Preparing for AI Compliance: What You Actually Need

The EU AI Act is in force. NIST published its AI RMF. Most teams aren't ready. Here's what the regulations require and how to meet them.

Share this article

Preparing for AI Compliance: What You Actually Need

The EU AI Act entered into force in August 2024, with high-risk obligations phasing in through 2026. NIST published the AI Risk Management Framework. China's Generative AI Measures are operational. Brazil, Canada, and India have bills in progress.

AI compliance is no longer theoretical. Most teams aren't ready.

What the regulations require

1. Risk classification. The EU AI Act classifies AI systems by risk tier: unacceptable, high, limited, minimal. Your first task is determining where your system falls. Customer-facing AI assistants are typically "limited risk." Systems making decisions about employment, credit, or education are "high risk" with substantially greater requirements.

2. Transparency obligations. Limited-risk systems must disclose that users are interacting with AI. High-risk systems must explain how decisions are made. You need: a disclosure mechanism in your interface, decision logging with reasoning traces, and a pathway for users to request human review.

3. Technical documentation. High-risk systems require documentation covering intended purpose, system architecture, training data description, performance metrics, and known limitations. This isn't a formality. Auditors will read it.

4. Quality management. A documented quality management system covering risk assessment, testing procedures, and ongoing monitoring. This must reflect actual practice, not aspirations.

5. Post-market monitoring. You must monitor your AI system in production. Behavioral monitoring, not just uptime. Are outputs drifting from expected patterns? Are safety properties holding? Are new failure modes emerging?

Where most teams fall short

The gap is usually between "we have guidelines" and "we can prove compliance." Most organizations have informal rules about how their AI should behave. Few have those rules documented in a format that satisfies regulatory scrutiny. Fewer still can produce an audit trail showing that the rules were enforced, when, and how.

How Creed Space addresses each requirement

Constitutional documentation. Your creeds are your behavioral specification. They document what rules govern the AI, why, and with what priority. They're machine-readable, versioned, and exportable as compliance artifacts.

Decision audit trails. Every Policy Decision Point evaluation is logged with the principle that applied, the confidence level, and the alternatives considered. This is your explainability layer, generated automatically from normal operation.

Real-time monitoring. The safety stack monitors behavioral properties in production: drift detection, anomaly flagging, runtime signals. This is post-market monitoring built into the platform, not bolted on after the fact.

Compliance export. Creed Space generates compliance documentation aligned with EU AI Act requirements. Not a template you fill in: a reflection of your actual system configuration, generated from your live creeds and decision logs.

Risk assessment tooling. The Safety Globe runs automated scenario testing against your creed configuration, identifying coverage gaps before auditors do.

The practical advice

Start with your creeds. Document what values your AI should follow. Make those values machine-readable and enforceable. Build the audit trail from day one.

Compliance is easier to build in than to bolt on. The organizations that treat safety infrastructure as a launch requirement, rather than a post-incident addition, will spend less time and money reaching compliance than those who retrofit.

Nell Watson
Founder, Creed Space

AI ethics researcher and IEEE Fellow. Author of Taming the Machine.