Innovation, Quantum-AI Technology & Law

Blog over Kunstmatige Intelligentie, Quantum, Deep Learning, Blockchain en Big Data Law

Blog over juridische, sociale, ethische en policy aspecten van Kunstmatige Intelligentie, Quantum Computing, Sensing & Communication, Augmented Reality en Robotica, Big Data Wetgeving en Machine Learning Regelgeving. Kennisartikelen inzake de EU AI Act, de Data Governance Act, cloud computing, algoritmes, privacy, virtual reality, blockchain, robotlaw, smart contracts, informatierecht, ICT contracten, online platforms, apps en tools. Europese regels, auteursrecht, chipsrecht, databankrechten en juridische diensten AI recht.

Berichten met de tag NIST AI RMF
AI Regulation in California: The Daiki SB-53 Recipe for the Transparency in Frontier Artificial Intelligence Act

California's Senate Bill 53—the Transparency in Frontier Artificial Intelligence Act—is the first U.S. law aimed squarely at frontier AI models through a compute threshold. Daiki, the AI and quantum governance company co-founded by Mauritz Kop, has published a practical recipe for complying with it, and for turning compliance into governance capital.

From voluntary principles to enforceable rules

SB-53 marks the moment U.S. artificial intelligence regulation acquired teeth: a compute threshold of 1026 floating-point operations, a "large frontier developer" category above USD 500 million in revenue, published Frontier AI Frameworks, transparency reports on deployment, critical-incident reporting on a fifteen-day (sometimes twenty-four-hour) clock, whistleblower protections, and Attorney General penalties of up to USD 1 million per violation. Most obligations apply from January 1, 2026—which makes readiness a present-tense question, not a planning horizon. Kop has engaged U.S. lawmakers on these trajectories, including consulting Senator Mark Warner on AI and quantum technology policy.

Six steps to SB-53 readiness

The Daiki recipe walks an organization from applicability analysis (model inventory, compute estimation, revenue exposure) through a standards-based governance baseline on ISO/IEC 42001 and the NIST AI RMF, the design of an operational Frontier AI Framework, repeatable transparency-report workflows, incident and whistleblower pipelines, and finally harmonization with the EU AI Act and other regimes—one governance system, not a stack of statute-shaped silos.

Why boards should care

The deeper argument is strategic: a frontier-AI law built on evidence-generating transparency rewards organizations that can prove their safety practices. Boards that treat SB-53 as an opportunity to institutionalize frontier-grade discipline—rather than as an isolated burden—convert a regulatory deadline into trust, resilience, and license to operate.

Meer lezen
EU AI Act Compliance for Global Enterprises: The Daiki Solution for Mandatory AI Governance

The European Union's AI Act has crossed the line from proposal to binding law, and its phased rollout is now an active clock rather than a distant horizon. Daiki, the AI and quantum governance company co-founded by Mauritz Kop, has published an account of what mandatory AI governance demands of global enterprises—and how an integrated, standards-based platform can convert that obligation into a strategic advantage.

A calendar that has already started

The Act entered into force on August 1, 2024. The prohibition on unacceptable-risk practices took effect in February 2025; obligations for general-purpose AI models began in August 2025; and full application—conformity assessments, CE marking, EU-database registration, post-market monitoring for high-risk systems—arrives on August 2, 2026, with a final grace period for regulated-product components running to 2027. Because the Act binds any provider whose systems reach the EU market or whose outputs are used within it, its reach is extraterritorial: a firm headquartered in New York or Singapore is squarely within scope, and penalties of up to €35 million or 7% of worldwide turnover make non-compliance a board-level risk.

The pyramid of criticality

The Act's organizing idea is a risk-based pyramid: unacceptable-risk practices are banned; high-risk systems—reaching common enterprise uses in hiring, credit scoring, and critical infrastructure—carry the heaviest lifecycle obligations; limited-risk systems owe transparency; and minimal-risk applications attract no new mandates. The Daiki solution operationalizes that structure, classifying each system through a rules engine aligned with the Act's definitions and Annex III, then triggering a workflow proportionate to its tier, with every action logged to an auditable evidence trail. Its architecture is anchored in ISO/IEC 42001, bridged to the NIST AI Risk Management Framework, and bounded throughout by deliberate human oversight—mirroring the Act's own Article 14.

A risk-based reading with a documented lineage

The post's central reading—that a risk-based regime rewards organizations able to prove their governance—has a clear history in Kop's scholarship. As Mauritz Kop's record of work shows, his 2021 analysis of the EU AI Act anticipated the four-tier architecture that is now law, and the same logic carries across the Atlantic to California's compute-threshold approach for frontier models. For general counsel and compliance leaders, the practical takeaway is consistent: build one coherent, standards-based governance system now—rather than a reactive checklist per statute—and the era of enforcement will reward exactly the discipline the era of voluntary principles merely recommended. Mandatory AI governance, as the post observes, is here to stay; the enterprises that treat it as design rather than damage control will be the trusted artificial intelligence leaders of the regulated decade ahead.

Meer lezen
The US ISO 42001 Standards-Centric Approach to AI Governance: Compliance, Trust, and Innovation (Daiki Repost)

AIRecht reposts, in full and with permission, a Daiki essay by Mauritz Kop, Co-Founder, on why the United States is converging on a standards-centric model of artificial intelligence governance—and why ISO/IEC 42001 has become its anchor. The repost is presented as published on May 13, 2025, with its original spellings, figures, and references intact.

A standards-first answer to a fragmented regime

The American approach to AI is, by design, light on binding federal statute and heavy on voluntary, risk-based guidance: the NIST AI Risk Management Framework, sector-specific direction from the FTC, EEOC, and FDA, and a patchwork of state laws. Into that fragmentation steps ISO/IEC 42001, the world's first international standard for AI Management Systems, published in December 2023. The essay's argument is that a single, certifiable management system can do what a stack of statute-shaped checklists cannot—give an organization one coherent governance posture that travels across jurisdictions.

The transatlantic bridge

The stakes are clearest for U.S. companies selling into Europe. ISO 42001 certification is not the same as EU AI Act compliance, but the two overlap heavily on risk management, data governance, transparency, documentation, and human oversight—precisely the obligations the Act imposes on high-risk systems. The repost frames the standard as a "common language" that lets a U.S. firm demonstrate diligence to European regulators and partners without building a separate compliance machine for each market. It is the same standards-first logic Kop and colleagues have argued for in quantum governance, where international standards substitute for legislation that has not yet caught up to the technology.

From paperwork to governance asset

The closing move is strategic rather than procedural. Under an anticipated period of U.S. federal deregulation, the essay contends, a globally recognized standard offers stability that domestic political cycles cannot: a baseline of good governance that holds regardless of which executive orders survive. The Daiki method then operationalizes that posture through six integrated components—an AI system registry, an EU AI Act toolkit, an ISO 42001 implementation framework, ISO 27001 data-security integration, MDR/ISO 13485 support for medical AI, and a responsible generative-AI framework—so overlapping requirements are managed once, not many times. The throughline connects to Daiki's wider body of work on operationalizing regulation, including its EU AI Act compliance solution and its quantum-governance recipe.

Why repost it here

For boards, general counsel, and AI program leads, the practical message is that the era of principles is giving way to an era of evidence: organizations will increasingly be asked to prove their governance, not merely assert it. Reposting the essay in full preserves Kop's argument verbatim while placing it alongside AIRecht's running coverage of Mauritz Kop's work at the intersection of AI, standards, and responsible technology governance.

Meer lezen