Knowledge Base → Frameworks & law → 🤖 AI Governance & Security
🤖 AI Governance & Security
Covers the EU AI Act (Reg. (EU) 2024/1689) plus global AI governance (NIST AI RMF, ISO/IEC 42001), the AI–data-protection interface (Art. 22 automated decisions / profiling — see Data Subject Rights) and AI security (adversarial ML, model privacy).
EU AI Act (Reg. (EU) 2024/1689) and wider AI-governance resources — texts, guidance and the data-protection interface.
Key resources (13)
- NIST — AI Risk Management Framework (AI RMF)
- ISO/IEC 42001 — AI management system (citation)
- EU AI Act (Reg. (EU) 2024/1689) — full text
- Proton country dashboard: Mapping the spread of age-verification laws — EU: General-Purpose AI Code of Practice now available
- AI Models for Medicine Google published — KI-Modelle für die Medizin: Google veröffentlicht MedGemma 1.5 und MedASR
- KI Modelle pbD node — Germany: BSI - Consultation on the data protection-compliant handling of personal data in AI models
- Germany: BfDI. — Germany: BfDI. KI-Fraegnkatalog - AI Questions Catalog
- Unerwartete Roaming-Rechnung wegen Chatbot-Fehler: Wer haftet? - Kassensturz Espresso - SRF — Roaming Rechnung wegen Chatbot Fehler (AI)
- Orientierungshilfe für KI-Projekte: IT-Planungsrat veröffentlicht Anonymisierungsleitfaden
- Amazon: “AWS Cloud Adoption Framework for Artificial Intelligence, Machine Learning, and ( Generative AI”, Amazon White Paper, 2024. — Cisco: “The Cisco Responsible AI Framework” ( 2024.
- Australian Signals Directorate: “An introduction to Artificial Intelligence” ( 2023. — NIST AI 100-1: ( “AI Risk Management Framework (AI RMF 1.0)”, 2023.
- EU AI Act has - Regulation 2024/1689
- Information gathering with AI: Being plausible is not enough
- ISO/IEC 22989:2022: ( “Information technology — Artificial intelligence — Artificial intelligence concepts and terminology”. — Regulation (EU) 20241689 ( of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 3002008, (EU) No 1672013, (EU) No 1682013, (EU) 2018858, (EU) 20181139 and (EU) 20192144 and Directives 201490EU, (EU) 2016797 and (EU) 20201828 (Artificial Intelligence Act).
- NIST AI 100-2 E2023: ( “Adversarial Machine Learning: A Taxonomy and Terminology of Attacks and Mitigations”. — Amazon: “AWS Cloud Adoption Framework for Artificial Intelligence, Machine Learning, and ( Generative AI”, Amazon White Paper, 2024.
- Regulation (EU) 2024/1689 ( of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence and amending Regulations (EC) No 300/2008, (EU) No 167 — Informative references ETSI TR 104 128: “Securing Artificial Intelligence (SAI); Guide to Cyber Security for AI Models and Systems”.
🆕 Recent additions (auto)
- 2026-09-07 Qualification and Quantification of Risks under the AI Regulation — The article ‘Qualifying and Quantifying Risk under the EU AI Act’, published here, addresses questions regarding risks under the AI Regulation. The AI Regulation pursues a risk-based approach in regulating AI systems, whereby the intensity of regulation is adjusted according to the risks emanating from the systems. Although the definition of the term ‘risk’ in the AI Act (as a combination of probability and severity of harm) implies quantification,… (Datenzirkus (BvD))
- 2026-09-04 Digital Risk Report, September 2026 — The September edition of the Digital Risk Report covers the evolving intersection of artificial intelligence (AI), financial technology, and data privacy regulation. This month, we examine key considerations for allocating AI-generated intellectual property rights in commercial and licensing agreements and analyze the growing debate over the AMA’s new AI billing codes and their implications for reimbursement, liability, and health care compliance……By: Shumaker, Loop & Kendrick, LLP (Privacy RSS Feed)
- 2026-09-04 Negotiating HR Vendor Agreements in the Age of AI: Key Provisions and Considerations — Artificial intelligence is rapidly transforming human resources operations. From AI-powered recruiting platforms that screen résumés and rank candidates, to onboarding tools that personalize new-hire experiences, performance management systems that predict attrition, identity verification solutions using biometrics, and platforms administering ERISA-governed benefit plans, employers are increasingly relying on third-party vendors whose products are built on or enabled by AI….By: Jackson Lewis… (Privacy RSS Feed)
- 2026-09-04 Patient rights and AI medical chatbots alignment between the GDPR and EU AI Act (IAPP — News)
- 2026-09-04 The OpenAI TanStack incident shows why EU AI Act deployers need supplier incident evidence (IAPP — News)
- 2026-08-27 LLM-Based Social Engineering Scams — OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving cryptocurrencies and spot gold trading (Schneier on Security)
- 2026-08-27 What Zero Trust Can Teach Us About AI Watermarks (Cloud Security Alliance)
Curated from the personal reference library. Add items directly on this page.