Jurisdictions
Cogniveil in the European Union
Five instruments define what an EU regulated enterprise must be able to prove about the AI it deploys:
The regulatory frame
Five instruments define what an EU regulated enterprise must be able to prove about the AI it deploys:
- DORA governs ICT risk and operational resilience for the financial sector. For banks and insurers it is usually the first question in any AI evaluation.
- The EU AI Act sets obligations on deployers of AI in regulated contexts: transparency, record keeping, human oversight, data governance. Use-case risk classification under the Act stays with you, the deployer.
- GDPR governs personal data wherever it appears in the work: onboarding files, access requests, HR records, client correspondence.
- NIS2 sets cybersecurity expectations for essential and important entities, including energy, telecommunications, and parts of public administration.
- CSRD obliges large companies to report on sustainability, and the evidence behind the report has to stand up to assurance.
Our posture on each is stated precisely, per regulation, on the compliance page. Our regulatory posture
Who this binds
BankingDORA, GDPR, the AI Act, and the supervisory frame around them.InsuranceSolvency II and the same operational resilience and data protection expectations.Energy and utilitiesCSRD, the EU Taxonomy, and NIS2.TelecommunicationsNIS2, GDPR at consumer scale, and license conditions.Public sectorNIS2, GDPR, and procurement rules.PharmaEU regulatory practice alongside the global frame.
Book a demoNext step
Start with one workflow
Bring the work, the approved sources, and the people who must stand behind the answer.
Or contact sales@cogniveil.ai