Several significant artificial intelligence governance and quality standards have been adopted as national standards in Latvia. They form the basis for the systematic, auditable and trustworthy implementation of AI solutions in both the public and private sectors.
LVS ISO/IEC 42001:2026 sets out requirements for establishing, implementing and continually improving an artificial intelligence management system within an organisation. LVS ISO/IEC 42006:2026, in turn, sets out requirements for bodies that audit and certify such management systems.
Of particular significance is the new LVS EN 18286:2026, "Artificial intelligence — Quality management system for the regulatory purposes of the EU Artificial Intelligence Act." It helps translate the requirements of the EU Artificial Intelligence Act into a practical quality management system, covering the full life cycle of AI solutions.
PPPA's role: turning standards' requirements into practical infrastructure
A standard on its own does not yet implement an AI system. An organisation needs practical processes, a clear division of responsibility, contractual mechanisms, system registers, and reliable evidence of the controls carried out.
PPPA provides standardised public–private sector implementation and evidence infrastructure that helps organisations implement ISO/IEC 42001 governance and meet the requirements of EN 18286 and the EU AI Act. PPPA's mutually complementary frameworks cover the key elements of AI implementation:
- Process-as-Code turns an organisation's processes and decision logic into a machine-readable, versionable and auditable form.
- Records-as-Code creates a structured environment for managing documents, metadata, evidence and life-cycle events.
- Agreement-as-Code helps standardise the requirements, responsibilities, controls and enforcement oversight of public procurement and PPP contracts.
- AI Register provides a record of an organisation's AI systems, their owners, risks and compliance status.
- AI Regulatory Sandbox allows AI solutions to be piloted and validated in a controlled environment before wider rollout.
- AI LV Exchange lays the groundwork for a trustworthy ecosystem for the exchange of AI agents and services.
These tools can help organisations not only describe their AI governance, but also retain verifiable evidence of how the requirements are implemented in practice.
From a standalone pilot project to a managed AI life cycle
The new standards change the approach to AI implementation. Going forward, a technically successful solution or trial project alone will not be enough. An organisation will need to be able to demonstrate:
- who is responsible for the AI system;
- how risks have been assessed and managed;
- how data, models and suppliers are controlled;
- how system changes are documented;
- how human oversight is ensured;
- how incidents are detected and managed;
- what evidence confirms the actual fulfilment of requirements;
- how post-market monitoring and continuous improvement are ensured.
The public–private partnership model allows public-sector accountability and the protection of the public interest to be combined, in this process, with the private sector's technology, expertise and implementation capacity.
At the same time, standardised contracts and auditable processes also help manage long-term risks: technological dependency, changing suppliers, access to data and documentation, system maintenance, audit rights, and accountability for results.
A single, trustworthy AI implementation chain
A mutually complementary AI governance ecosystem is taking shape in Latvia:
- standards set governance and quality requirements;
- organisations implement the necessary policies, processes and controls;
- PPPA helps structure public–private sector cooperation and the practical implementation infrastructure;
- the AI regulatory environment allows solutions to be tested in cooperation with the competent authorities;
- LATAK establishes the accreditation preconditions for trustworthy and competent conformity assessment.
This approach makes it possible to move from general principles of responsible AI toward systematic, traceable and demonstrable governance.
PPPA calls for standards-ready pilot projects
PPPA calls on government institutions, municipalities and companies to identify processes where AI can help reduce administrative burden, improve the quality of decisions, and ensure the availability of public services.
Pilot projects should be designed so that, from the outset, they already incorporate:
- a responsibility and role matrix;
- risk classification of the AI system;
- data and supplier management;
- documented controls and approval points;
- human oversight;
- incident and change management;
- retention of auditable evidence;
- alignment with the requirements of ISO/IEC 42001, EN 18286 and the EU AI Act.
PPPA's aim is to help translate this principle into a practically achievable public–private partnership model.
Do you have a process or a pilot project idea where these standards should be applied?