Exclusive interview: Anekanta’s Pauline Norstrom – part 3

anekanta

In the last of our not-to-be-missed exclusive interview series, Anekanta‘s CEO, Pauline Norstrom, helps to demystify some of the issues around AI, and in this piece, discusses discusses regulation and governance. This is part three, of three.

With EU AI regulation mandatory for many security AI systems, and biometric AI regulation evolving rapidly, what should businesses be doing now rather than waiting for the law to be enforced?

Pauline Norstom: “Waiting is the costliest option, for two reasons. The obligations take time to meet — data governance, documentation, oversight and conformity work cannot be assembled the week a deadline arrives — and the commercial demand is already ahead of the application of the high-risk requirements in EU AI law. Enterprise buyers, insurers and partners are asking how AI is governed now, well before any regulator appears. This is because it is the enterprise, and ultimately its board who shoulder the risk of a poor AI investment decision.

“The practical starting point is to establish what AI the organisation actually operates and how each system would be classified; to assess the risk each carries and design controls which mitigate it; to build AI literacy so the workforce can oversee these systems competently; and to put a governance framework around the whole estate, with ISO/IEC 42001 as the recognised structure for doing so. This is work that pays for itself before enforcement, because it is precisely what customers and insurers are now demanding — and it positions the organisation to address regulated markets.”

Are the trust pillars — AI strategy, risk assessment, literacy and governance — becoming imperatives for successful AI development and deployment, or are they still treated as an afterthought?

PN: “Smart enterprise has never considered these pillars an afterthought, that is why they are usually ahead competitively. Organisations that recognise the value hold the real advantage. Trustworthy AI is now the precondition for deploying AI at scale: systems that cannot be trusted do not clear procurement, do not get insured, and do not survive contact with regulation or an enterprise customer managing risk.

“The four pillars are not a compliance overhead sitting to one side of the business case — they are the business case. Strategy directs investment to where AI genuinely creates value. Risk assessment keeps deployment safe and defensible. Literacy lets people extract the benefit while retaining control. Governance sets out the consistent way of managing risk, demonstrable to others. Together they are what turn AI systems from expensive experiments into durable, returning assets. That is the shift the leading organisations have already made, and it is the one the rest of the market will be driven to make by their customers, their insurers and the law.”

To go back and read part one, click here, and part two, here

For more AI news, click here

Share this

Related News

Abloy UK has provided St Oswald’s Hospice in Newcastle…

News

Genetec Inc. has released retail-specific findings from its 2026…

News

Axis Communications has announced three purpose-built LPR camera kits…

News

Scroll to Top