Strategic Focus: Regulatory Radar And The Next Wave Of AI Risk Compliance

Renee Murphy

Renee Murphy

Katelyn Johnson

Katelyn Johnson

16 Oct, 2024

Access this research

Access all Corporate Risk Leaders content with a strategic subscription or buy this single report

Need help or have a question about this report? Contact us for assistance

Executive Summary

The EU’s Artificial Intelligence Act took effect on August 1, 2024, with firms facing enforcement around most requirements from August 1, 2026. The regulation transcends borders, applying to systems used in the EU, regardless of whether the providers, deployers, importers or distributors are based in the region themselves. With AI having rapidly permeated business activities and tasks, firms must now consider the implications of the EU AI Act and understand how to remain compliant. In this report, we provide risk and compliance executives with an overview of the Act and offer guidance on how to manage these new compliance risks.

Navigating the EU AI Act: a guide to AI compliance and risk
Businesses need to adapt – and governance is the answer
Risk management looms large in the legislation
Risk management is both a requirement – and the solution
Figure 1. The EU AI Act categorizes AI implementations into four risk categories

About the Authors

Renee Murphy

Renee Murphy

Principal Analyst

Renee Murphy is a Principal Analyst at Verdantix. Her current research targets GRC, with a particular focus on the integration of ESG into GRC. Prior to joining Verdantix, Ren...

Katelyn Johnson

Katelyn Johnson

Senior Manager

Katelyn is a Senior Manager at Verdantix, specializing in enterprise risk management and external risk and resilience. She helps executives navigate today’s evolving ris...

Other related content

Webinar
Third-Party Risk Management
Enterprise Risk & GRC
Corporate Risk Leaders
AI Platforms & Applications
AI-Driven Risk Management: Opportunity ...

The relationship between AI and risk in the software landscape is becoming increasingly central as organisations embed these capabilities into core governance, risk, and compliance...

Upcoming / 24 June, 2026

Blog
Corporate Risk Leaders
Where Is Cyber Security Heading? Key Ta...

In an era defined by AI, cyber security has become the least forgiving domain for CISOs and technical risk leads. Converging pressures from strict data security regulations, more s...

21 May, 2026

Blog
Corporate Risk Leaders
Middle East Crisis In Focus: Second-Ord...

The outbreak of the Israel/US-Iran conflict in early 2026 is not only a Middle East story. For risk professionals, procurement leaders and boards with global supply chain exposure,...

20 May, 2026

Blog
Corporate Risk Leaders
The Evolution Of The GRC Industry Signa...

The volume of media announcements from governance, risk and compliance (GRC) software vendors over recent months indicates that the industry is going through a transformation. Whil...

15 May, 2026

Blog
Corporate Risk Leaders
Computer Viruses, Real Viruses And War:...

During the month of April, two events occurred that may have left risk officers reeling. The first: AI firm Anthropic discovered that its Claude Mythos model had an unprecedented a...

13 May, 2026

Webinar
Enterprise Risk & GRC
Corporate Risk Leaders
Closing The Regulatory And Reputational...

Many organisations believe their risk intelligence capabilities are fit for purpose – but regulatory and reputational risk intelligence solve two very different problems, and both ...

14 May, 2026