Regulation, explained clearly.
Grounded analysis of the EU AI Act, ISO 42001, DORA, MaRisk/BAIT and AI governance in APAC — written for compliance leaders, not for the search engine. Every fact is anchored in the real regulation.
2 August 2026 and your 40-person company: what the EU AI Act really asks of SMEs
On 2 August 2026 the transparency obligations of Article 50 start to apply. For small and mid-sized companies, though, the real news is a different one: the demanding high-risk machinery will not usually touch you — while two obligations have been binding since 2 February 2025. This article separates deployer duties from provider duties, works through the SME-specific fine rule in Article 99(6), and ends with a table you can fill in this afternoon.
ResourcesThe EU AI Act enforcement timeline: what applies when
Regulation (EU) 2024/1689 applies in stages: prohibited practices since February 2025, GPAI obligations and penalties since August 2025, and broad transparency duties from August 2026. The most demanding high-risk obligations were pushed back by the 2026 ‘Digital Omnibus’ amendment — to December 2027 for standalone Annex III systems. This overview sets out the deadlines and fine ceilings for regulated teams.
ResourcesDORA and AI in Financial Services: ICT Third-Party Risk for Model Providers
The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied directly since 17 January 2025, turning AI and LLM vendors into regulated ICT third-party service providers. Compliance leaders in banking and insurance must govern registers, contracts, exit strategies and concentration risk accordingly.
ResourcesAI governance in APAC: Singapore's PDPA and MAS expectations
Singapore governs AI through a layered model: the binding PDPA data-protection statute as the floor, voluntary PDPC/IMDA governance frameworks, and sector-specific MAS expectations for financial institutions. This article maps the instruments and what regulated APAC teams must operationally evidence.
ResourcesISO/IEC 42001 and the EU AI Act: how an AI management system earns your compliance
ISO/IEC 42001:2023 provides a certifiable AI management system that mirrors many EU AI Act duties organisationally — but it does not replace the legal presumption of conformity, which only harmonised standards can grant.
ResourcesMaRisk, BAIT and AI: outsourcing and model governance in German banking
MaRisk and BAIT are the BaFin circulars that shape risk management and IT in German banks. They do not name AI, but they govern its use through outsourcing and IT-governance requirements — increasingly in interplay with DORA.
ResourcesUsing the NIST AI RMF as a bridge to the EU AI Act
The NIST AI Risk Management Framework is voluntary US guidance and not a certification. Its four functions provide a practical structure for building the risk management, testing and documentation that also support EU AI Act obligations.
ResourcesTurn the regulation into a running system.
30 minutes, scoped to your frameworks and integrations. You leave with a concrete plan — not a sales loop.