AI compliance is the routine work of making sure the AI your organisation builds or uses stays inside the law, matches what you tell people it does, and can be explained when someone asks. It is not a single certificate. It is a set of habits: knowing what you use, judging how risky each use is, keeping the right records, and giving people the notices and choices the law requires.
Two roles the law cares about
Almost every AI rule sorts you into one of two roles, and many organisations are both at once.
- Builder (the EU AI Act calls this the "provider"; Colorado and Texas say "developer"): you train, fine-tune or substantially modify a model or system, or you put one on the market under your own name. Builders carry the heaviest duties: technical documentation, testing, disclosures to customers, and in some cases registration.
- Deployer (also "user" or "employer" in some state laws): you use an AI system in your own operations, for example a hiring screen, a support chatbot or a credit model. Deployers must use the system as instructed, tell affected people, keep logs, and keep a human in the loop where the law says so.
If you take a vendor's model and wrap it in your own product, retrain it on your data, or change its intended purpose, several laws treat you as a builder of the new system. The EU AI Act says this explicitly for anyone who makes a "substantial modification" or rebrands a high-risk system (Article 25).
What compliance actually covers
Most frameworks, whether the EU AI Act, the NIST AI Risk Management Framework or ISO/IEC 42001, touch the same ten areas. They are the ten domains of the assessment in this Academy:
- Inventory: a list of every AI tool and model in use.
- Risk classification: which uses are prohibited, high-risk, or low-risk.
- Data and privacy: what personal data goes in, and on what legal basis.
- Transparency: telling people when AI is involved or content is synthetic.
- Human oversight: a person who can check, override or stop the system.
- Fairness: testing for discriminatory outcomes.
- Security and robustness: resisting attacks and behaving predictably.
- Vendors and contracts: knowing what your suppliers promise and prove.
- Governance: a named owner, a policy, and a way to handle incidents.
- Training: staff who understand the tools they use.
Why the order matters
You cannot classify risk without an inventory, and you cannot prove oversight without records. That is why the assessment caps your maturity level at "Emerging" until inventory and risk classification are in reasonable shape. Start there; the rest builds on it.
A note on advice
This Academy explains rules in plain words and points you to official sources. It is general information, not legal advice. Laws change, they differ by place and by sector, and how they apply depends on facts only you and your counsel know. Use the lessons to ask better questions, then confirm the answers that matter with a qualified professional.