Skip to main content
Resources

Regulation, explained clearly.

Grounded analysis of the EU AI Act, ISO 42001, DORA, MaRisk/BAIT and AI governance in APAC — written for compliance leaders, not for the search engine. Every fact is anchored in the real regulation.

SME practice25 Jul 2026 · 8 min read

2 August 2026 and your 40-person company: what the EU AI Act really asks of SMEs

On 2 August 2026 the transparency obligations of Article 50 start to apply. For small and mid-sized companies, though, the real news is a different one: the demanding high-risk machinery will not usually touch you — while two obligations have been binding since 2 February 2025. This article separates deployer duties from provider duties, works through the SME-specific fine rule in Article 99(6), and ends with a table you can fill in this afternoon.

Resources
EU AI Act15 Jul 2026 · 5 min read

The EU AI Act enforcement timeline: what applies when

Regulation (EU) 2024/1689 applies in stages: prohibited practices since February 2025, GPAI obligations and penalties since August 2025, and broad transparency duties from August 2026. The most demanding high-risk obligations were pushed back by the 2026 ‘Digital Omnibus’ amendment — to December 2027 for standalone Annex III systems. This overview sets out the deadlines and fine ceilings for regulated teams.

Resources
DORA7 Jul 2026 · 6 min read

DORA and AI in Financial Services: ICT Third-Party Risk for Model Providers

The Digital Operational Resilience Act (Regulation (EU) 2022/2554) has applied directly since 17 January 2025, turning AI and LLM vendors into regulated ICT third-party service providers. Compliance leaders in banking and insurance must govern registers, contracts, exit strategies and concentration risk accordingly.

Resources
APAC · PDPA29 Jun 2026 · 5 min read

AI governance in APAC: Singapore's PDPA and MAS expectations

Singapore governs AI through a layered model: the binding PDPA data-protection statute as the floor, voluntary PDPC/IMDA governance frameworks, and sector-specific MAS expectations for financial institutions. This article maps the instruments and what regulated APAC teams must operationally evidence.

Resources
ISO 4200118 Jun 2026 · 5 min read

ISO/IEC 42001 and the EU AI Act: how an AI management system earns your compliance

ISO/IEC 42001:2023 provides a certifiable AI management system that mirrors many EU AI Act duties organisationally — but it does not replace the legal presumption of conformity, which only harmonised standards can grant.

Resources
MaRisk · BAIT8 Jun 2026 · 5 min read

MaRisk, BAIT and AI: outsourcing and model governance in German banking

MaRisk and BAIT are the BaFin circulars that shape risk management and IT in German banks. They do not name AI, but they govern its use through outsourcing and IT-governance requirements — increasingly in interplay with DORA.

Resources
NIST AI RMF27 May 2026 · 5 min read

Using the NIST AI RMF as a bridge to the EU AI Act

The NIST AI Risk Management Framework is voluntary US guidance and not a certification. Its four functions provide a practical structure for building the risk management, testing and documentation that also support EU AI Act obligations.

Resources
Book a demo

Turn the regulation into a running system.

30 minutes, scoped to your frameworks and integrations. You leave with a concrete plan — not a sales loop.