Schedule a meeting

AI governance and EU AI Act compliance

Your obligations under the EU AI Act, GDPR, DORA and NIS2, mapped to the AI systems you actually run.

Overview

Lindstead's AI governance work maps every AI system to the obligations that apply to it: the EU AI Act role and risk class, GDPR processing, DORA and NIS2 third-party requirements. It records data flows and access rights, identifies gaps, and produces a governance framework the organisation can maintain.

Key questions

  • Are we a provider or a deployer under the EU AI Act, and for which systems?
  • Which of our AI systems are high-risk, and from when do obligations apply?
  • Who can access our data inside each AI provider, and under which law?
  • Can we exit each AI provider as DORA and NIS2 require?

Approach

  • AI system inventory All AI systems in use or planned are recorded with purpose, data, provider and owner.
  • Data-flow and access review For each system, where data goes, who can access it and which jurisdictions apply, including exposure to non-EU access laws.
  • Regulatory mapping Each system is mapped to its AI Act role and risk class, GDPR basis and DORA or NIS2 requirements, with deadlines after the Digital Omnibus.

Deliverables

  • AI system register An inventory of AI systems with owner, purpose, data and provider.
  • Regulatory map Obligations per system under the AI Act, GDPR, DORA and NIS2, with dates.
  • Governance framework Roles, controls and review cadence the organisation can run itself.

Frequently asked questions

  • After the Digital Omnibus (Regulation (EU) 2026/1744), obligations for high-risk systems listed in Annex III apply from 2 December 2027, and for AI in products covered by Annex I from 2 August 2028. Transparency obligations under Article 50 apply from 2 August 2026.

  • An inventory of AI systems, a review of data flows and access rights, a mapping of legal obligations per system, and a governance framework with roles, controls and review points.

  • No. The drivers for in-house deployment are data control, DORA and NIS2 exit requirements, and exposure to non-EU data-access legislation.

Discuss regulation and risk with Lindstead.

Schedule an introductory meeting with our team.