Policy-Aware Computing Models for Ethical AI Compliance
DOI:
https://doi.org/10.5281/Keywords:
policy-aware computing, AI compliance, regulatory formalisation, runtime enforcement, EU AI Act, GDPR, responsible AI, compliance automationAbstract
Policy-aware computing -- the integration of formal policy representations into the computational architecture of AI systems such that compliance with ethical and regulatory obligations is enforced at the system level rather than dependent on human procedural adherence -- provides a promising technical paradigm for automating AI compliance at scale. As the EU AI Act (2024) and GDPR (2016) impose increasingly specific technical obligations on AI systems, the translation of regulatory text into machine-enforceable policy representations is a critical and underexplored engineering challenge. This paper proposes the Policy-Aware AI Compliance (PAAC) framework, a computational architecture for embedding EU AI Act and GDPR policy constraints into AI system operation through three integrated components: a Policy Formalisation Engine (PFE) that translates regulatory obligations into formal constraint specifications; a Runtime Policy Enforcement Layer (RPEL) that evaluates AI system actions against formalised constraints at inference time; and a Policy Compliance Audit System (PCAS) that maintains a cryptographically verified audit trail of all policy evaluations and enforcement decisions. The PAAC framework is evaluated through implementation on four production AI systems spanning healthcare, financial services, public sector, and legal AI domains, and through an expert assessment of 30 AI compliance and policy engineering specialists. Implementation results demonstrate 99.7% policy constraint coverage across 847 formalised EU AI Act and GDPR provisions, sub-100ms enforcement latency at inference, and a 67.4% reduction in compliance incidents over 12 months compared to manual compliance procedures. Expert consensus (Kendall W = 0.76, p < 0.001) confirms strong agreement on PAAC component importance. The study contributes the PAAC specification, a Policy Formalisation Language (PFL) for AI regulatory constraints, and empirical evidence that policy-aware computing substantially reduces AI compliance incident rates in production deployments.

