Strategic Focus: Regulatory Radar And The Next Wave Of AI Risk Compliance

Renee Murphy

Renee Murphy

Katelyn Johnson

Katelyn Johnson

16 Oct, 2024

Access this research

Access all Corporate Risk Leaders content with a strategic subscription or buy this single report

Need help or have a question about this report? Contact us for assistance

Executive Summary

The EU’s Artificial Intelligence Act took effect on August 1, 2024, with firms facing enforcement around most requirements from August 1, 2026. The regulation transcends borders, applying to systems used in the EU, regardless of whether the providers, deployers, importers or distributors are based in the region themselves. With AI having rapidly permeated business activities and tasks, firms must now consider the implications of the EU AI Act and understand how to remain compliant. In this report, we provide risk and compliance executives with an overview of the Act and offer guidance on how to manage these new compliance risks.

Navigating the EU AI Act: a guide to AI compliance and risk
Businesses need to adapt – and governance is the answer
Risk management looms large in the legislation
Risk management is both a requirement – and the solution
Figure 1. The EU AI Act categorizes AI implementations into four risk categories

About the Authors

Renee Murphy

Renee Murphy

Principal Analyst

Renee Murphy is a Principal Analyst at Verdantix. Her current research targets GRC, with a particular focus on the integration of ESG into GRC. Prior to joining Verdantix, Ren...

Katelyn Johnson

Katelyn Johnson

Senior Manager

Katelyn is a Senior Manager at Verdantix, specializing in enterprise risk management and external risk and resilience. She helps executives navigate today’s evolving ris...

Other related content

Webinar
Third-Party Risk Management
Enterprise Risk & GRC
Corporate Risk Leaders
Decoding Risk Intelligence: What The Fi...

Risk leaders are being asked to monitor a widening range of external threats, many of which overlap in ways that make them difficult to track in isolation. Cybersecurity remains fr...

Upcoming / 04 November, 2026

Blog
Corporate Risk Leaders
Third-Party Risk Management
Where Your Data Live Is Only Half The R...

Geopolitical risk is increasingly becoming a third-party risk, and data sovereignty is emerging as a critical blind spot. The 2026 Verdantix global corporate survey found that 75...

02 October, 2026

Blog
Corporate Risk Leaders
Third-Party Risk Management
FCA, PRA And Bank of England Seek To Tu...

From March 18, 2027, UK firms will be required to report operational incidents within 24 hours of determining that a materiality threshold has been met, while the limit for payment...

02 October, 2026

Blog
Corporate Risk Leaders
Third-Party Risk Management
AI Platforms & Applications
Singapore Raises The Bar For AI Risk Ma...

In December 2025, Verdantix examined Singapore’s proposed approach to AI risk management in financial services following the Monetary Authority of Singapore's (MAS) launch of a ...

30 September, 2026

Blog
Corporate Risk Leaders
The US’s Hallucinated Nuclear Threat Sh...

In late September 2026, it came to light that a US intelligence report detailing the movements of Chinese naval vessels in the Middle East in spring 2026 identified nuclear-grade...

25 September, 2026

Blog
Corporate Risk Leaders
MCP Servers Are Closing The AI Context ...

2026 has brought a new trend to the governance, risk and compliance (GRC) software market. In April, Optro launched Model Context Protocol (MCP) server capabilities, and SureCloud ...

24 September, 2026