top of page

Profile

Join date: Feb 13, 2025

Posts (20)

Jul 29, 2026 ∙ 4 min
AI Third-Party Risk Management
AI is increasingly delivered through software that procurement has already approved. A vendor review completed at onboarding may not cover a later AI capability, model, connector, or data-use term. AI third-party risk management, or AI TPRM, extends the existing vendor process to the AI capability and its organizational use. It connects due diligence, contracts, controls, owners, and reassessment as the product changes. The vendor lifecycle needs an AI layer AI features may be included when...

2
0
Jul 29, 2026 ∙ 7 min
Third-Party Embedded AI Under the EU AI Act
The EU AI Act can apply even if your company has never bought or selected a standalone AI product. AI is now built into document tools, meeting platforms, HR systems, CRM software, and other business applications. And given the speed of software improvement and SaaS deployment models, changes to these systems are happening more like daily than quarterly or yearly as in the past. When staff use one of these AI features for work under the company's authority, the company generally becomes the...

2
0
Jul 8, 2026 ∙ 6 min
Healthcare AI Under the EU AI Act
Clinical AI usually qualifies as a medical device under EU rules and is therefore high-risk under the AI Act, while administrative AI usually is not. The product's stated intended purpose decides which category applies. Classifying Clinical AI under the EU AI Act The EU AI Act's "high-risk list" names only a few healthcare uses, but that list is not the main route for clinical AI. AI that diagnoses, guides treatment, or monitors a patient's condition is usually a medical device under EU rules...

91
0
bottom of page