Regulations, Compliance and Acts
One estate, several regulators
A European enterprise of any size is now inside several regimes at once. Data protection applies to personal records wherever they sit, under the European regime and, for Swiss entities, the domestic one (European Union, 2016) (Swiss Confederation, 2020). Network and information security obligations reach further into the supply chain than they used to (European Union, 2022). Financial entities carry operational resilience requirements with their own evidence expectations (European Union, 2022). Information security management has a certifiable standard that customers increasingly ask for by name (International Organization for Standardization, 2022). And the AI Act has arrived on top of all of it (European Union, 2024), with its own amending package still moving (European Union, 2026).
Each of these is usually treated as a project. That is how an organisation ends up with four registers of the same systems, maintained by four teams, agreeing with each other only by accident.
What they have in common
Strip the language and the same four demands appear in each.
An inventory: what information exists, where it sits, and who is accountable for it. Access control: who may reach it, on what basis, and how that is reviewed. A rule that is actually applied: retention, deletion, classification or protection, enforced by a system rather than promised in a policy. And evidence: the ability to show, after the fact, that the first three were true on a particular date.
Build those four once, in the estate rather than in a binder, and each new obligation becomes a mapping exercise rather than a programme.
The AI Act changes the order, not the work
The AI Act is the first regulation many organisations have met that cares less about the model than about the information it was trained on and the information it produces. That makes it an information governance question wearing new clothes.
It also creates the deadline that finally funds work people have deferred for years. An organisation that cannot say what it holds cannot say what its models were trained on, and that answer is now required rather than merely advisable (European Union, 2024). The practical order is therefore inventory first, governance second, AI third, which is the same order that
AI readiness sets out.How we deliver it
As one register and one set of controls, mapped to the acts rather than duplicated per act. We are not a law firm and we do not give legal advice: your counsel decides what the obligations mean for you, and we build the estate that can satisfy them and evidence it.
Two neighbouring pages carry the parts this depends on: records management for the rules themselves, and data privacy for personal data.
Bring us the act that is worrying you and we will tell you honestly how much of it your estate already answers. It is usually more than the compliance team fears and less than the vendor says.