PHÖNIXThe AI Operating System
Knowledge

AI governance, AI audit, AI compliance, AI operating system: four terms, four jobs

This page informs; it is not legal advice.

The terms, cleanly separated.

The four terms are used interchangeably in the market. They mean different things, and whoever separates them buys the right thing.

AI governance
Definition the rules, responsibilities and checkpoints by which a company uses AI.
What it is not a one-off project or a PDF on a shared drive.
When you need it as soon as AI works in processes regularly and more than one person uses it.
AI audit
Definition the review of a specific AI deployment with a documented findings report: data paths, accountability, documentation, connection to the legal position.
What it is not a certification, a seal or an official inspection.
When you need it when AI is already working and it is open whether the deployment is tenable and verifiable.
AI compliance
Definition adherence to the rules that apply to the AI deployment, above all the AI Act and the GDPR.
What it is not the same as governance. Compliance is the obligation, governance is the way to fulfil it durably.
When you need it always. The scope depends on the role: whoever only uses AI has different obligations than whoever develops or offers it.
AI operating system
Definition the order around the AI tools: rules, knowledge base, evidence and responsibilities as one coherent layer.
What it is not a piece of software you buy and install.
When you need it when AI use is meant to be repeatable, transferable and verifiable instead of depending on individual people.

The deadlines of the AI Act, dated. (Last updated: 8 August 2026)

DateWhat appliesSource
1 Aug 2024AI Act (Regulation (EU) 2024/1689) entered into forceRegulation (EU) 2024/1689, EUR-Lex
2 Feb 2025Prohibited practices banned, duty of AI literacy for staffArt. 113 Regulation (EU) 2024/1689
2 Aug 2025Obligations for providers of general-purpose AI modelsArt. 113 Regulation (EU) 2024/1689
2 Aug 2026Transparency obligations under Art. 50 applicableRegulation (EU) 2024/1689
2 Dec 2027Obligations for high-risk systems applicable (postponed)Digital Omnibus, agreement of 6 May 2026

The GDPR applies independently of these deadlines as soon as personal data is processed.

Questions and answers.

Does the EU AI Act affect our company?

Very likely yes, but the scope depends on your role. The regulation distinguishes, among others, providers (who develop AI systems or offer them under their own name) and deployers (who use them). A company that only uses ready-made AI tools has considerably leaner obligations than a provider, above all transparency and literacy obligations. The reliable answer starts with an inventory of your own AI deployments.

Does the AI Act also apply to small companies?

Yes. The regulation attaches to the role and risk class of the AI deployment, not to company size alone. There are reliefs for small and medium-sized enterprises in individual places, but no general exemption. Being small does not exempt you; it usually just shrinks the inventory that needs ordering.

We only use ChatGPT and similar tools. Do we still have to do anything?

Yes, to a manageable extent. Mere use also triggers obligations: staff must be sufficiently AI-literate, AI interaction and AI-generated content must be recognisable in certain cases, and the GDPR applies to everything that touches personal data. On top of that comes the practical question of which company data your people enter into third-party tools. A short inventory and clear usage rules cover the most common gaps.

What is the difference between AI governance and AI compliance?

Compliance is the state of adhering to the applicable rules. Governance is the steering system that produces this state durably: rules, responsibilities, checkpoints, evidence. You can be compliant in the short term without governance, but you lose that state at the next staffing or legal change. The detailed distinction is above in the terms section.

What does an AI audit review, and how long does it take?

What gets reviewed is the workflow, not the model alone: data paths, accountability, documentation and the connection to the legal position. The result is a findings report with priorities. The duration depends on scope; the binding range for the individual case is stated in the proposal before commissioning. Details on the audit page.

Is an AI audit a certification?

No. A certification attests conformity with a standard and comes from an accredited body. An audit in the sense described here delivers a findings report on a specific deployment. The findings can prepare a later certification but do not replace it, and conversely a certificate says little about whether an individual workflow holds up in daily operation.

Local models or cloud: which is more privacy-friendly?

Neither, as a blanket statement, but control is distributed differently. Local models keep data in your own house and cost your own computing power and maintenance. Cloud services move operation and maintenance outside; in return, data paths, data processing agreements and storage locations must be settled contractually and technically. What matters is not the label but whether the data path in the specific case can be described, limited and evidenced.

How does the AI Act relate to the GDPR?

Both apply side by side. The GDPR governs the handling of personal data, regardless of whether an AI is involved. The AI Act governs the placing on the market and the use of AI systems by risk class. An AI deployment can be GDPR-compliant and still carry obligations under the AI Act, and vice versa. In practice this means: both reviews belong in the same process, not in two separate projects.

What is ISO/IEC 42001, and do we need it?

ISO/IEC 42001 is an international standard for management systems for artificial intelligence, comparable to what ISO 27001 is for information security. It is voluntary: no law requires the certificate. It is useful above all when customers or tenders demand a recognised attestation. For most organisations, order in their own inventory comes first, the question of the standard second.

What is an AI operating system?

The order around the AI tools: rules, knowledge base, evidence and responsibilities as a coherent layer between tools and work. It is not software you install but a structure that gets set up. The full explanation with an example is on the operating system page.

Which obligations have applied since 2 August 2026?

Since 2 August 2026 the transparency obligations under Art. 50 of the AI Act are applicable. In essence: in certain cases, people must be able to recognise that they are interacting with an AI or looking at AI-generated or AI-edited content. The obligations for high-risk systems follow on 2 December 2027. The full table with sources is above.

Do AI-generated contents have to be labelled?

In certain cases yes, since 2 August 2026 under Art. 50 of the AI Act, for instance for artificially generated or manipulated image, audio and video content and for AI systems that interact with people. Where exactly the line runs in your own organisation belongs in the inventory and the approval checkpoints, so that labelling happens in the process and does not depend on case-by-case memory.

Who writes here.

Matthias Downey, founder of PHÖNIX

Matthias Downey is the founder of PHÖNIX. His path begins in the real estate industry: property management and acquisition, most recently as Head of Property & Acquisition, in an industry where every number must be verifiable and every mistake has documented consequences. Degrees in real estate management (Hochschule Fresenius Heidelberg) and industrial engineering (Hochschule Mannheim). Today he builds and reviews AI deployments in regulated industries: systems that do not just work but hold up when someone asks questions. German-American, works in German and English. Reachable at info@phoenixcitadel.de.

What we are currently checking: As of 8 August 2026: deadline table checked against Art. 113 of Regulation (EU) 2024/1689, supervisory authority address corrected after the authority moved.

Contact

Write to info@phoenixcitadel.de. You will receive a reply from Matthias Downey personally.

Last updated: 8 August 2026 · Matthias Downey