Unacceptable risk
Practices such as social scoring and manipulative techniques are prohibited. AIZEC flags and blocks such usage in the inventory.
The EU AI Act, ISO/IEC 42001, NIST AI RMF and data protection law speak different languages but ask the same thing: who decided what, on what basis, and how do you prove it?
The Regulation binds not only model developers but also deployers who use an AI system under their own authority. Scope depends less on where you are established than on where the output is used.
The Regulation entered into force.
Unacceptable-risk practices became prohibited; the AI literacy obligation for staff began.
Obligations for general-purpose AI models and the competent authority / penalty regime took effect.
Most of the Regulation applies, including Annex III high-risk systems.
The transition period ends for high-risk systems covered by product safety legislation.
Practices such as social scoring and manipulative techniques are prohibited. AIZEC flags and blocks such usage in the inventory.
Systems producing decisions in areas such as employment, credit and education. In AIZEC these map directly to the red tier.
Systems with transparency obligations (for example chatbots). User disclosure is linked to the inventory record.
Free to use. In AIZEC this maps to the green tier: recording and logging are sufficient.
This page is informational and is not legal advice. The scope of your obligations depends on the role of the system and its context of use.
ISO/IEC 42001 is the first management system standard for artificial intelligence. It does for AI governance what ISO 27001 does for information security: policy, roles, risk and a continual improvement cycle.
Some of the records an ISO 42001 auditor will ask for are produced as a by-product of daily operations. The list below shows which ones.
The four functions of the NIST framework map to concrete modules in the platform.
Policy, roles and accountability. In AIZEC: RBAC, CoE ownership and the mandatory decision rationale.
Establishing context and risks. In AIZEC: inventory, use-case intake and data sensitivity flags.
Measuring risk and performance. In AIZEC: risk assessment, DLP checks and business impact metrics.
Responding to and monitoring risk. In AIZEC: approval flows, gateway monitoring and the kill switch.
When an AI use-case processes personal data, AI governance and data protection obligations become two sides of the same record.
AIZEC records which data category a use-case touches. That way the question "what data did the model see?" is answered at intake, not after an incident.
The same record serves as evidence across multiple frameworks. Produce it once, present it in every audit.
| Obligation | EU AI Act | ISO/IEC 42001 | NIST AI RMF | AIZEC module |
|---|---|---|---|---|
| Risk classification | Risk categories | Risk assessment | Map | Risk & Autonomy Tiering |
| Inventory and scope | System records | Context definition | Map | AI Inventory & Discovery |
| Human oversight | Art. 14 human oversight | Operational control | Manage | Approval flows |
| Record-keeping | Automatic logging | Documented information | Measure | Audit Trail & Evidence |
| Incident response | Serious incident reporting | Improvement | Manage | Kill switch & revocation |
| Management review | Quality management system | Management review | Govern | Monthly report |
The matrix is an orientation aid showing how obligations map to the platform; it is not a declaration of legal conformity.
The Regulation can cover providers and deployers established in third countries where the output of the AI system is used within the EU. If you have customers, subsidiaries or operations in the EU, a scoping assessment is needed. That assessment belongs with your legal team.
No, and you should distrust any product that claims otherwise. AIZEC provides the process, decision and evidence infrastructure that compliance requires; interpreting obligations and bearing final responsibility remain with your organisation.
In practice the hardest part is reconstructing records after the fact. Turning on inventory and decision records as early as possible removes the need to reconstruct records retroactively during audit preparation.
Classification, approval, rejection and revocation decisions are held in the audit trail with actor, rationale and timestamp, and can be exported. Monthly report snapshots serve as periodic evidence.
We will assess your current AI usage against four frameworks and produce a prioritised remediation plan.
The information on this page is general in nature and does not constitute legal advice.