EU AI Act · Regulation (EU) 2024/1689

EU AI Act compliance software for teams that ship AI

ai-governance.be is a single system of record for operationalising the EU AI Act. Inventory every AI system and model, classify its risk, assemble the technical documentation, run the conformity assessment, and keep evidence audit-ready — with the controls wired into the MLOps and DevOps pipelines you already run.

No spam. One launch email and occasional product notes. Unsubscribe anytime.

One platform, the full obligation lifecycle

The AI Act treats compliance as a continuous process, not a one-off certificate. ai-governance.be is built around that lifecycle — from the first use-case intake to post-market monitoring and serious-incident reporting — so the evidence is produced as a by-product of building and running AI, not as a parallel paper exercise.

Know your estate

Discover and register every AI system and general-purpose model in use, with owner, intended purpose, lifecycle stage and the role you play — provider, deployer, importer or distributor.

Classify the risk

A guided assessment maps each system to its AI Act risk tier — prohibited, high-risk (Annex III), limited or minimal — and records the reasoning and sign-off behind the call.

Prove it continuously

Generate technical documentation, capture logs and oversight decisions, and keep a versioned evidence vault that stays ready for auditors, market-surveillance authorities and notified bodies.

What the platform does

Each capability maps to a specific obligation in Regulation (EU) 2024/1689, so you can trace any requirement to the control that satisfies it.

AI system inventory & registry

A living catalogue of AI systems and GPAI models, with intended purpose, data sources, deployment context and accountable roles.

Risk classification engine

Decision-tree assessment against Articles 5 and 6 and Annex III, with an auditable record of inputs, outcome and sign-off.

Risk management system

Continuous risk identification, evaluation and mitigation aligned to Article 9, linked to each high-risk system.

Data & data governance records

Document training, validation and testing data practices, bias examination and quality criteria under Article 10.

Technical documentation generator

Assemble and maintain the Annex IV / Article 11 file from structured inputs, exportable as a single dossier.

Logging & traceability

Capture automatically generated event logs and retention evidence to meet Article 12.

Human oversight configuration

Define and record oversight measures, roles and intervention points required by Article 14.

Accuracy, robustness & cybersecurity

Record the metrics, testing and resilience measures that evidence Article 15 before release and over time.

Transparency obligations

Manage user-facing disclosures and AI-generated content marking under Articles 13 and 50.

Conformity assessment workflows

Track the route to conformity, the EU declaration of conformity and CE marking, including notified-body interactions and EU-database registration.

GPAI model obligations

Model documentation, downstream information, copyright policy and training-content summaries for Articles 53–55, with systemic-risk extras.

Post-market monitoring & incidents

Run the monitoring plan under Article 72 and manage serious-incident reporting under Article 73.

How AI work happens in an organisation — and where compliance fits

Most organisations already run an AI delivery process: a use case is proposed, data is prepared, models are trained and evaluated, something is deployed, and it is monitored in production. The AI Act adds an obligation to almost every one of those stages. ai-governance.be places its controls on the process you already have, so responsibility is clear and evidence accumulates as the work moves forward.

Lifecycle stage What the AI Act asks for Captured in ai-governance.be
Use-case intake & design Screen for prohibited practices (Art. 5); determine the risk tier (Art. 6, Annex III); fix the intended purpose. An intake form opens the project record, runs the classification, and captures the intended purpose and a dated sign-off before build work starts.
Data preparation Data governance and quality: relevance, representativeness, bias examination, documented provenance (Art. 10). Dataset datasheets, bias-check results and lineage links pulled from your data catalogue or feature store, attached to the system record.
Training & experimentation Operate the risk management system (Art. 9); keep records that make results traceable. Run metadata, model versions and metrics imported from your experiment tracker and linked to open risk items and mitigations.
Validation & pre-deployment Evidence accuracy, robustness and cybersecurity (Art. 15); design human oversight (Art. 14); complete the technical documentation (Art. 11 / Annex IV). The tech-doc dossier is assembled from structured inputs; a release checklist gate blocks promotion until required evidence and oversight design are in place.
Deployment & release Complete the conformity assessment, draw up the EU declaration of conformity, apply CE marking, register the system in the EU database. A pipeline status check confirms readiness; the declaration is generated from the record and the registration reference is stored with it.
Production & monitoring Post-market monitoring (Art. 72); keep automatic logs (Art. 12); report serious incidents within the deadlines (Art. 73). Monitoring metrics and alerts are ingested from your observability stack; drift or failures open an incident workflow with the reporting clock and templates.
Change & retirement Re-assess after a substantial modification; keep documentation for 10 years; decommission cleanly. Version diffs flag when a change is substantial and re-open the assessment; the evidence vault retains superseded versions.

Working with your MLOps

ai-governance.be connects to model registries and experiment trackers — MLflow, Azure Machine Learning, Amazon SageMaker, Vertex AI, Databricks — and reads model versions, datasets, parameters and evaluation metrics through their APIs.

  • A newly registered model, or a model promoted to staging or production, automatically creates or updates its compliance record — no re-keying.
  • Datasets and metrics stay linked to the exact model version they belong to, so the technical documentation reflects what actually shipped.
  • Webhooks keep the AI system inventory in sync as the registry changes.

Working with your DevOps & CI/CD

Compliance becomes a check in the pipeline you already run — GitHub Actions, GitLab CI, Azure DevOps, Jenkins — rather than a separate approval outside the toolchain.

  • A release gate fails the build when a high-risk system is missing required documentation, a risk sign-off or an oversight configuration.
  • Obligations sync to issue trackers — Jira, Azure Boards, ServiceNow — as tasks with owners and due dates tied to the Act's deadlines.
  • SSO and SCIM for access, plus an immutable audit log of who approved what and when.

The effect is shift-left compliance: classification and documentation gaps are caught at design and release time, inside the developer's workflow, instead of surfacing during an audit.

The EU AI Act is already phasing in

  • 1 Aug 2024 Regulation (EU) 2024/1689 enters into force.
  • 2 Feb 2025 Prohibited AI practices (Article 5) and AI literacy obligations apply.
  • 2 Aug 2025 Obligations for general-purpose AI models, plus the governance and penalties framework, take effect.
  • 2 Aug 2026 The bulk of the Act applies, including high-risk systems listed in Annex III.
  • 2 Aug 2027 High-risk obligations extend to AI as a safety component of regulated products under Annex I.

Dates reflect Regulation (EU) 2024/1689 as published in the Official Journal. This site is informational and is not legal advice.

EU AI Act — frequently asked questions

Who has to comply with the EU AI Act?

The Act binds providers, deployers, importers and distributors of AI systems, plus providers of general-purpose AI models. It applies extraterritorially: an organisation established outside the EU is in scope if it places an AI system or GPAI model on the EU market, or if the output of its system is used in the EU. Obligations are heaviest for providers of high-risk AI systems.

What is a high-risk AI system under the EU AI Act?

Two routes. First, AI used as a safety component of a product covered by EU harmonised legislation in Annex I (for example medical devices or machinery). Second, AI used in one of the Annex III areas: biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice. High-risk systems must meet the requirements in Articles 8 to 15 before being placed on the market.

When do the EU AI Act obligations start applying?

The Regulation entered into force on 1 August 2024 and applies in phases. 2 February 2025: prohibited practices and AI literacy. 2 August 2025: obligations for general-purpose AI models and the governance and penalties framework. 2 August 2026: the bulk of the Act, including high-risk systems under Annex III. 2 August 2027: high-risk obligations for AI as a safety component of products under Annex I.

What is the difference between a provider and a deployer?

A provider develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional context. Providers carry the design-time obligations such as conformity assessment and technical documentation; deployers carry use-time obligations such as human oversight, monitoring and, in some cases, a fundamental-rights impact assessment. A deployer that substantially modifies a high-risk system, or puts its own name on it, can become a provider.

What are the obligations for general-purpose AI (GPAI) models?

Under Articles 53 to 55, every GPAI model provider must keep up-to-date technical documentation, provide information to downstream providers who build on the model, put in place a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training. Models presenting systemic risk have extra duties: model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident tracking and reporting, and adequate cybersecurity.

What are the penalties for non-compliance with the EU AI Act?

Fines are tiered. Breaching the prohibited-practices rules can cost up to 35 million euro or 7% of total worldwide annual turnover, whichever is higher. Breaching most other obligations can cost up to 15 million euro or 3% of turnover. Supplying incorrect, incomplete or misleading information to authorities can cost up to 7.5 million euro or 1% of turnover. For SMEs and start-ups the lower of the fixed amount or the percentage applies.

Does ai-governance.be integrate with our existing MLOps and DevOps stack?

Yes. It connects to model registries and experiment trackers such as MLflow, Azure Machine Learning, Amazon SageMaker, Vertex AI and Databricks to populate the AI system inventory automatically, and it exposes a compliance status check for CI/CD pipelines such as GitHub Actions, GitLab CI and Azure DevOps so a release can be gated when required documentation or sign-off is missing. Obligations sync to issue trackers like Jira and Azure Boards.

Is ai-governance.be legal advice?

No. ai-governance.be is a compliance-management tool and this website is informational only. It helps you organise, evidence and track your obligations, but it does not replace advice from a qualified lawyer or a conformity assessment by a notified body.

Join the waiting list

We're onboarding a first group of design partners — AI providers, deployers and compliance teams in the EU. Leave your email and we'll be in touch with early access and product updates.