Independent documentation of algorithmic compliance frameworks, AI governance standards and sovereign AI metrics.
Initiative de recherche indépendante sur l'EU AI Act, les normes ISO et les métriques d'IA souveraine.
WASA Confidence is a non-profit research hub documenting how organisations demonstrate EU AI Act compliance and prepare for ISO/IEC 42001 certification. The regulation entered into force in August 2024, with obligations for high-risk AI systems phasing in through August 2026. Most operators discover late that the difficulty is not the technology but the evidence: what has to be written down, tested, retained and shown to an auditor.
Our research covers the four questions compliance teams ask most often. Which systems are actually high-risk? Annex III of the AI Act lists specific use cases — creditworthiness assessment of natural persons, biometric identification, employment and worker management, essential public services, education, law enforcement and critical infrastructure. A system outside those categories is not high-risk merely because it is powerful. What does Article 14 human oversight require in practice? Not a person watching a dashboard, but a documented ability to interpret output, override it, and stop the system. What does an AI management system look like? ISO/IEC 42001 specifies the AIMS structure: policy, system inventory, impact assessment, dataset documentation, incident handling and continual improvement. And what does a certificate actually prove? That an organisation runs a documented process — never that a given model is accurate, unbiased or fit for your data.
Alongside the regulatory work, we publish an AI job exposure index mapping automation pressure across professional sectors, research notes on explainable AI (XAI) and ante-hoc interpretability, and documentation of the Analysis of Algorithms conference series. All material is free, non-commercial and academically referenced.
Primary research on high-risk AI classification under Annex III, conformity assessment, technical documentation duties, and how the 2008 consumer-protection reforms inform today's algorithmic fairness requirements.
How Annex III defines high-risk AI systems, what technical documentation Article 11 requires, and the conformity assessment route for providers and deployers.
Read the EU AI Act research →Ongoing study mapping the exposure of professional occupations to AI and robotics, by task composition rather than job title.
View the AI exposure index →Documentation of the Analysis of Algorithms and Workshop on Analytic Algorithmics protocol series, and the institutional network behind them.
Read the heritage documentation →How post-2008 financial reform shaped modern fairness testing for credit scoring models now classified as high-risk under the AI Act.
View the fairness policy research →Shorter analytical notes on specific compliance problems — interpretability architecture, algorithmic provenance, and deepfake detection in asset markets.
Why models interpretable by construction hold a structural advantage over post-hoc explanation methods when transparency has to be evidenced to a regulator.
Read the XAI note →Algorithmic provenance research, deepfake and forgery detection, and how ISO 42001 governance applies to the fine art and cultural heritage market.
Read the heritage AI note →Four ISO/IEC standards form the practical backbone of an auditable AI compliance programme: 42001 for management, 27001 for information security and data sovereignty, 23894 for risk, and 5259 for training data quality. None is legally mandatory — all four are what auditors and insurers now ask to see.
The AI governance standard: policy, system inventory, AI impact assessment, dataset documentation and the Article 14 human-in-the-loop oversight it operationalises. What certification covers, and what it does not.
ISO 42001 requirements →Information security management applied to training data and model artefacts: access control, encryption at rest, and defence against adversarial data poisoning of the training pipeline.
ISO 27001 for AI systems →Risk management guidance for AI: adversarial stress-testing, failure-mode analysis, and continuous monitoring for algorithmic drift once a model is in production.
ISO 23894 risk guidance →Data quality requirements for analytics and machine learning: representativeness, labelling accuracy, completeness and the bias measurement expected of training datasets.
ISO 5259 data quality →Short answers to the questions that bring most readers to this hub. Each links to the full research.
No. ISO/IEC 42001 is a voluntary standard; the EU AI Act is binding law. They are not substitutes for one another. What 42001 provides is a structure for producing the evidence the AI Act demands — risk management, technical documentation, logging, human oversight and post-market monitoring. An organisation can comply with the AI Act without certification, and can hold certification while still failing a specific AI Act obligation. In practice, certification is increasingly requested by procurement teams, insurers and lenders as a proxy for maturity.
Annex III enumerates the categories: biometric identification and categorisation; safety components of critical infrastructure; education and vocational training access; employment, worker management and access to self-employment; access to essential private and public services — which is where creditworthiness assessment of natural persons sits; law enforcement; migration and border control; and administration of justice.
Two misreadings are common. First, a system is not high-risk because it is large or generative — capability is not the criterion, use case is. Second, adjacency to a listed use case can pull a system in: a model that only values an asset is outside Annex III, but if its output feeds directly into a credit decision on an individual, the chain matters. Full classification research →
Article 14 requires that high-risk AI systems be designed so that natural persons can effectively oversee them during use. Effectively is the operative word. The person must be able to understand the system's capacities and limits, remain aware of automation bias, correctly interpret the output, decide not to use it in a given case, and intervene or halt operation.
A reviewer who approves 400 model decisions a day without the ability to see why the model decided, or without organisational authority to overrule it, does not constitute oversight — regardless of what the process diagram says. How ISO 42001 operationalises this →
The regulation entered into force in August 2024. Prohibited practices and AI literacy duties applied first, from February 2025. General-purpose AI model obligations followed in August 2025. The bulk of high-risk system obligations under Annex III apply from August 2026, with a longer runway for high-risk AI embedded in products already covered by EU product-safety legislation. Dates and guidance have moved before; verify against the current official text for any compliance decision.
ISO/IEC 27001 governs information security — confidentiality, integrity and availability of information, including training data and model artefacts. ISO/IEC 42001 governs the AI system itself: how models are inventoried, impact-assessed, monitored for drift, and kept under human control.
They overlap on data governance and are designed to run as integrated management systems. Neither replaces the other: 27001 stops your training pipeline being poisoned; 42001 stops your model quietly discriminating. ISO 27001 for AI →
No, and this is the most consequential misunderstanding in the market. Certification attests to a management system, not to a result. A certified organisation has demonstrated that it has a documented process for asking whether a model is biased and for recording the answer. It has not demonstrated that any particular model is accurate, fair, or appropriate for your dataset.
Three questions separate a useful certificate from a decorative one: what exact scope does it cover, which accredited body issued it, and what non-conformities were raised at the last surveillance audit. A supplier who cannot answer all three has a logo, not a system.
Index of the subject areas covered across this hub.
WASA Confidence preserves the academic legacy of Analysis of Algorithms (AOFA), the conference series co-founded by Philippe Flajolet, whose work on analytic combinatorics underpins much of modern algorithm analysis. Our archival page documents the 2007 edition held at Juan-les-Pins and the institutional network behind it — INRIA, Purdue, École Polytechnique, Carleton, Hokkaido, Victoria, UPC Barcelona and Concordia among them.
Explore the AOFA 2007 archive →