Why does AI need "special" compliance responses?
AI has the characteristics of probabilistic output (answers fluctuate even with the same input), dependence on training data (inheritance of bias and privacy concerns), opacity (difficult to explain), and continuous evolution (change during operation), creating risks that are difficult to catch with traditional IT controls alone. Microsoft has established the principles of responsible AI (fairness, trust and safety, privacy and security, transparency, accountability, and inclusiveness) and a shared responsibility model, and recommends that controls be built in from the design stage. (Responsible AI - Microsoft)
About the use of AI in Japan
In Japan, the AI Law will be fully enforced in 2025, and the Cabinet Office's Artificial Intelligence Strategy Headquarters has begun to implement the AI Basic Plan and guidelines for ensuring its appropriateness. Although it is a philosophy law, transparency, risk management, and information provision practices are emphasized. (AI Law - Cabinet Office)
Overseas AI Usage
Full application of the EU:EU AI Act
Ahead of Japan, the EU has enforced stricter laws on the use of AI. The EU AI Act has been phased into effect since 2024. From August 2026 this year, high-risk requirements and other requirements will be applied in earnest, and extraterritorial application, high fines, and GPAI obligations will occur. If the law is applicable, the following measures are required. (EU Artifical Intelligence Act - EU)
- Risk classification: Confirmation of whether or not high-risk areas such as recruitment, education, and critical infrastructure are applicable
- GPAI Ready: Technical documentation, training data summaries, copyright compliance
- Transparency obligations: Disclosure of information about AI service providers
- Governance: risk management, data management, technical document management
- Human monitoring: Human monitoring including system operation status and usage status
United States: NIST
Although there is no law enforced at the federal level in the United States, NIST has presented a policy for the use of AI. Among them, "validity and reliability", "safety", "security and resilience", "accountability and transparency", "explainability and interpretability", "enhanced privacy" and "fairness" are required.
How to respond to laws and regulations
Effective Use of Microsoft Products
In aiming for responsible use of AI, it is important to make effective use of the products provided by Microsoft. Therefore, we will introduce the use cases of various products.
- Purview Compliance Manager: Visualize assessments and gaps with EU AI Act, ISO/IEC 42001, and NIST AI RMF templates
- Defender for Cloud Apps+Purview: Detect, evaluate, and manage internal and external AI apps, and detect and investigate interactions with generative AI through communication and compliance
- Azure AI Content Safety: Detects harmful content such as violence, hate, and self-harm
- Audit, Retention, and eDiscovery: Utilize retention and audit logs, including Copilot's prompts/responses.
Using SOC Services
It is important to detect inappropriate use of AI systems, such as using Microsoft products, and to respond promptly. To achieve this, it is necessary to have a system in place that can handle the security use of AI from design to operation. If it is difficult to build such a system in-house, using an external SOC service is also an effective measure.
What Colorkrew can help You can do Colorkrew Security provides services that perform SOC operation from the above security design.
If you have any requests such as "I want to reduce the operational burden" or "I want to quickly detect cyber attacks", please feel free to contact us. Let's strengthen your company's security operations together.