Your journey
  1. 1
  2. 2
  3. 3
  4. 4
  5. 5
  6. 6
0 of 34 units

You are in Degree 5 · Governance and resilienceunit 4 of 6Ahead of you: An approved use policy and a completed maturity assessment.

Degree 5 · Unit 5.4

The regulatory landscape

Artificial intelligence is not regulated as a technology. It is regulated as a use. The very same model may be entirely unproblematic for summarising an article and tightly restricted for screening job applications. Once you understand that logic, you can read any new regulation that appears.

FIG. 28 — Four levels of risk
1
Unacceptable
Uses prohibited outright — such as harmful behavioural manipulation and general social scoring.
2
High risk
Employment, education, credit, health, critical infrastructure — requiring an impact assessment, human oversight, data quality, documentation and logs.
3
Limited
Whatever interacts with people or generates content — the core obligation is disclosure.
4
Minimal
The overwhelming majority — no special obligations, and good practice stays voluntary.
Identify, analyse, treat

Risk is not abolished; it is managed by a conscious, written decision for each risk — the same logic the four regulatory tiers above rest on.

FIG. B26 — From the asset to the treatment decision
Identify the assets
Files, servers, reputation, client lists
⟶
Assess the threats
Ransomware, phishing, IP theft, impersonation
⟶
Vulnerability assessment
Weak passwords, an absent policy
▼
Analyse the likelihood
How probable is the risk? Qualitatively (high/medium/low) or in numbers.
Analyse the impact
Financial? Reputational? Legal? Operational? — with a scenario showing how it happens.
▼
Mitigate
Controls that lower the likelihood or the impact — the commonest
Transfer
Insurance, or handing it to a specialist provider
Avoid
Declining the activity or the project
Accept
When treatment costs more than the impact

Every risk needs one documented choice in the treatment plan, with an owner and a date. "Accept" is a legitimate decision, but an unwritten acceptance is negligence.

The Gulf and the Arab world

The Gulf states have taken a different approach in method: guidance, national strategies and ethics frameworks issued by the competent authorities, with tighter sectoral regulation in banking, health and personal data. The general direction there is an enabling one — encouraging adoption while putting barriers around sensitive sectors — which is unlike the European direction, built as it is on graduated prior prohibition.

Build to the strictest

Frameworks change faster than any book's print cycle, so the working rule matters a great deal more than the list: build to the strictest. If you design your system to the standards that apply to high-risk use — an impact assessment, human oversight, documentation and logs — then you are ready for any regulation that appears, in any jurisdiction.

And do not overlook effect across borders. If you have clients or employees in a jurisdiction that regulates strictly, its obligations follow you even when you are established somewhere else entirely. Check the scope of application before you assume you fall outside it.

There is a third thing worth knowing: regulation does not punish the use, it punishes the absence of proof. An organisation that holds a record of what it did and who reviewed it comes out of an audit intact, even where it got something wrong. An organisation with no record is asked about everything and can prove nothing at all.

The governance and risk cycle

Governance is not a document written once but a cycle that turns — and every turn leaves the organisation firmer than the last.

FIG. A6 — Six stages that keep turning
1WatchWhat is going on?2RiskHow large is the impact?3PolicyWhat is the rule?4ControlWhat is the measure?5TestDoes it hold?6ImproveWhat is the lesson?One turn everytwelve months

One turn every twelve months at least: watch, assess, set policy, control, test, improve — and then watching begins again with better knowledge than it had.

Do this

  1. 1 — In your field. Classify every system in your register across the four levels. How many fell into "high risk" while you do not treat them as such?

  2. 2 — In writing. Write down where your disclosure appears telling the user that a system took part in the service. If it is not visible, add it today.

How to walk through a new regulation in twenty minutes

New regulations will appear long after this programme is printed, and you will not need to read any of them in full. Read four things, in this order: the scope of application, which tells you whom it applies to; then the classification, which tells you how it grades different uses; then the documentary obligations, which tell you what you have to be able to prove; and then the dates it takes effect.

Everything else — the definitions and the technical exceptions — you read when you need it. Master those four and you will know where you stand in any regulatory text in a single sitting, without waiting for anyone else's interpretation of it.

Where to after this unit? You know what is imposed on you. The next unit gives you your own instrument for measuring your maturity: UCSMM.