The rules that reach you when your team uses AI
Seven frameworks govern the use of artificial intelligence in a European company today. No organisation has to meet all of them, and almost none knows which ones apply.
The seven frameworks, one by one
What each one requires, who it applies to, and what has to change day to day.
GDPR
The European data protection regulation. It applies to any company processing data about people in the EU, with no size threshold.
What the GDPR requires when you use AI →EU AI Act
The European artificial intelligence regulation. Its literacy and transparency obligations are already enforceable.
What the EU AI Act requires of my company →ISO 42001
The only certifiable AI management standard. Voluntary, but increasingly a customer requirement.
What ISO 42001 is →NIS2
The European cybersecurity directive. It makes the management body accountable and reaches the supply chain.
What NIS2 requires, and where Spain stands →ENS
Spain's National Security Framework. Mandatory for the Spanish public sector and anyone supplying it.
HIPAA
The United States health information regime. It applies if you handle patient clinical information in the US.
NIST AI RMF
The voluntary AI risk management framework. The starting point when nothing is in place.
How to start with the NIST AI RMF →
Which ones apply to me?
If you operate in the European Union, the GDPR and the EU AI Act almost certainly apply to you. NIS2 and the ENS depend on your sector: NIS2 reaches eighteen essential sectors from 50 employees, and the ENS anyone working with the Spanish public sector. ISO 42001, HIPAA and the NIST AI RMF usually arrive another way: a customer, a parent company or a tender asks for them.