Back to engagement patterns
    Engagement pattern

    AI governance stand-up under the EU AI Act

    Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.

    Governance3 Sept 20265 min read

    ISO/IEC 42001:2023NIST AI 100-1Regulation (EU) 2024/1689
    On this page

    Scope

    Almost every obligation in the AI Act turns on two prior answers: the role the organisation holds, and the risk class the system falls into. Governance built before those answers aims at nothing in particular.

    Article 6 sets the classification rules and points to Annex III for the listed high-risk areas 1. Dates matter as much as classes. The regulation applies generally from 2 August 2026, and its first two chapters applied from 2 February 2025 2. Regulation (EU) 2026/1744 then moved the Chapter III high-risk dates to 2 December 2027 under Article 6(2), and to 2 August 2028 under Article 6(1) 3.

    In scope: the inventory, the role and class determination per system, the management system that carries the obligations, impact assessment, and the incident clocks.

    Out of scope: obligations on general-purpose model providers, national supervisory procedure, and model engineering.

    Phases

    PhasePurposePlanning horizonCloses when
    1. Inventory and rolesFind the systems in use, then decide provider or deployerusually planned over 4–6 weeksEvery system has a named owner and a role decision
    2. ClassificationTest each system against Article 6 and the listed areasusually planned over 3–5 weeksEach system carries a written class, with reasons
    3. Management systemBuild the policy, risk and documentation machinery on the ISO/IEC 42001:2023 clause structureusually planned over 4–6 monthsRisk assessment, treatment and impact assessment all run
    4. Operate and reportHuman oversight, monitoring and the incident chainusually planned over 6–10 weeksA rehearsal produces a report inside the statutory limit
    Horizons are planning input. They describe how this shape of work is scheduled, never how long anything took.

    Deliverables

    DeliverableRequired byWho maintains it afterwards
    Role and classification recordArticle 6, read with Annex IIIAI governance owner
    AI policy and accountability recordArticle 17; ISO/IEC 42001:2023, 5.2 and 5.3Executive sponsor
    Risk management system recordArticle 9, iterative across the lifecycle 4Risk owner
    Technical documentationArticle 11, content per Annex IVProvider-side product owner
    Fundamental rights impact assessmentArticle 27, where its terms catch the deployer 5Deployer-side business owner
    Human oversight assignmentArticle 26(2)Deployer-side business owner
    AI literacy measuresArticle 4 6People function

    Roles

    RoleSideAccountable for
    Executive sponsorOrganisationPolicy, resourcing, review
    AI governance ownerOrganisationInventory, classification, documentation, reporting
    Business owner per systemOrganisationHuman oversight and the impact assessment
    AdviserExternalMethod, classification and rehearsal design

    What the authority asks

    Failure modes

    Mapping

    Clause titles 7 and function names 8 are as published.

    ObligationAI ActISO/IEC 42001:2023NIST AI RMF
    Set policy and assign authorityArt. 175.2 AI policy, 5.3 Roles, responsibilities and authoritiesGovern 1, Govern 2
    Inventory and classify systemsArt. 6, Annex III4.4 AI management systemMap 2
    Assess and treat AI riskArt. 98.2 AI risk assessment, 8.3 AI risk treatmentMeasure 1, Manage 1
    Assess impact on peopleArt. 278.4 AI system impact assessmentMap 5
    Document the systemArt. 11, Annex IV7.5 Documented informationMap 3
    Monitor after releaseArt. 729.1 Monitoring, measurement, analysis and evaluationMeasure 3
    Correct, improve and reportArt. 20, Art. 73 910.2 Nonconformity and corrective actionManage 4
    One obligation, three frameworks.

    References

    1. Regulation (EU) 2024/1689 (AI Act), OJ L, 2024/1689, 12.7.2024 10.
    2. Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026, amending Article 113 of the AI Act 11.
    3. ISO/IEC 42001:2023 — Artificial intelligence — Management system. ISO/IEC JTC 1/SC 42, 2023-12. https://www.iso.org/standard/42001, accessed 2026-09-03. The annexes were not readable free of charge, so none is cited.
    4. NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, January 2023. https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf; Core names read on airc.nist.gov, accessed 2026-09-03.

    Sources

    1. 1Regulation (EU) 2024/1689, Art. 6 and Annex III, CELEX 32024R1689 · verified 2026-09-03
    2. 2Regulation (EU) 2024/1689, Art. 113, CELEX 32024R1689 · verified 2026-09-03
    3. 3Regulation (EU) 2026/1744, Art. 1(40), CELEX 32026R1744 · verified 2026-09-03
    4. 4Regulation (EU) 2024/1689, Art. 9(1)–(2), CELEX 32024R1689 · verified 2026-09-03
    5. 5Regulation (EU) 2024/1689, Art. 27(1), CELEX 32024R1689 · verified 2026-09-03
    6. 6Regulation (EU) 2024/1689, Art. 4, CELEX 32024R1689 · verified 2026-09-03
    7. 7ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03
    8. 8NIST AI 100-1, AI RMF Core, airc.nist.gov · verified 2026-09-03
    9. 9Regulation (EU) 2024/1689, Art. 73(2)–(4), CELEX 32024R1689 · verified 2026-09-03
    10. 10Regulation (EU) 2024/1689, full text, CELEX 32024R1689 · verified 2026-09-03
    11. 11Regulation (EU) 2026/1744, full text, CELEX 32026R1744 · verified 2026-09-03