Exclusive interview: Anekanta’s Pauline Norstrom

anekanta
Over the past five to 10 years, the use of AI technology has gradually built momentum in the security industry, to a point now where it is almost ubiquitous. But, the technology, which is still poorly understood and developing at speed, can present issues, both in terms of its ethical use and more general implementation. It can be used as a buzz word to help sell products, or it can used to add real value. In this exclusive interview series, Anekanta‘s CEO, Pauline Norstrom, helps to demystify some of the issues, offers insight into the EU AI Act and what it does, discusses adoption, implementation and trust, and gives some advice on regulation and governance. This is a series not to be missed. This is part one, of three.

What is Anekanta?

PN: “Anekanta® is a highly specialised AI advisory firm that helps enterprises develop and use AI effectively in high-stakes sectors, to improve business and operational outcomes and deliver a return on investment. Its work is built on four pillars which foster trustworthy AI — strategy, risk, literacy and governance — which together create the conditions for AI to succeed at scale and keep succeeding as the risk landscape evolves. Trust is not a soft consideration here: McKinsey’s 2026 AI Trust Maturity research identifies it as one of the decisive levers separating organisations that capture value from AI from those that stall.

“Underpinning trustworthy AI is a new body of regulation, led by the EU AI Act. For developers and users of high-risk AI, compliance is mandatory — and the Act is rapidly becoming the template for how high-risk AI is developed and governed worldwide, extending its influence well beyond Europe’s borders (Thomas Reuters Foundation 2026).

“A second ‘de-facto’ foundation is the new AI management system standard, ISO/IEC 42001. Leading enterprises are already achieving certification to demonstrate that their organisational practices which manage the development and use of AI are designed to manage objectives for success and risk both internally and externally to the organisation. Certification builds customer confidence, satisfying enterprise procurement, and reducing risk across the supply chain. For an organisation deploying AI across a large, multi-site or multinational operation, this is fast becoming the credential that buyers, insurers and regulators look for.”

For people who don’t know, can you explain what the AI Act is and what it does?

PN: “The EU AI Act is the world’s first comprehensive law governing artificial intelligence. It is a form of product regulation which entered into force on 1 August 2024, with its obligations taking effect in stages. It governs AI in the way that product safety and CE-marking regimes govern physical goods.

“Its purpose is to prevent and reduce the risk of harm to the health, safety and fundamental rights of people in the EU whilst fostering innovation. It does that by classifying AI systems according to the risk they present — determined by what the system does, the data it processes and the impact it can have — and attaching obligations proportionate to that risk:

• Unacceptable risk. Systems that manipulate behaviour, exploit vulnerability or profile people to their detriment are prohibited.

• High risk. Systems which may cause significant harm if poorly managed carry mandatory obligations. The high-risk category spans the use of biometric based AI systems and those developed or used for recruitment, education, essential public and private services, credit scoring, law enforcement, criminal justice and the administration of justice.

• Transparency requirements. Systems that interact with people, or generate synthetic content, must meet transparency obligations so a person is informed or it is obvious they are interacting with an AI system.

• Minimal risk. Everything else, where adoption of good practice is voluntary.

“Two points are widely missed. First, although most AI systems fall into the minimal-risk category where good practice is voluntary, the Act’s AI literacy obligation applies to every organisation using AI, regardless of risk level — and other laws, such as the GDPR, also apply. Second, for high-risk systems specific requirements must be met which include data governance, technical documentation, record-keeping, transparency, human oversight, and accuracy, robustness and cybersecurity. Every provider of a high-risk system must issue a declaration of conformity which depending on the conformity route can be self-certified or in the case of certain biometrics systems, mandatorily assessed by a recognised third party.”

Look out for the next interview in the series focusing on AI adoption, implementation, and trust.

For more AI news, click here

Share this

Related News

According to Tim Leehealey, Vice President of Corporate Strategy…

News

According to Anekanta, the reality is that too many…

News

Governed by strict compliance standards, a fiercely loyal installer…

News

Scroll to Top