AI Ethics, Governance & Your Career

AI Regulations for PMs

5 min read

AI regulation is no longer future—it's now. The EU AI Act is law, and other regions are following. Here's what you need to know.

The Regulatory Landscape (2026)

RegionStatusKey Regulation
European UnionIn forceEU AI Act
United StatesState-by-state + Executive OrdersVarious state laws, NIST AI RMF
United KingdomFrameworkAI Safety Institute guidance
ChinaIn forceGenerative AI regulations
CanadaProposedAIDA (Artificial Intelligence and Data Act)

EU AI Act: What PMs Must Know

The Risk-Based Framework

The EU AI Act categorizes AI by risk level:

Risk LevelExamplesRequirements
UnacceptableSocial scoring, manipulative AIBanned
HighHiring, credit, healthcare, educationStrict compliance
LimitedChatbots, emotion recognitionTransparency
MinimalSpam filters, recommendationsNo specific requirements

High-Risk AI Requirements

If your AI falls in the high-risk category, you need:

RequirementWhat It Means
Risk managementDocument and mitigate AI risks
Data governanceTraining data must be relevant, representative, error-free
Technical documentationDetailed system description
Record keepingLog AI decisions for traceability
TransparencyClear information to users
Human oversightHumans can intervene/override
Accuracy & robustnessMeet defined performance standards

Is Your AI High-Risk?

Answer these questions:

  1. Does it make decisions about people's:

    • Employment or recruitment?
    • Creditworthiness or loans?
    • Education or training access?
    • Essential services access?
    • Law enforcement or immigration?
  2. Is it a safety component in:

    • Medical devices?
    • Transportation systems?
    • Critical infrastructure?

If yes to any: Likely high-risk. Consult legal.

GDPR Implications for AI

GDPR already applies to AI that processes personal data:

GDPR RequirementAI Implication
Lawful basisNeed legal ground to use data for AI
Purpose limitationCan't repurpose training data freely
Data minimizationOnly collect what's necessary
Right to explanationUsers can ask how decisions were made
Right to objectUsers can opt out of automated decisions
Right not to be subject to automated decisionsSignificant decisions need human involvement

Article 22: Automated Decision-Making

Key restrictions:

  • Right to human review for decisions with legal/significant effects
  • Right to explanation of the logic involved
  • Right to contest the decision

PM Action: Ensure appeals process exists for AI-driven decisions.

Compliance Checklist for PMs

Before Development

  • Classify AI risk level (unacceptable/high/limited/minimal)
  • Identify applicable regulations (EU AI Act, GDPR, local laws)
  • Consult legal/compliance team
  • Document intended use and limitations

During Development

  • Training data documented and audited
  • Model testing includes fairness evaluation
  • Technical documentation maintained
  • Human oversight mechanisms designed

Before Launch

  • Risk assessment completed
  • User disclosure/transparency in place
  • Appeals/override process implemented
  • Logging and audit trails enabled

After Launch

  • Ongoing monitoring active
  • Incident response plan ready
  • Regular compliance audits scheduled
  • User complaint handling process defined

Common Compliance Mistakes

MistakeWhy It's RiskyFix
"We're not in EU, so EU AI Act doesn't apply"Applies if serving EU usersKnow your user geography
"It's just recommendations, not decisions"Recommendations can have significant effectsAssess actual impact
"Users agreed to ToS"Consent doesn't override all requirementsCompliance is still needed
"We'll add compliance later"Retrofitting is expensiveBuild in from start

Working with Legal/Compliance

  1. "What risk category does our AI feature fall into?"
  2. "What documentation do we need to create?"
  3. "Do we need impact assessments?"
  4. "What user rights must we support?"
  5. "What happens if we get it wrong?"
  • Clear description of AI functionality
  • Data sources and processing
  • Decision scope and impact
  • User interaction points
  • Geographic scope

Future-Proofing Your AI Products

Regulations will only increase. Build for compliance:

PrincipleImplementation
Transparency by designExplainability from day one
Privacy by designMinimize data, anonymize when possible
AuditabilityComprehensive logging
Human oversightOverride capabilities built in
DocumentationContinuous, not retrofit

Key Takeaway

Regulation is a product requirement, not a legal afterthought. The EU AI Act sets the global baseline. Build compliance into your product from the start—it's cheaper and safer than fixing it later.


Next: How do you grow your career as an AI Product Manager? Let's explore the path forward. :::

Quick check: how does this lesson land for you?

Quiz

Module 4: AI Ethics, Governance & Your Career

Take Quiz
FREE WEEKLY NEWSLETTER

Stay on the Nerd Track

One email per week — courses, deep dives, tools, and AI experiments.

No spam. Unsubscribe anytime.