AI governance stand-up under the EU AI Act
Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.
Governance3 Sept 20265 min read
On this page
Scope
Almost every obligation in the AI Act turns on two prior answers: the role the organisation holds, and the risk class the system falls into. Governance built before those answers aims at nothing in particular.
Article 6 sets the classification rules and points to Annex III for the listed high-risk areas 1. Dates matter as much as classes. The regulation applies generally from 2 August 2026, and its first two chapters applied from 2 February 2025 2. Regulation (EU) 2026/1744 then moved the Chapter III high-risk dates to 2 December 2027 under Article 6(2), and to 2 August 2028 under Article 6(1) 3.
In scope: the inventory, the role and class determination per system, the management system that carries the obligations, impact assessment, and the incident clocks.
Out of scope: obligations on general-purpose model providers, national supervisory procedure, and model engineering.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Inventory and roles | Find the systems in use, then decide provider or deployer | usually planned over 4–6 weeks | Every system has a named owner and a role decision |
| 2. Classification | Test each system against Article 6 and the listed areas | usually planned over 3–5 weeks | Each system carries a written class, with reasons |
| 3. Management system | Build the policy, risk and documentation machinery on the ISO/IEC 42001:2023 clause structure | usually planned over 4–6 months | Risk assessment, treatment and impact assessment all run |
| 4. Operate and report | Human oversight, monitoring and the incident chain | usually planned over 6–10 weeks | A rehearsal produces a report inside the statutory limit |
Deliverables
| Deliverable | Required by | Who maintains it afterwards |
|---|---|---|
| Role and classification record | Article 6, read with Annex III | AI governance owner |
| AI policy and accountability record | Article 17; ISO/IEC 42001:2023, 5.2 and 5.3 | Executive sponsor |
| Risk management system record | Article 9, iterative across the lifecycle 4 | Risk owner |
| Technical documentation | Article 11, content per Annex IV | Provider-side product owner |
| Fundamental rights impact assessment | Article 27, where its terms catch the deployer 5 | Deployer-side business owner |
| Human oversight assignment | Article 26(2) | Deployer-side business owner |
| AI literacy measures | Article 4 6 | People function |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Executive sponsor | Organisation | Policy, resourcing, review |
| AI governance owner | Organisation | Inventory, classification, documentation, reporting |
| Business owner per system | Organisation | Human oversight and the impact assessment |
| Adviser | External | Method, classification and rehearsal design |
What the authority asks
Failure modes
Mapping
Clause titles 7 and function names 8 are as published.
| Obligation | AI Act | ISO/IEC 42001:2023 | NIST AI RMF |
|---|---|---|---|
| Set policy and assign authority | Art. 17 | 5.2 AI policy, 5.3 Roles, responsibilities and authorities | Govern 1, Govern 2 |
| Inventory and classify systems | Art. 6, Annex III | 4.4 AI management system | Map 2 |
| Assess and treat AI risk | Art. 9 | 8.2 AI risk assessment, 8.3 AI risk treatment | Measure 1, Manage 1 |
| Assess impact on people | Art. 27 | 8.4 AI system impact assessment | Map 5 |
| Document the system | Art. 11, Annex IV | 7.5 Documented information | Map 3 |
| Monitor after release | Art. 72 | 9.1 Monitoring, measurement, analysis and evaluation | Measure 3 |
| Correct, improve and report | Art. 20, Art. 73 9 | 10.2 Nonconformity and corrective action | Manage 4 |
References
- Regulation (EU) 2024/1689 (AI Act), OJ L, 2024/1689, 12.7.2024 10.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026, amending Article 113 of the AI Act 11.
- ISO/IEC 42001:2023 — Artificial intelligence — Management system. ISO/IEC JTC 1/SC 42, 2023-12.
https://www.iso.org/standard/42001, accessed 2026-09-03. The annexes were not readable free of charge, so none is cited. - NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, January 2023.
https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf; Core names read onairc.nist.gov, accessed 2026-09-03.
Sources
- 1Regulation (EU) 2024/1689, Art. 6 and Annex III, CELEX 32024R1689 · verified 2026-09-03
- 2Regulation (EU) 2024/1689, Art. 113, CELEX 32024R1689 · verified 2026-09-03
- 3Regulation (EU) 2026/1744, Art. 1(40), CELEX 32026R1744 · verified 2026-09-03
- 4Regulation (EU) 2024/1689, Art. 9(1)–(2), CELEX 32024R1689 · verified 2026-09-03
- 5Regulation (EU) 2024/1689, Art. 27(1), CELEX 32024R1689 · verified 2026-09-03
- 6Regulation (EU) 2024/1689, Art. 4, CELEX 32024R1689 · verified 2026-09-03
- 7ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03
- 8NIST AI 100-1, AI RMF Core, airc.nist.gov · verified 2026-09-03
- 9Regulation (EU) 2024/1689, Art. 73(2)–(4), CELEX 32024R1689 · verified 2026-09-03
- 10Regulation (EU) 2024/1689, full text, CELEX 32024R1689 · verified 2026-09-03
- 11Regulation (EU) 2026/1744, full text, CELEX 32026R1744 · verified 2026-09-03