Welcome to Anekanta® AI Insights – AI Governance Newsletter – September 2026
Estimated reading time: 6 minutes
Welcome to the September 2026 edition of Anekanta® AI Insights AI governance newsletter for enterprise business leaders focused on AI strategy, risk, literacy and governance.
As the EU AI Act enforcement phases progress, the window for theoretical planning is closing. For enterprise boards and executive committees, it is time to move from awareness to action. Organisations need to critically check their current AI estate to understand their risk exposure, and make firm decisions on how they will govern these systems before regulatory deadlines arrive.
In this month’s edition, we cover:
- Feature Article: How an AI system’s “intended purpose” dictates its high-risk classification under the EU AI Act.
- From the Podium: The three critical AI questions boards are asking right now.
- Podcast: Anekanta® on the BSI Standards Show discussing the EU AI Act and ISO/IEC 42001.
- Security on Screen: The final chapter in our guest series on AI in the security sector.
Feature Article: How Intended Purpose Defines High-Risk AI under the EU AI Act

Under the EU AI Act, an AI system’s risk classification is not determined solely by the complexity of its technology, but by its intended purpose. For enterprises developing or deploying AI in critical sectors – specifically those listed under Annex III of the Act – defining and constraining this intended purpose is the difference between manageable compliance and triggering stringent regulatory obligations.
Many organisations are currently treating AI risk assessment as a static, tick-box exercise. This is a dangerous approach. If an AI system drifts beyond its originally documented intended purpose in production, it can inadvertently be reclassified as a high-risk system.
In our latest comprehensive guide, we break down:
- Why static compliance checklists fail high-risk AI.
- How to document and constrain your AI use cases to prevent “function creep.”
- The differing responsibilities between AI providers and deployers.
- How to align EU AI Act conformity and the QMS EN 18286 with global AI governance standards like ISO/IEC 42001.
👉 Read the full guide here: How Intended Purpose Defines High-Risk AI under the EU AI Act
From the Podium: Three Questions Boards and Senior Leaders Are Asking Now
During our continual industry engagement we have seen a clear shift in the conversation at the executive level. Boards are moving past the hype of AI and focusing strictly on ROI, liability, assurance, and operational control.
Boards must have answers to these three critical questions:
- “Are we a Provider, a Deployer, or both?”
Why they are asking: The EU AI Act assigns different legal liabilities based on your role. Boards want to know if the business is simply using a third-party tool (Deployer) or if internal teams have adapted a system enough to legally become a Provider, which triggers conformity assessment requirements. - “How do we prove our AI is safe and compliant?”
Why they are asking: Regulators and supply chain partners do not just want promises, they want auditable proof. Boards are seeking assurance architectures – such as ISO/IEC 42001 – to provide an internationally recognised baseline for governance. - “What happens if the system behaves unexpectedly?”
Why they are asking: Automated decisions in HR, finance, or operations carry reputational and legal risk. Boards are demanding clarity on human-in-the-loop oversight, post-market monitoring, and the escalation protocols for AI drift.
Security on Screen: The Final Chapter
This month, we published the concluding article in our long-running guest series with Security on Screen. Throughout the series, we have explored the profound impact of AI on the security sector, covering everything from the responsible deployment of biometrics to the complex supply chain risks of intelligent surveillance technologies.
In this final piece, we bring the threads together to look at the future of the security sector under the incoming regulatory weight of the EU AI Act. A huge thank you to the Security on Screen team for hosting this vital conversation.
👉 Read Part Three: The final article here
👉 Read Part One: Exclusive interview — Anekanta’s Pauline Norstrom
👉 Read Part Two: Anekanta’s Pauline Norstrom — Part 2
Listen: Anekanta® on the BSI Standards Show
Anekanta®’s founder Pauline Norstrom recently joined the BSI Standards Show podcast to discuss the intersection of AI innovation, risk management, and international standards. We explore how frameworks like ISO/IEC 42001 act as the bridge between regulatory requirements and safe, scalable enterprise AI adoption.
Whether you are walking the dog or commuting, it is a highly practical listen for anyone tasked with bringing AI governance to life in their organisation through ISO/IEC 42001 and the EN 18286 QMS for high-risk AI in the EU.
AI Literacy and Governance Workshops

Next open workshop
23 September 2026 Hosted by ISACA London Chapter book now to avoid disappointment.
In-house workshops
This is also an opportunity for organisations considering booking an in-house board session or enterprise workshop to experience Anekanta®’s approach in a professional environment.
Ready to build your AI assurance architecture for 2027?
Anekanta® supports enterprise organisations with AI discovery, EU AI Act high-risk classification, ISO/IEC 42001 alignment, and board-level AI literacy.
Budgeting for AI governance cannot wait until the regulations are already enforceable.
Contact us today to discuss your roadmap for the year ahead.
About Anekanta®
Anekanta® was established in 2016. Since 2020, we have developed specialist AI strategy, risk, literacy and governance services for boards, senior leaders and organisations developing and deploying AI.
Our 12 Principles of AI Governance were developed specifically for board-level application and pre-date ISO/IEC 42001. The framework has been recognised through international and UK initiatives and continues to underpin our approach to accountable, measurable AI governance.
Anekanta® has also developed specialist AI Risk Intelligence Systems™ featured by the OECD and UK Government, for high-risk AI, biometrics and EU AI Act readiness, supporting our work across system classification, impact, risk and assurance.
Our focus is practical: helping organisations connect AI opportunity with the governance, evidence and executive decision-making required to adopt it with confidence.
The Anekanta® Team
Subscribe to receive Anekanta® AI Insights by email. You can unsubscribe at any time. Privacy Policy.
23 earlier newsletter editions are currently accessible on the Anekanta LinkedIn newsletter page.

Anekanta®AI and Anekanta®Consulting
AI Strategy | Risk | Literacy | Governance
Contact us | Explore our services | Subscribe to our newsletter | Follow us on LinkedIn
Intellectual Property: © 2016–2026 Anekanta®. All rights reserved. Unless otherwise expressly stated, all materials published on this website, including the Anekanta® AI Governance Framework for Boards, the 12 Principles, and all AI risk and impact evaluation methodologies, software, models, diagrams, text and materials, are proprietary intellectual property of Anekanta®. No reproduction, adaptation, distribution, or commercial exploitation is permitted without prior written authorisation. No rights are granted other than those expressly stated. The Anekanta® AI Governance Framework and 12 Principles are developed, maintained and continuously enhanced as part of Anekanta®’s proprietary governance architecture.
Professional Disclaimer: The information provided on this website is for general informational purposes only and does not constitute legal, regulatory, financial or professional advice. Any reliance placed on the information is strictly at the user’s own risk. Professional advice should be sought in relation to specific circumstances through a formal engagement with Anekanta®.
Use of Generative AI: Generative AI tools may be utilised in research and drafting processes. All published materials are subject to substantive human review, professional judgment and oversight prior to release.
