NVDA 224.58 ▼0.41%GOOGL 342.36 ▲1.34%MSFT 497.93 ▼0.53%AMD 629.26 ▲2.38%INTC 127.39 ▲3.91%TSMC 451.15 ▲1.03%AMZN 249.38 ▲0.04%META 777.59 ▲4.50%AAPL 335.92 ▼0.33%PLTR 192.59 ▲0.42%
Markets at last close

Policy

AI governance frameworks mapped to compliance, security and delivery

·1 min read

The EU AI Act’s Digital Omnibus, Regulation 2026/1744, deferred Chapter III high-risk system duties to December 2, 2027 for standalone systems and August 2, 2028 for embedded systems. Other requirements remain on track, including AI literacy and Article 5 bans since February 2025, GPAI provider duties since August 2025, most Article 50 transparency duties from August 2, 2026, and a ninth banned-practice category from December 2, 2026.

The governance landscape is organized around three practical jobs: proving compliance, defending against attacks and building systems. The mapped set includes the EU AI Act, ISO 42001, NIST AI RMF, NIST AI 600-1, NIST COSAiS, OWASP LLM/Agentic Top 10, MITRE ATLAS, CSA AICM, AIUC-1 and SOC 2.

A central warning is that ISO 42001 certification alone does not equal EU AI Act compliance. Cited gaps include incident reporting, change management and fundamental-rights assessments, along with limitations in per-system regulatory mapping and AI-specific supply-chain provisions.

The recommended approach starts with sequencing obligations by role and risk, then using crosswalks where they exist. WunderGraph’s Cosmo and Hub API governance tooling can provide supporting evidence such as audit logs and schema change approvals, but is not positioned as an AI-governance product.

Originally reported by daily.devRead the source →
Related coverage