A model card is more than just a static PDF. It documents the model version, usage context, data sources, risks, performance, approvals, and reviews—and must address the
Data protection records are only audit-ready if the processing, risk, approval, version, and measures remain traceably linked. Why email, Teams, and drives are often insufficient for this purpose.
A model card describes the purpose, data, limitations, and risks of an AI model. For AI governance and the EU AI Act, it is more than just documentation, because it
A model card describes the purpose, data, limitations, and risks of an AI model. For AI governance and the EU AI Act, it is more than just documentation, because it
An external data protection officer needs more than just expertise. Why roles, escalation procedures, project intake, and evidence of the impact of a DPO mandate are crucial.
Excel is often a good starting point for data protection. But when it comes to RoPA, approvals, version control, documentation, and audits, a spreadsheet alone isn't enough in the long run.
Effective August 2, 2026, the key transparency requirements of the European AI Act will take effect. Under these requirements, companies will be required in certain cases to disclose whether content has been generated by
Many AI projects get off to a fast start technically but lack organizational oversight. Why AI governance requires a collaborative decision-making process involving the CIO, DPO, Legal, Security, and business units.
Who is responsible under data protection law when advertising is sent through a mailing list provider? Is it the advertising company that defines the target audience, or the mailing list provider that selects the recipients?
When you enter into a business relationship, you want to know: „Can I really trust this provider?” The CyberVadis score from 2B Advice—920—answers exactly that question.