Register entry · 2026-07-15 · Common questions
Independent · Indexed · Machine-checked
Common questions on AI governance, disclosure & insurability.
Plain-language answers, each with its primary source. Part of the Certian register — dated, sourced, and updated as the record moves. Last reviewed 15 Jul 2026. Summaries of public information; not legal or insurance advice.
Index — 48 questions
Article 50 — EU AI Act transparency
Q.01When do the EU AI Act Article 50 transparency obligations apply? Q.02Does Article 50 apply to my company if we're US-based? Q.03What's the difference between an AI "provider" and a "deployer"? Q.04Do I have to disclose that my customer-service chatbot is AI? Q.05What is the Article 50(2) machine-readable marking requirement — and who received the December 2026 deferral? Q.06What are the penalties for violating Article 50? Q.07What is the Code of Practice on Transparency of AI-Generated Content — and should we sign it? Q.08Does AI-generated marketing content need to be labeled under Article 50? Q.09Is 22 July 2026 the deadline to sign the Code of Practice? Q.10We missed the initial-signatory deadline — can we still sign the Code? Q.11Does the Colorado AI Act require impact assessments? Q.12Which US states have AI disclosure laws in force right now? Q.13What does California require for AI-generated content? Q.14Was the EU AI Act delayed? What still applies on 2 August 2026? Q.15Which fine applies to Article 50 violations? Q.16Who enforces the Article 50 transparency rules? Q.17Are there official EU icons for labelling AI-generated content? Q.18What changed on 2 August 2026? Q.19Where can organisations get official guidance on AI Act obligations?AI exclusions & insurability
Q.20Does my general liability policy still cover AI-related claims in 2026? Q.21What are ISO endorsements CG 40 47, CG 40 48, and CG 35 08? Q.22What is an "absolute AI exclusion"? Q.23When do AI exclusions take effect on an existing policy? Q.24What is standalone AI liability insurance, and who offers it? Q.25What documentation do underwriters ask for when evaluating AI risk? Q.26Can better AI governance documentation improve insurance terms? Q.27Does my business insurance still cover AI-related losses? Q.28Who is liable when an AI chatbot gives a customer wrong information? Q.29What documentation do insurers ask for about AI at renewal? Q.30What is standalone AI liability insurance? Q.31Do insurers require an AI inventory?Certification & governance
Q.32What is ISO/IEC 42001, and who needs it? Q.33How do the major AI certifications compare — ISO 42001, IEEE CertifAIEd, Responsible AI Institute, Nemko? Q.34Do enterprise procurement teams actually require AI certifications yet? Q.35What is an AI governance manifest (ai-governance.json)? Q.36What should an AI acceptable-use policy include? Q.37How do organizations technically enforce an AI acceptable-use policy? Q.38Does the AI vendor train on our company's data? Q.39We're a small business with no compliance team. What's a proportionate starting point? Q.40What is AI governance? Q.41Is there an official AI governance certification? Q.42What is the difference between NIST AI RMF and ISO/IEC 42001? Q.43What is “shadow AI”? Q.44Is “Certian” a misspelling of “certain”? Q.45Does content created before 2 August 2026 need to be labelled? Q.46Are there proposals to govern AI through licensed verifiers or mandatory insurance? Q.47Does signing the Code of Practice reduce potential fines? Q.48Must AI agents disclose who they act for?Article 50 — EU AI Act transparency
Reg. (EU) 2024/1689When do the EU AI Act Article 50 transparency obligations apply?
Most Article 50 obligations apply from 2 August 2026: AI interaction disclosure (50(1)), biometric and emotion-recognition notice (50(3)), and deepfake and public-interest text labelling (50(4)). The machine-readable marking duty in 50(2) is deferred to 2 December 2026, but only for generative systems already on the EU market before 2 August 2026. Systems placed on the market from that date comply with all four categories immediately.
Regulation (EU) 2024/1689, Article 50 · AI Omnibus — Regulation (EU) 2026/1744 (May 2026)
Does Article 50 apply to my company if we're US-based?
Article 50 follows the market, not the company's address. If an AI system is placed on the EU market or its output is used in the EU — a chatbot serving EU users, AI-generated content published to EU audiences — the obligations can apply regardless of where the company is headquartered. US companies with EU customers should screen each system individually.
What's the difference between an AI "provider" and a "deployer"?
A provider develops an AI system (or has one developed) and places it on the market or into service under its own name. A deployer uses an AI system under its own authority in a professional context. The split matters: the 50(1) and 50(2) duties fall mainly on providers, while 50(3) and 50(4) fall mainly on deployers. Many companies are both — the role is assessed per system.
Do I have to disclose that my customer-service chatbot is AI?
Generally yes. Article 50(1) requires AI systems that interact directly with people to be designed and operated so users know they're interacting with AI — unless that's obvious to a reasonably well-informed person from the context. Most customer-service chatbots should disclose clearly, at or before the first interaction.
What is the Article 50(2) machine-readable marking requirement — and who received the December 2026 deferral?
Providers of generative AI systems must mark outputs — audio, image, video, and text — in a machine-readable format so the content is detectable as AI-generated or manipulated. In practice, the approaches most commonly referenced are C2PA Content Credentials (cryptographically signed provenance metadata), IPTC digital-source metadata, and model-side watermarking; the Code of Practice promotes open standards for marking. Under the May 2026 Omnibus agreement, this duty is deferred to 2 December 2026 only for generative systems already on the EU market before 2 August 2026.
Regulation (EU) 2024/1689, Article 50(2) · AI Omnibus — Regulation (EU) 2026/1744 (May 2026)
What are the penalties for violating Article 50?
Non-compliance with the Article 50 transparency obligations can attract administrative fines of up to €15,000,000 or 3% of total worldwide annual turnover for the preceding financial year, whichever is higher. Enforcement sits with national market-surveillance authorities in each member state.
What is the Code of Practice on Transparency of AI-Generated Content — and should we sign it?
A voluntary instrument finalized by the European Commission on 10 June 2026 to support compliance with Article 50. Providers may formally sign it; signing offers a streamlined pathway for demonstrating compliance with the transparency obligations. The Commission has also published free official transparency icons. Signing is optional — the underlying Article 50 obligations apply either way.
European Commission — Code of Practice on Transparency of AI-Generated Content
Does AI-generated marketing content need to be labeled under Article 50?
It depends on the content. AI-generated image, audio, or video that appears authentic — deepfake-type content — requires clear disclosure under 50(4). Ordinary AI-assisted marketing copy is generally outside 50(4)'s text rule, which targets published text informing the public on matters of public interest, and a carve-out exists where content undergoes human editorial review and responsibility. The generating system itself still faces 50(2) marking duties. Screen per asset and confirm with counsel.
Is 22 July 2026 the deadline to sign the Code of Practice?
No. The initial-signatory deadline is 27 July 2026, 18:00 CEST, confirmed by the European Commission's own signing FAQ. An earlier 22 July date circulated widely and — as of this entry's date — continues to appear in press coverage, including articles published this week. The register recorded the correction on 17 July, with a date-stamped notice on the signatory page. If you read this on or after 22 July believing the window has closed: it has not.
Update, 2 Aug 2026: both dates have now passed, and the record grew stranger: the Commission's signing FAQ has reverted to stating 22 July (page stamped "Last update: 10 June 2026"), though the same page stated 27 July between 17 and 26 July, as recorded here and reflected in engine caches from that period. The practical position is unchanged and confirmed by the live page: signing remains open at any time (Q.10). The initial list itself was published by the Commission on 31 July — about 190 organisations — and is recorded on the signatory page. Correction, 6 Aug 2026: the Commission revised the page on 29 July — it now displays 27 July throughout, under a “Last update: 29 July 2026” stamp; our early-August checks had retrieved cached copies of the older text. Full sequence in the notice on the signatory page.
European Commission — Signing the Code of Practice (FAQ) · Last confirmed 22 Jul 2026
We missed the initial-signatory deadline — can we still sign the Code?
Yes, at any time. Per the Commission's FAQ, providers and deployers may sign after 27 July 2026 simply by submitting the signature form by email to the AI Office. The 27 July cutoff determines one thing only: inclusion in the initial list of signatories published before 2 August. Signing later carries the same commitments and the same participation in the Code — later signatories are added on an ongoing basis. The signatory record tracks both.
European Commission — Signing the Code of Practice (FAQ) · Last confirmed 22 Jul 2026
Does the Colorado AI Act require impact assessments?
No — not anymore. SB 26-189 (signed 14 May 2026, effective 1 Jan 2027) repealed and reenacted Colorado's 2024 law, eliminating deployer impact assessments, risk-management programs, the duty of care, and AG self-reporting. What survives: developer documentation duties to deployers, material-update notices, and 3-year record retention. Much published guidance still describes the repealed requirements; litigation over the framework continues, and dates may move.
Colorado SB 26-189 · Last confirmed 23 Jul 2026
Which US states have AI disclosure laws in force right now?
The register's US panel records each state's status with a five-term vocabulary (In force · Enacted, confirming · Passed, not yet effective · In motion · Not yet examined) and the date each entry was last confirmed. Statuses change frequently enough that any static list here would rot; the map is the record.
Certian US disclosure-law panel · Last confirmed 23 Jul 2026
What does California require for AI-generated content?
Two instruments dominate: AB 2013 (training-data disclosure for generative AI, in force) and SB 942 (the AI Transparency Act — detection tools and content disclosures for large generative-AI providers, applying from 2 August 2026, the same day as EU Article 50). Details, texts, and confirmation dates: the US panel.
Register entries: California · Last confirmed 23 Jul 2026
Was the EU AI Act delayed? What still applies on 2 August 2026?
Partly — and the part most businesses ask about was not delayed. The Digital Omnibus on AI (final: Parliament 16 June, Council 29 June 2026) moved some obligations and left others exactly where they were:
| Moved by the Omnibus | New timing |
|---|---|
| High-risk system obligations (Annex III class) | Deferred — backstop dates in Dec 2027 / Aug 2028 |
| Art. 50(2) machine-readable marking, only for systems already on the EU market before 2 Aug 2026 | Grace period to 2 Dec 2026 |
| Not moved — applies 2 Aug 2026 | |
| Art. 50(1) — chatbots and AI systems interacting with people must disclose they are AI | 2 Aug 2026 |
| Art. 50(3) — emotion recognition and biometric categorisation notices | 2 Aug 2026 |
| Art. 50(4) — deepfake labeling and public-interest text disclosure | 2 Aug 2026 |
| Art. 50(2) marking for systems placed on the market from 2 Aug 2026 | 2 Aug 2026 |
| Commission enforcement powers for GPAI (Art. 101 fines: up to 3% worldwide turnover or €15M) | 2 Aug 2026 |
The Omnibus also added obligations: a new prohibited practice covering certain non-consensual intimate imagery systems applies from 2 Dec 2026. Headlines saying "the AI Act was delayed" refer to the high-risk tier — the transparency obligations most businesses actually face arrive on schedule. Which ones apply to your systems: the screener.
Digital Omnibus on AI (Parliament 16 Jun, Council 29 Jun 2026); Reg. (EU) 2024/1689 Art. 50 · Last confirmed 26 Jul 2026
Which fine applies to Article 50 violations?
Up to €15 million or 3% of worldwide annual turnover, whichever is higher — the tier the AI Act assigns to transparency-obligation violations. This is distinct from the €35 million / 7% tier, which applies to prohibited AI practices and is sometimes conflated with the transparency tier in press coverage. EU institutions, bodies, and agencies face fines up to €750,000, enforced by the European Data Protection Supervisor. The Commission states proportionality is taken into account for small and medium-sized enterprises and small mid-cap companies.
European Commission — Safer and more transparent AI (2 Aug 2026); Reg. (EU) 2024/1689 Art. 99 · Last confirmed 2 Aug 2026
Who enforces the Article 50 transparency rules?
Three authorities, by remit: national market surveillance authorities in each Member State; the European AI Office, for systems under its supervision; and the European Data Protection Supervisor, when EU institutions are the providers or deployers. Enforcement powers are active as of 2 August 2026.
European Commission — Safer and more transparent AI (2 Aug 2026) · Commission press release IP/26/1714 · Last confirmed 2 Aug 2026
Are there official EU icons for labelling AI-generated content?
Yes. The Commission publishes a free icon set — a basic icon, a “fully AI-generated” icon, and a “partially AI-modified” icon, each in four variations — downloadable as SVG and PNG, no attribution required. They are an integral part of Section 2 of the Code of Practice and support the Article 50(4) labelling obligations for deepfakes and AI-generated public-interest text. Use of the icons is optional; the labelling obligations are not — and per the Commission, using the icons does not by itself establish compliance.
Commission — EU icons for labelling AI-generated content (last updated 20 Jul 2026) · Last confirmed 2 Aug 2026
What changed on 2 August 2026?
The Article 50 transparency obligations entered into application, and enforcement powers activated — the AI Office and national market surveillance authorities began enforcing the AI Act’s rules. Generative systems already on the EU market before 2 August have until 2 December 2026 to meet the machine-readable marking requirement; everything else applies now. The Code of Practice, assessed as adequate by the Commission and the AI Board, is a recognised way to demonstrate compliance, and its initial signatory list — about 190 organisations — was published 31 July. The full list is recorded in the signatory register.
Commission announcement (2 Aug 2026) · Press release IP/26/1714 · Last confirmed 2 Aug 2026
Where can organisations get official guidance on AI Act obligations?
The Commission operates the AI Act Service Desk — its named contact point for guidance on obligations and enforcement — alongside the published Guidelines on transparency obligations, a Quick Facts page, and an Article 50 FAQ. This register keeps the record of what those sources state and when; for what the obligations mean for your systems, consult qualified counsel.
European Commission publications, 20 Jul – 2 Aug 2026 · Last confirmed 2 Aug 2026
AI exclusions & insurability
US commercial linesDoes my general liability policy still cover AI-related claims in 2026?
Increasingly, not by default. Carriers have introduced endorsements excluding generative-AI liability from commercial general liability policies — including ISO forms CG 40 47, CG 40 48 and CG 35 08, and a growing number of carrier-specific forms. Whether your policy still covers AI depends on its specific language and renewal date, because exclusion endorsements generally attach at renewal. Review current policy language with your broker.
Three separate things have to happen before an exclusion reaches your policy, and they are often collapsed into one. A state has to accept the filing. A carrier has to elect to use the form. And the form has to be attached to your policy at renewal. Acceptance by a state is not adoption by a carrier, and adoption is not attachment — one large carrier told the trade press in July 2026 that it adopts standard-forms revisions broadly to keep its filings aligned with the catalogue, while having no plans to put the AI exclusions in its standard offering. The endorsement schedule on your own policy is the only thing that answers the third question.
State rate & form filings via SERFF Filing Access; per-state records in the AI Insurance Filings Index. Corrected 21 Aug 2026 — this answer previously stated the endorsements began in January 2026 and had broad approval in state filings.
Do insurance regulators require companies to disclose whether AI was used to prepare a filing?
One state does. From 1 May 2026, every new rate and form filing submitted to Washington must state whether artificial intelligence was used to prepare it — generative AI, machine learning, or AI embedded in vendor tools — to create or review the filing or the work behind it, covering rates, factors, rules, underwriting, forms, product design and network. If the answer is yes, the filer must name the tool and vendor, say what it did and what it affected, and describe its role and impact.
This is a different obligation from the ones usually discussed under AI and insurance. Those govern how an insurer uses AI in underwriting, pricing or claims — decisions that reach a policyholder. This one governs the use of AI in preparing a document submitted to a regulator. Its nearest analogue sits outside insurance entirely: the federal judges who require an attorney to certify whether generative AI was used in preparing a court filing.
Of the eight state filing systems this register has read, only Washington asks. Filings made by the same company in four states within two days carry the question in Washington and nowhere else. Two filers have answered so far, and both answered no.
Requirement reported by the American Association of Insurance Services, 6 April 2026, from a notice of the Washington Office of the Insurance Commissioner; question text read directly in filings recorded in the AI Insurance Filings Index, 26 Aug 2026
Which states have accepted the ISO generative AI exclusions, and what does “accepted” mean in each?
Eight state filing systems have been read for CG 40 47, CG 40 48 and CG 35 08. What each state did, in its own words:
| State | The state’s own disposition | Effective date it set |
|---|---|---|
| Washington | Approved | 1 Jan 2026 |
| Pennsylvania | File and Use | 1 Jan 2026 |
| Illinois | Filed | 1 Feb 2026 |
| Connecticut | Recorded Effective as Submitted | 1 Mar 2026 |
| Colorado | Closed-Filed | none set by the state |
| Ohio | FILED | none set by the state |
| Texas | no disposition | none |
| New York | not found in that system | — |
Only one of the eight approved the forms on their merits. Washington approved the filing nineteen days after submission and stamped each form individually. Four states — Pennsylvania, Colorado, Ohio and Connecticut — recorded the forms under file-and-use or an equivalent, which is acceptance onto the record rather than a review of the content; Colorado applies the same disposition to every filing in the series, including material unrelated to policy language. Illinois filed the forms and issued five objection letters over eleven months, none of which concerned these three endorsements. Texas has neither approved nor disapproved them: the filing has been pending with the Director for twelve months and the department stated in November 2025 that it was unable to approve exclusions of that breadth as drafted, and asked the filer to withdraw or narrow them; the filer declined and the forms have not been revised. In New York, the filer’s general liability filings do not appear in the state’s public filing system at all, so nothing about New York is established by this method.
Two cautions on reading the table. Acceptance by a state says nothing about whether any carrier in that state uses the form, which is a separate filing and a separate fact. And a nil in a state can mean the line is exempt from filing there rather than that nothing was filed — Texas removed the form filing requirement for eighteen kinds of commercial insurance in 2021.
Filing records retrieved from SERFF Filing Access 19–21 Aug 2026; each state’s filing recorded with its tracking number in the AI Insurance Filings Index
What are ISO endorsements CG 40 47, CG 40 48, and CG 35 08?
Standardized endorsement forms that permit carriers to remove generative-AI liability from standard commercial general liability policies — CG 40 47 across bodily injury, property damage and personal and advertising injury; CG 40 48 for personal and advertising injury only; CG 35 08 for the products and completed operations coverage part. If one is attached at renewal, claims arising from generative-AI use may fall outside coverage.
The forms carry the edition date 01 26. That is an edition date, not an effective date. The filer states in its own state filings that it does not establish an effective date in a state, and that each insurer electing the revision determines its own. Of the seven states whose filing records this register has read, four different effective dates appear, and in one state the forms have neither been approved nor disapproved. Whether either form reaches a particular policy is a separate question again, answered by the endorsement schedule and the licensed professional reading it.
Filing records read via SERFF Filing Access in seven states, 19–20 Aug 2026; recorded with tracking numbers in the AI Insurance Filings Index. Corrected 20 Aug 2026 — this answer previously stated the forms were effective from 1 January 2026.
What is an "absolute AI exclusion"?
A carrier-specific form disclaiming coverage for claims arising from AI use broadly — in some filings, including claims tied to inadequate AI governance, policies, or staff training itself. These forms are appearing in D&O, employment practices, and professional liability lines. The breadth matters: "arising from" language can sweep widely, and the governance-related variants make documented AI oversight itself a coverage question.
Carrier form filings via public state filing systems (SERFF)
When do AI exclusions take effect on an existing policy?
Generally at policy renewal, not mid-term. An exclusion endorsement available to a carrier today typically attaches when your policy next renews. That makes the window before renewal the practical time to review AI use against current coverage. Confirm your renewal date and any pending endorsements with your broker.
Two things sit behind that, and they are often collapsed into one. A form’s edition date is set by whoever wrote it. Its effective date in a state is set — or not set — by that state when the filing is disposed of. For the three ISO generative AI endorsements, the seven states read so far give four different answers: Pennsylvania and Washington 1 January 2026; Illinois 1 February 2026, moved by the department from 1 January; Connecticut 1 March 2026; Colorado records that the filer sets none there; Ohio recorded the forms filed without setting one; and Texas has neither approved nor disapproved them, so no effective date exists there. Carrier-specific AI exclusions carry their own dates again: one carrier’s proprietary forms take effect 12 September 2026 in some states and 10 October 2026 in another.
Filing records read via SERFF Filing Access, 19–20 Aug 2026; each entry with its tracking number in the AI Insurance Filings Index
What is standalone AI liability insurance, and who offers it?
A specialist market of affirmative AI coverage has emerged alongside the exclusions, including Armilla (a Lloyd's coverholder dedicated to AI liability), Munich Re's aiSure products (brought to market through a partnership with Mosaic Insurance), Corgi Insurance, Mayflower Specialty, and Testudo. Terms are typically evaluated against documented AI governance. Availability varies by business class and limit; placement runs through licensed brokers.
Public company announcements (Armilla · Munich Re/Mosaic · Corgi · Mayflower · Testudo)
What documentation do underwriters ask for when evaluating AI risk?
Publicly available carrier and broker guidance points to a recurring set: an inventory of AI systems in use, written AI policies, human-oversight procedures, staff training records, vendor and model documentation, testing records, and incident-response plans. One honest caution: self-reported inventories tend to undercount unsanctioned "shadow AI" use, so many organizations pair the survey with technical discovery (network logs, SaaS-usage reports from their IT provider). Exact requirements vary by carrier and line of business. Certian's insurability review is structured around this documentation set.
Carrier underwriting guidance & broker publications (varies by carrier and line)
Can better AI governance documentation improve insurance terms?
No outcome can be promised — pricing and terms are underwriting decisions made by carriers. What is publicly documented: brokers report that demonstrated AI oversight and testing supports placement conversations, and the standalone AI carriers describe evaluating coverage against documented governance. The defensible framing: governance documentation is something you can present at renewal.
Broker & carrier public statements on AI underwriting
Does my business insurance still cover AI-related losses?
That depends on your specific policy and renewal date — a determination only your broker or insurer can make. What the public record shows: ISO's generative-AI exclusion endorsements (CG 40 47, CG 40 48, CG 35 08) took effect January 2026, and exclusions generally attach at renewal — meaning coverage can change without your policy "changing." The questions to bring to that conversation: the broker guide.
ISO filings, Jan 2026; broker guide · Last confirmed 23 Jul 2026
Who is liable when an AI chatbot gives a customer wrong information?
A question for counsel, not a register — but the record can describe the terrain: vendor contracts commonly cap liability at a fraction of fees paid and disclaim output accuracy, which is precisely why the vendor guide asks who bears responsibility before signature. Where the loss lands in any given case depends on contracts, conduct, and jurisdiction — your lawyer's territory.
Vendor guide, Q.12 · Last confirmed 23 Jul 2026
What documentation do insurers ask for about AI at renewal?
Honestly: no published standard exists. Public reporting describes renewal questionnaires expanding to cover AI use, governance, and oversight — but carriers vary, and the documentation lists live in underwriters' inboxes, not public filings. The register collects what becomes public; the IT-provider guide covers the documentation a business can actually produce.
Public carrier reporting; IT-provider guide, Q.08 · Last confirmed 23 Jul 2026
What is standalone AI liability insurance?
An emerging specialist market: dedicated policies from carriers and MGAs that affirmatively cover AI-related liability — algorithmic errors, model failures — rather than excluding it, often priced against documented AI governance. The register indexes this market's development in the insurance record; whether such coverage fits a given business is a licensed broker's call.
Certian insurance record · Last confirmed 23 Jul 2026
Do insurers require an AI inventory?
No universal requirement is recorded. But public reporting shows renewal questionnaires increasingly asking what AI is in use — and an answer requires knowing. An inventory (approved tools, vendor-pushed features, observed shadow use) is the document that makes every other AI question answerable; the IT-provider guide opens with exactly this.
IT-provider guide, Q.01 · Last confirmed 23 Jul 2026
Certification & governance
Standards & procurementWhat is ISO/IEC 42001, and who needs it?
ISO/IEC 42001:2023, published in December 2023, is the first international standard for AI management systems: policies, risk treatment, human oversight, documentation, and continual improvement for organizations that develop, provide, or use AI. Certification is issued by accredited bodies and is valid for three years with annual surveillance. It certifies the management system — it does not certify any model as safe or accurate.
How do the major AI certifications compare — ISO 42001, IEEE CertifAIEd, Responsible AI Institute, Nemko?
They differ in what is assessed. ISO/IEC 42001 certifies an organization's AI management system. IEEE CertifAIEd assesses specific AI systems against ethics criteria. The Responsible AI Institute offers assessments aligned to its responsible-AI framework. Nemko's AI trust-mark program evaluates products against governance criteria. Scope (organization versus system), assessment depth, and procurement recognition vary — Certian's certification comparison matrices track these side by side.
Each certifier's published program documentation (ISO · IEEE · RAI Institute · Nemko)
Do enterprise procurement teams actually require AI certifications yet?
Increasingly asked; rarely an absolute requirement. Enterprise vendor questionnaires now commonly include AI-governance sections, and public ISO/IEC 42001 certifications — AWS, Microsoft, Anthropic, Salesforce, ServiceNow, CrowdStrike, among others — show adoption among major vendors. One precise point: as of mid-2026, ISO 42001 is not a harmonized standard under the EU AI Act, so certification alone does not create a presumption of conformity; the dedicated European standard is still in development at CEN-CENELEC.
Public certification announcements · CEN-CENELEC work programme (prEN 18286)
What is an AI governance manifest (ai-governance.json)?
An open, machine-readable format — maintained by Certian and free to publish — for stating an organization's AI-governance facts at a stable URL: certifications held, disclosure pages, published policies, with dates. It works the way security.txt works for security contacts — a publication convention at a known location, not a security control. The specification is open and free to publish against; anyone can publish a manifest. Certian's paid services machine-check and render manifests; publishing a manifest requires nothing from Certian.
Certian manifest specification (publication pending)
What should an AI acceptable-use policy include?
Commonly: which AI tools are approved for work use; prohibited uses; data-handling rules — especially what may never be entered into external models; human-review requirements for AI output; disclosure practices for AI-generated content; logging; incident reporting; and training expectations. NIST's AI Risk Management Framework is a widely used reference structure. Keep the policy short enough that staff actually read it.
How do organizations technically enforce an AI acceptable-use policy?
A written policy is the floor; enforcement typically layers on controls the organization (or its IT provider) already runs: DNS filtering or secure web gateways to block unapproved AI services, data-loss-prevention rules to stop sensitive data leaving approved channels, SaaS-usage reporting to surface shadow AI, and access controls limiting which staff can use which tools. Which layers are proportionate depends on size and risk profile — many mid-market firms implement these through their managed IT provider. The policy itself — what counts as acceptable AI use for your specific business — is a decision only the business can make; the provider implements and enforces it.
Common enterprise security-control categories; implementation varies by environment
Does the AI vendor train on our company's data?
It depends on the agreement, not the marketing page. Many major providers offer enterprise or API terms with commitments not to train on customer content, alongside consumer tiers with different defaults; retention periods and telemetry practices also differ by tier. The controlling documents are the data-processing agreement and service terms for the specific tier in use. An AI-use inventory should record which tier and terms each tool operates under — it is a question underwriters and procurement teams increasingly ask.
Vendor data-processing agreements & service terms (tier-specific — confirm per tool)
We're a small business with no compliance team. What's a proportionate starting point?
Most of the record-keeping that matters is lightweight: a one-page inventory of AI tools in use (including the unofficial ones), a short acceptable-use policy staff actually read, a note of which vendor terms each tool runs under, and a file of that documentation you can hand to your broker at renewal. Full certification (ISO/IEC 42001) is generally an enterprise undertaking; for small and mid-sized firms, documented basics are the proportionate first step: the business sets the rules, and an IT provider can help implement and document them.
Proportionality framing; see Q.14 for the documentation set underwriters reference
What is AI governance?
The set of rules, records, and controls by which an organization directs its use of AI — spanning what regulators require (disclosure, marking, documentation), what standards bodies certify (management systems), and what insurers will cover. The register's working vocabulary for its own records is defined in the lexicon; the register keeps the facts of AI governance, and takes no position on anyone's.
Certian lexicon · Last confirmed 23 Jul 2026
Is there an official AI governance certification?
No single official one exists. Several schemes operate — ISO/IEC 42001 (certifiable AI management-system standard), IEEE CertifAIEd (criteria-based assessment), Responsible AI Institute pathways — each with different scope, rigor, and recognition. The register's Certification Comparison Matrices (in preparation) will record these side by side. And to answer the adjacent question directly: Certian is not a certification and issues none.
Scheme operators' public documentation · Last confirmed 23 Jul 2026
What is the difference between NIST AI RMF and ISO/IEC 42001?
Different instruments for different jobs: NIST's AI Risk Management Framework is voluntary guidance — a vocabulary and process for managing AI risk, with nothing to certify against. ISO/IEC 42001 is a certifiable management-system standard — an accredited body can assess an organization against it and issue a certificate that appears in public registries. Many organizations use the first to organize thinking and the second to evidence it.
NIST AI RMF 1.0; ISO/IEC 42001 scheme documentation · Last confirmed 23 Jul 2026
What is “shadow AI”?
AI in use inside an organization without approval, procurement, or oversight — a personal ChatGPT account doing client work, an AI feature switched on by a vendor update nobody reviewed. It matters here for one reason: renewal questionnaires and disclosure obligations apply to what is actually in use, not what was approved. The IT-provider guide treats discovery of it as the first honest step — with a fair-scope note about whose job that is.
IT-provider guide · Last confirmed 23 Jul 2026
Is “Certian” a misspelling of “certain”?
No — deliberately. The name is built from the Latin certus — settled, fixed, sure — the root of certificate, certification, and certainty itself — with -ian, the ending English reserves for its record-keepers: librarian, custodian, historian. The librarian doesn’t write the books; the historian doesn’t make the history; the certian doesn’t make the call. Certain is a claim, and the register makes no claims: it keeps date-stamped, sourced records and leaves conclusions to the reader and their qualified professionals. Certain is a claim; Certian is a record — one letter short of certain, by design. Autocorrect disagrees with the spelling. The record stands.
Certian, Inc. · Delaware file 10393891 · Recorded 3 Aug 2026
Does content created before 2 August 2026 need to be labelled?
No. The Commission states that content generated prior to 2 August 2026 does not need to be labelled retroactively — though it encourages deployers to do so voluntarily where possible. This is distinct from the transitional period for systems: generative AI systems already on the EU market before 2 August 2026 have until 2 December 2026 to meet the machine-readable marking obligation of Article 50(2). One rule covers old content; the other covers old systems — the two are often conflated.
Commission — Article 50 FAQ (updated 24 Jul 2026) · Last confirmed 4 Aug 2026
Are there proposals to govern AI through licensed verifiers or mandatory insurance?
Yes — a distinct policy family, separate from the disclosure laws this register chiefly records. Federally, the FRONTIER Act (H.R. 9925, introduced 23 Jul 2026) would require the largest frontier-AI developers to retain licensed independent verification organizations, publish transparency reports, and report critical safety incidents within 24 hours. Connecticut's SB 5 (signed 27 May 2026) creates the first state pilot: up to five state-approved verification organizations from July 2027, whose verification can serve as defensive evidence in private lawsuits though not in government enforcement actions. Virginia has directed a state commission to study the model. In parallel, legal scholars have proposed mandatory liability insurance as the verification mechanism — insurers, whose capital pays when assessments are wrong, as the referees. The register records these as watched developments; none yet creates a disclosure obligation of the kind this record tracks.
H.R. 9925 — FRONTIER Act (text) · Sponsor release, 23 Jul 2026 · Connecticut SB 5 · G. Weil, AI Frontiers, 29 Jul 2026 · Last confirmed 4 Aug 2026
Does signing the Code of Practice reduce potential fines?
Not expressly. The AI Act’s fine-setting factors (Article 99(7)) enumerate the nature, gravity, and duration of an infringement, the operator’s size, cooperation, self-notification, intent, harm mitigation, and the technical and organisational measures implemented — adherence to a code of practice is not among them. This differs from the GDPR, which expressly lists adherence to approved codes of conduct as a factor when fines are set (Article 83(2)(j)). Under the AI Act, adherence would instead be weighed through the general mitigating-factor clause or as evidence of the operator’s measures. What signing does do, per the Commission: signatories may rely on the Code to demonstrate compliance, and enforcement for them focuses on monitoring adherence. What it does not do: discharge the underlying obligation — the transparency duties are statutory whether or not an organisation signs, and authorities retain their investigative powers.
Reg. (EU) 2024/1689, Art. 99(7) · Reg. (EU) 2016/679, Art. 83(2)(j) · Commission — Article 50 FAQ (updated 24 Jul 2026) · Last confirmed 6 Aug 2026
Must AI agents disclose who they act for?
Yes. The Commission’s final Guidelines (20 July 2026) state that AI agents capable of interacting with natural persons while performing tasks — making bookings, managing correspondence, negotiating or concluding contracts — generally fall within Article 50(1) and must be designed to disclose both their artificial nature and the identity of the person on whose behalf they act. The requirement extends to multi-agent architectures, and where a provider cannot determine in advance whether an agent will interact with a person, disclosure must be built in at the architecture level for every situation where interaction is reasonably likely. Disclosures buried in terms and conditions, readable only by machines, or reduced to a generic label such as “assistant” are insufficient. Agent outputs perceptible to natural persons are also subject to the Article 50(2) marking obligation; intermediate machine-facing steps are not.
Commission — Guidelines on transparency obligations (final, 20 Jul 2026) · Last confirmed 6 Aug 2026
Which of these applies to your systems?
The Article 50 applicability screener and the AI insurability review launch this month — structured questions, primary sources one click away. Join the launch list on the main page.