Understanding the European Union’s approach to AI governance, transparency, safety and responsible artificial intelligence

Artificial intelligence is becoming increasingly embedded in business operations, products and services. As organisations adopt generative AI, automated decision-making and AI-powered applications, effective governance, risk management and accountability are becoming increasingly important.

The European Union’s Artificial Intelligence Act (EU AI Act) represents one of the world’s most significant regulatory frameworks for artificial intelligence. Alongside the legislation, the European Commission has developed a General-Purpose AI (GPAI) Code of Practice to help providers of general-purpose AI models meet relevant obligations under the AI Act.

Together, these developments highlight the growing importance of structured AI governance for organisations developing, providing or using AI.


What is the EU AI Act?

The EU AI Act establishes a harmonised legal framework for artificial intelligence across the European Union.

It takes a risk-based approach, with requirements depending on the nature and potential impact of an AI system. Areas addressed by the legislation include:

  • AI risk management
  • Transparency
  • Data governance
  • Human oversight
  • Accuracy and robustness
  • Cybersecurity
  • Technical documentation
  • Record keeping
  • AI literacy
  • Fundamental rights
  • Incident management

The legislation is being introduced progressively, with provisions for general-purpose AI models becoming applicable from August 2025 and further requirements and enforcement developing as the framework is implemented.


What is the General-Purpose AI Code of Practice?

The General-Purpose AI Code of Practice was developed at European level through a multi-stakeholder process involving industry, academia, civil society, rightsholders, Member States and independent experts.

The Code provides a voluntary means for providers of general-purpose AI models to demonstrate compliance with relevant obligations under the EU AI Act.

It focuses on three principal areas:

Transparency

Providers are expected to maintain appropriate technical documentation and provide relevant information about their models to downstream providers and authorities.

Copyright

The Code addresses policies relating to copyright and information concerning content used to train general-purpose AI models.

Safety and Security

For general-purpose AI models presenting systemic risk, the Code includes measures relating to risk assessment and mitigation, model evaluation, incident reporting, cybersecurity and systemic-risk management


Is the Code mandatory?

An important distinction is that the General-Purpose AI Code of Practice itself is voluntary. It does not create separate legal obligations beyond those established by the EU AI Act.

However, the underlying applicable requirements of the EU AI Act are legally binding, and enforcement of the relevant GPAI provisions began in August 2026.

The Code therefore provides an important practical framework for relevant AI providers seeking to demonstrate compliance.
What does this mean for organisations using AI?


What does this mean for organisations using AI?

Although the GPAI Code is primarily aimed at providers of general-purpose AI models, the wider EU AI Act has implications for organisations developing, procuring and deploying AI.

Organisations should consider questions such as:

  • What AI systems are we currently using?
  • What data is being processed?
  • What risks could arise from their use?
  • How are third-party AI providers assessed?
  • Who is responsible for AI governance?
  • How are AI-related incidents managed?
  • Is appropriate human oversight in place?
  • Are employees sufficiently trained?
  • How are AI policies, controls and responsibilities documented?

AI governance can therefore extend beyond IT, involving senior management, compliance, information security, data protection, procurement, legal and operational teams.


ISO 42001 and Artificial Intelligence Management Systems

ISO/IEC 42001 provides an internationally recognised management-system framework specifically designed for Artificial Intelligence Management Systems (AIMS).

An ISO 42001-based management system can help organisations establish a structured and repeatable approach to AI governance, including:

  • AI policies and objectives
  • AI risk assessment and risk treatment
  • AI governance and accountability
  • Data governance
  • AI lifecycle management
  • Supplier and third-party management
  • Human oversight
  • Transparency and responsible AI
  • Internal audits and management reviews
  • Continual improvement

While the EU AI Act establishes legal requirements for applicable organisations and AI systems, ISO 42001 provides a structured management-system framework that can help organisations identify, manage, monitor and continually improve their approach to AI-related risks and opportunities.


How Vassallo Associates can help

Vassallo Associates provides Artificial Intelligence Management System consultancy, audit and support services for organisations looking to establish a structured approach to AI governance and ISO 42001.

Our services include:

  • ISO 42001 gap assessments
  • AI Management System implementation
  • AI risk assessment and risk management
  • AI policies and governance frameworks
  • Management system documentation
  • Internal audits
  • Certification preparation
  • Continual improvement
  • Integration with existing ISO management systems

Our approach focuses on translating AI governance requirements into practical policies, processes and controls that can be embedded within an organisation’s existing management and compliance framework.


Preparing for the future of AI governance

The regulatory landscape surrounding artificial intelligence continues to develop, with further provisions of the EU AI Act becoming applicable and enforcement expanding.

Organisations should therefore consider how AI is being used across their business and whether appropriate governance, risk management and accountability processes are in place.

A structured ISO 42001 Artificial Intelligence Management System can provide a practical foundation for managing AI responsibly while supporting an organisation’s wider governance and compliance objectives.

Vassallo Associates can support your organisation in developing and implementing an Artificial Intelligence Management System aligned with ISO 42001.


Find out more

ISO 42001 Artificial Intelligence Audit and Support

Speak to Vassallo Associates about how an ISO 42001 Artificial Intelligence Management System could support your organisation’s approach to AI governance, risk management and compliance.