What is AI compliance?

By Identra · Updated

AI compliance is meeting the legal, regulatory and contractual requirements that apply to how an organization builds and uses AI, and keeping evidence that shows it. In practice it ties each AI use case to an accountable owner, working controls and records a reviewer can check.

What does AI compliance actually cover?

Compliance attaches to the use case. Approving ChatGPT Enterprise for marketing drafts says nothing about whether HR can use it to screen candidates. Those are two use cases with different data, different people affected and different rules.

AI governance decides who approves what. Compliance asks which requirements apply and whether you meet them. Security protects the data and access underneath both. A deployment can pass a security review and still have open questions on privacy, transparency, intellectual property or discriminatory outcomes.

Write down what each approval excludes. A later release can add connectors to an assistant you approved for meeting summaries. The approval record should say whether those are in scope.

Which laws, standards and frameworks apply?

Separate what binds you from what guides you. Law binds within its scope. A contract binds you to whatever you promised, and that can include following a particular standard. Legal owners document applicability by jurisdiction, role and use.

Three names come up in almost every review. The European Commission describes the EU AI Act as a risk-based legal framework for AI developers and deployers. NIST calls its AI Risk Management Framework voluntary. ISO describes ISO/IEC 42001 as a management system standard for AI. They do different jobs and are not interchangeable badges.

  • Law or regulation

    Binding?
    Yes, within its scope
    What you do with it
    Document applicability and the controls it requires
  • Customer or vendor contract

    Binding?
    Yes, between the parties
    What you do with it
    Map each commitment to an owner and evidence
  • Management system standard

    Binding?
    When you certify to it or a contract requires it
    What you do with it
    Define which parts of the organization it covers
  • Voluntary risk framework

    Binding?
    No
    What you do with it
    Use it to structure assessments and find gaps

How do you run an AI compliance program?

Start with an inventory and assume it is incomplete. Procurement knows about the ChatGPT Enterprise contract. It probably doesn't know about the analyst on a personal Claude account or the AI features someone switched on inside a SaaS app. That gap is shadow AI. Cover browser services, desktop apps, agents and connected identity, SaaS and cloud systems.

For each use case record the owner, purpose, accounts, reachable data, integrations and approval status.

Run an AI risk assessment before approval. Does the system advise a person, make a decision or take an action? That one question changes most of the review. Open items get a named owner. Missing information is not acceptance.

Then map each requirement to a control, an owner and evidence. Say what the evidence proves and what nobody has tested yet. Redo the mapping when provider terms change or an agent picks up new permissions.

What does AI compliance look like for a real use case?

Say a support team wants an assistant that drafts replies from Zendesk tickets. The tickets carry personal data and the occasional confidential attachment. One support rep already pastes tickets into a personal chatbot account to get the same result.

The review records the purpose, checks the provider's data handling terms and decides which ticket categories are in scope. Security limits the connector to the queues the team actually works. A person sends every reply. The team runs synthetic tickets with fake card numbers through it and keeps the results.

Approval covers drafting. If someone later wants the assistant to issue refunds or send replies on its own, that is a new review because its authority changed. None of this is a legal opinion on the workflow.

Which controls matter most?

Write the AI acceptable use policy so an employee can follow it without calling legal. Name the approved tools and accounts. Give people an approved path that works, or they will route around it.

  • An owner and an approver for every AI use case.
  • Limits on what goes into prompts and uploads, based on data classification and purpose.
  • Least privilege for connected apps and agents. Remove OAuth grants and connections nobody uses.
  • Human approval before consequential actions, by someone with the context and authority to say no.
  • Tests of the prohibited paths too. Personal accounts, sensitive attachments, agent actions outside scope.
  • Exceptions with an owner, a reason, compensating controls and an expiry date.

What evidence will an auditor ask for?

Policies, use case assessments, vendor reviews, approvals, configuration records, test results and fixes. An AI audit trail should show who acted, which system was involved, which policy applied and what happened.

A screenshot of a setting shows intent. A recorded test shows behavior.

Evidence is sensitive data too. Set access and retention rules before you collect it, and don't copy whole prompts or customer documents into logs by default. Keep a list of known gaps with owners, so a reviewer can tell verified operation from assumption.

How Identra thinks about it

Identra shows security teams which AI apps, accounts and agents are in use across browsers, endpoints and connected identity, SaaS and cloud providers, so a compliance inventory starts from what people actually use. Policies can govern supported AI use and sensitive data in prompts. Every AI agent run on an endpoint is recorded with the user, device, AI client and whether it was allowed or blocked.

Go deeper: AI security, built on identity

Frequently asked questions

Does AI compliance apply if we only use third-party AI?

Yes. Obligations can attach to your use of AI even when another company supplies the model. Your purpose, data handling, access and oversight still need review alongside the provider's commitments.

Who should own AI compliance?

One program owner with authority to pull in legal, privacy, security and the business. Each use case also needs a business owner who answers for its approved purpose and conditions.

Does ISO 42001 certification or NIST alignment prove legal compliance?

No. Each supports an assessment within its own scope. Legal obligations still need their own analysis of your organization and your AI uses.

Do we have to keep every AI prompt?

There is no universal rule that says so. Work out which records your obligations and reviews need, keep sensitive content to a minimum and set access and retention rules.

When does an approved AI use case need another review?

When its purpose, data access, provider terms, model behavior or ability to act changes. Incidents, failed control tests and new requirements are triggers too.

Related terms

Keep exploring · AI security programs and controls