Home / Solutions / Regions / Europe
In Europe, the rulebook is written down. Now you have to evidence it.
The EU codified AI governance before anyone else - a risk-based AI Act, an operational-resilience regime for finance, and automated-decision rights under GDPR. The obligations are concrete and the penalties are turnover-based. Five questions European institutions, and the firms that serve them, must be able to answer.
What EU regulators will actually ask
We deploy AI in hiring, credit, and other high-risk uses - and can't show the records the AI Act expects.
EU AI Act · Regulation 2024/1689The AI Act takes a risk-based approach: high-risk systems (recruitment, creditworthiness, essential services, and more) carry obligations for risk management, logging, human oversight, transparency, and post-market monitoring. The Digital Omnibus agreed in May 2026 deferred Annex III high-risk obligations to December 2027, but governance and transparency duties land from August 2, 2026 - and fines reach the higher of €35M or 7% of global turnover.
→ Map registers and risk-classifies every agent, MCP and endpoint; Measure keeps the session-level logs and monitoring evidence the Act expects high-risk operators to maintain.
As a financial entity we must prove operational resilience over every ICT and AI dependency - continuously.
DORA · in force since Jan 17, 2025The Digital Operational Resilience Act binds banks, insurers, investment firms, and 20+ entity types to ICT risk management, a register of ICT third-party arrangements, rapid incident reporting, and resilience testing. Critical ICT third-party providers fall under direct EU oversight, with periodic penalties up to 1% of average daily worldwide turnover.
→ Runtime evidence of what AI-driven ICT components actually do feeds the incident reporting, third-party monitoring, and resilience testing DORA requires - from ground truth, not attestations.
A customer demanded an explanation for an automated decision - and we couldn't give a meaningful one.
GDPR · Articles 22 & 15GDPR restricts solely automated decisions with legal or similarly significant effects, and grants data subjects meaningful information about the logic involved. Supervisory authorities and courts continue to read these rights expansively, and AI-driven decisions sit squarely inside their scope.
→ Action-level decision evidence reconstructs what data drove an automated outcome - the basis for the meaningful explanation the right of access requires.
We are an Indian or US firm serving EU clients - and assumed these rules stop at the EU border.
Extraterritorial reachBoth regimes reach beyond the EU. The AI Act applies where a system's output is used in the Union; DORA reaches ICT third-party providers serving EU financial entities, and can require a designated critical provider to establish an EU subsidiary. The IT and BPO firms serving European banks are squarely in scope.
→ One security layer that produces EU-aligned evidence wherever your agents run - so serving European clients does not mean rebuilding governance per jurisdiction.
Our AI governance is a folder of policies. Enforcement and evidence live nowhere.
AI Act governance · ISO/IEC 42001From August 2, 2026 the AI Act's governance architecture and transparency duties apply, national authorities take up enforcement, and ISO/IEC 42001 is emerging as the management-system standard auditors expect. Written policy without operating evidence will not satisfy any of them.
→ Manage compiles policy into controls that act at the endpoint and gateway, and Measure generates the operating evidence, the proof an AI management system is working, mapped to ISO/IEC 42001 clauses.
Europe: codified, phased, and turnover-weighted
Unlike the US patchwork, the EU wrote the rules down - then phased them in. The dates below are what a European institution, and its service providers, are building toward now.
Jan 17, 2025
DORA applies
Financial-sector ICT resilience in force: third-party registers, incident reporting, resilience testing, board accountability.
Aug 2, 2025
GPAI & governance rules
Obligations for general-purpose AI models and the EU governance structures (AI Office, national authorities) became applicable.
Aug 2, 2026
AI Act - main obligations
The bulk of the Act applies: transparency duties, governance, and enforcement at national and EU level begin.
Dec 2, 2027
High-risk obligations (Annex III)
Deferred by the May 2026 Digital Omnibus: full high-risk duties for use-based systems such as hiring and credit.
AI Act penalties reach the higher of €35M or 7% of global annual turnover; DORA exposes critical ICT providers to periodic penalties up to 1% of average daily worldwide turnover. Dates reflect the Digital Omnibus political agreement reached May 7, 2026, still subject to formal adoption.
Codified rules deserve codified evidence.
We're engaging with European enterprises, and serving the Indian and US firms that answer to EU clients. A demo maps your AI estate against the AI Act, DORA, and GDPR obligations that actually apply to you.