Skip to main content

Techné AI · Free reference · Edition 3.0.0

Audience-Specific Guidance

Practical starting points for practitioners, compliance teams, executives and policymakers who need to govern AI in a defined setting.

Reviewed Download complete PDF Corrections
On this page
  1. AI Practitioners
  2. Compliance Officers
  3. Executives & Board Members
  4. Policymakers & Regulators
  5. Cross-audience: the shared language

Different roles contribute different evidence and decisions. This chapter offers practical guidance for AI practitioners, compliance officers, executives and board members, and policymakers and regulators. These are suggested responsibilities to adapt to your organisation, not a universal allocation of legal liability.

AI Practitioners

Data scientists, ML engineers, AI developers

Focus

Practitioners are at the front lines of building and deploying AI. The job is to operationalise governance and safety inside the development process: build models that perform well on accuracy metrics and meet criteria for fairness, explainability, robustness, and compliance.

Specific practices

  • Translate principles into code. Ethics guidelines mean nothing if they don’t show up as concrete model-validation steps, bias checks, or model-card sections.
  • Handle data with a documented basis. Establish applicable permissions and lawful bases, respect relevant rights and restrictions, and involve privacy reviewers early. Consent is not the only possible basis; pseudonymisation is not anonymity.
  • Test proportionately and record gaps. Add stress tests, adversarial tests, fairness checks and, for relevant GenAI risks, red-teaming. No finite test suite exhausts all possible failures.
  • Maintain a system inventory. Document purpose, owner, data, model version, dependencies, evaluations and deployment context. The inventory supports analysis; it is not proof of compliance.
  • Monitor in production. Set up performance dashboards and drift alerts. Plan retraining cadence.
  • Partner with compliance early. Check actual classification and dates for the EU AI Act, NYC LL 144 and relevant state rules. Colorado’s SB 26-189 replaced the earlier SB 24-205 regime; do not design around the repealed framework. See US State Laws.
  • Cultivate a safety culture. Ethical AI is everyone’s job, like security. Speak up when something looks wrong; build feedback into development culture, not just review gates.

What changed for practitioners in 2025-2026

  • Frontier governance combines different legal duties and voluntary commitments; a California transparency report is not identical to a safety case. See Frontier Models.
  • Training-data transparency requirements have specific provider, release and jurisdictional scope. See Copyright & IP.
  • Agentic systems add action-layer risks: permission scoping, reliable records, retry handling and reversibility analysis. The burden depends on capability and use, not the “agent” label alone.

Compliance Officers

Legal, regulatory, ethics, and risk personnel

Focus

Compliance officers ensure AI systems and processes adhere to law, regulation, and policy. They translate regulatory requirements into controls, guide AI projects, and verify controls are working.

Specific practices

  • Track the regulatory landscape. EU AI Act (and Omnibus rebase), US federal EOs, state laws (CO, TX, CA, UT, IL, NYC), Korea AI Basic Act, Japan AI Promotion Act, China labelling rules, sector regulators. See Legal & Regulatory.
  • Develop internal policies. AI governance policy, model-development standards, third-party AI usage policy, AI procurement standards.
  • Run role-specific training. Teach classification, escalation and the actual controls each role must operate. Update training when legislation or deployment scope changes.
  • Review evidence. Coordinate applicable data-protection and fundamental-rights impact assessments, independent bias reviews, model risk assessments and third-party contract review. Follow each requirement’s actual scope.
  • Incident handling. Coordinate response to compliance issues; regulator notifications (EU AI Office, Cal OES, state AGs); cross-functional incident triage.
  • Choose standards deliberately. ISO/IEC 42001, 23894 and 42005 may support the programme. They are generally voluntary unless incorporated into an applicable obligation or contract; organisational size alone does not make them compulsory.

Key concerns

Map liability, regulatory exposure and operational harm to the actual actor and conduct. Penalty ceilings are not predictions of a likely fine, and statutes have different coverage, enforcement powers and cure provisions. Use the Legal & Regulatory chapters for source-backed details instead of a single headline penalty table.

What changed in 2025-2026

  • Federal preemption uncertainty in the US complicates multi-state compliance — track the December 2025 EO and litigation outcomes.
  • Certification-body requirements in ISO/IEC 42006 supplement management-system certification practice. Verify scope, accreditation and validity; certification is not regulatory approval.
  • Frontier-model rules add a layer for large developers — see Frontier Models.

Executives & Board Members

C-suite, board directors, AI sponsors

Focus

Executives are responsible for strategic oversight and organisational commitment to AI governance. The job is to balance innovation with risk and to maintain stakeholder trust.

Specific practices

  • Set strategy. Decide which AI use cases the organisation will pursue, which are out of bounds, and the corresponding risk appetite.
  • Establish governance structures. AI Governance Council, model risk management function, AI ethics committee with real authority and budget.
  • Set the tone. Communicate that responsible AI is a core value; reward responsible behaviour; back compliance teams when they say “not yet.”
  • Ask for decision-useful evidence. Seek the material AI uses, responsible owners, unresolved risks, incidents, test limitations and overdue actions. Minutes should record what was considered and decided, not imply that a dashboard proves effective oversight.
  • Prepare for regulation. Fund applicable requirements and track enacted-but-not-yet-applicable duties separately from proposals. Avoid treating every proposed “AI Bill” as law.
  • Evaluate credentials and partnerships separately. ISO/IEC 42001 certification, GPAI Code signature and CAISI research agreements are three different mechanisms. Choose them for a reason and do not describe the latter two as certifications.

Considerations for 2025-2026

  • Public claims — substantiate statements about responsible AI, environmental effects, fairness and safety; publish limitations alongside benefits.
  • AI workforce — reskilling, AI literacy obligations under EU AI Act Article 4, internal AI usage policies.
  • Geopolitical risk — export controls, data-localisation rules, jurisdictional fragmentation. The US December 2025 preemption EO and the ongoing state-federal tension affect operational planning.

What changed in 2025-2026

  • AI copyright requires careful separation of acquisition, training and output risks. The Bartz settlement received final court approval in July 2026; it did not settle all AI copyright questions. See Copyright & IP.
  • Frontier developers may face additional framework, transparency and whistleblower duties, depending on their statutory category. See Frontier Models.

Policymakers & Regulators

Government officials, regulators, standards body participants

Focus

Policymakers create and enforce the rules. The job is to address public risks while preserving innovation and accommodating sectoral diversity.

Specific focus areas

  • Develop and refine AI regulations. EU AI Act implementation and Omnibus refinement, state legislative work, sector-specific rules.
  • Harmonise where possible. OECD, G7 Hiroshima Process, ISO/IEC, IEEE; bilateral cooperation agreements (e.g., the International Network of AI Safety Institutes).
  • Build enforcement capacity. Stand up AI offices and inspectorates; train staff; develop technical evaluation capability.
  • Address societal impacts. Workforce displacement, AI literacy, public-sector AI use, election integrity, deepfake harms.

Concerns

Prevent harm; preserve fundamental rights; ensure national security; maintain transparency and accountability; balance with innovation; avoid over-regulation.

What changed in 2025-2026

  • Evidence sharing. International scientific reports and testing partnerships can support common methods without creating identical legal duties. See Frontier Models.
  • Capacity building. Invest in technical expertise, accessible complaint processes and methods for assessing real-world effects, not only published commitments.
  • Legal uncertainty. Distinguish an executive direction, a filed lawsuit, an enacted amendment and a final court holding when communicating changes to the public. See US Federal and EU AI Act.

Cross-audience: the shared language

These audiences need a shared record, even when they use different frameworks:

  • An inventory and ownership map identifying systems, purposes, people affected and accountable decision-makers.
  • An obligations register separating law, contracts, internal policy and voluntary commitments.
  • A risk and evidence record documenting testing, assumptions, unresolved gaps and residual-risk decisions.
  • An escalation and change log showing how incidents, complaints and material releases prompt action.

NIST AI RMF and ISO management-system standards can help organise this work, but no single framework replaces applicable law. The handoff should tell the next team what is known, what remains untested and who decides — not simply attach a certificate or a maturity label.

This free handbook is a dated educational reference, not a determination of your organization's obligations. Check the source, jurisdiction and role before applying a requirement. For working documents, see TalentSight Intelligence and BoardSight Intelligence.