AI Compliance FAQ
Short, sourced answers to the most-asked questions about AI compliance. Frameworks, vendors, cost, and methodology. Every claim traceable to a public source.
Frameworks & regulations
22 answers
- Frameworks & regulationsWhat is ISO/IEC 42001?
The first international management-system standard for AI, published December 2023 — certifiable, auditable, and already adopted by major AI vendors.
- Frameworks & regulationsEU AI Act fines and penalties
Non-compliance with the EU AI Act can cost up to EUR 35 million or 7 percent of global annual turnover — higher than GDPR's 4 percent cap.
- Frameworks & regulationsNIST AI RMF vs ISO/IEC 42001
Two of the most-referenced AI governance frameworks — one is a voluntary US framework, the other an international standard that can be certified. Most mature programs use both.
- Frameworks & regulationsWho needs to comply with the EU AI Act?
If your AI system lands in the EU market or its output is used in the EU, you are in scope — regardless of where your company is headquartered.
- Frameworks & regulationsWhen does the Colorado AI Act take effect?
Colorado SB 24-205 applies 30 June 2026 (delayed from 1 February 2026 by SB 25B-004) and imposes duties on both developers and deployers of high-risk AI used for consequential decisions.
- Frameworks & regulationsGDPR Article 22: automated decision-making explained
Article 22 of the GDPR gives individuals the right not to be subject to a decision based solely on automated processing that produces legal or similarly significant effects — with three narrow exceptions.
- Frameworks & regulationsNYC Local Law 144 bias audit: what employers must do
NYC employers using AEDTs must commission an independent bias audit each year, post a public summary, and notify candidates — enforced by DCWP since 5 July 2023 with $500–$1,500 per-day penalties.
- Frameworks & regulationsEU AI Act prohibited practices (Article 5)
Eight categories of AI practice are outright banned across the EU under Article 5 of the AI Act — enforced from 2 February 2025, with the highest fine tier (EUR 35M or 7% of turnover).
- Frameworks & regulationsEU AI Act high-risk AI systems: scope and obligations
High-risk AI systems under the EU AI Act face the heaviest obligations — risk management, data governance, technical documentation, human oversight, conformity assessment — with most rules applying from 2 August 2026.
- Frameworks & regulationsWhat is SEC AI Disclosure?
The SEC has brought enforcement actions and issued guidance requiring public companies to accurately disclose their use of AI in securities filings, avoid "AI washing," and ensure
- Frameworks & regulationsWhat is HIPAA?
HIPAA governs the privacy and security of Protected Health Information (PHI) in the United States. AI vendors operating in healthcare must meet HIPAA Security Rule requirements (ac
- Frameworks & regulationsWhat is UK AI Framework?
The UK's pro-innovation, context-specific approach to AI regulation relies on existing regulators (ICO, FCA, CMA, MHRA, Ofcom) applying five cross-sectoral principles: safety; tran
- Frameworks & regulationsWhat is SOC 2?
SOC 2 is an AICPA auditing standard for service organizations, evaluating controls relevant to security, availability, processing integrity, confidentiality, and privacy. While not
- Frameworks & regulationsWhat is NYC LL 144?
New York City Local Law 144 of 2021 prohibits employers and employment agencies from using an automated employment decision tool (AEDT) to screen a candidate or employee for a posi
- Frameworks & regulationsWhat is ISO/IEC 42001?
ISO/IEC 42001:2023 is the first international management-system standard for artificial intelligence, published in December 2023 jointly by ISO and IEC. It specifies requirements f
- Frameworks & regulationsWhat is ISO 27001?
ISO/IEC 27001 is the international standard for information security management systems (ISMS). It complements ISO/IEC 42001 (AI management systems) and is often held by AI governa
- Frameworks & regulationsWhat is PCI DSS?
PCI DSS governs the handling of payment card data. AI vendors serving fintech, retail, and payment processors often need to demonstrate PCI DSS alignment when their platforms touch
- Frameworks & regulationsWhat is FedRAMP?
FedRAMP is the U.S. federal program that standardizes security assessment, authorization, and continuous monitoring for cloud services used by federal agencies. AI governance vendo
- Frameworks & regulationsWhat is EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the world's first comprehensive horizontal regulation of artificial intelligence systems. It entered into force on August 1, 2024 and a
- Frameworks & regulationsWhat is NIST AI RMF?
The NIST AI Risk Management Framework (AI RMF 1.0) was published by the U.S. National Institute of Standards and Technology in January 2023, with a Generative AI Profile (NIST-AI-6
- Frameworks & regulationsWhat is GDPR Art. 22?
Article 22 of the EU General Data Protection Regulation gives data subjects the right not to be subject to a decision based solely on automated processing — including profiling — t
- Frameworks & regulationsWhat is Colorado AI Act?
Colorado SB 24-205, the Colorado Artificial Intelligence Act, was signed into law in May 2024 and takes effect on February 1, 2026. It is the first comprehensive U.S. state law reg
Cost & pricing
1 answer
Glossary
1 answer
How this site works
3 answers
- How this site worksHow do you rank AI compliance vendors?
Editorial best-of rankings, head-to-head comparison verdicts, and written commentary reflect editorial judgment based on public evidence only and cannot be bought. Vendors can pay for a Featured slot in directory listings; every Featured slot is clearly labeled.
- How this site worksSOC 2 vs ISO/IEC 42001: which do AI vendors need?
SOC 2 and ISO/IEC 42001 are not substitutes — one attests to information security and operational trust, the other to AI-specific governance. Mature AI vendors carry both.
- How this site worksHow AI Compliance Vendors stays independent
Editorial best-of rankings and comparison verdicts are not for sale. Vendors can pay only for a clearly labeled Featured slot in directory listings.
Per-vendor evaluation questions
55 auto-generated pages — one per vendor in the directory. Procurement-oriented questions (frameworks, certifications, pricing, red-teaming, references).
Per-vendor evaluation questions
55 auto-generated pages — one per vendor in the directory. Procurement-oriented questions (frameworks, certifications, pricing, red-teaming, references).
- How to evaluate 2021.AI
- How to evaluate Aporia
- How to evaluate Arize AI
- How to evaluate Arthur
- How to evaluate BABL AI
- How to evaluate BigID
- How to evaluate Braintrust
- How to evaluate CalypsoAI
- How to evaluate Citrusˣ
- How to evaluate Collibra AI Governance
- How to evaluate Cranium
- How to evaluate Credo AI
- How to evaluate Dataiku Govern
- How to evaluate DataRobot
- How to evaluate Drata
- How to evaluate Enzai
- How to evaluate Fairly AI
- How to evaluate FairNow
- How to evaluate Fiddler AI
- How to evaluate Galileo
- How to evaluate Giskard
- How to evaluate HiddenLayer
- How to evaluate Holistic AI
- How to evaluate IBM watsonx.governance
- How to evaluate Knostic
- How to evaluate Lakera
- How to evaluate Langfuse
- How to evaluate LangSmith
- How to evaluate Lasso Security
- How to evaluate LatticeFlow AI
- How to evaluate Luminos.Law (ZwillGen AI Division)
- How to evaluate Mind Foundry
- How to evaluate ModelOp
- How to evaluate Modulos AI Governance
- How to evaluate Monitaur
- How to evaluate Naaia
- How to evaluate OneTrust AI Governance
- How to evaluate ORCAA
- How to evaluate Patronus AI
- How to evaluate Pillar Security
- How to evaluate Prompt Security
- How to evaluate Promptfoo
- How to evaluate Protect AI
- How to evaluate Robust Intelligence
- How to evaluate Saidot
- How to evaluate Scrut Automation
- How to evaluate Securiti Data Command Center
- How to evaluate ServiceNow AI Control Tower
- How to evaluate TrojAI
- How to evaluate TrustArc
- How to evaluate Trustible
- How to evaluate ValidMind
- How to evaluate Vanta
- How to evaluate Weights & Biases Weave
- How to evaluate WhyLabs