How to De-Risk AI Deployment

Any company operating in the EU must comply to the EU AI Act. Here, Chris Whyborn, Head of Cybersecurity Services (UK & Europe) for TÜV SÜD Business Assurance, a global provider of auditing and certification services, offers his insights on de-risking AI deployment.

Any manufacturers deploying AI within their systems must successfully integrate technical safeguards with ethical and legal compliance across the entire AI lifecycle. They must ensure they fully understand their responsibilities, liabilities and potential exposure, ensuring that any AI systems are trustworthy, fair and secure.

The EU AI Act requires companies to take a risk-based compliance approach, and non-compliance may result in significant fines. While this does not apply to organisations based outside the EU, it does apply if they operate in it. An organisation should therefore classify AI systems into the risk classes defined in the EU AI Act to understand applicable requirements, and whether it is affected by the regulation.

Manufacturers that want to harness the full potential of AI must assess organisational readiness and ensure risks are managed effectively so that the AI system is fit for large-scale deployment. Risks include those associated with safety, security, legality, ethics, societal, performance and sustainability.

Chris Whyborn, Head of Cybersecurity Services (UK & Europe), TÜV SÜD Business Assurance

Effective due diligence reduces the likelihood of occurrence and demonstrates that proportionate measures have been taken to address the risk or the consequence. All aspects along the lifecycle of an AI system and its data must be covered, including data preparation and quality, model development and fairness, explainability, deployment readiness, and ongoing monitoring and feedback. The organisation must, therefore, be fully prepared, both technically and culturally, for widespread adoption, making staff training and readiness for effective incident response essential.

ISO/IEC 42001:2023 is the first internationally recognised standard for AI management systems (AIMS). It provides a structured framework for organisations to develop, implement and operate AI systems, analyse risks and impacts, and establish protective measures.

As AI deployment gains traction, ISO 42001 helps organisations overcome associated pressures, including building trust and ensuring readiness for laws like the EU AI Act. It also provides a competitive edge if any part of a manufacturer’s supply chain requires proof of AI safety.

AI governance is not solely a topic for the IT department as seemingly harmless systems can introduce bias due to faulty or one-sided training data. An AIMS will help to keep processes and decisions transparent and controllable by prompting companies through structured risk management.

Although ISO/IEC 42001:2023 certification is not a regulatory requirement, it represents a solid basis for compliance with current and future AI regulations, helping organisations manage their AI responsibly in the long term. A certified AIMS helps to secure innovations, minimise risks and increase the trust of stakeholders and customers. 

tuvsud.com/en-gb

Related Articles

LATEST ISSUE

- Advertisements -



FEATURED VIDEO

Latest News