Kanonik

Help center

Law, standard, or guidance: reading the AI-governance landscape.

The tier changes what you must do versus what the market will expect of you.

The fastest way to lose a security buyer's trust is to call a voluntary framework a law. The fastest way to earn it is to get the distinction right when most vendors do not. This article lays out the AI-governance landscape the way a practitioner needs to hold it: by tier, because the tier changes what you must do versus what the market will expect of you.

Dates, penalty figures, and clause numbers in this space move. Treat the specifics below as orientation and verify against the primary source before you rely on them in an audit or a contract.

Three tiers, and why the tier is the point

Binding law. Legal force, penalties, an enforcement body. In AI governance today, the clearest example is the EU AI Act. It is risk-based: high-risk systems carry obligations for documentation, risk management, human oversight, data governance, and ongoing monitoring. Its reach is extraterritorial, so a US vendor can be in scope if the system is used by someone in the EU. Its high-risk provisions have a published effective date in 2026 (verify the exact date and the current text before relying on it). This one is a law. Treat it as one.

Certifiable standard. Voluntary, but auditable and certifiable, which makes it a procurement bar in practice. ISO/IEC 42001 is the example: it defines an AI management system the way ISO/IEC 27001:2022 defines an information security management system, and the two interlock. It is not a law. It is the bar a buyer or a board increasingly expects you to meet.

Voluntary framework. No direct enforcement, but cited by regulators and buyers, and effectively required through procurement and liability over time. The NIST AI Risk Management Framework is the dominant US reference here. The NIST AI Agent Standards work and Singapore's Model AI Governance Framework sit in the same tier: voluntary, influential, moving quickly.

The pattern worth internalizing: voluntary today does not mean optional tomorrow. The NIST Cybersecurity Framework was published as voluntary, then showed up in vendor questionnaires, then in litigation as evidence of reasonable care. AI governance is on the same trajectory.

What this means for how you talk about your program

Precision protects you. Saying "we align to ISO/IEC 42001" is defensible. Saying "we are ISO 42001 certified" is only true once you hold the certificate. Saying "the EU AI Act requires X of us" is only true if you are actually in scope. Knowing which tier you are speaking about is not pedantry; it is the difference between a claim that survives a procurement review and one that does not.

How Kanonik relates to these

Kanonik does not provide compliance with any of these frameworks, and it does not certify you against them. What it does is support the work: it produces the decision-chain record, the independent verification, and the human-approval evidence that map to specific clauses across these frameworks (for example, record-keeping obligations). The framework is the destination. Kanonik is one of the things that helps you prove you got there.

For the precise map of what Kanonik supports, see How Kanonik supports your AI-governance work.

More help

Browse every article in the Help center, where you can also ask the Kanonik assistant directly. For anything else, email support@kanonik.ai and a person who works on the product answers.