The Strategic Choice
With the AI Office now able to enforce fines up to 3% of global turnover, your team faces a critical decision: should EU AI Act compliance be approached like GDPR, with its broad territorial reach, or like SR 11-7, which reshaped how banks manage model risk?
This decision isn't just theoretical. It impacts your budget, organizational structure, and whether you build a compliance function or a risk management discipline. I've seen teams make both choices, and the differences are clear.
The GDPR Approach
Treating the AI Act like GDPR means building a compliance framework. You'd hire legal experts to handle Annex IV documentation, set up an AI governance team to review systems before deployment, and create workflows for attestation and training. This approach suits companies deploying consumer-facing AI at scale. The transparency rules effective August 2, 2026, require AI disclosures similar to cookie banners, not risk assessments.
If your AI systems interact with European users but your risk management is based elsewhere, you don't need a quantitative modeling team. You need operational controls and a legal team ready to handle complaints through the AI Office's new tool. The penalties, like GDPR's, are revenue-based, posing a compliance risk for multinationals with thin margins.
The SR 11-7 Approach
For General-Purpose AI Models or high-risk systems under Annex III, the GDPR analogy falls short. SR 11-7, the Federal Reserve's guidance on model risk management, offers a better template. It treats models as ongoing risks, not one-time compliance tasks.
Under SR 11-7, you don't just document a model at deployment. You establish independent validation, continuous monitoring, and escalation paths for model issues. The AI Act's requirements for high-risk models follow this logic: risk assessment and mitigation are ongoing processes.
The AI Office can request technical documentation and model evaluations, not just privacy notices. This isn't a GDPR-style audit; it's a technical examination. When OpenAI's models were involved in the Hugging Face breach, the issue was about assessing and mitigating systemic risks, not just disclosure.
The SR 11-7 approach is also more scalable for organizations with existing model risk management. If you're a bank already validating models under SR 11-7 or OCC Bulletin 2011-12, extending that framework to AI systems is more efficient than starting from scratch.
Practical Implementation
Most organizations are adopting a hybrid approach based on system type. For limited-risk AI like chatbots and content generators, they're using the GDPR playbook: legal reviews, transparency disclosures, and training programs. The compliance effort is significant but manageable.
For high-risk systems and General-Purpose AI Models, they're incorporating model risk management practices. This includes independent validation, ongoing performance monitoring, and governance over model changes. The AI Office's focus on technical expertise indicates the depth of scrutiny expected.
Organizations struggling the most are those relying solely on legal teams. If your AI governance team can't evaluate model robustness or assess systemic risk, you're unprepared for the AI Office's technical demands. Job postings for contract agents highlight the need for expertise in model evaluations and regulatory dynamics, areas beyond GDPR's scope.
Our Recommendation
Align transparency obligations with GDPR and model risk with SR 11-7. The AI Act is both a disclosure regulation and a risk management framework. Mixing these approaches leads to gaps.
For transparency rules effective August 2, 2026, your legal and compliance teams should handle implementation with policies, training, and controls. If you've managed GDPR, you know the process.
For General-Purpose AI Models and high-risk systems, enhance your model risk function. You need experts to assess model robustness, validate claims, and evaluate systemic risks. The AI Office's technical evaluations and specialist hiring indicate the level of scrutiny expected. A legal team alone can't meet these demands.
The SR 11-7 approach requires more investment upfront. Independent validation and ongoing monitoring need infrastructure but scale better as your AI portfolio grows. This prepares you for the high-risk rules effective December 2, 2027. If you're still treating AI governance as a legal task then, you'll face regulatory pressure to rebuild.
Ask yourself: are you disclosing AI use, or managing AI risk? For most deploying advanced models, it's both. Your governance structure should reflect that.



