Editorial Team

Governome Editorial Team

Articles on Governome are researched and written by the site's editorial team, working from primary sources — statutes, official regulator guidance, and enforcement records — rather than secondary summaries or vendor content. Every guide covering a regulatory requirement is checked against the source before publication and carries a visible "last reviewed" date so you can judge currency for yourself. We're a small, early-stage team and don't yet publish individually named bylines for every contributor; when a specific article has a named external reviewer — outside counsel, a credentialed practitioner — that person is credited directly on the article, in addition to this team byline. See our editorial standards for the full sourcing and review process.

Telecom fraud analysts monitoring call traffic for suspicious AI-generated voice robocalls
Photo: Luke Chesser via Unsplash
The FCC's February 2024 declaratory ruling confirmed that an AI-generated voice counts as an 'artificial voice' under the TCPA, closing an argument a political operative tried to use against a wave of AI-cloned robocalls. A separate rule requiring calls to disclose AI use is still pending, not in force.
Governome Editorial Team · 7 min read
A digital health engineering team preparing an FDA regulatory submission for an AI-enabled diagnostic device
Photo: David Schultz via Unsplash
AI-enabled medical software doesn't get its own FDA lane. It goes through the same device pathways as a stethoscope or an infusion pump, with one addition built for software that keeps learning after it ships — and a real threshold question of whether it's regulated as a device at all.
Governome Editorial Team · 8 min read
An investment adviser's leadership team reviewing marketing claims about their AI-driven investment process
Photo: Campaign Creators via Unsplash
Four SEC cases so far — two investment advisers, a trading-fraud scheme, and a public company's SEC filings — show the agency doesn't need new legislation to charge AI-washing. It just applies the antifraud and disclosure rules that already existed to a specific, checkable capability claim that turned out to be false.
Governome Editorial Team · 8 min read
A credit union compliance team reviewing an AI-driven loan denial in an office
Photo: Vitaly Gariev via Unsplash
A machine-learning underwriting model that can't explain why it declined an application isn't a legal gray area. ECOA has required a specific, accurate reason since 1974, and the CFPB spent 2022 and 2023 explaining exactly how that applies to AI — before withdrawing the explanation, not the rule, in 2025.
Governome Editorial Team · 9 min read
HR staff reviewing algorithmic hiring-tool results in a modern office
Photo: Md Ishak Rahman via Unsplash
The EEOC's AI hiring guidance no longer exists on eeoc.gov. That doesn't mean algorithmic hiring discrimination became legal — it means the agency's own explanation of the law disappeared while the law itself stayed exactly as it was. Here's what the withdrawn guidance said, and what actually still applies.
Governome Editorial Team · 7 min read
A compliance team reviewing AI marketing claims for legal exposure
Photo: Walls.io via Unsplash
There's no federal AI enforcement statute, yet the FTC has extracted settlements — including forced deletion of the AI models themselves — from companies making AI claims. Here's the legal theory behind 'algorithmic deception,' the real case record, and what actually crosses the line.
Governome Editorial Team · 9 min read
Compliance and legal professionals comparing two separate regulatory frameworks in a meeting
Photo: Vitaly Gariev via Unsplash
Article 2(7) of the EU AI Act states plainly that the Act applies without prejudice to the GDPR. The two regimes overlap on automated decision-making and impact assessments, but diverge on scope triggers, risk classification, and enforcement — and meeting one doesn't discharge the other.
Governome Editorial Team · 7 min read
Legal and compliance staff reviewing the commitments in the EU's GPAI Code of Practice
Photo: Anastassia Anufrieva via Unsplash
The EU AI Act's General-Purpose AI Code of Practice gets covered as a headline — 'OpenAI and Anthropic signed a pledge' — when it's actually three chapters of specific, auditable commitments tied to Article 53 and 55 obligations. Here's what a signatory agrees to do, chapter by chapter, and what happens to a provider that skips it or signs only part.
Governome Editorial Team · 7 min read
Legal and compliance team at a non-EU company reviewing whether the EU AI Act applies to their AI system
Photo: Zulfugar Karimov via Unsplash
The EU AI Act doesn't ask where your company is incorporated. Article 2 sets two independent triggers — placing an AI system on the EU market, and having its output used in the Union — and the second one catches non-EU companies with no EU office, no EU sale, and no EU contract at all. Here's how both triggers actually work, what genuinely takes a company out of scope, and what happens next once you're in it.
Governome Editorial Team · 8 min read
European Union policy officials reviewing a phased regulatory implementation schedule
Photo: Zoshua Colah via Unsplash
The EU AI Act's original phased schedule got rewritten mid-2026: the Digital Omnibus on AI pushed the high-risk-system deadline from August 2026 to December 2027, and the product-embedded high-risk deadline from August 2027 to August 2028. Article 5 prohibited practices, GPAI obligations, and the governance framework weren't touched. Here's what's actually in force right now, what moved, what didn't, and why.
Governome Editorial Team · 8 min read
Compliance team calculating potential EU AI Act fine exposure across the tiered penalty structure
Photo: Vitaly Gariev via Unsplash
EU AI Act fines aren't a single €35 million number. Article 99 defines three separate tiers by violation type, Article 101 sets a fourth track for general-purpose AI model providers enforced directly by the Commission, and Article 100 even reaches EU institutions themselves. Here's the full structure, including the SME inversion rule that changes real exposure by orders of magnitude.
Governome Editorial Team · 7 min read
European Commission officials at a policy meeting discussing AI regulation
Photo: Zoshua Colah via Unsplash
The EU AI Office is a European Commission body with real fining power — but only over one specific category of company: providers of general-purpose AI models. Everyone else's high-risk obligations are enforced by their national market surveillance authority instead. Here's the actual jurisdiction map, the fine amounts, and how the Office differs from the AI Board, the Advisory Forum, and the Scientific Panel.
Governome Editorial Team · 7 min read
Compliance team reviewing CE marking documentation for a high-risk AI system before EU market placement
Photo: Vitaly Gariev via Unsplash
CE marking under Article 48 of the EU AI Act is the provider's own compliance signal, applied after conformity assessment — for most high-risk systems, with no external body involved at all. Here's what has to be visible, legible, and indelible, how digital marking works for software-delivered AI, and what importers have to verify before a marked system reaches the EU market.
Governome Editorial Team · 8 min read
Compliance team reviewing conformity assessment documentation for a high-risk AI system
Photo: Zulfugar Karimov via Unsplash
Article 43 conformity assessment has two routes: internal control, which covers most high-risk systems and involves no external reviewer at all, and notified-body assessment, reserved for a narrow slice of biometric systems. Here's how each one actually works, what gets produced, and what forces a redo.
Governome Editorial Team · 7 min read
Engineers and compliance staff reviewing technical documentation for a general-purpose AI model
Photo: selcuk sarikoz via Unsplash
Articles 51 through 56 of the EU AI Act put a separate, model-level obligations track on any provider of a general-purpose AI model — documentation, copyright, and training-data transparency for everyone, with a further layer of testing and incident-reporting duties for the models classified as posing systemic risk. Here's exactly what applies to whom, and what open source does and doesn't exempt.
Governome Editorial Team · 9 min read
Compliance team building an inventory of AI systems across the organization
Photo: Vitaly Gariev via Unsplash
You can't govern, risk-tier, or classify a system you don't know exists. Here's a practical process for building a first AI systems inventory, including the part most guides skip: how to find the AI nobody officially procured.
Governome Editorial Team · 5 min read
Data science team reviewing training data governance documentation
Photo: Jakub Żerdzicki via Unsplash
Article 10 requires documented data governance practices for training, validation, and testing data — provenance, bias examination, gap identification, and relevance to intended purpose — a materially different and broader standard than generic data cleaning. Here's what it actually covers.
Governome Editorial Team · 4 min read
Compliance team assembling technical documentation for a high-risk AI system
Photo: Vitaly Gariev via Unsplash
Article 11 requires a technical documentation file, built before market placement and kept current, that lets regulators verify a high-risk system's compliance. Annex IV's scope is real, but the more expensive mistake is assembling it retroactively instead of incrementally — here's what's actually required.
Governome Editorial Team · 5 min read
Engineers reviewing automated system logs on server monitoring screens
Photo: Tyler via Unsplash
Article 12 requires high-risk AI systems to automatically log events built for three specific purposes — risk identification, post-market monitoring, and deployer oversight — plus an extra minimum spec for remote biometric identification systems. Generic application logs rarely satisfy all three by accident.
Governome Editorial Team · 5 min read
Compliance reviewer checking a technical documentation package against requirements
Photo: Vitaly Gariev via Unsplash
Article 13 requires high-risk AI providers to produce instructions for use that let deployers interpret and correctly apply the system's output. It's routinely confused with end-user AI disclosure rules elsewhere in the Act — here's what it actually requires and why the distinction matters.
Governome Editorial Team · 6 min read
Compliance team reviewing human oversight design for a high-risk AI system
Photo: Benjamin Child via Unsplash
Article 14 requires human oversight measures that give a person real capability to understand, monitor, interpret, and override a high-risk AI system — not a procedural approval step. Here's the five specific capabilities the Act requires, including the automation-bias problem most teams never design for.
Governome Editorial Team · 5 min read
Security analysts reviewing AI-specific threat monitoring for a high-risk system
Photo: Rob Simmons via Unsplash
Article 15 requires high-risk AI systems to meet defined, maintained levels of accuracy, robustness, and cybersecurity — including AI-specific threats like data and model poisoning that a standard application security review typically doesn't test for. Here's what's actually required, and who tends to miss it.
Governome Editorial Team · 5 min read
Legal and compliance professionals reviewing which AI practices are prohibited under the EU AI Act
Photo: Leon Seibert via Unsplash
Article 5 of the EU AI Act prohibits eight specific AI practices — social scoring, manipulative and exploitative AI, untargeted facial-recognition scraping, workplace emotion inference, and more — with no compliance path around them. It's also been in force since February 2025, earlier than almost everything else in the Act.
Governome Editorial Team · 8 min read
Compliance team running a risk management review meeting around a whiteboard
Photo: Fiqih Alfarish via Unsplash
Article 9 requires high-risk AI providers to run a continuous risk management process across the system's entire lifecycle, not produce a one-time document. Here's what the process actually has to include, and the gap auditors flag most.
Governome Editorial Team · 7 min read
Compliance team running a gap assessment against ISO 42001 requirements
Photo: Vitaly Gariev via Unsplash
A gap assessment is the diagnostic step before committing budget to ISO/IEC 42001 certification — a structured comparison against both the clause 4-10 management-system requirements and the Annex A AI-specific controls. Here's how to actually run one, and why an existing ISO 27001 program changes the math significantly.
Governome Editorial Team · 5 min read
Executive leadership team discussing AI governance accountability and risk ownership
Photo: Andreea Avramescu via Unsplash
NIST's own framework describes Govern as cross-cutting, not sequential — it's the organizational accountability and culture layer that makes Map, Measure, and Manage meaningful. Here's what implementing it actually requires, and how to tell a real governance program from a policy document that only looks like one.
Governome Editorial Team · 6 min read
The formal process a high-risk AI system goes through to demonstrate it meets the EU AI Act's requirements — internal self-assessment for most Annex III systems, or third-party assessment where a notified body is involved — before the system can be placed on the market or put into service.
Governome Editorial Team
An AI model trained on broad data at scale that can competently perform a wide range of distinct tasks and be integrated into many different downstream systems — the EU AI Act's term for foundation-model-scale AI, subject to its own separate obligations track rather than the risk-tier system that governs most AI systems.
Governome Editorial Team
Government policy officials in discussion about AI regulation enforcement
Photo: Zac Nielson via Unsplash
Colorado's SB 205 has been amended and delayed more than once since passage. Here's a plain accounting of what changed in the latest round, and which obligations were never in dispute.
Governome Editorial Team · 2 min read
An AI system subject to heightened legal obligations because of what it's used for — not because of the underlying technology — typically because it materially affects access to employment, credit, healthcare, housing, or legal standing.
Governome Editorial Team

ai governance

AI Governance

The structure of accountability, review, and decision rights a company puts in place to control how it builds, buys, and deploys AI systems.
Governome Editorial Team

risk management

Algorithmic Bias

A systematic pattern in a model's outputs that disadvantages a particular group, arising from training data, feature selection, or optimization choices rather than random error.
Governome Editorial Team
Compliance reviewer working through a classification checklist at a desk
Photo: Zulfugar Karimov via Unsplash
Step through this checklist before concluding an AI system falls outside the EU AI Act's high-risk category. It mirrors the actual two-track Article 6 test, not a simplified summary of it.
Governome Editorial Team · 2 min read
Legal and compliance staff drafting an AI acceptable use policy document
Photo: Mana Akbarzadegan via Unsplash
A practical AI acceptable use policy template covering approved tools, data handling rules, prohibited uses, and disclosure requirements. Adapt the bracketed sections before adopting it.
Governome Editorial Team · 3 min read
Board directors in discussion about AI oversight responsibilities
Photo: Christina @ wocintechchat.com M via Unsplash
Board-level AI oversight usually fails in one of two directions: no oversight at all, or oversight so generic it doesn't change what management does. Here's what directors should actually be asking.
Governome Editorial Team · 3 min read
Executive leadership team in a meeting establishing AI governance oversight
Photo: Ninthgrid via Unsplash
Most AI governance committees fail for the same reason most committees fail: no real decision authority, no clear charter, and no named accountability when something goes wrong. Here's what a working one actually looks like.
Governome Editorial Team · 3 min read
Australian government policy officials discussing AI guardrail consultation
Photo: Karson via Unsplash

regulations australia

Australia AI Regulation

Australia has consulted extensively on mandatory AI guardrails modeled conceptually on risk-tiered approaches elsewhere, but hasn't enacted comprehensive AI legislation as of this writing.
Governome Editorial Team · 2 min read
Government policy officials reviewing Canada's stalled federal AI bill
Photo: Ruth Leong via Unsplash

regulations canada

Canada AI Regulation

Canada's proposed Artificial Intelligence and Data Act did not survive the federal legislative process. Here's what actually governs AI in Canada right now.
Governome Editorial Team · 2 min read
UK sector regulators discussing cross-sectoral AI principles
Photo: Kunal Saha via Unsplash

regulations uk

UK AI Regulation

The UK's pro-innovation approach empowers existing regulators like the FCA and ICO to apply shared AI principles within their own sectors, rather than passing a single comprehensive AI law.
Governome Editorial Team · 2 min read
Government policy officials discussing international AI principles
Photo: SAYAN Bhaskar via Unsplash
The OECD AI Principles are the highest-level, most widely adopted AI governance principles internationally — the shared foundation most national AI policies, including the EU AI Act, build on.
Governome Editorial Team · 1 min read
Compliance counsel reviewing California automated decision-making rules
Photo: Amina Atar via Unsplash

regulations us california

California AI Regulations

California regulates AI through several parallel tracks rather than one comprehensive law: CPPA rulemaking on automated decision-making technology, generative AI disclosure statutes, and employment law amendments.
Governome Editorial Team · 2 min read
Risk analysts mapping AI risk factors on a whiteboard during a working session
Photo: Walls.io via Unsplash

frameworks

ISO/IEC 23894

ISO/IEC 23894 adapts ISO 31000 risk management principles specifically for AI systems. It's guidance, not a certifiable standard — but it's the practical reference for the risk-assessment work ISO 42001 requires.
Governome Editorial Team · 2 min read
Legal team reviewing duty-of-care obligations under Colorado's AI Act
Photo: Junior Verhelst via Unsplash

regulations us colorado

Colorado AI Act (SB 205)

Colorado's SB 205 imposes duties of reasonable care on both developers and deployers of high-risk AI systems, with impact assessment and consumer notice requirements tied to consequential decisions.
Governome Editorial Team · 2 min read
Auditor reviewing AI management system documentation for certification
Photo: Zulfugar Karimov via Unsplash

frameworks

ISO/IEC 42001

ISO/IEC 42001 is a certifiable AI management system standard. Unlike the NIST AI RMF, an accredited body can actually audit you against it and issue a certificate.
Governome Editorial Team · 2 min read
US federal agency officials discussing AI enforcement policy
Photo: Noa van Ieperen via Unsplash
There's no single federal AI law in the US. Here's what federal agencies have actually said about AI, and why existing law already covers more AI use cases than most companies assume.
Governome Editorial Team · 3 min read
Risk management team analyzing AI system risk factors in a meeting
Photo: Christina @ wocintechchat.com M via Unsplash
The NIST AI RMF is a voluntary, four-function framework for managing AI risk. It carries real legal weight in the US — Colorado's AI Act ties an affirmative defense directly to it.
Governome Editorial Team · 2 min read
European Union policy officials in discussion at a government building
Photo: Karson via Unsplash

regulations eu

The EU AI Act

The EU AI Act classifies AI systems into risk tiers and phases its obligations in on a multi-year schedule. Here's what's actually in force today, what's still phasing in, and how the risk tiers work.
Governome Editorial Team · 4 min read
Compliance and legal professionals reviewing AI system documentation together
Photo: Sherwin Ker via Unsplash
Article 6 of the EU AI Act classifies a system as high-risk through a combination of Annex I product-safety overlap and Annex III use-case categories. Here's how the two-step test actually applies, with the exemption most teams get wrong.
Governome Editorial Team · 3 min read
Compliance team meeting around a table to review an AI governance framework
Photo: Beatriz Cattel via Unsplash
Most AI governance frameworks fail for the same reason: they're written to look complete in a slide deck, not to survive contact with a real model deployment. Here's what to build first, in what order, and why the sequence matters more than the paperwork.
Governome Editorial Team · 4 min read