Help Center
Compliance & frameworks
What EU AI Act, GDPR, and US employment-AI rules require — and which Shield policy operationalizes each.
DIFC Regulation 10 — AI & autonomous systems
DIFC Regulation 10 governs personal data processed through autonomous and semi-autonomous systems. Who counts as Deployer and Operator, the core duties, and how Shield helps you meet them.
Updated July 15, 2026
EU AI Act — Provider vs deployer (roles & when the line shifts)
EU AI Act provider vs deployer: what separates a deployer (Betreiber) from a provider (Anbieter) under Article 3, and the Article 25 triggers that turn a deployer into a provider of a high-risk system.
Updated July 13, 2026
EU AI Act Article 26 — Deployer obligations
Article 26 defines your duties when deploying high-risk AI — applicable from December 2027 under the Digital Omnibus. What paragraphs (1), (5), and (6) require and how Shield prepares you now.
Updated July 14, 2026
EU AI Act Article 4 — AI literacy
Article 4 requires a sufficient level of AI literacy in your workforce — already in force. What that means in practice, and how Shield turns it into an operational program.
Updated July 5, 2026
EU AI Act Article 5 — Prohibited practices
Article 5 bans AI practices deemed unacceptable — already in force. What is prohibited, why shadow AI is your exposure, and how Shield keeps prohibited-class tools out.
Updated July 5, 2026
EU AI Act Article 50 — Transparency obligations
Article 50 sets the EU AI Act transparency obligations: AI chatbots must disclose they are AI, and AI-generated content and deepfakes must be marked. Applicable from 2 August 2026, with a narrow Article 50(2) marking transition to 2 December 2026 for pre-existing systems.
Updated July 15, 2026
EU AI Act Article 6 — High-risk classification
Article 6 sets the EU AI Act high-risk classification: the Annex III areas, the 6(3) filter, and why the label attaches per use case × context — not per app. Applicable from December 2027 under the Digital Omnibus.
Updated July 13, 2026
GDPR Article 32 — Security of processing
Appropriate technical and organizational measures, including for the AI channel: how blocking secrets, redacting personal data, and warning on source code map to Article 32.
Updated July 14, 2026
GDPR Article 5 — Principles of processing
Data minimization, purpose limitation, accountability — Article 5's principles apply fully when employees paste personal data into AI tools. How Shield enforces them at the prompt boundary.
Updated July 5, 2026
GDPR Article 6 — Lawfulness of processing
Personal data needs a legal basis — including when it flows into an AI tool nobody vetted. What Article 6 requires and how Shield prevents basis-less processing before it happens.
Updated July 5, 2026
Illinois HB 3773 — AI in employment
Since January 2026, Illinois employers may not use AI in employment decisions in a discriminatory way and must notify employees. What HB 3773 requires and how Shield builds the evidence base.
Updated July 5, 2026
ISO/IEC 42001 — AI management system
ISO/IEC 42001 is the world's first AI management system standard. What an AIMS requires, who it is for, and how Shield contributes operational controls toward it.
Updated July 6, 2026
Korea AI Basic Act — trustworthy AI obligations
South Korea's AI Basic Act took effect in January 2026. What it requires around high-impact and generative AI, who it applies to, and how Shield supports the operating routine.
Updated July 15, 2026
NIST AI Risk Management Framework (AI RMF)
The NIST AI Risk Management Framework (AI RMF 1.0) is a voluntary framework for managing AI risk. Its four functions — Govern, Map, Measure, Manage — and how Shield supports them.
Updated July 6, 2026
NYC Local Law 144 — Automated employment decision tools
New York City requires a bias audit and candidate notice before an automated employment decision tool may be used. What LL 144 covers and how Shield keeps your AEDT inventory honest.
Updated July 5, 2026