Home / Knowledge Base
Knowledge Base

AI regulation & frameworks, explained for security teams.

Plain-English references for the regulations and frameworks that shape AI risk today — the EU AI Act, the NIST AI Risk Management Framework, and the fast-moving US landscape. These are the same sources Shadow AI Discovery maps your findings against, so your reports and your reading share one vocabulary.

Referenced from your reports. Shadow AI Discovery reports — such as the EU AI Act Readiness assessment — deep-link into these pages by article and section (for example, eu-ai-act.html#article-9). That means a finding in a report and the underlying obligation always point to the same explanation.

Why a knowledge base?

AI risk lives at the intersection of several rulebooks at once — a single deployed model can be a high-risk system under the EU AI Act, a "GAI" risk under the NIST profile, and subject to a US state transparency law. Rather than repeat definitions in every report, we keep one authoritative, plain-English reference here and map every framework to the same evidence you already collect.

EU AI Act NIST AI RMF US State & Federal ISO 42001 OWASP LLM Top 10