation builds products and applications with the models they provide, the more exposed you may be in case something dramatic goes wrong. The reputational risks of working with certain vendors, as well as their AI and data compliance posture, are key considerations when selecting which foundation models to use.</p></li></ul><p><strong>Practical solutions</strong><br><br>It is difficult to outline comprehensive solutions to these novel challenges without proposing a full enterprise AI governance framework, which is clearly beyond the scope of this article. However, that is what you can expect from my <a href="https://aigovernancebook.com/">forthcoming book</a>.<br><br>However, what can be said is that the common thread across these challenges is dependency and complexity. The imperative for AI governance leaders is to:</p><ul><li><p>manage the dependency proactively rather than reactively; and</p></li><li><p>simplify the complexity of this domain into practical and actionable guidance for the wider organisation. </p></li></ul><p>Foundation model providers&#8212;like AI vendors providing domain-specific AI products and services&#8212;require continuous and dynamic oversight and monitoring, as opposed to one-time procurement due diligence and contracts that are left to gather dust. A key part of this is maintaining centralised visibility regarding which models are approved and available for use, which jurisdictions these models can be used in, what the applicable terms of use are, which use cases and AI systems use which foundation models, and how much compute these engineering teams are using. Doing this requires modern tooling, such as an enterprise AI catalogue, which is linked to dynamic AI governance assessment and monitoring processes, as well as role-based training for AI engineering and data science teams, so that they are aware of their responsibilities.<br><br>Finally, do not rely solely on vendor assurances about compliance, safety, or performance. Independently test and evaluate foundation model performance for your specific use cases and with your data, as this matters much more than external benchmarks. And implement and document compensating controls if inherent limitations like explainability cannot be overcome. <br><br>Good luck! </p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[How could the EU AI Act change?]]></title><description><![CDATA[Explaining the Commission's proposed amendments | #33]]></description><link>https://oliverpatel.substack.com/p/how-could-the-eu-ai-act-change</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/how-could-the-eu-ai-act-change</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Mon, 24 Nov 2025 11:32:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Lc4W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Lc4W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Lc4W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5342887,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/179800916?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Lc4W!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa86752c3-3adb-4d0a-9023-cc5744e59336_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em><strong>Enterprise AI Governance</strong></em>.<br><br><em>On Wednesday 19 November 2025, the European Commission unveiled its Digital Omnibus Package, proposing targeted yet impactful amendments to the EU AI Act. This article distils what could change, why it matters for enterprise AI governance practitioners, and what to watch as trilogue negotiations begin.<br><br></em>If you value my work and want to learn more about the EU AI Act and AI governance implementation, sign up to secure a 25% discount for my forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026).</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure a 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure a 25% discount</span></a></p><h4><strong><br>What are the most important proposed EU AI Act changes?</strong></h4><div><hr></div><p>On Wednesday 19 November 2025, the European Commission (henceforth the Commission) announced proposed changes to the AI Act. These changes are presented as &#8220;innovation-friendly AI rules&#8221; that will &#8220;reduce compliance costs for businesses&#8221;. It did so by publishing a proposal for a new regulation. The purpose of this proposed regulation is to &#8220;simplify&#8221; the AI Act with targeted yet meaningful amendments. <br><br>This is part of the Commission&#8217;s broader &#8220;Digital Package&#8221;, which is a major programme of work aiming to &#8220;simplify EU digital rules and boost innovation&#8221;. The Digital Package&#8212;which encompasses the &#8220;Digital Omnibus Regulation&#8221;&#8212;includes proposals to amend flagship digital laws like the AI Act, the GDPR, the ePrivacy Directive, the Data Act, and the NIS 2 Directive. Specifically, the Commission simultaneously published proposals for two regulations (so it&#8217;s not really an &#8220;omnibus&#8221; anymore):</p><ul><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-ai-regulation-proposal">Proposal for Regulation on simplification of AI rules</a> (which covers the AI Act amendments); and</p></li><li><p><a href="https://digital-strategy.ec.europa.eu/en/library/digital-omnibus-regulation-proposal">Proposal for Regulation on simplification of the digital legislation</a> (which covers the amendments to the other EU digital laws mentioned above).</p></li></ul><p>This article explains and analyses the six most important AI Act amendments that enterprise AI governance professionals need to understand. These are:</p><ol><li><p><strong>Timeline changes for high-risk AI system compliance.</strong></p></li><li><p><strong>Timeline changes for transparency-requiring AI system compliance.</strong></p></li><li><p><strong>Limiting registration in the public EU database for high-risk AI systems.</strong></p></li><li><p><strong>Softening of the AI literacy obligation.</strong></p></li><li><p><strong>Expanding the scope of the European AI Office&#8217;s regulatory powers.</strong></p></li><li><p><strong>Proportionality for small mid-cap (SMC) enterprises.</strong></p></li></ol><p>For each of these six proposed amendments, I explain what is in the law today, what changes are being proposed, and what the impact of these changes would be.<br><br>Earlier this week, I published an <strong><a href="/__u/oliverpatel.substack.com/p/whats-next-for-eu-ai-act-simplification">article on Enterprise AI Governance</a></strong> that explains how we got to this point and why the EU is now doing this. It provides a detailed account of the background context to AI Act simplification, highlighting how the &#8216;Draghi report&#8217;&#8212;which argued that digital regulatory burdens are impeding European growth and competitiveness&#8212;has influenced the Commission&#8217;s proposals. <br><br>It also outlines three important caveats on the EU&#8217;s legislative process that are worth repeating:</p><ul><li><p>This merely represents the proposal of one EU institution (the Commission). Such amendments of EU law require formal approval from both the European Parliament and the EU member states via the Council of the EU (the Council).</p></li><li><p>Therefore, this proposal will now be followed by lengthy and potentially fraught trilogue negotiations between the Commission, European Parliament, and Council.</p></li><li><p>Finally, it is impossible to predict what the final legislative text will consist of, how long the negotiation and approval process will take, and whether approval to amend the AI Act will ultimately be agreed on and enacted. </p></li></ul><p><strong>Scope of this article: </strong><em>this is not an exhaustive analysis of the entire AI Act simplification proposal and it does not cover every proposed amendment in the Commission&#8217;s 65-page document. Rather, it focuses on the six proposed changes that would be most consequential (if passed) for enterprises implementing AI governance. Also, it intentionally does not cover the proposed changes to the GDPR, nor the AI Act amendments that are directly related to the processing of personal data (e.g., use of sensitive personal data for bias mitigation), as this topic will be addressed in a future article on Enterprise AI Governance. </em><strong><br><br>Disclaimer: </strong><em>this article is not intended to be legal advice and must not be relied upon or used in that way. Always consult a qualified legal professional.</em><br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><strong><br>1. Timeline changes for high-risk AI system compliance</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>The key provisions relating to high-risk AI systems apply from 2 August 2026. This means that from 2 August 2026, unless there is a change in the law, providers and deployers must adhere to the obligations and requirements for high-risk AI systems and can be subject to investigations and penalties for non-compliance. However, this applicable date only applies to high-risk AI systems listed in Annex III (e.g., education, employment, administration of justice etc.) that are placed on the market or put into service from 2 August 2026 onwards.</p><p>For such Annex III high-risk AI systems that were placed on the market or put into service before 2 August 2026, providers and deployers are only subject to AI Act obligations and requirements if, from that date onwards, there is a significant change in design or intended purpose of the AI system. Furthermore, for high-risk AI systems that are products, or safety components of products, regulated by specific EU product safety laws listed in Annex I, the applicable date is 2 August 2027. <br><br><strong>What changes are being proposed?<br><br></strong>If you are asked <em>&#8220;when do the compliance obligations for high-risk AI systems apply?&#8221;</em>, your answer now has to be &#8220;it depends&#8221;. </p><p>Given the nature of the proposed amendments, there are various potential scenarios. The Commission is seeking to link the applicability of high-risk AI system provisions with the availability of technical standards and associated support tools. However, if these artefacts are not approved and available within a certain timeframe, there is a backstop date, which represents the latest applicable date. <br><br>Under this proposal there are, broadly speaking, three potential scenarios for when most of the provisions relating to high-risk AI systems may apply (covering high-risk AI system classification, development requirements, and obligations of providers, deployers, and other parties):<br><br><strong>Scenario 1.</strong> If technical standards and associated support tools for high-risk AI system compliance are finalised and approved by the Commission, then the applicable compliance date will be six months after this approval (for high-risk AI systems listed in Annex III) and 12 months after this approval (for high-risk AI systems that are products, or safety components of products, regulated by an EU law listed in Annex I).<br><br><strong>Scenario 2. </strong>However, if technical standards and associated support tools for high-risk AI system compliance are not finalised or approved by the Commission in time (i.e., before the dates below), then the applicable compliance dates will be 2 December 2027 (for high-risk AI systems listed in Annex III) and 2 August 2028 (for high-risk AI systems that are products, or safety components of products, regulated by an EU law listed in Annex I). <br><br><strong>Scenario 3. </strong>Given that the applicable date in law today is 2 August 2026, if these amendments are not approved and enacted before this date, then the provisions relating to high-risk AI systems will, technically speaking, apply from then. This creates timeline pressure to get these changes approved within the next few months.<strong><br><br>What impact would these changes have?</strong><br><br>To clarify, 2 December 2027 and 2 August 2028 are the backstop dates for high-risk AI system compliance. To reinforce this point, the Commission has explained that the grace period will be up to sixteen months (referring to the time between 2 August 2026 and 2 December 2027). This means that if technical standards come too late (i.e., after 2 June 2027, which is six months before 2 December 2027) these backstop dates will apply. <br><br>These amendments shine the spotlight on the ongoing work being led by CEN/CENELEC to agree and publish technical standards. They also highlight the importance that the Commission places on these artefacts to support organisations and facilitate compliance. <br><br>However, even if the applicable date may be delayed&#8212;giving providers and deployers more time to prepare&#8212;this extra time has been achieved at the expense of certainty, with organisations now not knowing what the applicable date will be.</p><h4><br>2. Timeline changes for transparency-requiring AI system compliance </h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Article 50 of the AI Act outlines transparency obligations for providers and deployers of certain AI systems. Article 50 covers obligations relating to disclosure, informing end users about the use of AI, labelling certain deep fake content, and detectability of AI system outputs. Specifically, Article 50(2) stipulates that:<br><br><em> &#8220;providers of AI systems, including general-purpose AI systems, that generate synthetic audio, image, video, or text content shall ensure that the outputs of the AI system are marked in a machine-readable format and detectable as artificially generated or manipulated&#8221;.</em><strong><br><br></strong>Currently, this specific obligation applies from 2 August 2026. This compliance date applies to all AI systems, irrespective of whether they are placed on the market or put into service before or after 2 August 2026.<br><strong><br>What changes are being proposed?</strong></p><p>The Commission proposes to push back the applicable date for this specific transparency obligation to 2 February 2027 for providers of AI systems that have been placed on the market before 2 August 2026. This proposed six month delay to the applicable date only applies to obligation stipulated in Article 50(2) (on AI system output machine readability and detectability) and not the other transparency obligations outlined in Article 50.<br><strong><br>What impact would these changes have?</strong></p><p>This change would give providers of AI systems that have already been placed on the market or put into service, or that will be before 2 August 2026, and that generate synthetic audio, image, video, or text content (i.e., most generative AI systems), an additional six months to ensure that these AI systems are developed in such a way that ensures the outputs they generate are detectable as AI-generated.<br><br>Although this is a relatively short delay, it is nonetheless an acknowledgement by the Commission of the technical and engineering challenges providers face in developing or modifying their AI systems to adhere to this obligation. However, any AI systems placed on the market on or after 2 August 2026 will have to comply with this obligation from their release date. </p><h4><strong><br>3. Limiting registration in the EU public database for high-risk AI systems</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Annex III of the AI Act lists eight categories of high-risk AI system, including law enforcement (#6), education and vocational training (#3), and employment, workers&#8217; management and access to self-employment (#5). However, there are classification rules which mean that just because an AI system is intended for use or used in one of these domains does not necessarily mean it is a high-risk AI system.</p><p>AI systems listed in Annex III are not considered high-risk if it is demonstrated that they do not pose significant risk of harm to health, safety, or fundamental rights. For example, if the AI system does not materially influence decisions or is only used for a narrow procedural task, the provider is entitled to demonstrate, based on a documented assessment, that it is not a high-risk AI system. This derogation, including the conditions to fulfil it, is outlined in Article 6(3) and only applies to AI systems listed in Annex III.<br><br>Providers must register high-risk AI systems listed in Annex III in the EU public database for high-risk AI systems, before those AI systems are placed on the market or put into service. Interestingly, this registration obligation also includes AI systems that the provider has concluded are not high-risk via the derogation procedure outlined in Article 6(3).</p><p><strong>What changes are being proposed?<br><br></strong>The Commission proposes to limit the scope of this registration obligation so that it no longer applies to AI systems that providers have concluded are not high-risk via the Article 6(3) derogation procedure. Simply put, where a provider has assessed and documented that an AI system used in an Annex III domain is not high-risk, the provider will not have to register that AI system in the EU public database for high-risk AI systems.</p><p>However, although providers can make this assessment independently and do not require any external approval (e.g., from the AI Office or market surveillance authority), providers will still be obliged to share the documentation of the assessment, containing the justification and supporting evidence, upon request from a regulator. </p><p><strong>What impact would this have?<br><br></strong>This may seem like a subtle change at first glance, but it would be consequential for organisations using AI at scale. </p><p>Most enterprise AI governance practitioners likely raised their eyebrows when they realised that every AI system used in a high-risk domain, including AI systems that are not high-risk due to their use for mere assistive, procedural, or preparatory tasks, would have to be registered. This will be difficult (or perhaps near impossible) to keep track of and implement, due to the increasingly ubiquitous use of AI to support and augment workflows across virtually all domains of enterprise activity. Indeed, the Commission describes this current registration obligation as a &#8220;disproportionate compliance burden&#8221;. <br><br>Therefore, the most obvious impacts of this change would likely be far fewer AI systems registered in the EU public database for high-risk AI systems and reduced administrative overheads for organisations developing and deploying AI systems. </p><p>However, it would also reduce public transparency regarding which AI systems providers deem not to be high-risk and how they have made such determinations. This could incentivise some providers to take a more expansive approach to interpreting Article 6(3) and determining what is not a high-risk AI system, as they may reasonably judge that the risk of doing so (and being penalised for getting it wrong) is lower with significantly less public scrutiny. </p><h4><strong><br>4. Softening of the AI literacy obligation</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Under Article 4 of the AI Act providers and deployers of AI systems are obliged to implement &#8220;AI literacy&#8221;. This is one of the most important aspects of the law, because it has contributed to many organisations in the EU and further afield rolling out AI training and upskilling initiatives for their workforce. Specifically, Article 4 requires organisations to ensure that &#8220;staff and other persons dealing with the operation and use of AI systems&#8221; have a &#8220;sufficient level of AI literacy&#8221;. <br><br>In practice, given that all staff in modern organisations can use AI systems (e.g., ChatGPT or Gemini), a reasonable interpretation of Article 4 is that all of these staff should receive some form of AI-focused training. The AI literacy obligation has been applicable since February 2025. However, there are no enforcement penalties for non-compliance with it. Although non-compliance could be taken into account during enforcement investigations or proceedings relating to other aspects of non-compliance.<br><br><strong>What changes are being proposed?<br><br></strong>The Commission proposes to remove the obligation for providers and deployers to implement AI literacy. Rather than providers and deployers being legally required to ensure their staff operating and using AI systems have sufficient levels of AI literacy, the Commission and Member States will be required to foster AI literacy and <em>&#8220;encourage providers and deployers of AI systems to take measures to ensure a sufficient level of AI literacy&#8221;</em>. The Commission has alluded to the fact that the ambiguity of the current &#8220;unspecified obligation&#8221; has caused issues for businesses&#8212;especially smaller firms. <br><br><strong>What impact would this have?<br><br></strong>This change would be significant because it would remove the broad and expansive legal obligation for companies to implement AI literacy. However, human oversight of high-risk AI systems must still be assigned to staff with sufficient training and competence. Therefore, ensuring AI literacy is still required in that context. <br><br>Moreover, it will be practically impossible for any organisation to comply with the AI Act&#8212;or to manage AI risks, implement AI at scale, and maximise the value of AI&#8212;without educational and training initiatives focused on AI. Therefore, forward-thinking enterprises are unlikely to abandon their AI literacy programmes because it is no longer a legal requirement. However, certain initiatives may be scaled back, deprioritised, or change in focus or scope. </p><h4><strong><br><br>5. Expanding the scope of the European AI Office&#8217;s regulatory powers</strong></h4><div><hr></div><p><strong>What is in law today?<br><br></strong>Here is a simplified summary of the (rather complex) AI Act governance regime:</p><ul><li><p>There are governance and regulatory bodies at both the EU and member state level.</p></li><li><p>At the EU level, the most important bodies are the European AI Office (which is part of the Commission) and the European AI Board.</p></li><li><p>At the member state level, the most important bodies are the market surveillance authorities. They are responsible for monitoring, investigations, and enforcement of the AI Act. There will potentially be several in each EU member state. </p></li><li><p>The AI Office is responsible for overseeing and enforcing the provisions on general-purpose AI models, whereas the market surveillance authorities are responsible for overseeing and enforcing the provisions on AI systems (e.g., high-risk and transparency-requiring AI systems), as well as most other AI Act provisions.</p></li></ul><p><br><strong>What changes are being proposed?<br><br></strong>The Commission proposes to &#8220;centralise oversight over a large number of AI systems built on general-purpose AI models&#8221; when the same provider develops both the general-purpose AI model and the AI system.</p><p>The proposed amendments to Article 75 would render the AI Office as the body responsible for monitoring and supervising compliance of AI systems that leverage general-purpose AI models. However, this would only apply when the general-purpose AI model and the AI system are developed and placed on the market or put into service by the same provider. In such scenarios, the AI Office would be &#8220;exclusively competent&#8221;, which means that the market surveillance authorities in the respective EU member states would no longer have a supervisory role. The AI Office would also have &#8220;all the powers of a market surveillance authority&#8221;.</p><p>This expansion in scope of the AI Office&#8217;s responsibilities does not apply to high-risk AI systems covered by an Annex I EU product safety law. Therefore, this change primarily impacts high-risk AI systems listed in Annex III and transparency-requiring AI systems regulated by Article 50 (where such AI systems leverage general-purpose AI models).</p><p>Finally, under this proposal, the AI Office would also have exclusive competence as the regulator of &#8220;AI systems that constitute or that are integrated into a designated very large online platform or very large online search engine&#8221; (as defined and regulated by the Digital Services Act).<strong><br><br>What impact would this have?<br><br></strong>The implied rationale behind this change is that the Commission does not think it makes sense for the AI Office to be responsible for overseeing providers of general-purpose AI models but not the AI systems developed, made available, and put into service by those same providers. <br><strong><br></strong>These changes would make the AI Office the supervisory authority for many of the most widely used AI systems worldwide. This is because most mainstream generative AI platforms, such as ChatGPT, Gemini, Claude, Grok, and Microsoft Copilot, are AI systems built on general-purpose AI models, with the same organisation being the provider of both the AI model and the AI system. Therefore, this would represent a meaningful increase in the relevance and prominence of the AI Office for AI Act oversight and enforcement, and it would also enable the AI Office to pursue investigations and enforcement action relevant for both general-purpose AI model and AI system compliance in a coordinated manner. <br><br>This would also mean that certain AI system providers would not be subject to regulatory investigations and enforcement action across multiple EU member states, which is possible if the law isn&#8217;t amended.</p><h4><strong><br><br>6. Proportionality for small mid-cap (SMC) enterprises</strong></h4><div><hr></div><p>The AI Act provides an element of flexibility and proportionality for micro, small, and medium-size enterprises (SMEs), including start-ups. For example, the compliance penalties which SMEs can face are capped in the following way:</p><ul><li><p>35 million EUR or 7% of total worldwide annual turnover (whichever is lower).</p></li><li><p>15 million EUR or 3% of total worldwide annual turnover (whichever is lower).</p></li><li><p>7.5 million EUR or 1% of total worldwide annual turnover (whichever is lower).</p></li></ul><p>This contrasts with the &#8220;whichever is higher&#8221; penalty logic that applies for all other businesses (i.e., those which are not SMEs). In practice, this means that many non-SME businesses could face potential penalties into the billions of euros, whereas penalties for SMEs will always be capped as per the above. <br><br>Other ways in which the AI Act seeks to ease compliance burdens for SMEs include allowing SME providers of high-risk AI systems to provide the required technical documentation in a simplified way and providing SMEs with free access to AI regulatory sandboxes.<br><br><strong>What changes are being proposed?<br><br></strong>The first proposed change is to add legal definitions of SME and small mid-cap enterprise (SMC) to the AI Act. These are:</p><ul><li><p>SME: an enterprise which employs fewer than 250 people and which has an annual turnover not exceeding 50 million EUR, and/or an annual balance sheet total not exceeding 43 million EUR.</p></li><li><p>SMC: an enterprise which employs fewer than 750 people and which has an annual turnover not exceeding 150m EUR or an annual balance sheet total not exceeding 129m EUR.</p></li></ul><p>The second and more significant proposed change is to extend the flexibility and proportionality penalties afforded to SMEs to SMCs also. This means that SMCs would benefit from the same capped enforcement penalty regime as SMEs, significantly reducing their total potential penalty exposure in certain circumstances. SMCs that are providers of high-risk AI systems would also be able to provide the required technical documentation in a simplified manner.<br><br><strong>What impact would this have?</strong></p><p>Core threads from the Draghi report are woven throughout this proposal. The Commission will be hoping that easing regulatory compliance burdens and softening the enforcement environment for a larger pool of companies will make it easier for EU digital start-ups and scale-ups to grow, innovate, and compete internationally. Indeed, the Draghi report argued that &#8220;regulatory burdens&#8221; are particularly damaging for digital sector SMEs trying to rapidly scale up.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[What's next for EU AI Act “simplification"?]]></title><description><![CDATA[Previewing the EU's Digital Omnibus announcemnt | #32]]></description><link>https://oliverpatel.substack.com/p/whats-next-for-eu-ai-act-simplification</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/whats-next-for-eu-ai-act-simplification</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Mon, 17 Nov 2025 10:53:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Qpzx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!Qpzx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!Qpzx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5332787,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/179118514?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!Qpzx!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc34ab8db-55e3-4510-a1eb-c5ffc04d63e4_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><br>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance</em> and author of the forthcoming book, <em><strong><a href="https://aigovernancebook.com/">Fundamentals of AI Governance</a></strong></em> (2026).<br><br><em>On Wednesday 19 November 2025, the European Commission will publish its Digital Omnibus Package&#8212;a sweeping proposal to reform the EU&#8217;s digital legislative framework. The EU AI Act is in sharp focus, alongside the GDPR and a host of other flagship EU laws. This article explains how we got here, what&#8217;s at stake, and the potential changes being discussed in Brussels. It will be followed by in-depth analysis of the proposed changes, once they are published.</em></p><h4><strong><br>How did we get here?</strong></h4><div><hr></div><p>The EU has consistently sought to shape global regulatory standards on digital technology, data, and AI. The EU has been open about its policy objectives of protecting citizens and promoting global regulatory convergence towards its high standards, in domains like data protection and privacy. And in some ways, it has succeeded. <br><br>With GDPR, for example, there has been a demonstrable &#8220;Brussels effect&#8221;. Many countries worldwide have enacted data protection laws of a similar flavour and corporations have prioritised aligning their internal frameworks accordingly. Despite the lack of U.S. federal privacy law (which renders the U.S. a global outlier), almost all major American enterprises are significantly impacted by the GDPR and have implemented dedicated privacy compliance programmes.<br><br>However, as EU laws covering digital governance have proliferated, the picture has become increasingly complex and convoluted. Keeping track of the EU&#8217;s regulations and directives covering the digital sphere is no mean feat. </p><p>CEPS and Kai Zenner&#8217;s  <a href="https://cdn.ceps.eu/wp-content/uploads/2025/07/CEPS-Zenner-Dataset-July-2025-1.pdf">dataset of EU digital sector legislation</a>, updated in July 2025, lists <strong>101 different laws</strong>, including the EU AI Act and the GDPR. The authors remark that there has been an &#8220;<em>absolute explosion</em>&#8221; of EU digital laws and that &#8220;even the best experts struggle to keep up with this torrent of legal and policy instruments&#8221;. To complement the 101 laws, there exists a far greater number of regulatory bodies covering digital issues.<br><br>Enterprises require large teams of people to make sense of these developments and determine how to be compliant, not least because obtaining deep expertise in just one legislative area takes years. In response, enterprises have also established a range of somewhat separate yet overlapping digital governance capabilities to address key legal obligations and requirements. This includes implementing enterprise AI governance, which has become a core priority in recent years due to both the EU AI Act and the surge in AI adoption. But you didn&#8217;t need me to tell you that&#8230;<br><br>For AI governance professionals, this regulatory complexity is especially acute, as AI systems frequently trigger multiple regulatory requirements simultaneously&#8212;from GDPR&#8217;s rules on automated decision-making and use of sensitive personal data, to the AI Act&#8217;s requirements for high-risk and transparency-requiring AI systems, cybersecurity mandates, copyright and intellectual property, and existing sectoral laws. <br><br>In recent months, discussion regarding simplification of the EU&#8217;s digital rulebook has intensified&#8212;both within the EU and externally. It is widely reported that EU officials and member states have faced sustained lobbying from U.S. industry and the Trump administration. There are <a href="https://www.techpolicy.press/trump-squares-off-with-brussels-over-its-digital-rulebook/">even reports of President Trump</a> considering imposing tariffs and sanctions on the EU and its officials, due to the perceived impact of EU digital laws on U.S. companies and citizens.<br><br>This pressure has been accompanied by increasingly vocal calls from segments of European industry that EU digital regulations need to be reformed, streamlined, simplified, to reduce compliance burdens. For example, in July 2025, dozens of companies&#8212;including industry heavyweights like Mercedes Benz, Deutsche Bank, and L&#8217;Oreal&#8212;<a href="https://aichampions.eu/#stoptheclock">signed an open letter</a> to the EU urging for a two-year delay to the EU AI Act&#8217;s key provisions on general-purpose AI (GPAI) models and high-risk AI systems.<br><br>This is coming to a head on Wednesday 19 November, as the European Commission is set to publish its &#8220;Digital Omnibus Package&#8221; proposal. This will outline, for the first time, the comprehensive set of legislative amendments the Commission proposes, to simplify the EU&#8217;s digital rulebook.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><strong><br>What was the Draghi report?</strong></h4><div><hr></div><p>Although this situation has evolved over several years, the September 2024 publication of the <a href="https://commission.europa.eu/document/download/97e481fd-2dc3-412d-be4c-f152a8232961_en?filename=The%20future%20of%20European%20competitiveness%20_%20A%20competitiveness%20strategy%20for%20Europe.pdf">&#8220;Draghi report&#8221; on The Future of European Competitiveness</a> was an important milestone in this story. Mario Draghi is the former president of the European Central Bank and former prime minister of Italy. This independent report, commissioned by the EU, is shaping aspects of the European Commission&#8217;s policy agenda.<br><br>The report presents the EU&#8217;s economic challenges, focusing on diminished competitiveness, weakening productivity, and slowing growth. Draghi frames the economic outlook as an &#8220;existential challenge&#8221; for the EU, arguing that it will be unable to finance its social model, achieve its environmental ambitions, and deliver the prosperous and fair society that represents its raison d&#8217;&#234;tre if it fails to make radical changes.  <br><br>The Draghi report outlines three action areas to &#8220;reignite growth&#8221;. These are:</p><ol><li><p>Closing the innovation gap with the U.S. and China, especially in advanced technologies. </p></li><li><p>Forging a joint plan for decarbonisation and competitiveness. </p></li><li><p>Increasing security and reducing dependencies.</p></li></ol><p>It is the first action area which is most relevant for our focus&#8212;EU AI Act simplification. The Draghi report argues that the EU&#8217;s complex digital regulatory environment impedes innovation and growth. It elevates &#8220;reducing the regulatory burden&#8221; as a core priority for transforming the EU&#8217;s economic prospects. <br><br>Examining the &#8220;innovation gap&#8221; between the U.S. and China on the one hand and the EU on the other, the report claims that innovative European companies attempting to scale up are &#8220;hindered at every stage by inconsistent and restrictive regulations&#8221;. This is why, the report argues, European tech entrepreneurs routinely seek to grow their businesses in the U.S. The report also cites that 55% of SMEs flag &#8220;regulatory obstacles and administrative burden&#8221; as their greatest challenge, arguing that these &#8220;regulatory burdens&#8221; are particularly damaging for digital sector SMEs.<br><br>The report criticises the &#8220;precautionary approach&#8221; taken by EU digital laws, including the EU AI Act. It specifically calls out the compute threshold for determining whether a general-purpose AI (GPAI) model poses &#8220;systemic risk&#8221;, noting that various frontier AI models already exceed the threshold, despite the EU AI Act&#8217;s nascency. It also highlights the increasing difficulty that companies face in navigating the various overlapping laws relevant for AI and the hundreds of regulatory bodies across the EU responsible for digital governance. <br><br>It is important to note that a vast array of other impediments and challenges are highlighted&#8212;from inadequate research talent pipelines to low investment in innovation commercialisation&#8212;as contributing factors to the EU&#8217;s competitiveness challenge. Therefore, my intention is not to claim that the Draghi report is all about digital &#8220;regulatory burdens&#8221;, as that would be misleading. It would be equally misleading to claim the Digital Omnibus Package results solely from the Draghi report. However, the complexity of the EU&#8217;s digital legislative framework has undeniably become a totemic issue, which the Draghi report shone a very bright light on. <br><br>Next, we turn our attention to the European Commission&#8217;s Digital Omnibus Package. Will it deliver the changes that Draghi seeks? And what could this mean for the EU AI Act?</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><br>What is the EU&#8217;s Digital Omnibus Package?</h4><div><hr></div><p>The Digital Omnibus Package is the European Commission&#8217;s much anticipated proposal to reform the EU&#8217;s digital legislative framework. It is due to be announced and published on Wednesday 19 November. This follows public consultations earlier in the year.<br><br>The proposal will feature meaningful amendments to some of the EU&#8217;s flagship laws and perhaps even the repeal of specific instruments. The Digital Omnibus Package is expected to focus on the EU AI Act, the GDPR, the ePrivacy Directive, the Data Act, and the NIS2 Directive&#8212;horizontally cutting across the core digital governance domains of AI, data protection and privacy, and cyber security.<br><br>The purpose of the Digital Omnibus Package is to simplify and streamline the EU&#8217;s digital legislative framework, to ease compliance burdens and cut costs for organisations (particularly startups and SMEs), promote the growth and competitiveness of European companies, and boost innovation. It is inevitable that the core threads from the Draghi report will be woven into the European Commission&#8217;s proposal.<br><br>Before engaging in any further analysis of the imminent proposal, several caveats are required. <br><br>First, the current discussion, including this article, is based on leaked documents, media reporting, speculation, and rumours. Brussels is a famously leaky city, so this is nothing new. However, until the European Commission officially publishes its proposal, we do not know exactly what the proposal consists of. At the time of writing, nothing official has been published. <br><br>Second, the Digital Omnibus Package that will be published later this week merely represents the European Commission&#8217;s initial proposal on this controversial set of issues. Therefore, even when we have the proposal, all we will have is the official starting position of one of the EU&#8217;s institutions. To amend EU laws in this way will require extensive trilogue negotiations and approval from the European Parliament and EU member states via the Council of the EU (the Council).<br><br>Third, the aforementioned trilogue negotiations&#8212;and the process of amending and repealing a suite of EU laws in this way&#8212;are bound to be lengthy, complex, and fraught with drama. Although the precise legislative instrument to operationalise the Digital Omnibus Package is yet to be confirmed, it is most likely to be an EU regulation (which is the same legal instrument as laws like the GDPR and the EU AI Act). <br><br>To amend existing EU laws via a new regulation, the EU&#8217;s &#8220;<a href="https://www.europarl.europa.eu/olp/en/ordinary-legislative-procedure/overview">ordinary legislative procedure&#8221;</a> must be followed. This necessitates dual approval from both the European Parliament and the Council, following trilogue negotiations where both institutions have several opportunities to amend and update the legislative proposal. On average, it takes the EU 19 months to agree new laws, from the initial Commission proposal to formal adoption. <br><br>Plainly speaking, what all this means is that: </p><ul><li><p>We don&#8217;t yet have an official proposal from the European Commission, merely leaks and media speculation.</p></li><li><p>When we do, it will be subject to lengthy and fraught trilogue negotiations, the outcome of which is impossible to predict.</p><ul><li><p>However, what <em>can</em> be predicted with a degree of certainty is that there will be a substantial difference between the European Commission&#8217;s initial legislative proposal and the final text that is voted on. </p></li></ul></li><li><p>Following this, formal approval will be required from both the European Parliament and the Council to pass any regulation that meaningfully amends existing EU laws.</p></li><li><p>It is impossible to predict what the final legislative text will consist of and how long the negotiation and approval process will take. </p></li><li><p>Finally, there is no guarantee that any legislative changes will be approved&#8212;although this does seem unlikely given the various points made above.</p></li></ul><h4><strong><br>How could the EU AI Act change?</strong></h4><div><hr></div><p>Caveats aside, the final part of this article will highlight some of the potential changes that are reported to be on the cards for the EU AI Act. </p><p>Although based primarily on leaks and tip-offs, recent media reporting nonetheless shines a light on what is being discussed in the EU&#8217;s corridors of power. Below is a list of the various potential EU AI Act changes that have been reported. A special shout out for <a href="https://www.mlex.com/mlex/articles/2408203/planned-eu-ai-act-changes-to-include-centralized-enforcement-regulatory-tweaks">the reporting from MLex&#8217;s Luca Bertuzzi</a> (who is a must follow for AI governance practitioners), which this list is largely based on:</p><ul><li><p>Delaying the applicable date for the obligations for providers and deployers of transparency-requiring AI systems.</p></li><li><p>Delaying the applicable date for the obligations for providers and deployers of high-risk AI systems.</p><ul><li><p>These obligations apply from 2 August 2026, but this enforcement could reportedly be delayed for one year. This is partly due to delays in finalising technical standards that organisations can use to comply with these provisions.</p></li></ul></li><li><p>Scrapping the AI literacy obligation for organisations and shifting it to governments, regulators, and EU institutions.</p></li><li><p>Centralising enforcement powers with the European Commission&#8217;s AI Office.</p><ul><li><p>This could be done by designating the AI Office as the regulatory authority responsible for supervising AI systems based on GPAI models. This is partly driven by concerns regarding readiness and capacity of EU member state regulators (some of which have not yet been designated), as well as the complexity firms could face in engaging with many different regulatory bodies.</p></li></ul></li><li><p>Introducing smaller and more proportionate compliance penalties for &#8216;small mid-caps&#8217; (defined as companies that employ up to 750 people and have an annual turnover of under &#8364;150 million). </p><ul><li><p>This would complement and expand the scope of the existing proportionality for compliance penalties for SMEs.</p></li></ul></li><li><p>Removing the obligation for providers to register, in the EU&#8217;s public database, AI systems that are used in a high-risk domain which they have deemed and demonstrated are not high-risk due to the nature of the use.</p></li></ul><p>It will be interesting to see which (if any) of these potential changes survive in the Digital Omnibus Package that the European Commission publishes on Wednesday. Given the speculative nature of this, I will not provide any further analysis on these potential changes in this article.</p><p>One final point to note is that the European Commission does have powers to amend or change aspects of the EU AI Act, via instruments called delegated acts and implementing acts. For example, the European Commission can modify the compute threshold for GPAI models with systemic risk via a delegated act.<br><br>Where these powers exist, the European Commission is able to drive changes without the need for the ordinary legislative procedure and formal approval from the European Parliament and Council. Although, there is always a degree of oversight from these institutions, who retain veto powers. However, the EU AI Act &#8220;simplification&#8221; changes discussed above extend far beyond the scope of the Commission&#8217;s powers to drive changes via delegated and implementing acts.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[The PROTECT Framework: Managing Data Risks in the AI Era ]]></title><description><![CDATA[Protect your confidential business data | #31]]></description><link>https://oliverpatel.substack.com/p/the-protect-framework-managing-data</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/the-protect-framework-managing-data</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Sun, 02 Nov 2025 15:38:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!J1U4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!J1U4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!J1U4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:5061096,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/177800139?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!J1U4!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F689b98d3-61a6-4da4-abeb-9d0b472a66a2_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance</em>.<br><br>This week&#8217;s newsletter presents, for the first time, my <strong>PROTECT Framework for Managing Data Risks in the AI Era</strong> &#169; 2025.<br><br>Last week I <a href="/__u/oliverpatel.substack.com/p/top-10-challenges-for-ai-governance">published Part 1</a> of my 2-part series on the Top 10 Challenges for AI Governance Leaders in 2025. It focused on how the democratisation of AI, coupled with the sheer volume and rapid velocity of AI initiatives, is putting serious strain on the enterprise AI governance function. It outlined how, in response to these challenges, AI governance leaders must refine and update their risk-based approach and narrow the focus of their teams&#8217; work, to avoid being overwhelmed, distracted, or neglecting the most serious risks. <br><br>Although I promised Part 2 this week, I ended up writing a full article on the fourth challenge: <strong>protecting confidential business data.</strong> This is a hugely important topic and there was simply too much to say. The beauty of having your own Substack is that you can follow whichever creative or intellectual direction most appeals to you, rather than rigidly sticking to prior plans. I hope that you will indulge my partial detour and that you find value in this article for your work. The &#8220;real&#8221; Part 2, covering challenges 5-10, will have to wait another week.<br><br><strong>Challenge 4. Protecting Confidential Business Data </strong><br><em><br>How can enterprises protect confidential business data when there is immense hunger to experiment with and use the latest AI applications that are released on the market? <br></em><br>The generative AI boom has amplified and exacerbated a plethora of data risks that all enterprises are exposed to. It has never been more important to ensure that your AI governance, cybersecurity, and information security frameworks are designed to, and capable of, mitigating these risks.<br><br>However, designing, implementing, and scaling robust controls that actually protect your organisation&#8217;s data and intellectual property requires precise understanding of what these risks are and how they are impacted by AI. That&#8217;s where my PROTECT Framework comes in. <br><br>The PROTECT Framework empowers you to understand, map, and mitigate the most pertinent data risks that are fuelled by widespread adoption of generative AI. Below is a high-level summary of the framework, followed by a detailed breakdown of each of the 7 themes.<br><br><strong>PROTECT: Managing Data Risks in the AI Era<br><br></strong>The PROTECT Framework focuses primarily on protecting (<em>no surprises there</em>) confidential business data from exposure, disclosure, and misuse&#8212;as well as associated data privacy and security risks fuelled by AI. It also outlines how organisations can use data in a compliant way, in the context of AI development, deployment, and use. <br><br><strong>P - Public AI Tool Usage </strong></p><p><strong>R - Rogue Internal AI Projects</strong></p><p><strong>O - Opportunistic Vendors </strong></p><p><strong>T - Technical Attacks and Vulnerabilities</strong></p><p><strong>E - Embedded Assistants and Agents</strong></p><p><strong>C - Compliance, Copyright, and Contractual Breaches </strong></p><p><strong>T - Transfer Violations<br><br></strong>The rest of the article breaks down each of the seven themes, highlighting both the core risks that enterprises are exposed to, as well as practical mitigations that can be implemented to manage and control these risks.<br><br>My forthcoming book, <em><a href="https://aigovernancebook.com/">Fundamentals of AI </a></em><a href="https://aigovernancebook.com/">Governance</a>, provides a comprehensive visual overview of the PROTECT Framework, as well as a deep-dive on the Top 10 AI Risks impacting the modern enterprise. To secure a 25% discount during the pre-launch period, sign up at the link below.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure your 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure your 25% discount</span></a></p><h4><strong>P - Public AI Tool Usage</strong></h4><div><hr></div><p><strong>Enterprise risks: </strong>Use of publicly available AI tools is arguably the most severe data risk, because of how easy it is to do and how difficult it is to prevent. Simply put, there are thousands of publicly available AI tools that anyone can access via the internet, most of which are free or cheap. As well as mainstream generative AI chatbots like Claude, Gemini and ChatGPT, there are countless AI tools for creating presentations, managing email inboxes, transcribing meetings, and generating videos. <br><br>No matter how mature your enterprise AI capabilities are&#8212;and even if you are a frontier AI company&#8212; it is not going to be feasible to keep up with the latest and greatest AI tools and AI models that are released on the market each day, whilst also performing robust due diligence on AI vendors. Even with enterprise-grade licenses to mainstream generative AI services, you will not always get immediate access to the latest features included in the consumer version. This fuels immense hunger for employees to experiment with and use the most cutting-edge AI tools, irrespective of whether they are &#8220;internal&#8221; and approved or &#8220;publicly available&#8221; and unapproved.<br><br>This inability to keep pace with the market, coupled with a lack of awareness regarding the risks of using publicly available AI tools and the pressure that employees and teams are under to become &#8220;AI-first&#8221;, exacerbates the risks. Many employees may not understand the difference, from a data risk perspective, between using internal AI tools and public AI tools. But the risk is real. For example, when enterprise data is shared with publicly available AI tools, the organisation no longer has any control over what happens to it. This confidential business data could be used to train the AI models that power publicly available AI tools and in turn be disclosed, via future AI outputs, to competitors or malicious actors. It may even end up on the public internet&#8212;as we saw when various shared AI chat logs were indexed and publicly accessible online&#8212;or be retained indefinitely, as a result of court orders like the one OpenAI faced from the New York Court. Simply put, if you want to be in control of how your data and intellectual property is used, who has access to it, and for how long it is retained, your employees should avoid using publicly available AI tools.</p><p><strong>Practical mitigations:</strong> Although shadow AI use is ubiquitous, there are various controls you can implement to mitigate this risk. My <strong>3 Gs for Governing AI Democratisation</strong> offers a useful starting point:<br><br><strong>Guidance: </strong>educate and train the workforce on the risks of using publicly available AI tools and the importance of protecting confidential business data. <br><br><strong>Greenlight: </strong>provide access to secure, best-in-class AI tools, platforms, and capabilities that are approved for internal use and can process confidential business data. <br><br><strong>Guardrails: </strong>implement guardrails&#8212;including technical and legal mitigations&#8212;to mitigate outstanding data risks that the use of internally approved AI tools entails. This can include scanning and blocking certain types of data from being uploaded as an input or generated as an output. <em><br></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><strong>R - Rogue Internal AI Projects</strong></h4><div><hr></div><p><strong>Enterprise risks: </strong>Bypassing governance, especially when it happens at scale, creates compliance blind spots. Various risks emerge, and are difficult to manage, when teams develop and deploy AI systems, or procure AI solutions from vendors, without adhering to the mandatory AI governance, privacy, and cyber security processes.</p><p>In such scenarios, there is unlikely to have been any legal or compliance review, privacy assessment, or security evaluation. In turn, this means that genuine risks are unlikely to be understood, required documentation and artefacts may not have been produced, and robust mitigations will not be in place to address any important risks.</p><p>This increases organisational technical debt, which can lead to costly and burdensome efforts to retrospectively re-engineer non-compliant AI systems that are already deployed in production. Finally, it increases the likelihood that data is used without authorisation, and in a manner that constitutes a contractual breach or potential compliance violation.<br><br>In most cases, this does not happen because of malicious internal actors or intentional rule-breaking. Rather, it is more likely due to enthusiasm, competitive internal pressures and competing priorities, or a lack of awareness of internal governance processes and how to navigate them.<br><br><strong>Practical mitigations:</strong> To mitigate the risk of rogue internal AI projects bypassing compliance checks, a proportionate degree of oversight must be applied to all AI projects. The level of governance scrutiny and oversight should flex in relation to the type of data being used. The use of sensitive personal data, confidential business data, or copyright protected material should entail more rigorous oversight, both at the project outset and throughout the AI lifecycle. Oversight should also be more rigorous for scenarios that involve sharing data with external vendors and the applications they provide. <br><br>The most important thing you can do is to make your AI and digital governance processes as easy to navigate as possible, by integrating different processes where possible, providing accessible guidance and support, and using automation to streamline processes and improve the user experience.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><br>O - Opportunistic Vendors</h4><div><hr></div><p><strong>Enterprise risks:</strong> Almost all enterprises must work with, and procure from, external organisations to progress with their AI ambitions. In the generative AI era, the trend is from build to buy. Whether it is leveraging pre-trained foundation models and generative AI chatbots, or working with vendors that provide bespoke AI products, exposure to third-party AI risk is unavoidable. In some cases, AI vendors and service providers may seek to use your confidential business data to train, develop, and improve their AI models and services&#8212;potentially without your explicit knowledge or consent.</p><p>The terms of service for many AI platforms and products are ambiguous or difficult to understand, and grant vendors broad rights over customer data. The key risk is whether your organisation&#8217;s data is used to train AI models that other customers can access and use. If so, competitors (or any other organisation) using that same vendor&#8217;s products and services may benefit from insights derived from your data. The risk is lower&#8212;or potentially fully mitigated&#8212;if your data is only used to train AI models and services that only your organisation has access to. This can enable you to benefit from feature improvements and customisation whilst mitigating data exposure and leakage risks. <br><br><strong>Practical mitigations:</strong> Consider contractually prohibiting AI vendors from using your data (e.g., prompt, input, log, and output data), to train AI models and improve services that are accessible to other customers. This requires robust vendor due diligence, and a specific AI governance process pathway for AI procurement. It also requires clear guidance and training on third-party AI risks, acceptable data use terms, as well as template contracts and addendums that can be used across the business. Although the demand for AI vendors (and the products they provide) is high, the presence of opportunistic or shady operators in the market&#8212;and the immense value of the data they can obtain from enterprise customers&#8212;makes rigorous due diligence and contractual safeguards essential.</p><h4><strong><br>T - Technical Attacks and Vulnerabilities</strong></h4><div><hr></div><p><strong>Enterprise risks: </strong>AI systems introduce novel attack vectors that are linked to the distinct vulnerabilities of these systems. In particular, generative AI and agentic AI systems can be compromised and exploited, leading to confidential data&#8212;that was part of the AI model&#8217;s training, input, or output data&#8212;being extracted and stolen. Such data exfiltration is a known and widely documented AI vulnerability and can be caused by various attack methods. Prompt injection attacks, for example, are when an AI model is provided with malicious inputs (during inference) that are designed to manipulate and steer the outputs it generates, by jailbreaking model guardrails.</p><p>Simply put, the goal of prompt injection is to make the AI model do something that it is not supposed to. This includes, but is not limited to, data exfiltration, as well as reconstruction of training data. This risk of prompt injection is amplified with agentic AI, given the ability of AI agents to use tools and execute actions that can have a material impact (rather than &#8220;just&#8221; generate outputs for consumption).<br><strong><br>Practical Mitigations: </strong>Although there are no foolproof mitigations against prompt injection attacks, there are nonetheless important steps you can take. Consider implementing AI system-level security controls and guardrails including input validation, prompt sanitisation, output filtering, and incident monitoring and detection. Also, for high risk applications, conduct red-teaming and adversarial testing. Cybersecurity best practice emphasises the importance of multiple overlapping security layers. However, no technical controls can fully prevent prompt injection or data exfiltration. Therefore, carefully control who has access to sensitive AI systems, what data they can access, and what actions agentic AI can execute.<em><br></em></p><h4><strong><br>E - Embedded Assistants and Agents</strong></h4><div><hr></div><p><strong>Enterprise risks: </strong>The AI assistants and agents that are increasingly embedded in the core workplace software we all use pose novel data risks. In particular, these embedded AI tools can inappropriately disclose and disseminate data to people and groups that were not supposed to have access to it. For example, a personalised AI assistant that summarises your emails and daily tasks can analyse wider organisational data that you have access to, such as document libraries and shared calendars. If that data has not been protected with appropriate file sharing permissions&#8212;and moreover has erroneously been made available to the entire organisation&#8212;then elements of it may be surfaced to you via your handy AI assistant. <br><br>Although the root cause of this is often inappropriate or inadequate file sharing permissions, AI significantly increases the likelihood of such data being shared with the wrong person. It also provides malicious internal actors with a powerful tool for mischief. <br><br>AI meeting assistants and note-taking applications are of particular concern. It is commonplace to join calls with external organisations, only to find that a random AI bot is also on the call, recording and transcribing everything that is said. From an enterprise perspective, this is akin to uploading all of this information into a publicly available AI tool (which poses similar risks to those outlined in &#8216;Public AI Tool Usage &#8217;), unless you have assurances from the external organisation regarding the technology they are using and how it processes your data. Furthermore, be wary of individuals having access to AI meeting recordings and transcripts of parts of the discussion they were not part of.</p><p>Increasingly autonomous agentic AI systems exacerbate these risks. In order to effectively determine the best course of action and use tools to execute tasks, LLM-based AI agents will need to mine, retrieve from, and synthesise myriad enterprise data sources. Establishing appropriate access controls, and maintaining AI agent audit trails, will become increasingly complex yet important.<br><br><strong>Practical mitigations: </strong>Robust data governance and data risk management is critical to ensuring your increasingly autonomous AI tools do not cause havoc. Ensuring appropriate file sharing permissions for sensitive and critical data sources is paramount, given the ways in which AI agents can mine through your document libraries and other repositories, as well as the obvious value this capability provides. Also, when deploying agentic AI, start with lower risk use cases, applications, and data sources. Furthermore, apply the principle of least privilege, to ensure that AI agents only have access to data that is necessary for their tasks. </p><h4><strong><br>C - Compliance, Copyright, and Contractual Breaches</strong></h4><div><hr></div><p><strong>Enterprise risks: </strong>Data science, AI, and business teams are under significant pressure to leverage AI to deliver value for the business. To do so, they require seamless access to vast amounts of high-quality, business-critical data. However, the increasingly stringent data and AI regulatory landscape&#8212;particularly in the EU&#8212;creates numerous compliance risks when using data for AI activities. It is therefore crucial to have robust controls in place to prevent unauthorised or non-compliant use of data. The most important regulatory and legal domains to consider are:<br><br><strong>Privacy and data protection: </strong>Privacy and data protection laws restrict the way in which personal data&#8212;in particular sensitive personal data&#8212;can be used. For example, under the EU&#8217;s GDPR, you must have a lawful basis to process personal data. Personal data processing is therefore only lawful if at least one of the following lawful bases apply: i) consent, ii) performance of a contract, iii) legal compliance, iv) protection of vital interests, v) performance of a task in the public interest, or vi) legitimate interests. Therefore, just because you have access to personal data, does not mean you are permitted by default to use it to develop or deploy AI. <br><br><strong>Copyright and intellectual property: </strong>Organisations must be cautious when using external data for AI development and deployment, as it is often copyright protected. Different data sources come with different licenses, terms, and conditions. This cautiousness must extend to &#8220;everyday&#8221; employee use of generative AI tools&#8212;in particular their prompts and document uploads. <strong><br><br>Contracts: </strong>Your organisation may have access to data that another organisation provided in the course of an engagement, such as the use of a product or service you provide, that is governed by a bespoke legal agreement. Therefore, you must protect and handle that data in accordance with the applicable legal agreement. <br><br><strong>AI-specific laws: </strong>Finally, AI regulations like the EU AI Act typically include provisions that stipulate how data should be used in the context of AI activities. For example, the AI Act requires providers of high-risk AI systems to use high quality, accurate, and &#8220;representative&#8221; training, validation, and testing data sets, in order to mitigate bias risks and promote reliable AI performance.<br><br><strong>Practical mitigations:</strong> The legal and regulatory domains outlined above are vast; comprehensive risk mitigation across all of them is beyond the scope of the PROTECT Framework. However, the overarching principle is that you must embed proportionate governance and oversight throughout the AI lifecycle, to prevent non-compliant or unauthorised data use. This means legal and compliance review must occur at critical stages, including before data is sourced, before AI models are trained, and before AI systems are deployed in production or released on the market. As ever, this governance must be complemented and reinforced by company-wide and role-specific training. When these governance checkpoints are bypassed&#8212;as discussed in the &#8216;Rogue Internal AI Projects&#8217; theme&#8212;the aforementioned data-related compliance and legal risks materialise. </p><h4><strong><br>T - Transfer Violations</strong></h4><div><hr></div><p><strong>Enterprise risks: </strong>Leveraging cloud-based AI services, such as platforms for accessing and using foundation models, almost always involves international data transfers. Given that AI processing is rarely confined to one jurisdiction, navigating international data transfer compliance is an important part of AI governance.<br><br>Privacy and data protection regimes worldwide restrict the way in which personal data can be transferred internationally. Under the GDPR, organisations can transfer personal data freely from the EU to entities in a non-EU country if there is an EU adequacy decision in place. An adequacy decision is the EU&#8217;s way of &#8220;<em>protecting the rights of its citizens by insisting upon a high standard of data protection in foreign countries where their data is processed</em>&#8221;. 15 jurisdictions are recognised as &#8220;adequate&#8221; by the EU. This includes the U.S.&#8212;but it only applies to commercial organisations participating in and certified under the EU-U.S. Data Privacy Framework. If there is no EU adequacy decision, alternative legal safeguards must be put in place (e.g., Standard Contractual Clauses), before personal data can be transferred from the EU to the non-EU jurisdiction. <br><br>On a separate note, the U.S. &#8220;Bulk Data Transfer Rule&#8221; prohibits or restricts organisations from transferring &#8220;U.S. sensitive personal data&#8221; and &#8220;government-related data&#8221; to &#8220;countries of concern&#8221;, including China, Cuba, Iran, North Korea, Russia, and Venezuela. The Rule was issued by the Department of Justice in January 2025.<strong><br><br>Practical mitigations: </strong>Although the above was far from an exhaustive overview of international data transfer regulations, the key point is that you must implement specific mitigations&#8212;as required by the applicable law&#8212;prior to transferring personal data across borders. For example, before onboarding U.S. AI vendors and service providers, verify whether they are certified under the EU-U.S. Data Privacy Framework, and implement Standard Contractual Clauses if not.</p><p>Transfer violations can result from the governance failures outlined earlier&#8212;such as onboarding AI vendors without proper due diligence and robust contracts, or deploying AI systems in production without completing privacy impact assessments. International data transfer-specific mitigations include mapping your organisation&#8217;s data flows to understand and track where data is processed, which vendors have access to it, and what sub-processors they may share that data with. Finally, complete transfer impact assessments as part of your privacy impact assessment process.<br></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[Top 10 Challenges for AI Governance Leaders in 2025 (Part 1)]]></title><description><![CDATA[Dealing with the AI 'democratisation dilemma' | #30]]></description><link>https://oliverpatel.substack.com/p/top-10-challenges-for-ai-governance</link><guid isPermaLink="false">https://oliverpatel.substack.com/p/top-10-challenges-for-ai-governance</guid><dc:creator><![CDATA[Oliver Patel]]></dc:creator><pubDate>Mon, 20 Oct 2025 10:30:49 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!NvcF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="/__u/substackcdn.com/image/fetch/$s_!NvcF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="/__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_webp, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 1456w" sizes="100vw"><img src="/__u/substackcdn.com/image/fetch/$s_!NvcF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png" width="1456" height="1048" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1048,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4943674,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://oliverpatel.substack.com/i/176562010?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="/__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_424, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 424w, /__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_848, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 848w, /__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_1272, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 1272w, /__u/substackcdn.com/image/fetch/$s_!NvcF!, /__u/oliverpatel.substack.com/w_1456, /__u/oliverpatel.substack.com/c_limit, /__u/oliverpatel.substack.com/f_auto, /__u/oliverpatel.substack.com/q_auto:good, /__u/oliverpatel.substack.com/fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F55b16134-0dcf-460b-9ab5-370194cf0c53_4550x3275.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg aria-hidden="true" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Hey &#128075;</p><p>I&#8217;m <a href="https://www.linkedin.com/in/oliver-patel/">Oliver Patel</a>, author and creator of <em>Enterprise AI Governance</em>&#8212;which today celebrates its 30th edition! Thanks for all your support and engagement on this journey! <em><br><br></em>This two-part series provides my personal view, from the enterprise AI governance coalface, on the top 10 challenges facing AI governance leaders today.</p><p>This is not a theoretical, policy, or legal analysis. Rather, it is a contemporary examination of the messy and relentless reality of being tasked with leading AI governance in an enterprise context&#8212;where AI is being adopted at scale and promoted as integral to the future competitiveness and relevance of the organisation. <br><br>The purpose of this two-part series is to guide AI governance professionals with practical insights on how to tackle some of the most pressing challenges we face. Below are the 10 challenges this series covers in detail. Part 1 covers challenges 1-3 (as they are inextricably linked) and part 2 (coming next week) covers challenges 4-10. <br><br>The lack of an established blueprint for enterprise AI governance, and the immense, interdisciplinary challenges we face each day, is exactly why I am writing my upcoming book, <em><a href="https://aigovernancebook.com/">Fundamentals of AI </a></em><a href="https://aigovernancebook.com/">Governance.</a> It is packed full of practical tips and strategies for enterprise AI governance leaders, including a visual deep dive on each of these 10 challenges. To secure a 25% discount during the pre-launch period, sign up at the link below.<br></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://aigovernancebook.com/&quot;,&quot;text&quot;:&quot;Secure your 25% discount&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://aigovernancebook.com/"><span>Secure your 25% discount</span></a></p><h4><strong><br>Top 10 Challenges for AI Governance Leaders in 2025</strong></h4><div><hr></div><ol><li><p><strong>The &#8216;democratisation dilemma&#8217;</strong>. <em>How to maintain robust oversight and promote compliance when the ability to develop, deploy, and use AI is democratised and widely accessible?</em></p></li><li><p><strong>Volume and velocity. </strong><em>How to keep up with the sheer volume and rapid pace of enterprise<strong> </strong>AI initiatives, whilst cutting through the noise and deploying finite resources and expertise on the highest value work?</em></p></li><li><p><strong>Refining the risk-based approach</strong>. <em>How to respond to the AI risk &#8216;vibe shift&#8217; and effectively target governance on the relatively small proportion of AI systems and use cases that could pose significant risks?</em></p></li><li><p><strong>Protecting confidential business data</strong>. <em>How to protect confidential business data when there is immense hunger to experiment with and use the latest AI applications that are released on the market?</em></p></li><li><p><strong>Ongoing vendor due diligence and oversight. </strong><em>How to move beyond &#8216;paper-based&#8217; vendor due diligence and apply continuous oversight on the performance, trustworthiness, and safety of externally provided AI applications?</em></p></li><li><p><strong>AI engineering: building with foundation models</strong>. <em>How to determine your rights, responsibilities, and liabilities&#8212;as well as the novel risks and tangible mitigations&#8212;when building AI systems with foundation models provided by external organisations?</em></p></li><li><p><strong>Open-source AI model oversight. </strong><em>How to effectively govern the widespread access and use of open-source AI models, to safeguard your organisation from legal, compliance, and cyber security risks, whilst promoting innovation?</em></p></li><li><p><strong>Embedding compliance by design. </strong><em>How to build AI systems that promote compliance by design and default, to make it seamless for your workforce to do the right thing?</em></p></li><li><p><em><strong>Agentic AI governance: taking the human out of the loop. </strong>How to promote responsible, meaningful, and empowered human oversight of AI, when the fundamental goal of agentic AI is to take the human out of the loop?</em></p></li><li><p><strong>Digital governance silos and inefficiencies. </strong><em>How to effectively streamline and integrate your disparate digital governance and risk management processes and capabilities, to improve the user experience and accelerate AI innovation, whilst also strengthening your compliance posture?<br></em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div></li></ol><h4><strong>1. The &#8216;Democratisation Dilemma&#8217;</strong></h4><div><hr></div><p><em>How to maintain robust oversight and promote compliance when the ability to develop, deploy, and use AI is democratised and widely accessible?<br><br></em>The launch of ChatGPT in November 2022, and the subsequent generative AI boom, was a watershed moment. Not only because of fundamental advances in model architecture or training and inference techniques, but because powerful generative AI applications were now, for the first time, at the fingertips of all employees. By <a href="https://www.reuters.com/technology/chatgpt-sets-record-fastest-growing-user-base-analyst-note-2023-02-01/">some user adoption measures</a>, ChatGPT was the fastest-growing consumer application of all time. Fast forward nearly three years, and it is evident that the democratisation of AI&#8212;and its widespread accessibility and availability&#8212;is perhaps the most important development impacting the enterprise AI world.<br><br>Things have moved on from everyone merely having access to powerful chatbots for simple personal assistance and productivity tasks. The ability to customise, use, and share generative AI applications, for scalable, business critical use cases&#8212;and even to build AI powered-tools for production deployment in business workflows without any hard technical skills&#8212;is significantly increasing the volume of AI activities and use cases for which oversight is often lacking. <br><br>For example, non-technical employees can use no-/low-code agent builder platforms for &#8220;drag-and-drop&#8221; creation of domain specific chatbots and assistants that can retrieve and surface information, call APIs, execute tasks, and augment and automate important business workflows. Similarly, non-technical employees can also build and scale custom GPTs and generative AI &#8216;projects&#8217; that are augmented with vast amounts of data and documentation, and optimised to perform in a particular way, via detailed prompts and instructions<br><br>All major AI product releases highlight that the trend towards democratisation is accelerating. And it is safe to assume that what the average non-technical employee can do with AI will only become more sophisticated over time.<br><br>This compels AI governance leaders to reevaluate how to govern the development and use of AI. Up until now, most organisations distinguished between the AI models and AI systems that their data science and engineering teams build, for production deployment, and the everyday use of generative AI applications by the wider workforce. With respect to the latter, AI governance frameworks do not typically require AI governance and risk assessments, or the implementation of lifecycle controls and risk mitigations. Aside from following the AI usage policies and guidelines, employees are generally free to use approved generative AI applications for their personal work without oversight.<br><br>However, this position won&#8217;t hold for much longer. For example, if anyone can use a no-code AI platform to build a high-risk CV screening tool that dozens of other employees can use, then, given the compliance responsibilities and ethical implications, this cannot be considered an everyday use of AI warranting no formal governance.<br><br>Remember, under the EU AI Act, if your organisation uses a general-purpose AI system for recruitment and candidate selection, and it was not intended to be used for this purpose, you could inadvertently become the provider and the deployer of a high-risk AI system&#8212;without even realising.<br><br><strong>Practical solutions: </strong><em><strong>the three Gs for dealing with AI democratisation</strong></em></p><ul><li><p><strong>Guidance</strong>: Educate all employees on their responsibilities and the way in which their seemingly everyday use of AI can give rise to compliance obligations. Furthermore, ensure that any AI use case or AI system that has the potential to be classified as a high-risk AI system under the EU AI Act, or even a potentially prohibited AI practice, undergoes rigorous AI governance assessment and review, irrespective of the AI platform, technology, or approach used to develop and deploy it. Remember, the law is technology neutral. </p></li><li><p><strong>Guardrails: </strong>Implement guardrails and technical safeguards into the AI platforms that are widely available and &#8220;democratised&#8221;, so that certain types of AI use cases cannot be pursued or progressed to production (e.g., those that could be prohibited), and to enable potential compliance risks and incidents to be monitored, detected, and flagged on a continuous basis. This could involve monitoring specific content in prompts, documentation, and model outputs to flag potential violations or data-related risks. </p></li><li><p><strong>Greenlight:</strong> Make it clear precisely which AI platforms and tools are available and approved for use, as well as which data sources, AI-powered workflows, and patterns have been approved for production use. This enhances organisation-wide understanding of what is permissible, effective, and safe, thereby enhancing your AI governance posture without slowing the business down.</p></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading Enterprise AI Governance! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><h4><br>2. <strong>The Volume and Velocity Challenge</strong></h4><div><hr></div><p><em>How to keep up with the sheer volume and rapid pace of enterprise AI initiatives, whilst cutting through the noise and deploying finite resources and expertise on the highest value work?<br><br></em>The volume and velocity challenge is directly linked to, and amplified by, the &#8220;democratisation dilemma&#8221;. The easier it becomes to develop, use, and scale AI applications for business-critical use cases, the more AI use cases there are to govern. </p><p>However, surging AI volume and velocity has other causes, such as increased investment in AI capabilities across the board, strong incentives for corporate leaders to demonstrate successful AI adoption, reduced barriers to entry due to the widespread availability of foundation models, rapid advances in AI engineering techniques to capitalise on these models, and technology vendors introducing myriad AI capabilities into every product, platform, and offering.<br><br>In this context, AI governance functions are struggling to keep up with the sheer volume of AI initiatives and use cases which they are tasked with assessing, reviewing, monitoring, and approving. Furthermore, the rapid pace at which this volume is increasing, combined with the ever-changing nature of the AI use cases and their underpinning technology&#8212; makes it even harder to know how to tackle this problem and structure your AI governance function&#8217;s workload. <br><br>There are three common symptoms of this challenge, all of which are detrimental to long-term AI governance success.</p><p>First, the volume challenge leads to practitioners with expertise on AI ethics, regulatory compliance, and broader legal or technical issues spending excessive time on lower value work, such as processing and reviewing inherently low-risk AI use cases, or providing similar advice repeatedly. <br><br>Second, the velocity challenge means that the nature of AI use cases and AI technology is changing fast. Risk assessment questions, lifecycle control frameworks, and training and guidance can quickly become outdated. For example, risk assessment and documentation artefacts designed for generative AI will likely be missing the mark for the new agentic AI systems that are being developed and prepared for production. <br><br>Finally, increased &#8216;demand&#8217; on the AI governance function means more noise and more potential distractions. This can lead to mission drift and not prioritising the most important work that is essential to protect the organisation. <br><br><strong>Practical solutions: </strong><em><strong>the three As for handling AI overload</strong></em></p><ul><li><p><strong>Automate: </strong>Leverage automation and AI to speed up the process of triaging, classifying, and assessing AI use cases, as well as assigning governance and oversight pathways and reviewers (based on the inputs provided in AI governance assessment submissions). Given the volume, it may not be feasible to stick with manual human review of every single submission. Therefore, leveraging automation enables smarter allocation of work to AI governance experts. However, assurance and quality control processes should be implemented to ensure the automation is effectively serving its purpose. It should also be implemented in parallel to the human-led process, at least initially.</p></li><li><p><strong>Artefacts: </strong>Develop and distribute reusable governance artefacts for common AI patterns and applications&#8212;such as chatbots, research agents, and document processing. When the twentieth team wants to build a document assistant bot, they need not start from scratch. Pre-approved patterns, risk mitigation control sets, and documentation templates are win-win, as they support the business and free up AI governance SME time for higher-value work.</p></li><li><p><strong>Adapt: </strong>Dealing with velocity requires constant and targeted adaptation. Continuously and periodically review and assess whether your policies, risk assessment processes, guidelines, and artefacts are fit for purpose, making focused and impactful changes where necessary. </p><p></p></li></ul><h4><strong><br>3. Refining the risk-based approach</strong></h4><div><hr></div><p><em>How to respond to the AI risk &#8216;vibe shift&#8217; and effectively target governance on the relatively small proportion of AI systems and use cases that could pose significant risks?<br><br></em>Democratisation is making it easier for anyone to develop and deploy AI, which is challenging the notion of what type of AI activities do and do not require oversight and governance. It is also a chief contributor to the volume and velocity challenge, which risks overwhelming enterprise AI governance teams, unless they effectively adapt and restructure their work. <br><br>These three trends&#8212;democratisation, volume, and velocity&#8212;are also contributing to an AI risk &#8216;vibe shift&#8217;, which many AI governance leaders are noticing and impacted by.</p><p>The use of AI is now ubiquitous and embedded in the daily lives of millions of people and workers worldwide. A <a href="https://hbr.org/2025/04/how-people-are-really-using-gen-ai-in-2025">Harvard Business Review study</a> from April 2025 found that &#8220;therapy and companionship&#8221; was the top generative AI use case. A <a href="https://openai.com/index/how-people-are-using-chatgpt/">more recent study</a> from economists at OpenAI and the National Bureau of Economic Research found that &#8220;practical guidance&#8221; is the most common conversation theme for ChatGPT, with the top three topic areas being 1) tutoring or teaching, 2) &#8220;how to&#8221; advice, and 3) health, fitness, beauty, and self-care.<br><br>As AI adoption increases, the perception of AI risk is changing. The common everyday use of AI is undoubtedly impacting how its risks and potential dangers are perceived. For many in the corporate world, it may be hard to connect more abstract risk themes, such as bias, explainability, and safety, with their everyday use of AI, which could feel merely assistive and somewhat harmless. Furthermore, if the organisation you work for is yet to suffer or be impacted by a major AI incident, and it is not an issue that is much discussed by the company leadership, this can also make the importance of AI governance feel harder to grasp.<br><br>But this is not just about perception. As AI adoption increases, the actual proportion of fundamentally low risk and non-material use cases is also likely increasing. Although this will vary for each organisation, the more people that use AI, and the more it is deployed to augment, optimise, and automate the vast range of back-office processes that, on balance, probably do not have the potential to materially impact people&#8217;s lives, the more important it is for AI governance leaders to focus their attention and resources on what matters most.<br><br>AI governance practitioners need to be alert to the resulting &#8216;vibe shift&#8217;&#8212;as well as the actual changes in the nature and distribution of AI use cases and their inherent risk levels, that are being driven by these trends. <br><br>As I have always said, <strong>AI governance does not mean governing all AI</strong>. You need to be proportionate, pragmatic, and risk-based in your approach. Trying to wrap your arms around anything and everything just because it has &#8216;AI&#8217; in it is futile. <br><br>A better path forward is to refine and reevaluate your risk-based approach to AI governance, including how you classify the risk level of AI systems and AI use cases, and deploy resources and mandate governance and oversight accordingly. <br><br>This refinement needs to account for the fact that ostensibly everyday uses of AI can give rise to high-risk use cases, but also that most AI use cases and initiatives should probably not be classified as high-risk, irrespective of their development techniques and underpinning technology. </p><p>This is because as AI adoption surges, the volume of use cases and activities is becoming almost impossible to manage. Therefore, it&#8217;s never been more important to filter out the noise with razor sharp triaging, risk classification, and prioritisation. <br><br>In sum, to govern AI effectively in 2025, it is crucial for AI governance leaders to adapt to the societal and corporate &#8216;vibe shift&#8217; that is underway. We must be targeted, selective, and proportionate in our approach, to stay credible and focused on what really matters. Structure your approach so that a large majority of your team&#8217;s time and invaluable expertise is spent on the small proportion of AI activities that pose significant risks. <br><br><strong>Practical solutions: </strong><em><strong>the three Ps for refining your risk-based approach</strong></em></p><ul><li><p><strong>Prioritise: </strong>Lead the conversation to redefine exactly what constitutes high-risk AI in your organisation in 2025. Instead of navigating opaque vibe shifts, formally agree and document your leadership&#8217;s risk appetite and risk-based approach to AI, in light of all the themes covered above. Most AI use cases don&#8217;t warrant intensive governance&#8212;pretending otherwise will undermine your credibility. Once you have done this, ensure your teams are spending most of their time on what is truly high-risk.</p></li><li><p><strong>Proportionate: </strong>Apply governance intensity and scrutiny that matches the actual risk level. The rigour applied to and experts involved in the AI governance review, the amount of technical documentation required, the lifecycle controls that must be implemented, and the level of continuous monitoring and governance oversight must all flex, depending on the nature of the AI system or AI use case. This ensures your governance effort scales with impact and risk, not just with AI adoption. </p></li><li><p><strong>Prove: </strong>Combat the vibe shift head-on by making your catches and wins visible. If you prevent an AI system from being deployed that poses potential ethical, legal, compliance, or reputational risks&#8212;or if a similar incident materialised in another organisation&#8212;document and communicate this to the right people in a subtle yet informative manner. This could be packaged up as periodic AI governance impact reports. If senior stakeholders can&#8217;t see the fires you&#8217;re preventing, they may question why you need the fire extinguisher.</p><div><hr></div></li></ul><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://oliverpatel.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading! Subscribe below for weekly updates from Enterprise AI Governance.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item></channel></rss>