Business
What does this obligate us to build, and by when.
Handbook §62 · 30 sections
Drafting material: not yet published or verified for publication. States what the sources say; not legal advice.
62.1 /
What this handbook is
The business lens, assembled from the fifteen six-lens blocks that carry one.
Who it is for. The person accountable for whether an organisation meets these obligations, and the person who has to fund it.
What it is not. It is not a build guide. Part VI is: section 55 sets out six control families, section 56 how to build each, section 58 who owns what, section 59 what it costs. This handbook explains why an organisation should care and where its money will actually go, and it cites Part VI rather than repeating it.
What it adds that Part VI does not. The competitive analysis, at sections 62.21 to 62.24. Every lens block records a competitive effect, they are scattered across six volumes, and they do not all point the same way. Assembling them into one honest account is this handbook’s contribution.
The three negatives it collects. What a certificate does not get you, at section 62.18. What no amount of documentation fixes, at section 62.19. And what cannot be bought at all, at section 62.20.
Vol. 40 · §62.1 · Currency 2026-09-03 · drafting
62.2 /
The honest summary
Four propositions, and an organisation that acts on these will be ahead of one that reads everything else.
The obligations are fewer and more specific than the volume of commentary implies. Section 54.19: five genuinely new obligations beyond a mature data protection and security programme. Everything else is an extension of a control that already exists or a restatement of one.
The work is done upstream or it is not done. Section 35.28 says it for rights, section 37.15 for breach severity, section 60.9 generalises it across seven worked scenarios. By the time a problem is visible, the decisions that determined it were taken months earlier. Section 62.29 makes this the argument for sequencing.
The largest recurring cost is one thing, and it is not documentation. Section 55.23 and section 59.3: only human oversight scales with decision volume. Everything else scales with how many systems an organisation has, which is a number in the tens.
The apparatus is not the point and is what gets built. Section 38.15 records the failure mode and section 60.9 records that in six of seven worked scenarios the artefact existed and the capability did not.
Vol. 40 · §62.2 · Currency 2026-09-03 · drafting
62.3 /
The shape of the cost
Section 5.9’s lens block gives the frame and it holds across every regime in this document. A fixed cost with a variable tail.
The fixed cost is the apparatus. Records, notices, contracts, an assessment methodology, and usually an officer. It is incurred whether or not anything happens.
The variable tail is what happens. Incident response, request handling, regulator engagement.
What Part VI adds to that frame. Section 54.24 and section 59.2 break the fixed cost into four kinds. One-time and documentary — classifying the estate, extending templates, amending contracts, and it ends. Recurring and documentary — the gate, the register, the reviews, and it is small if attached to a gate that already runs. Recurring and staffed — oversight, and only oversight. And engineering, which applies only to providers and which section 62.20 records cannot be bought.
The proportion that matters. Section 59.2: for a deployer the fourth is zero and the whole programme is a governance change plus one staffed role. For a provider the fourth dominates everything else combined.
The planning error section 59.3 names. An organisation estimating by counting systems will underestimate, and the entire error sits in oversight. Systems are in the tens; decisions may be in the millions.
Vol. 40 · §62.3 · Currency 2026-09-03 · drafting
62.4 /
What determines the obligations
Four questions, answered in this order, and everything follows from them.
Where are the people? Not where the organisation is. Section 40.5 records the Union’s output limb and section 46.3 Korea’s effects-based reach, and section 43.13 records that in the United States the answer is which state.
What is the decision about? Section 43.2 records that this is the American question rather than what tier the system is. Credit, employment, housing, insurance, education, benefits and law enforcement carry obligations that other subject matter does not, in every jurisdiction in Part III.
What is the organisation’s role? Section 62.5, and it is the question that propagates.
Is personal data involved? Asked last, deliberately. Section 54.4 records that the AI instruments do not trigger on personal data at all, and section 54.5 that a system with no personal data anywhere in it is squarely inside them. An organisation that scoped its AI inventory by asking where personal data is has an incomplete inventory.
Vol. 40 · §62.4 · Currency 2026-09-03 · drafting
62.5 /
Roles: the decision that propagates
Section 2’s lens block states it in one sentence and it is the most useful sentence in the business lens: the role you occupy is determined by what you decide, not by what you signed.
Two role systems, and section 54.7 records that they are orthogonal. Controller and processor turn on who determines purposes and means. Provider and deployer turn on position in a supply chain. A party’s position in one says almost nothing about its position in the other, and section 54.8 records that the provider-is-processor shortcut fails.
Both are questions of fact. Section 34.2 for data protection, section 40.25 for the AI Act. No contract can allocate either away.
The expensive pattern, per section 2’s lens block. A supplier contract naming the supplier a processor while the supplier behaves as a controller. The customer’s records are wrong, the supplier has no lawful basis, and both are exposed.
When to audit it. At design time, per section 2’s lens block, because section 2.2 sets out how the error propagates. A role determined wrongly at the start is wrong in the record of processing, in the contract, in the transfer analysis and in the rights process, and each is corrected separately.
The trigger that changes it later. Section 40.25 and section 62.14.
Groups, where the role question becomes a question about which legal person.
Section 34.12 records the failure. A group operating as one brand, discovering at a rights request that nobody can say which entity is the controller. Section 35.22 records the consequence for the individual: they should not have to work out the corporate structure, and a group that cannot route a request internally will answer late or partially.
What AI adds. Section 58.9: the AI roles turn on conduct, so which entity placed a system on the market and which put it into service are questions of fact about different legal persons. A parent that builds and a subsidiary that deploys are provider and deployer respectively — so the engineering obligations sit with one entity and the oversight obligations with another.
The document that must actually pass between them. Section 58.9: the instructions for use, which section 40.20 requires and which everyone is tempted to skip because both parties already know how the system works. An internal system with no instructions for use has no stated operating envelope.
The register consequence. Section 58.9: one classification register for the group, with the entity recorded per entry. A register recording “provider” without naming which entity cannot support any downstream family.
Vol. 40 · §62.5 · Currency 2026-09-03 · drafting
62.6 /
The vendor estate
Where most organisations discover the role question, and usually late.
The obligations. Section 34.3’s contract requirements, section 34.4’s diligence before appointment, section 34.5’s sub-processor chain.
The limit that cannot be contracted around. Section 34.6: the chain cannot be verified below the first hop, and the controller is responsible for it anyway. That is not closeable by drafting and section 34.6 records that it should be recognised rather than papered over.
The substitution that is near-universal. Section 34.7 and section 20.17’s lens block: third-party reports accepted in place of the audit right. It is a negotiated reduction in a statutory entitlement, adopted because nothing else scales.
What AI adds, and it is small. Section 55.21: the same diligence, with the AI roles established as well as the data protection ones, and three documents asked for at procurement — the instructions for use, the declaration of conformity, and the technical documentation summary.
Why asking is worth it even where nothing requires it. Section 54.22: the supplier’s home regime has already produced these documents, they are the cheapest assurance available, and section 59.8 records that asking costs nothing. Procurement is the only moment of leverage.
The cost shape. Section 2’s lens block: mapping roles across a large vendor estate is a fixed cost an incumbent absorbs into existing headcount and an entrant pays for in cash.
Being the supplier, which section 62.6 has so far treated only from the buyer’s side and which is a large share of readers.
What to expect. Diligence questionnaires that do not match each other, an audit right you will be asked to substitute out of, per section 34.7, and sub-processor consent mechanics that constrain your own supply chain.
What to prepare once and reuse. The processor contract terms at section 34.3. A current sub-processor list, per section 34.5. The assistance commitments at section 35.21 with a period expressed in hours rather than “without undue delay” — section 35.21 records why: a controller with thirty days in total cannot use a processor that will assist within thirty days. And the three AI documents at section 55.21 if you supply anything in scope, because section 54.22 records that customers in jurisdictions with no AI law will still ask.
The commercial fact worth knowing. Section 34.6: the chain cannot be verified below your first hop either. Your customer is responsible for your sub-processors and cannot check them, which is why sub-processor terms are negotiated harder than the rest of the contract.
The capability that shortens every diligence conversation. Section 35.21: self-service tooling that lets the customer extract and delete directly. It is a better predictor of whether their rights can be honoured than any contractual clause, and section 35.21 records it as worth asking for — which means it is worth having.
Vol. 40 · §62.6 · Currency 2026-09-03 · drafting
62.7 /
Acquisition: where it is won and lost
Section 30.28’s lens block states it: acquisition decisions are cheap to make and expensive to unwind.
Why. Section 30.1: every later obligation inherits from here. A basis chosen wrongly cannot usually be repaired, because the defect is in how the data was obtained and the data is already held.
What is decided here. Purpose, necessity, basis, notice, consent mechanics, age assurance, special category identification, the record, and the retention period.
What AI adds. Section 54.10, and it is less than expected: a quality obligation, not a lawfulness one. Section 40.18 requires training data to be relevant and representative. Nothing in any AI instrument supplies a lawful basis, and section 30.23 is where the question lives.
The consequence that makes this the most expensive mistake available. Section 55.17: an acquisition error cannot be corrected out of a trained model. A retention error can be fixed. Section 36.14 records that there is no shredding operation for a model, and section 43.8 the only remedy that reaches the asset — an order to delete models built on improperly obtained data.
The practical instruction. Assess the training purpose separately from the operational one. Section 55.17: a basis assessed for service delivery does not carry over to model development because someone assumed it would.
Vol. 40 · §62.7 · Currency 2026-09-03 · drafting
62.8 /
The demonstrability trap
Section 38.16’s lens block names it as the obligation organisations under-scope, and it is worth stating why.
The obligation is not to comply. It is to be able to show it. Section 38.2: compliance is a state, demonstrability is a capability, and it has to exist at the moment someone asks.
What that converts. Every compliance decision becomes a documentation requirement at the moment the decision is taken. Not afterwards — section 38.2 records that a decision made correctly two years ago and now unattributable is a position that cannot be defended.
The practical test, per section 38.2. Pick a processing operation. Ask who decided it was lawful, on what basis, when, and where that is written. In most organisations the answer for most operations is that nobody knows — and it is rarely a refusal to document. The decision was made in a meeting or a ticket and was never written as a decision.
What it is not. A requirement to document everything. Section 38.2: a very large accountability apparatus is not evidence of accountability, and section 38.15 records that it is sometimes evidence of the opposite.
Vol. 40 · §62.8 · Currency 2026-09-03 · drafting
62.9 /
The record that decays
The single largest fixed cost in this document and the one most often mis-funded.
Section 38.16’s lens block records it: the record of processing is the largest cost and it is a maintenance cost rather than a build cost. The build is a project with an end. The maintenance is permanent.
Why it decays. Section 38.3: built as a project, from interviews, in a spreadsheet, and not maintained. Within eighteen months it describes an organisation that no longer exists.
What makes one survive, per section 38.3. Ownership per entry, not for the document. A trigger attached to a gate that already exists — a new system, vendor or purpose cannot go live without its entry. And use: a record consulted when answering a request or scoping a breach gets corrected, because its errors become visible to people relying on it. A record only ever read by a regulator is a record nobody has checked.
The funding failure, per section 59.5. A programme budget with no operating budget behind it. The artefacts all exist at the end of the project and half decay. Fund the trigger, not the exercise.
Why it matters beyond compliance. Section 35.28: it is one of six capabilities that determine whether a rights request can be answered at all. Section 62.28’s argument rests on it.
Vol. 40 · §62.9 · Currency 2026-09-03 · drafting
62.10 /
Transfers
Section 19.29’s lens block gives the obligation list and the cost driver, and both are worth carrying.
The obligations. Identify every transfer, including remote access. Select and execute a mechanism. Conduct and document a transfer impact assessment. Maintain back-to-back onward transfer terms. Monitor destination law for change. Re-evaluate at intervals.
The phrase to notice. Including remote access. Support staff viewing a screen from another country is a transfer, and it is the category most often missing from a transfer register.
The cost driver. Section 19.29: the assessment is the expensive item, because it requires an analysis of foreign surveillance law per destination. And vendor chains multiply it — an organisation with two hundred processors does not have two hundred assessments’ worth of work, it has more, because each has its own onward chain.
What AI does not add. Section 54.6: no AI instrument restricts moving a model or a training corpus across a border, and section 19’s analysis applies unchanged to both.
Vol. 40 · §62.10 · Currency 2026-09-03 · drafting
62.11 /
Certification: whether to bother
Section 20.17’s lens block frames it as a decision rather than an obligation, which is correct: it is voluntary.
The reasons to do it. A customer requires it. The discipline of an external audit is useful. It shortens vendor diligence conversations. Section 57.10 records these as legitimate uses.
The reason not to expect much. Section 57.9’s coverage table: there is no Full cell. The most AI-specific certifiable standard covers four of six control families partially and two not at all. Section 22.11 records what a general security certificate is worth.
The Article 42 position specifically. Section 26.15’s lens block records that almost nobody seeks one, and section 19.16 that one scheme now permits certification as a transfer tool — against standard contractual clauses, which are free.
The cost item most organisations mis-plan, per section 20.17’s lens block. Remediation before assessment is usually the largest cost, and it is the item that produces the actual security benefit. The fees are the visible part and the smaller one.
The sequencing rule. Section 57.10: do not sequence the build around a certification timetable. Build the families from section 56 regardless, because certification will leave two of them untouched.
Vol. 40 · §62.11 · Currency 2026-09-03 · drafting
62.12 /
Certification: scope
Section 20.17’s lens block calls it the decision with the most consequence and the least visibility, and that is the whole of what a business reader needs to know about certificates.
What scope does. It defines what the certificate covers. Section 22.26 records scope in practice and section 22.24 how to read a certificate.
Why it is invisible. A customer sees a certificate and infers coverage. The scope statement is on it and is rarely read, and section 20.17’s lens block records that a seal conveys that somebody checked something and nothing more.
The incentive, stated plainly because both sides face it. A narrower scope is cheaper to achieve and produces a cleaner opinion. Section 55.26 records the equivalent temptation in classification: drawing a boundary to exclude the hard case.
What that means when reading a supplier’s certificate. Section 34.4’s diligence: ask what the scope covers and whether it covers the processing you care about. Very frequently it does not, and section 62.18 records what a certificate does not get you in any event.
Vol. 40 · §62.12 · Currency 2026-09-03 · drafting
62.13 /
The AI delta, in one page
Section 54 is the full treatment. This is what a business reader needs from it.
Five genuinely new obligations, per section 54.19. Classification — no data protection analogue exists. Model properties as legal requirements — nothing in data protection law requires a system to work or to state how well. Human oversight as a designed and staffed capability. Conformity assessment, marking and registration. Content provenance and labelling.
Everything else is an extension or a restatement, and section 54.18 scores six of ten obligation areas as substantially discharged by an existing programme.
Where the delta is concentrated. Section 54.9: at design and pre-deployment, and near zero at the lifecycle ends. Acquisition and termination are data protection problems.
Where it is largest. Section 54.20: the provider of a general purpose model, then the provider of a high-risk system, then the organisation that fine-tuned, per section 62.14.
Where it is zero. Section 54.21: an organisation using a purchased tool on non-personal data in a jurisdiction with no AI instrument. That is the majority of organisations in the majority of jurisdictions in Part III.
Vol. 40 · §62.13 · Currency 2026-09-03 · drafting
62.14 /
The fine-tune decision
Given its own section because section 54.8 records it as the case organisations discover late and section 58.9 records that a small organisation cannot staff what follows.
The rule. Section 40.25: a deployer becomes a provider by specified acts — putting its name on a system, making a substantial modification, or modifying the intended purpose of a system so that it becomes high risk. No contract can allocate that away.
What it costs. Section 55.24 and section 55.25: the organisation moves from three families to six, and the three it acquires — training data governance, model assurance, conformity — are the engineering ones section 62.20 records cannot be bought.
Which makes it an architectural decision taken as a technical one. Section 54.24: a single engineering decision moves an organisation from a governance change plus one role to an engineering programme. It is typically taken in a sprint, by people who are not told what follows.
The control. Section 55.6: a classification trigger on fine-tuning, wired into whatever gate engineering already passes through. Section 60.3 works the scenario.
Vol. 40 · §62.14 · Currency 2026-09-03 · drafting
62.15 /
Oversight: the cost that scales
The only obligation in this document proportional to how much business an organisation does.
Section 55.23 and section 59.3. Every other family scales with system count, model count or product count. Oversight scales with decisions.
The arithmetic, per section 59.4. Decisions per period, multiplied by minutes of genuine consideration, divided by productive minutes available per person. Three inputs, all of which the organisation has or can observe.
What running it honestly reveals, per section 59.4. Either the headcount is larger than expected, or the minutes per decision are smaller than genuine consideration requires. Section 56.10 records the second as the failure mode.
The only design lever. Section 59.4: reduce the number of decisions requiring oversight, by narrowing the system’s scope to where it performs well and routing the rest to people directly. That is a product decision with a compliance cost attached, and product takes it without anyone framing it that way.
The measure. Section 55.13: the override rate, which is the only meaningful proxy for whether the function works, and section 58.7 records it as the single most informative number available to a board.
Vol. 40 · §62.15 · Currency 2026-09-03 · drafting
62.16 /
When three regimes hit one incident
Section 5.12A’s lens block records the position: a bank is under one instrument and outside another for the same systems; its non-financial subsidiaries may be under the second; and a connected product brings a third on its own timetable.
What follows. Three registers, three incident taxonomies and three sets of deadlines, and they do not align.
Section 37.11 and section 55.20 give the operational answer. One intake, one assessment, and every applicable trigger evaluated at once. Assessing sequentially guarantees missing the shortest deadline.
The specific misalignment to design for. Section 37.11: a serious incident is not a personal data breach and a personal data breach is not a serious incident. Section 37.4 records that the data protection clock starts on awareness, not confirmation, which is the most commonly mishandled element in the whole area.
The cost driver worth naming, per section 5.12A’s lens block. A register of information is a data engineering project, not a document. Organisations budget for it as the latter.
Vol. 40 · §62.16 · Currency 2026-09-03 · drafting
62.17 /
The candour problem
Section 38.16’s lens block treats it as a genuine dilemma rather than a failure of will, and that framing is the right one.
The dilemma. A frank impact assessment identifying an unmitigated high risk is discoverable — by a regulator, and by a claimant. A bland one is not.
The answer, and section 38.16 gives it as an expectation calculation rather than a moral one. Candour is cheaper in expectation and more expensive in the tail. A documented risk with a documented mitigation decision is defensible. A risk the process failed to identify establishes that the process was inadequate, which is a finding about everything the organisation does rather than about one system.
The evidence. Section 38.16: organisations that have been through an enforcement matter document more candidly afterwards.
The related temptation, and the answer is the same. Section 56.5 and section 62.12: classifying out because the answer is convenient, and scoping narrowly to exclude the hard case. Both produce a position that survives a documentary inspection and fails the first time anyone looks at the substance.
Vol. 40 · §62.17 · Currency 2026-09-03 · drafting
62.18 /
What a certificate does not get you
The first of the three negatives, collected because they are scattered.
It is not a defence. Section 38.14: adherence is evidence, not a defence. A certificate goes to the diligence of the process rather than to the legality of the outcome, and a certified organisation processing unlawfully is processing unlawfully.
It does not cover two of the six AI control families at all. Section 57.8 and section 57.11: conformity and provenance, because neither is a management activity — one is a legal process against a statute and the other a technical property of an artefact.
It does not carry a presumption of conformity. Section 27.7: that requires a cited harmonised standard, and section 53.14 records that none of the frameworks in section 57.3 is one.
What it does not tell a customer either. Section 62.12: the scope. And section 27.4 records the sharpest version for AI — for most high-risk systems the default conformity route is self-assessment, so a mark means the provider assessed itself and is indistinguishable from one that does not.
The one thing it genuinely does. Section 57.10: it is evidence of care, worth having in an enforcement matter or a claim, and it shortens vendor conversations.
Vol. 40 · §62.18 · Currency 2026-09-03 · drafting
62.19 /
What no amount of documentation fixes
The second negative, and section 38.15 is the general statement of it.
The failure mode. A complete record of processing. Impact assessments for every qualifying operation. An appointed officer. A full policy set. Training completion at ninety-eight per cent. An audit programme. And processing that is unlawful, or a purpose nobody assessed, or a vendor nobody checked.
Why it happens, and section 38.15 records that it is rarely cynical. The artefacts become the objective. A team measured on completion produces completion.
The diagnostic questions, per section 38.15, which cut through it faster than any assessment. When did an assessment last change a design? When did the officer last say no, and what happened? What was the last processing operation stopped on privacy grounds? When did the organisation last decide not to collect something it could have collected?
The AI version. Section 55.13 and section 56.10: oversight that is documented, assigned and unable to function. Section 60.9 records that in six of seven worked scenarios the artefact existed and the capability did not.
Why this matters commercially rather than morally. Section 39.12: enforcement selects for what is externally assessable, so this failure is systematically under-detected — until a breach or a complaint exposes the substance, at which point the apparatus becomes evidence that the organisation knew what was required.
Vol. 40 · §62.19 · Currency 2026-09-03 · drafting
62.20 /
What cannot be bought
The third negative, and the shortest.
Section 54.24 states it. An organisation can buy a policy, a template and an audit. It cannot buy a model that meets a declared accuracy on its intended population.
What that covers. Section 55.25: model properties at section 40.22, design for oversight at section 40.21, and the data governance at section 40.18. These are engineering obligations and they apply only to providers — which section 62.14 records an organisation can become in a sprint.
The related item that cannot be bought either. The classification trigger. Section 59.9: a consultant can classify an estate; the trigger has to be wired into the organisation’s own gates, and section 56.5 records that an organisation which populates a register without wiring one has built a snapshot.
And oversight authority. Section 55.13: competence can be trained and time can be funded. Authority to depart from a system’s output is a management decision, and section 56.10 records that a culture treating an override as a challenge to the system has defeated the control without changing any process.
Vol. 40 · §62.20 · Currency 2026-09-03 · drafting
62.21 /
Competitive effects: the general case
Every lens block records one and they do not all point the same way. Sections 62.21 to 62.24 assemble them, which no single section of this document has done.
The general case is that compliance cost favours incumbents, and it appears in more lens blocks than any other competitive finding.
Why. Section 38.16: accountability costs are substantially fixed. The record, the officer, the policy set and the audit programme cost approximately the same for an organisation with one hundred thousand customers as for one with ten million. The cost per customer falls with scale.
Section 5.9’s lens block says it directly: a fixed compliance overhead falls harder on a small entrant than on an incumbent. Section 2’s lens block gives the clearest instance: mapping roles across a large vendor estate is a fixed cost an incumbent absorbs into existing headcount and an entrant pays for in cash.
Section 43.22 records the American version, which is sharper: monitoring fifty legislatures is a permanent function, and a small firm cannot carry it.
And section 34.14 states the consequence. The compliance apparatus concentrates the market it regulates.
Vol. 40 · §62.21 · Currency 2026-09-03 · drafting
62.22 /
Competitive effects: where it inverts
One clear inversion and one partial one, and both are worth knowing because they are the exceptions that test the rule.
Destruction partially inverts it, and section 36.16’s lens block records why. A large organisation carries decades of accumulated systems, acquisitions, migrations and abandoned platforms, and its exposure grows with its history. Section 36.11 records decommissioning as where destruction actually fails. A new entrant born on cloud infrastructure inherits the provider’s decommissioning process, which is better than what a small firm could operate itself, and has no legacy estate.
Its limit, per section 36.16. The entrant’s disadvantage is that it cannot verify anything, per section 36.8. On balance the stage is close to neutral between incumbent and entrant, which makes it unusual rather than reversed.
The jurisdictional inversion, per section 43.22. The absence of a pre-market gate in the United States is a genuine advantage over the Union — no conformity assessment, no mark, no registration, no notified body to wait for, so a system can be deployed the day it is built. Section 27.5 records the Union deadlock that has no American equivalent. That is not a firm-size effect; it is a jurisdiction-choice effect, and it cuts across the general case rather than reversing it.
Vol. 40 · §62.22 · Currency 2026-09-03 · drafting
62.23 /
Competitive effects: customisation and standards
Two mechanisms that concentrate markets without operating through cost at all, and they are the least obvious findings in this handbook.
The AI Act penalises customisation. Section 40.40’s lens block records it: an organisation large enough to fine-tune models for its own use thereby becomes a provider, with the full obligation set, while a smaller organisation using an off-the-shelf system stays a deployer. The predictable effect is to push the market towards standardised systems supplied by a few providers who carry the compliance apparatus.
Which is a concentrating mechanism operating on the supply side rather than on firm size, and section 62.14 records that the organisation triggering it usually does not know it has.
Standards participation is the extreme case, and section 53.21’s lens block states what makes it different in kind. Standards participation is expensive — national body membership, technical staff able to draft, delegates across multi-year cycles. But the output does not merely cost less per unit at scale. It binds competitors who were not in the room.
Section 53.21’s assessment. Standards participation is the highest-leverage compliance activity available and it is priced out of reach of everyone but large firms. Section 27.7 records that harmonised standards were to supply the content of the Union’s outcome obligations; where that content arrives, it will have been written substantially by the organisations it governs.
Vol. 40 · §62.23 · Currency 2026-09-03 · drafting
62.24 /
The competitive picture assembled
Four propositions, and the honest account is that the curve is not uniform.
The dominant effect is concentration through fixed cost. Sections 62.21 and 34.14. It appears in more lens blocks than any other finding in this document and it operates in every jurisdiction examined.
There is one partial exception and it is narrow. Section 62.22: destruction, where legacy estate is the liability and a cloud-native entrant is closer to parity. Close to neutral rather than reversed.
The jurisdictional effect runs across the firm-size effect rather than with it. Section 62.22: the absence of a gate is an advantage of place, not of size, and it advantages large and small alike in that jurisdiction.
And the strongest concentrating mechanism is not cost at all. Section 62.23: standards participation, where the advantaged firm writes the rule rather than merely affording it. Section 53.21 records that this operates through a process with no legislative scrutiny and no public consultation.
What an organisation should take from this. If it is large, standards participation is the highest-return compliance investment available and almost nobody treats it as one. If it is small, section 62.26 records the interventions that cost least, and section 62.22 records the one stage where its position is genuinely no worse.
Vol. 40 · §62.24 · Currency 2026-09-03 · drafting
62.25 /
Where organisations overspend
Section 59.9 collects four patterns and they share one shape.
Tooling before the register. Section 56.3: a purchased platform before the register exists is section 38.15’s failure mode bought rather than built. The tool encodes a process the organisation has not designed.
Parallel structure. Section 55.26: a separate AI risk register, incident process, vendor process, ethics committee or model inventory. Each duplicates an existing function and coordinates badly with it. Section 58.5 records the corrective: five of the ten obligation areas need no new owner at all.
Certification timetables driving the build. Section 57.10 and section 62.11.
Consultants classifying an estate nobody will maintain. Section 59.9: the classification exercise is the cheap part and the trigger is what makes it worth having, and section 62.20 records that the trigger cannot be outsourced.
The common shape. Section 59.9: buying an artefact instead of building a capability.
Vol. 40 · §62.25 · Currency 2026-09-03 · drafting
62.26 /
The cheapest things that work
Section 59.8 identifies three, and they produce half the evidence base at almost no cost.
The classification trigger at procurement. Section 56.5: it gates every other family and costs least. Section 54.22 records that most organisations acquire AI by buying it, which is why procurement is the highest-value place to put it.
The override log. Section 56.3: the family’s primary artefact, and section 55.13 the only measurable proxy for whether oversight works. Section 43.9 records that outcome-based discrimination claims reach algorithmic screening in jurisdictions with no AI law at all, which is why this is worth having regardless of where an organisation operates.
Three questions at procurement, per section 55.21 and section 62.6.
Why these three specifically. Section 59.8: they produce three of the six evidence artefacts at section 55.27, they are useful whatever the flagged legal questions in Part III resolve to, per section 56.4, and none requires a tool or a new function.
What to defer with a clear conscience, per section 59.8. Conformity beyond the technical file. Disaggregated evaluation, if not a provider. Tooling, always.
Why deferring is safer here than it looks. Section 56.4: sequence by what is useful regardless of the legal answer, and five of the six control families pass that test. Only conformity assessment depends entirely on how the flagged questions in Part III resolve, which means the uncertainty is a much smaller planning problem than the number of flags suggests.
What not to defer whatever the budget. Anything that gets harder with time. The technical documentation, per section 56.11. Design for oversight, per section 59.6. And the acquisition assessment, per section 62.7.
Vol. 40 · §62.26 · Currency 2026-09-03 · drafting
62.27 /
The first ninety days
Section 56.15 gives the sequence and section 59.7 extends it to a year. The summary a business reader needs.
Weeks one to three. Wire the classification trigger into procurement. Populate the register from the record of processing, the vendor inventory and the asset register. Do not buy a tool.
Weeks three to six. Triage the deployed estate by consequence, per section 56.6, and stop there. Determine the role for each system in scope. Check whether any fine-tune has made the organisation a provider, per section 62.14.
Weeks six to ten. Deployers: the override log and the section 59.4 arithmetic. Providers: the technical documentation and dataset records.
Weeks ten to thirteen. Extend the impact assessment, incident process and vendor diligence, per section 56.13. Build the route from oversight to engineering.
What is deliberately absent. Conformity assessment beyond documentation. A tool. A committee. A maturity score, per section 58.7.
What the organisation has at the end. Section 56.15: five of the six evidence artefacts, produced by people who already existed.
Vol. 40 · §62.27 · Currency 2026-09-03 · drafting
62.28 /
What happens if you get it wrong
Section 39 is the full treatment and a business handbook that omits it is incomplete.
The most useful finding, and it is worth more than most compliance spending. Section 39.7 records the accountability multiplier: the same underlying contravention attracts a materially different penalty depending on whether the organisation can show it assessed the question, documented the decision and implemented what it documented. An undocumented failure is negligence. A documented decision that turned out to be wrong is a judgement call.
What actually drives the number, per section 39.7. Turnover sets the scale where the maximum is turnover-linked. Within that, the largest movements come from duration, the number of individuals affected, whether special categories were involved, and cooperation. Section 37.7 records that the tone and candour of an initial breach notification frequently determines whether a matter proceeds at all.
What matters more than the number, and section 39.6 records that it is under-reported. Corrective powers. Orders to bring processing into compliance, to erase, to suspend transfers, and temporary or definitive limitation including a ban on processing. A penalty is a cost; a prohibition can end a product line, and it applies to the activity rather than to the balance sheet.
Sharper still for anything in scope of the AI instruments. Section 40.2: the remedies are product remedies — withdrawal, recall, prohibition of making available — and they operate on the product across every customer at once. Section 40.40 records that this is structurally more powerful than a penalty.
Why reported fines are a poor basis for calibrating investment. Two reasons. Section 39.6: penalties are reported because they carry a number and orders and reprimands are not, so the public account is a subset selected for headline value. And section 39.8: a meaningful proportion of large penalties are reduced on appeal, and the reduction is reported far less than the announcement.
And the selection effect that determines whether an organisation is looked at. Section 39.12: the enforcement record is a map of what can be seen from outside an organisation, not a map of where harm occurs. Consent interfaces, transparency notices and rights response times are visible; retention, destruction, vendor chains and assessment substance are not. An organisation calibrating purely against the enforcement record will invest where it is likely to be caught rather than where it is likely to cause harm.
The exposure most organisations understate. Sections 39.10 and 43.17: class actions with statutory damages, where available, produce figures no privacy regulator imposes, and section 39.10 records private enforcement growing faster than public enforcement in several jurisdictions.
Vol. 40 · §62.28 · Currency 2026-09-03 · drafting
62.29 /
The argument for doing it upstream
The closing proposition, and it is the strongest single argument in this document for spending money early.
Three findings, made independently in three parts, all saying the same thing.
Section 35.28. Rights operations cannot be fixed at the rights operations stage. A well-staffed rights team with none of the six upstream capabilities will answer late, partially and inaccurately, and no effort inside the response window changes that.
Section 37.15. Breach severity cannot be managed at breach time. By the time an incident occurs, every variable determining how bad it is has already been set — what was acquired, what was minimised, what was retained, what was destroyed. None of those is a security control.
Section 60.9, generalising across seven worked scenarios. Every one went wrong earlier than it was noticed. Every one was catchable by a gate costing almost nothing.
What that means for a budget. The expensive failures are all failures of a decision taken cheaply and early. Section 62.7 records the sharpest instance: an acquisition error cannot be corrected out of a trained model.
And the fourth finding, which section 62.28 supplies and which closes the argument. Section 39.7’s accountability multiplier: the same contravention attracts a materially different penalty depending on whether the organisation can show it assessed the question and documented the decision. That record is created upstream or it does not exist. An organisation that did the work early does not merely avoid more failures; it is treated differently for the failures it has, because an undocumented failure is negligence and a documented decision that turned out wrong is a judgement call.
The one sentence for a board. The gates are cheap, the failures are not, and the gap between them is the entire return on this programme.
Vol. 40 · §62.29 · Currency 2026-09-03 · drafting
62.30 /
Sources and confidence
This handbook assembles material recorded in Volumes 01 to 39 and introduces no new facts. It inherits the confidence of everything it cites.
No cost figures are stated and that is deliberate. Section 59.1 records the commitment: this document has no researched basis for absolute cost figures and states none. Rates, salaries, tool prices and consultancy fees were not researched. Section 62.3 gives the shape and section 62.15 the arithmetic, which is derivable rather than researched. A reader encountering absolute figures for this subject matter elsewhere should treat them as section 39.8 records penalty figures should be treated.
The flags that could change advice in this handbook rather than a detail, each recorded at its source and not repeated: the Union phased application status at sections 40.4 and 40.39, which governs section 62.13; whether harmonised standards have been cited at section 53.14, which governs sections 62.11 and 62.18; United States preemption at section 43.18, which governs section 62.4’s second question; the conformity machinery at sections 27.5 to 27.7, which governs section 62.11; and Canadian federal status at section 48.2. Section 56.4’s sequencing rule is designed to be robust to all of them, and section 62.26 applies it.
What is this handbook’s own rather than assembled. Sections 62.21 to 62.24, the competitive analysis. Every lens block records a competitive effect; they are scattered across six volumes and they do not all point the same way. The assembly and the four propositions at section 62.24 are stated here for the first time — in particular that the strongest concentrating mechanism is not cost but standards participation, where the advantaged firm writes the rule rather than merely affording it.
What is not affected by any flag. That the role is determined by what an organisation decides and not by what it signed, at section 62.5. That an acquisition error cannot be corrected out of a trained model, at section 62.7. That the record of processing is a maintenance cost mis-funded as a build cost, at section 62.9. That only oversight scales with decision volume, at section 62.15. That a certificate is evidence and not a defence and covers two of six AI families not at all, at section 62.18. That the artefact existing and the capability not existing is the characteristic failure, at section 62.19. That an organisation cannot buy a model that meets a declared accuracy on its intended population, at section 62.20. And the whole of section 62.28.
Forward reference. Section 63 is the government handbook, covering the policymaker and regulator lenses together, section 64 certifying bodies, section 65 front-line staff and section 66 human rights and advocacy. Part VII carries no six-lens blocks; section 53.21 was the last in the document.
Vol. 40 · §62.30 · Currency 2026-09-03 · drafting