Regulatory guidance
Turn obligations into information and decisions that can be reviewed
Regulation is not a single compliant-or-not checkbox. These guides connect official requirements to inventory, purpose, data, oversight and evidence.
Regulation
4 guides for a clear starting perimeter.
- 01 EU AI ActEU AI Act preparation starts with the system, purpose and organisational roleConnect AI inventory, purpose, human oversight and evidence to the EU AI Act without treating every AI use as high-risk.
- 02 GDPR and LLMsBefore personal data reaches an LLM, the organisation needs a reason and a routeApply purpose, minimisation, route and retention decisions to connected LLM traffic while keeping EU GDPR and UK GDPR contexts distinct.
- 03 NIS2AI routes belong in the wider security and supply-chain pictureRelate connected AI routes, access, incidents and supply-chain evidence to NIS2 security governance without claiming that DUBSAR delivers compliance.
- 04 ISO/IEC 27001AI governance evidence can support an ISMS, but it is not the ISMSUse AI route, policy, access, incident and review evidence as inputs to an information security management system without claiming certification.
The first useful result is a clear, bounded perimeter — not a blanket compliance claim.