{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,25]],"date-time":"2026-07-25T17:35:48Z","timestamp":1785000948807,"version":"3.55.0"},"reference-count":46,"publisher":"MDPI AG","issue":"4","license":[{"start":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T00:00:00Z","timestamp":1763424000000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"content-domain":{"domain":[],"crossmark-restriction":false},"short-container-title":["JCP"],"abstract":"<jats:p>This review examines AI governance centered on Regulation (EU) 2024\/1689 of the European Parliament and of the Council of 13 June 2024 laying down harmonised rules on artificial intelligence (the EU Artificial Intelligence Act), alongside comparable instruments (ISO\/IEC 42001, NIST AI RMF, OECD Principles, ALTAI). Using a hybrid systematic\u2013scoping method, it maps obligations across actor roles and risk tiers, with particular attention to low-capacity actors, especially SMEs and public authorities. Across the surveyed literature, persistent gaps emerge in enforceability, proportionality, and auditability, compounded by frictions between the AI Act and GDPR and fragmented accountability along the value chain. Rather than introducing a formal model, this paper develops a conceptual lens\u2014compliance asymmetry\u2014to interrogate the structural frictions between regulatory ambition and institutional capacity. This framing enables the identification of normative and operational gaps that must be addressed in future model design.<\/jats:p>","DOI":"10.3390\/jcp5040101","type":"journal-article","created":{"date-parts":[[2025,11,18]],"date-time":"2025-11-18T12:33:04Z","timestamp":1763469184000},"page":"101","update-policy":"https:\/\/doi.org\/10.3390\/mdpi_crossmark_policy","source":"Crossref","is-referenced-by-count":4,"title":["Gaps in AI-Compliant Complementary Governance Frameworks\u2019 Suitability (for Low-Capacity Actors), and Structural Asymmetries (in the Compliance Ecosystem)\u2014A Systematic Review"],"prefix":"10.3390","volume":"5","author":[{"given":"William Walter","family":"Finch","sequence":"first","affiliation":[{"name":"TOI, Inholland University of Applied Sciences, 2031 CS Haarlem, The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7754-5522","authenticated-orcid":false,"given":"Marya","family":"Butt","sequence":"additional","affiliation":[{"name":"Data-Driven Smart Society (DDSS), 1817 MN Alkmaar, The Netherlands"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"1968","published-online":{"date-parts":[[2025,11,18]]},"reference":[{"key":"ref_1","unstructured":"Zhao, W.X., Zhou, K., Li, J., Tang, T., Wang, X., Hou, Y., Min, Y., Zhang, B., Zhang, J., and Dong, Z. (2023). A Survey of Large Language Models. arXiv."},{"key":"ref_2","doi-asserted-by":"crossref","first-page":"036","DOI":"10.53771\/ijstra.2024.7.1.0055","article-title":"Driving SME Innovation with AI Solutions: Overcoming Adoption Barriers and Future Growth Opportunities","volume":"7","author":"Iyelolu","year":"2024","journal-title":"Int. J. Sci. Technol. Res. Arch."},{"key":"ref_3","doi-asserted-by":"crossref","first-page":"1016","DOI":"10.1007\/s10961-024-10122-5","article-title":"Supporting SME Companies in Mapping out AI Potential: A Finnish AI Development Case","volume":"50","author":"Jafarzadeh","year":"2024","journal-title":"J. Technol. Transf."},{"key":"ref_4","unstructured":"OECD (2019). Recommendation of the Council on Artificial Intelligence, OECD Publishing."},{"key":"ref_5","unstructured":"(2023). Artificial Intelligence Risk Management Framework (AI RMF 1.0) (Standard No. NIST AI 100-1)."},{"key":"ref_6","unstructured":"(2023). Information Technology\u2014Artificial Intelligence\u2014Management System (Standard No. ISO\/IEC 42001:2023)."},{"key":"ref_7","first-page":"189","article-title":"Comparison and Analysis of 3 Key AI Documents: EU\u2019s Proposed AI Act, Assessment List for Trustworthy AI (ALTAI), and ISO\/IEC 42001 AI Management System","volume":"Volume 1662","author":"Longo","year":"2023","journal-title":"Artificial Intelligence and Cognitive Science"},{"key":"ref_8","unstructured":"European Commission, Directorate-General for Communications Networks, Content and Technology (2020). The Assessment List for Trustworthy Artificial Intelligence (ALTAI) for Self-Assessment, Publications Office of the European Union."},{"key":"ref_9","unstructured":"Madhavan, K., Yazdinejad, A., Zarrinkalam, F., and Dehghantanha, A. (2025). Quantifying Security Vulnerabilities: A Metric-Driven Security Analysis of Gaps in Current AI Standards. arXiv."},{"key":"ref_10","doi-asserted-by":"crossref","first-page":"71","DOI":"10.1136\/bmj.n71","article-title":"The PRISMA 2020 Statement: An Updated Guideline for Reporting Systematic Reviews","volume":"372","author":"Page","year":"2021","journal-title":"BMJ"},{"key":"ref_11","doi-asserted-by":"crossref","unstructured":"Kalodanis, K., Rizomiliotis, P., Feretzakis, G., Papapavlou, C., and Anagnostopoulos, D. (2025). High-Risk AI Systems\u2014Lie Detection Application. Future Internet, 17.","DOI":"10.3390\/fi17010026"},{"key":"ref_12","doi-asserted-by":"crossref","first-page":"89","DOI":"10.54254\/2977-5701\/13\/2024130","article-title":"AI Ethics and Transparency in Operations Management: How Governance Mechanisms Can Reduce Data Bias and Privacy Risks","volume":"13","author":"Li","year":"2024","journal-title":"J. Appl. Econ. Policy Stud."},{"key":"ref_13","unstructured":"Rintamaki, T., and Pandit, H.J. (2024). Developing an Ontology for AI Act Fundamental Rights Impact Assessments. arXiv."},{"key":"ref_14","doi-asserted-by":"crossref","unstructured":"Golpayegani, D. (2024). Semantic Frameworks to Support the EU AI Act\u2019s Risk Management and Documentation. [Ph.D. Thesis, Trinity College Dublin].","DOI":"10.31237\/osf.io\/vzt7s"},{"key":"ref_15","doi-asserted-by":"crossref","unstructured":"Bhouri, H. (2025). Navigating Data Governance: A Critical Analysis of European Regulatory Framework for Artificial Intelligence. Recent Advances in Public Sector Management, IntechOpen.","DOI":"10.5772\/intechopen.114342"},{"key":"ref_16","doi-asserted-by":"crossref","unstructured":"Kriebitz, A., Corrigan, C., Boch, A., and Evans, K.D. (2024). Decoding the EU AI Act in the Context of Ethics and Fundamental Rights. The Elgar Companion to Applied AI Ethics, Edward Elgar Publishing Ltd.","DOI":"10.4337\/9781803928241.00014"},{"key":"ref_17","unstructured":"Sun, N., Miao, Y., Jiang, H., Ding, M., and Zhang, J. (2024). From Principles to Practice: A Deep Dive into AI Ethics and Regulations. arXiv."},{"key":"ref_18","doi-asserted-by":"crossref","first-page":"2706","DOI":"10.52783\/jes.7938","article-title":"Artificial Intelligence Governance in the European Union","volume":"20","author":"Karami","year":"2024","journal-title":"J. Electr. Syst."},{"key":"ref_19","first-page":"3","article-title":"A Value-Based Approach to AI Ethics: Accountability, Transparency, Explainability, and Usability","volume":"26","author":"Iyer","year":"2025","journal-title":"Merc. Neg."},{"key":"ref_20","doi-asserted-by":"crossref","unstructured":"Aiyankovil, K.G., and Lewis, D. (2024). Harmonizing AI Data Governance: Profiling ISO\/IEC 5259 to Meet the Requirements of the EU AI Act. Legal Knowledge and Information Systems, IOS Press.","DOI":"10.3233\/FAIA241270"},{"key":"ref_21","doi-asserted-by":"crossref","unstructured":"Ashraf, Z.A., and Mustafa, N. (2025). AI Standards and Regulations. Intersection of Human Rights and AI in Healthcare, IGI Global Scientific Publishing.","DOI":"10.4018\/979-8-3693-7051-3.ch014"},{"key":"ref_22","doi-asserted-by":"crossref","first-page":"42","DOI":"10.1038\/s41746-025-01443-2","article-title":"Preventing Unrestricted and Unmonitored AI Experimentation in Healthcare through Transparency and Accountability","volume":"8","author":"Comeau","year":"2025","journal-title":"npj Digit. Med."},{"key":"ref_23","doi-asserted-by":"crossref","first-page":"251","DOI":"10.1080\/15027570.2024.2440195","article-title":"Principles and Virtues in AI Ethics","volume":"23","author":"Scherz","year":"2024","journal-title":"J. Mil. Ethics"},{"key":"ref_24","first-page":"3","article-title":"A Risk-Based Regulatory Framework for Algorithm Auditing: Rethinking \u201cWho,\u201d \u201cWhen,\u201d and \u201cWhat\u201d","volume":"17","author":"Ho","year":"2025","journal-title":"Tenn. J. Law Policy"},{"key":"ref_25","doi-asserted-by":"crossref","first-page":"puae040","DOI":"10.1093\/polsoc\/puae040","article-title":"Responsible Governance of Generative AI: Conceptualizing GenAI as Complex Adaptive Systems","volume":"44","author":"Janssen","year":"2025","journal-title":"Policy Soc."},{"key":"ref_26","first-page":"80","article-title":"Governance and Ethical Frameworks for AI Integration in Higher Education: Enhancing Personalized Learning and Legal Compliance","volume":"4","author":"Alyousef","year":"2025","journal-title":"J. Ecohumanism"},{"key":"ref_27","doi-asserted-by":"crossref","unstructured":"Proietti, S., and Magnani, R. (2025). Assessing AI Adoption and Digitalization in SMEs: A Framework for Implementation. arXiv.","DOI":"10.32388\/0N53P4"},{"key":"ref_28","doi-asserted-by":"crossref","first-page":"1387","DOI":"10.30574\/ijsra.2025.14.1.0235","article-title":"Lessons from AI in Finance: Governance and Compliance in Practice","volume":"14","author":"Thoom","year":"2025","journal-title":"Int. J. Sci. Res. Arch."},{"key":"ref_29","first-page":"2550003","article-title":"Towards Responsible AI: A Framework for Ethical Design Utilizing Deontic Logic","volume":"33","author":"Dimitrios","year":"2025","journal-title":"Int. J. Artif. Intell. Tools"},{"key":"ref_30","doi-asserted-by":"crossref","unstructured":"Ajibesin, A.A., \u00c7ela, E., Vajjhala, N.R., and Eappen, P. (2025). Future Directions and Responsible AI for Social Impact. AI for Humanitarianism, CRC Press.","DOI":"10.1201\/9781003479109"},{"key":"ref_31","unstructured":"Meding, K. (2025). It\u2019s Complicated. The Relationship of Algorithmic Fairness and Non-Discrimination Regulations in the EU AI Act. arXiv."},{"key":"ref_32","doi-asserted-by":"crossref","unstructured":"Busch, F., Geis, R., Wang, Y.-C., Kather, J.N., Khori, N.A., Makowski, M.R., Kolawole, I.K., Truhn, D., Clements, W., and Gilbert, S. (2025). AI Regulation in Healthcare around the World: What Is the Status Quo?. medRxiv, medRxiv:2025.01.25.25321061.","DOI":"10.1101\/2025.01.25.25321061"},{"key":"ref_33","doi-asserted-by":"crossref","first-page":"770","DOI":"10.1017\/err.2024.97","article-title":"The AI Act Roller Coaster: The Evolution of Fundamental Rights Protection in the Legislative Process and the Future of the Regulation","volume":"16","author":"Palmiotto","year":"2025","journal-title":"Eur. J. Risk Regul."},{"key":"ref_34","doi-asserted-by":"crossref","first-page":"166","DOI":"10.54254\/2755-2721\/93\/20240964","article-title":"Leveraging Artificial Intelligence in Regulatory Technology (RegTech) for Financial Compliance","volume":"93","author":"Liang","year":"2024","journal-title":"Appl. Comput. Eng."},{"key":"ref_35","doi-asserted-by":"crossref","unstructured":"Paolini E Silva, M., Tamo-Larrieux, A., and Ammann, O. (2025). AI Literacy Under the AI Act: Tracing the Evolution of a Weakened Norm. OSF Prepr.","DOI":"10.31219\/osf.io\/th7c8_v2"},{"key":"ref_36","doi-asserted-by":"crossref","first-page":"114","DOI":"10.30574\/gjeta.2024.21.2.0212","article-title":"Policy Framework for Cloud Computing: AI, Governance, Compliance and Management","volume":"21","author":"Babalola","year":"2024","journal-title":"Glob. J. Eng. Technol. Adv."},{"key":"ref_37","doi-asserted-by":"crossref","first-page":"58","DOI":"10.1109\/MIC.2017.4180835","article-title":"A Layered Model for AI Governance","volume":"21","author":"Gasser","year":"2017","journal-title":"IEEE Internet Comput."},{"key":"ref_38","doi-asserted-by":"crossref","first-page":"90","DOI":"10.1177\/0266666916678282","article-title":"Data Justice for Development: What Would It Mean?","volume":"34","author":"Heeks","year":"2018","journal-title":"Inf. Dev."},{"key":"ref_39","doi-asserted-by":"crossref","first-page":"70","DOI":"10.1016\/j.cose.2015.10.006","article-title":"Information Security Policy Compliance Model in Organizations","volume":"56","author":"Safa","year":"2016","journal-title":"Comput. Secur."},{"key":"ref_40","doi-asserted-by":"crossref","unstructured":"Yeung, K., and Lodge, M. (2019). Algorithmic Regulation, Oxford University Press.","DOI":"10.1093\/oso\/9780198838494.001.0001"},{"key":"ref_41","doi-asserted-by":"crossref","first-page":"2789","DOI":"10.1007\/s43681-024-00596-2","article-title":"Frontrunner Model for Responsible AI Governance in the Public Sector: The Dutch Perspective","volume":"5","author":"Popa","year":"2024","journal-title":"AI Ethics"},{"key":"ref_42","doi-asserted-by":"crossref","first-page":"1539","DOI":"10.1609\/aies.v7i1.31745","article-title":"How Do AI Companies \u201cFine-Tune\u201d Policy? Examining Regulatory Capture in AI Governance","volume":"7","author":"Wei","year":"2024","journal-title":"AIES"},{"key":"ref_43","doi-asserted-by":"crossref","first-page":"39","DOI":"10.1609\/aies.v7i1.31615","article-title":"Introducing the AI Governance and Regulatory Archive (AGORA): An Analytic Infrastructure for Navigating the Emerging AI Governance Landscape","volume":"7","author":"Arnold","year":"2024","journal-title":"AIES"},{"key":"ref_44","doi-asserted-by":"crossref","unstructured":"Chelliah, P.R., Dutta, P.K., Kumar, A., Gonzalez, E.D.R.S., Mittal, M., and Gupta, S. (2025). Ethical and Regulatory Compliance Challenges of Generative AI in Human Resources. Generative Artificial Intelligence in Finance, Wiley.","DOI":"10.1002\/9781394271078"},{"key":"ref_45","unstructured":"(2022). Information Security, Cybersecurity and Privacy Protection\u2014Information Security Management Systems\u2014Requirements (Standard No. ISO\/IEC 27001:2022)."},{"key":"ref_46","unstructured":"(2015). Quality Management Systems\u2014Requirements (Standard No. ISO 9001:2015)."}],"container-title":["Journal of Cybersecurity and Privacy"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/101\/pdf","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,11,19]],"date-time":"2025-11-19T09:30:50Z","timestamp":1763544650000},"score":1,"resource":{"primary":{"URL":"https:\/\/www.mdpi.com\/2624-800X\/5\/4\/101"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,11,18]]},"references-count":46,"journal-issue":{"issue":"4","published-online":{"date-parts":[[2025,12]]}},"alternative-id":["jcp5040101"],"URL":"https:\/\/doi.org\/10.3390\/jcp5040101","relation":{},"ISSN":["2624-800X"],"issn-type":[{"value":"2624-800X","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,11,18]]}}}