5 jobs
ranked by payback against risk, with the prompts to run them
1 protocol
to prove a model works before it reaches a live file
12 questions
for any vendor that says the words "AI-powered"
Get the guide
14 pages, PDF. The download starts as soon as you submit.
What is inside
- 01
The honest map
Where the technology is strong, where it quietly fails, and the one-minute test that sorts any new task in your queue.
- 02
The line you do not cross
Four decisions that stay with a named human, and the habit (not the policy) that erodes them.
- 03
Before anything leaves your perimeter
A four-class data model any DPO will recognise, plus the redaction rule that moves most daily work out of scope.
- 04
Five jobs to automate first
Ranked by payback against risk, each with its failure mode written down so your validation knows what to catch.
- 05
Prompt patterns that survive an audit
Four you can copy today: adverse media triage, ownership chains, policy gap mapping and second-line quality sampling.
- 06
The validation protocol
The smallest set of evidence that makes an AI-assisted control defensible, achievable by two people in three weeks.
- 07
What the regulator will actually ask
The EU AI Act reality check after the 2026 amendment, plus GDPR, AMLR, the UK and the US on one page.
- 08
Twelve questions for any AI vendor
Including the three that end most sales conversations in the first forty minutes.
- 09
The first thirty days
A rollout that produces a number you can act on, without touching a live customer file.
Three things most compliance teams have wrong
Section 07 of the guide works through the EU AI Act as it actually reads after the 2026 amendment. These are the corrections that come up most often, and they are in the guide with the article references.
Commonly assumed
AI plus financial services means high risk under the EU AI Act
What the text says
Annex III excludes biometric systems whose sole purpose is confirming that a person is who they claim to be, which is exactly what onboarding face-match does. The creditworthiness category also carves out AI systems used to detect financial fraud.
Commonly assumed
The high-risk obligations landed on 2 August 2026
What the text says
Regulation (EU) 2026/1744, the Digital Omnibus on AI, entered into force on 27 July 2026 and moved standalone Annex III systems to 2 December 2027 and Annex I embedded systems to 2 August 2028. Article 50 transparency did apply from 2 August 2026.
Commonly assumed
Nothing in the AI Act applies to us yet
What the text says
Article 4, the AI literacy obligation, has applied since 2 February 2025 alongside the prohibited practices in Article 5. It is the obligation that bites today, and the evidence a supervisor will ask for is a training record.
Why this is free, and why it does not mention us
A guide that steers you toward one vendor is worth nothing to the person reading it at 11pm before a board pack is due. Sections 01 to 09 are agnostic on purpose. Zyphe appears once, in a single box on the last page, and every one of the twelve vendor questions on page 12 is a question we expect to answer ourselves. If you find something wrong in the guide, tell us: corrections are logged in public at zyphe.com/corrections.