Resource
EU AI Act: operational governance requirements
The Act is written in obligations. Organisations have to convert those obligations into a repeatable operational process that produces evidence. This is how that translation works in practice.
Start with your position in the value chain
The first operational question is not risk level — it is role. An organisation may be a provider of an AI system, a deployer of someone else's, an importer or a distributor, and it may hold different roles for different systems at the same time.
Role determines which duties attach. A deployer using a third-party system inherits oversight, transparency and monitoring obligations; a provider carries the heavier design, documentation, quality-management and post-market duties. Substantially modifying a system, or putting your own name on it, can move you from one role to the other.
Risk categories drive proportionality
Categorisation is a governance decision, not a label someone applies informally. It must be made from captured context, recorded with its reasoning, and revisited when the use case changes.
- Prohibited practices: screened out at intake, never scored away
- High-risk systems: full documentation, oversight and monitoring duties
- Transparency-obligation systems: disclosure to affected people
- General-purpose and foundation models: upstream provider dependencies
- Minimal-risk uses: registered and monitored, proportionate control
What the obligations demand operationally
- A risk management process that runs across the lifecycle, not once
- Data governance covering quality, relevance and representativeness
- Technical documentation kept current as the system changes
- Automatic logging and retention of system events
- Transparency and instructions for use to deployers
- Effective human oversight, designed rather than assumed
- Accuracy, robustness and cybersecurity commensurate with purpose
- Post-market monitoring, incident handling and corrective action
- AI literacy for the people operating and overseeing the system
Record-keeping is the practical test
Almost every obligation resolves, in an inspection, to a documentation question: show the assessment, show the criteria you applied, show who reviewed it, show who approved it, show the controls, show the monitoring, show what you did when something changed.
Organisations that treat this as a document-production exercise fall behind immediately, because the documents drift from reality. Organisations that generate the record as a by-product of the workflow stay current by default.
A reasonable sequence of work
- Build the inventory, including embedded vendor AI
- Determine role per system: provider, deployer or both
- Screen for prohibited practices immediately
- Classify risk from captured context, with recorded reasoning
- Derive applicable controls and assign named owners
- Stand up independent review and accountable approval
- Instrument monitoring, incidents and material-change triggers
- Schedule periodic reassessment and rehearse the evidence export
Important limitation
This page is general information about operational practice. It is not legal advice, and it does not determine the regulatory status of any specific system. AIRAS Cloud supports governance activity and evidence production; it does not certify compliance with the EU AI Act or any other framework. Obtain qualified legal advice for your own obligations.
Translate obligations into an operating model
We will walk through your AI estate, your role in the value chain and the evidence you would need to produce under scrutiny.
No pricing commitment. No confidential information required.