By mapping obligations (EU AI Act, GDPR/HIPAA) and implementing monitoring, controls, and incident response.