search.noResults

search.searching

saml.title
dataCollection.invalidEmail
note.createNoteMessage

search.noResults

search.searching

orderForm.title

orderForm.productCode
orderForm.description
orderForm.quantity
orderForm.itemPrice
orderForm.price
orderForm.totalPrice
orderForm.deliveryDetails.billingAddress
orderForm.deliveryDetails.deliveryAddress
orderForm.noItems
FEATURE Industrial AI


ADDRESSING THE RISKS OF AI DEPLOYMENT


Chris Whyborn, Head of Cybersecurity Services (UK & Europe), TÜV SÜD Business Assurance, outlines the challenges faced when deploying AI, and some of the solutions available to meet these challenges


A


ny organisation deploying AI within its systems must integrate technical safeguards with ethical and legal


compliance across the entire AI lifecycle, ensuring that systems are trustworthy, fair and secure. The EU AI Act requires a risk-based


approach for compliance, with fines of up to €15 million or up to three per cent of global annual revenue. This does not apply to organisations based solely in the UK, unless they operate within the EU. The EU’s market size often means its regulations become a global standard. Manufacturers should therefore classify AI systems into the risk classes defined in the EU AI Act to understand applicable requirements, and whether the organisation is affected by the regulation.


A different approach to legislation The UK is taking a different approach, currently favouring a pro-innovation and principles-based framework rather than the EU’s prescriptive legislation. The Government is currently relying on existing industry regulators to apply these principles using current law, rather than introducing a single piece of legislation. However, it has indicated that targeted legislation is likely in the future, particularly for the most powerful AI models. Organisations must demonstrate that an AI system does not violate expected ethical principles. All automated decisions should therefore be explainable through clear audit trails, maintaining human oversight for safety-critical systems and high- consequence activities. To harness the full potential of AI,


organisational readiness must be assessed and risks managed effectively so that the AI system is fit for large-scale deployment.


22 September 2026 | Automation


Risks include those associated with safety, security, legality, ethics, performance and sustainability. Effective due diligence reduces the likelihood of risk occurrence and demonstrates that proportionate measures have been taken to address the risk or the consequence. All aspects along the life cycle of an AI system and its data must therefore be covered. As AI systems are increasingly being integrated into critical infrastructure, poor AI quality can result in hallucination or biased decisions. If training data contains human prejudices, AI responses will reflect those biases, having significant implications for product reliability and liability. ISO/IEC 42001:2023 is the first internationally recognised standard for AI management systems (AIMS). It provides a structured framework for organisations to implement and operate AI systems, analyse risks and establish protective measures. As AI introduces risks that traditional IT standards are not equipped to handle, such as the algorithmic bias or hallucinations mentioned, ISO 42001 helps manage these through specific requirements. ISO/IEC 42001 can be easily integrated into any existing management systems, such as the widely used quality management standard ISO 9001 or information security management standard ISO 27001. All three standards support a management system implementation that can be adapted to individual corporate structures, enabling


needs-based integration into existing processes. Rather than prescribing specific technical solutions, ISO/IEC 42001 outlines what processes and controls need to be in place for responsible AI management.


Transparent and controllable


AI governance is no longer solely a topic for the IT department, as seemingly harmless systems, such as automated fault diagnosis or AI-driven production scheduling, can introduce bias. An AIMS will help to keep processes and decisions transparent and controllable, which is particularly important where AI-generated decisions are used to support or replace engineering judgement.


Although ISO/IEC 42001:2023 certification is not a regulatory requirement, it represents a solid basis for compliance with current and future AI regulations, helping organisations manage their AI responsibly in the long term. A certified AIMS helps to secure innovations, minimise risks, and increase the trust of stakeholders and customers.


AI deployment offers significant automation benefits, but complex regulatory and ethical landscapes must be successfully addressed. Proactive risk management and transparent governance are essential to building innovative AI systems that are trustworthy. New standards will help organisations with technical and legal compliance.


TÜV SÜD Business Assurance www.tuvsud.com/en-gb/services/assurance


automationmagazine.co.uk


Page 1  |  Page 2  |  Page 3  |  Page 4  |  Page 5  |  Page 6  |  Page 7  |  Page 8  |  Page 9  |  Page 10  |  Page 11  |  Page 12  |  Page 13  |  Page 14  |  Page 15  |  Page 16  |  Page 17  |  Page 18  |  Page 19  |  Page 20  |  Page 21  |  Page 22  |  Page 23  |  Page 24  |  Page 25  |  Page 26  |  Page 27  |  Page 28  |  Page 29  |  Page 30  |  Page 31  |  Page 32  |  Page 33  |  Page 34  |  Page 35  |  Page 36  |  Page 37  |  Page 38  |  Page 39  |  Page 40