Layer 06 · AI governance
AI Compliance: Turn Governance Into Proof
Prove your AI is compliant, accountable and ready for scrutiny.
AI compliance is no longer about having a policy document sitting in a folder. Organisations need to demonstrate that their AI systems meet applicable laws, regulations, standards and internal requirements — and produce evidence when regulators, auditors, customers or boards ask for it.
A strong AI compliance programme connects AI inventory, data governance, security, model assurance, human oversight and audit evidence into one structured governance framework. The result is a clear, defensible record of what your AI does, which obligations apply, what controls are in place and how those controls are working.
Always audit-ready
AI Compliance That Stands Up to Scrutiny
Regulators do not accept intentions; they ask for evidence. Effective AI compliance maps every relevant obligation to a control, assigns ownership, enforces policy and maintains the records needed to demonstrate conformity.
*Illustrative figures for a representative estate.
01 · Where AI Compliance Begins
Five Questions Every Organisation Must Answer
When a regulator, auditor or customer asks you to prove your AI is compliant, the answer cannot be “give us a few weeks”.
A mature AI governance framework starts with five practical questions. Each one connects to a control that strengthens AI compliance and creates evidence for future reviews.
02 · The controls, explained
The Controls Behind Effective AI Compliance
Effective AI compliance depends on more than policies. Each control needs a clear purpose, an owner, an operating mechanism and evidence that it works. Together, these five controls turn governance requirements into an auditable operating model.
EU AI Act mapping
Know exactly which AI obligations apply.
Definition
EU AI Act compliance starts with understanding where each AI system sits within the regulatory landscape.
How it works
Organisations need to identify intended use, risk classification, responsibilities across the AI value chain and the obligations associated with each system.
How we help
An effective AI governance audit should be able to trace every system from its inventory record to the relevant regulatory requirements and supporting evidence.
What this control covers
AI system classification
Applicable EU AI Act obligations
Risk-tier mapping
Provider and deployer responsibilities
Documentation requirements
Transparency requirements
Human oversight obligations
Monitoring requirements
Conformity assessment requirements
Evidence ownership
Result
The result is a structured foundation for AI regulatory compliance.
AI literacy
Give every AI user the knowledge to act responsibly.
Definition
AI technology cannot create compliant behaviour by itself.
How it works
AI literacy ensures that people understand AI capabilities, limitations, risks and responsibilities before they use or deploy AI systems.
How we help
Training should reflect the person's role. A developer, executive, compliance professional and frontline employee will interact with AI differently and therefore require different knowledge.
What this control covers
Role-based AI training
AI risk awareness
Responsible-use guidance
Model limitations
Human oversight responsibilities
Data handling
Prompt and output risks
Incident escalation
Training completion records
Records
Training records also become valuable evidence during an AI audit.
Policy enforcement
Turn AI policy into controls that actually work.
Definition
A policy has little value if nobody checks whether it is followed.
How it works
AI compliance requires written requirements to become operational controls. These can include approval gates, access restrictions, monitoring, exception management and accountability.
How we help
An AI governance audit should therefore examine not only what the policy says, but how the organisation enforces it.
What this control covers
Acceptable-use policies
AI approval workflows
Model deployment controls
Data-use restrictions
Third-party AI requirements
Exception management
Control ownership
Policy review cycles
Evidence of enforcement
Non-compliance escalation
Transforms
This transforms AI policy from static documentation into an active governance mechanism.
Incident reporting
Detect AI problems before they become regulatory problems.
Definition
AI incidents can involve inaccurate outputs, privacy breaches, discriminatory behaviour, security failures, unsafe recommendations or unexpected autonomous actions.
How it works
A mature AI governance framework establishes how incidents are detected, classified, escalated, investigated and documented.
How we help
Effective AI compliance means having this process ready before an incident occurs.
What this control covers
Incident detection
Severity classification
Named owners
Escalation routes
Reporting timelines
Root-cause analysis
Corrective actions
Regulatory notification
Lessons learned
Evidence retention
Records
Incident records also provide essential evidence during an AI audit.
Audit trails
Create a complete record of what AI did and why.
Definition
An audit trail connects governance controls with actual AI activity.
How it works
Strong AI audit readiness means being able to establish what happened, when it happened, which system was involved, which model version was used, who approved it and what actions followed.
What this control covers
AI system records
Model versions
Data changes
Approval decisions
Human overrides
Policy exceptions
Incident records
Testing results
Access activity
Compliance evidence
Without it
When evidence is captured continuously, an AI audit becomes an evidence-retrieval exercise rather than a last-minute reconstruction project.
The Regulatory Clock
EU AI Act Compliance Timeline
EU AI Act compliance requires organisations to understand not only what applies, but when different requirements take effect. The timeline below reflects Regulation (EU) 2026/1744 (the Digital Omnibus on AI), published in the Official Journal on 24 July 2026 and in force from 27 July 2026, which deferred the high-risk deadlines.

Aug 2, 2026Transparency Obligations Apply +
Article 50 transparency obligations apply in full, covering chatbot disclosure, synthetic-content marking, emotion-recognition notices and deepfake labelling, together with the associated market-surveillance enforcement powers. Contrary to the original timetable, the high-risk regime does not become applicable on this date.
Dec 2, 2026Legacy Transparency and New Prohibitions +
Article 50(2) transparency requirements extend to systems already on the market at 2 August 2026, and the new Article 5 prohibitions on AI-generated non-consensual intimate imagery and child sexual abuse material take effect.
Dec 2, 2027Regulatory Sandboxes+
Member States must have at least one national AI regulatory sandbox operational, deferred by one year from 2 August 2026.
Aug 2, 2028Embedded High-Risk AI+
AI embedded as a safety component of products already regulated under EU product-safety law (Annex I) reaches its high-risk requirements, deferred from 2 August 2027.
For organisations building an AI compliance programme, these dates need to connect to owners, controls, evidence requirements and review cycles.
03 · Framework Convergence
One Framework, Multiple Compliance Requirements
Different frameworks use different terminology, but much of the underlying evidence overlaps.
A strong AI governance framework creates a common evidence base that can be mapped across regulatory requirements and recognised standards.
| Framework | What it governs | Evidenced by layers |
|---|---|---|
| EU AI Act | Legal obligations by risk tier | All six layers, especially inventory, model assurance and compliance |
| NIST AI RMF | Govern, Map, Measure and Manage | Inventory, model assurance, human oversight and compliance |
| ISO/IEC 42001 | AI management system | All six layers |
| OWASP LLM Top 10 | AI application security | Security and access, model assurance |
| ISO/IEC 23894 · 42005 | AI risk and impact assessment | Inventory, model assurance and compliance |
04 · Build AI Compliance Into Everyday Operations
The AI Compliance Checklist
AI audit readiness is not a status achieved once and then forgotten. It is a continuous operating state.
A mature AI compliance programme maintains the following capabilities.
- A Per-System Obligation Map Every AI system is mapped against applicable legislation, standards, internal policies and current compliance status.
- Documented AI Literacy Role-based training is delivered, completed and recorded.
- Enforced AI Policy Every important policy requirement is connected to an operational control, with exceptions documented and approved.
- A Tested Incident Process Triggers, owners, SLAs and regulatory timelines are defined and exercised.
- Complete Audit Trails Decisions, model versions, approvals, changes and overrides are logged, retained and exportable.
- A Clear Transparency Statement A plain-language account of how AI is governed provides customers, employees and stakeholders with greater confidence.
Together, these capabilities form the evidence base needed for effective AI compliance.
From the White Paper — Compliance Is Proven by Evidence, Not Intent
“Who owns this when it breaks?” should have a name as the answer, not a department.Regulators ask for records, not intentions..
There is no universal AI audit-trail template. The evidence spans the complete AI lifecycle: inventory, validated data, security controls, model testing, human oversight, incident records, approvals and compliance documentation.
NIST provides a process for governing, mapping, measuring and managing AI risk, but organisations still need to define their own thresholds, controls and evidence.
That is why AI compliance should be built into the AI lifecycle rather than assembled immediately before an audit.
Failure Modes
Where AI Compliance Falls Apart
The most difficult governance gaps are often not missing policies. They are gaps between what an organisation says and what it can actually prove.
Principles Without a Purpose
Policies describe what should happen but fail to explain why, what outcome is expected or who owns the requirement.
Fix Give every principle a clear purpose, target outcome and named owner.Governance Stops at the Organisation Boundary
Internal teams are covered while suppliers, partners and third-party AI providers are overlooked.
Fix Extend AI governance requirements into vendor and third-party relationships..A Changelog Replaces a Review Cycle
An edit history shows that documents have changed but does not establish when they should be reviewed or who is responsible.
Fix Define a review cadence, ownership and consequences for non-compliance.Different Policy Problems Are Conflated
Contradictions, unclear requirements and missing requirements are treated as one issue.
Fix Violations — a system contradicts a requirement.Ambiguities — the requirement is unclear.
Gaps — no requirement exists.
This makes AI regulatory compliance easier to assess and remediation easier to prioritise.
Locate Yourself
The AI Compliance Maturity Lifecycle
Where does your organisation sit today?
Foundation
Principles are established, policies are drafted and organisational scope is defined.
Implementation
Controls are introduced across the AI lifecycle. Risk tiers are established and responsibilities assigned.
Productionization
Runtime guardrails, agentic autonomy controls and incident detection become operational.
Assurance
Independent validation, complete audit trails, ISO 42001 certification and EU conformity-assessment readiness become part of the operating model.
The goal is to move from documented intent to measurable AI compliance.
Go deeper
The AI Compliance Playbook
Six distinctions that separate defensible compliance from paperwork theatre.
DefinitionCompliance vs AI Audit Readiness+
AI compliance means meeting applicable requirements.
AI audit readiness means being able to demonstrate that compliance with reliable evidence when someone asks.
FrameworkHow an Obligation Becomes a Control+
A regulatory requirement becomes an operational requirement, which becomes a control, which produces measurable evidence.
FrameworkWhat Counts as Evidence?+
Evidence can include Policies
Approvals
Training records
Model documentation
Testing results
Incident records
Monitoring data
Audit logs
Risk assessments
Exception records
Field noteOne Evidence Base Can Satisfy Multiple Frameworks+
The same evidence can support EU AI Act compliance, ISO/IEC 42001, NIST AI RMF and internal governance requirements when it is structured correctly.
MethodAI Literacy Is Role-Based+
Different users have different responsibilities. AI literacy should therefore reflect the risks associated with each role.
MethodThe Incident Clock Starts Before You Are Ready+
Incident ownership, escalation routes and reporting requirements should be established before an incident occurs.
05 · In practice
AI Compliance in the Real World
AI compliance becomes more meaningful when governance principles are applied to real operational challenges. The following scenarios are illustrative composites based on common patterns across regulated industries.
Challenge
A bank faced a supervisory review and could not evidence, system by system, which regulatory obligations applied to its AI systems or whether those requirements were being met.
Controls applied
EU AI Act mappingAudit trails
Outcome
A per-system obligation map and consolidated audit trail enabled the bank to answer review questions with evidence rather than explanations. Open gaps were converted into a dated remediation plan.
Key learning
Regulators judge governance maturity partly by how quickly an organisation can produce reliable evidence. The ability to export evidence is more valuable than the ability to explain why it should exist.
Challenge
An NHS Trust needed to demonstrate governance over clinical AI processing sensitive patient information ahead of a joint review. Policy and operational practice had drifted apart.
Controls applied
Policy enforcementAI literacyIncident reporting
Outcome
Policies were connected to approval controls, role-based AI literacy training was delivered and recorded, and an incident process was tested to close the gap between documented governance and operational behaviour.
Key learning
A policy that is not enforced is not a strong compliance control. Enforcement, training and evidence make governance credible.
Challenge
An insurer pursuing ISO/IEC 42001 certification had governance evidence distributed across multiple teams, platforms and processes.
Controls applied
EU AI Act mappingPolicy enforcementAudit trails
Outcome
Evidence from the wider governance stack was consolidated into a management-system structure aligned with the standard.
Key learning
Effective AI audit preparation becomes significantly easier when evidence is generated continuously rather than assembled immediately before certification.
Challenge
A SaaS organisation repeatedly faced delays during enterprise procurement because customers requested evidence of its AI governance, but the company lacked a centralised evidence pack.
Controls applied
EU AI Act mappingAudit trailsIncident reporting
Outcome
A transparency statement and structured evidence pack became standard components of enterprise proposals.
Key learning
AI compliance evidence is increasingly becoming a commercial trust asset. Organisations that can demonstrate governance quickly can reduce friction during enterprise procurement.
Disclaimer: illustrative use cases based on anonymised real-world scenarios.
06 · Questions Leaders Ask
AI Compliance & Audit Q&A
Continue Through the Stack
Related AI Governance Layers
Every review, escalation and override from human oversight can become evidence within the compliance audit trail.
L01 · where it all beginsAI Inventory →AI compliance is only as complete as the inventory beneath it. Every obligation needs to connect to a known AI system.
Next step
Could You Prove Your AI Is Compliant Tomorrow?
Strong AI compliance starts before a regulator, customer or auditor asks for evidence.
A structured compliance review can examine obligation mapping, policy enforcement, incident response and audit trails against the five controls in this layer.
The objective is to identify where evidence already exists, where it is fragmented and where gaps could create regulatory or commercial exposure.
Why T3
Why T3 for AI Compliance?
T3 is an award-winning AI implementation partner for high-risk industries.
T3 supports trustworthy AI adoption across the entire lifecycle, from AI inventory and data foundations through security, model assurance, human oversight and AI compliance.
The team designs bespoke AI controls, conducts adversarial red teaming on models and AI systems, and implements end-to-end AI governance operating models aligned with standards including the EU AI Act, ISO/IEC 42001, and NIST AI RMF.
Where off-the-shelf GRC platforms stop, T3 builds the custom controls, integrations and assurance required to fit your technology stack, models and regulatory environment.
Trusted by two-thirds of BigTech and Financial Services, this is where policy meets engineering.