Regulatory Compliance Action Plan
This is a template document. All text in [square brackets] must be completed by your organisation. This template does not constitute legal advice. Review with your legal counsel before formal adoption.
1. Purpose
Plan the steps recommended by your AIRETT "Risk and Regulatory Awareness" result — covering the EU AI Act (or your jurisdiction's equivalent) and GDPR.
- Organisation name: [Organisation name]
- Compliance lead: [Name / role]
- Risk score: [e.g. 5/15]
2. Action plan
| Action | Owner | Target date | Status |
|---|---|---|---|
| Identify which AI regulation applies in your jurisdiction | [ ] | [ ] | [ ] |
| Assess AI tools against EU AI Act risk categories (or local equivalent) | [ ] | [ ] | [ ] |
| Add AI risk to the organisational risk register with named owners | [ ] | [ ] | [ ] |
| Confirm contractual human-override rights with AI vendors | [ ] | [ ] | [ ] |
3. Non-EU members
If your organisation operates outside the EU, identify the equivalent regulatory framework (e.g. state-level US rules, Canada's PIPEDA, or your national data protection law) and adapt this plan accordingly. See the FAQ page for jurisdiction-specific guidance.