AIAI Governance StackFree kit

GDPR

Regulation

What GDPR requires

The GDPR predates the current AI wave but governs a great deal of it, because most AI systems process personal data. The provisions that bite hardest on AI are the lawful-basis requirement, purpose limitation and data minimisation, the transparency obligations, and Article 22's restrictions on solely automated decision-making with legal or similarly significant effects. Data protection impact assessments are frequently the existing process AI governance gets bolted onto, which is why so many privacy platforms have extended into AI governance.

Who it applies to

Any organisation processing the personal data of people in the EU/EEA.

22 tools that map to GDPR

Grouped by what the tool actually does, because a documentation platform and a runtime guardrail both claiming support are solving different halves of the problem.

Policy, Compliance & GRC (13)

Compliance automation platform that extended into ISO 42001 and EU AI Act governance

ISO/IEC 42001EU AI ActNIST AI RMF

Security compliance automation platform, an early mover in supporting NIST AI RMF and ISO 42001

NIST AI RMFISO/IEC 42001GDPR

European compliance automation platform with an ISO 42001 and EU AI Act AI management system

EU AI ActISO/IEC 42001GDPR

AI-driven GRC platform pairing compliance automation with human experts for ISO 42001 and EU AI Act

ISO/IEC 42001EU AI ActNIST AI RMF

Multi-framework GRC and compliance operations platform with NIST AI RMF and ISO 42001 templates

NIST AI RMFISO/IEC 42001EU AI Act

AI-powered, modular GRC platform that operationalizes AI governance alongside security compliance

EU AI ActNIST AI RMFISO/IEC 42001

Autonomous compliance platform bringing ISO 42001 and EU AI Act governance onto its security GRC engine

EU AI ActNIST AI RMFISO/IEC 42001

Enterprise agentic GRC platform running on structured live-systems data, ISO 42001 certified

NIST AI RMFISO/IEC 42001GDPR

European responsible-AI platform unifying MLOps, model registry, and enterprise AI governance

EU AI ActGDPRNIST AI RMFOpen-source

Security compliance automation vendor with ISO 42001 and real-time AI agent governance

ISO/IEC 42001EU AI ActSOC 2

AI inventory, assessment and monitoring built on OneTrust's privacy and trust platform

EU AI ActNIST AI RMFISO/IEC 42001

Software that tests and documents AI systems for legal and regulatory risk under privilege

EU AI ActColorado SB 205GDPR

AI governance embedded in an integrated risk management platform

EU AI ActNIST AI RMFISO/IEC 42001

Observability & Monitoring (5)

AI observability and evaluation platform for ML models, LLM apps, and agents

SOC 2HIPAAGDPROpen-source

Enterprise AI observability, security, and governance control plane for models and agents

EU AI ActNIST AI RMFGDPR

AI quality, testing, and monitoring platform for evaluating and safeguarding models in production

ISO/IEC 42001GDPRHIPAAOpen-source

AI control platform combining ML observability with real-time guardrails for GenAI

SOC 2GDPRHIPAA

Open-source-led testing, evaluation and monitoring for ML models and LLM applications

SOC 2GDPRHIPAAOpen-source

Runtime Enforcement & Guardrails (1)

Runtime security for enterprise GenAI usage, applications, and AI agents

NIST AI RMFEU AI ActGDPR

Enterprise Incumbents (3)

Enterprise MLOps and governance platform for building and running AI in regulated industries

EU AI ActGDPRSOC 2

Lifecycle governance, risk and compliance for models and agentic AI, built on IBM's GRC heritage

EU AI ActNIST AI RMFISO/IEC 42001

AI Governance Tool Selection Kit

A vendor-comparison worksheet plus EU AI Act, NIST AI RMF and ISO/IEC 42001 requirement checklists — so you can shortlist tools against the obligations that actually apply to you.

Free. No spam — unsubscribe anytime.