AI Governance in 2026: Navigating the EU AI Act, GDPR, and SOC 2 Compliance
The EU AI Act now applies to high-risk systems. GDPR's reach into automated decision-making is growing. And SOC 2 auditors are starting to ask about AI model governance. Here's what enterprise AI teams need to do before their next audit.
Norvik Research & Practice Team
The regulatory environment for enterprise AI has gotten significantly more complex in the past twelve months. The EU AI Act's requirements for high-risk AI systems are now enforceable. GDPR's Article 22 — the right not to be subject to solely automated decisions — is being interpreted more broadly by EU data protection authorities. SOC 2 frameworks are also expanding to include AI-specific controls. Organizations that treated AI governance as a future concern now face active audit exposure.
EU AI Act: What High-Risk Means in Practice
The Act defines high-risk AI systems across eight domains, including employment, credit scoring, and critical infrastructure. If your AI system makes or significantly influences decisions about someone's employment, creditworthiness, or access to essential services, it likely qualifies. The obligations are clear: maintain technical documentation, implement human oversight, log system activity, and complete conformity assessments before deployment.
GDPR and Automated Decision-Making
Article 22 gives EU data subjects the right not to be subject to decisions based solely on automated processing when those decisions have legal or similarly significant effects. Most enterprise AI systems are designed to support human decisions, not replace them. But documentation of that oversight needs to be solid. 'A human reviewed it' is no longer enough. Regulators want proof that the human had real authority to override the system — and that overrides actually happen at a meaningful rate.
Model Cards and the Documentation Standard
Model cards — structured documentation covering a model's intended use, training data, performance characteristics, and known limitations — have moved from best practice to regulatory requirement. The EU AI Act's technical documentation requirements map closely to the model card format. A well-maintained model card for a high-risk AI system should cover: the business purpose and the decision it informs, training data sources and any known biases, performance metrics across demographic subgroups, conditions where performance degrades, and the human oversight mechanisms in place. For organizations deploying multiple AI systems, a centralized model registry that stores these cards and tracks version history is no longer optional.
The Practical Audit Trail
When a SOC 2 auditor or data protection authority requests evidence about your AI system, they want proof that the controls you claim are actually working. Here's what they expect to see:
- Decision logs: every AI-informed decision logged with input data, model output, confidence score, and any human override
- Model versioning: a complete record of which model version was live at every point in time
- Incident records: documentation of every case where the model produced incorrect or harmful output, plus the remediation steps taken
- Oversight evidence: proof that human review is actually happening — override rates, review timestamps, and reviewer identities, not just a checkbox
A 90-Day Governance Readiness Sprint
Organizations approaching their first AI-related regulatory audit typically have 60–90 days to close the important gaps. The sprint follows a predictable sequence. In week one, inventory all AI systems in production. In weeks two and three, assess each system against the EU AI Act risk tiers and GDPR Article 22 obligations. In weeks four through eight, prioritize the highest-risk systems for documentation work. By week twelve, implement monitoring and human oversight for any system that lacks it. The goal isn't perfection — it's defensible compliance: the ability to show that material risks are identified, controlled, and monitored.
The three pillars of AI governance — explainability, documentation, and human oversight — remain the core of every major regulatory framework, from the EU AI Act to emerging US state legislation.
Sources & Further Reading
The Hidden Costs of AI Proof-of-Concepts: Why 85% Never Reach Production
January 2026How to Build an AI Center of Excellence Without Hiring an Army
October 2025Agentic AI in the Enterprise: Moving Beyond Chatbots to Autonomous Workflows
April 2026Ready to turn this into results?
Our team works with enterprise clients to implement the approaches covered in our insights. Let's talk about your context.
Book a Discovery Call