AI governance stand-up under the EU AI Act
Standing up AI governance from a blank sheet: role and classification first, then the management system, the impact work and the incident clocks.
Governance3 Sept 20265 min readUpdated 5 Sept 2026
On this page
Scope
Almost every obligation in the AI Act turns on two prior answers: the role the organisation holds, and the risk class the system falls into.
Article 6 sets the classification rules and points to Annex III for the listed high-risk areas 1. The regulation applies generally from 2 August 2026, and its first two chapters applied from 2 February 2025 2. Regulation (EU) 2026/1744 then moved the Chapter III high-risk dates to 2 December 2027 under Article 6(2), and to 2 August 2028 under Article 6(1) 3.
In scope: the inventory, the role and class determination per system, the management system that carries the obligations, impact assessment, and the incident clocks.
Out of scope: obligations on general-purpose model providers, national supervisory procedure, and model engineering.
Phases
| Phase | Purpose | Planning horizon | Closes when |
|---|---|---|---|
| 1. Inventory and roles | Find the systems in use, then decide provider or deployer | usually planned over 4–6 weeks | Every system has a named owner and a role decision |
| 2. Classification | Test each system against Article 6 and the listed areas | usually planned over 3–5 weeks | Each system carries a written class, with reasons |
| 3. Management system | Build the policy, risk and documentation machinery on the ISO/IEC 42001:2023 clause structure | usually planned over 4–6 months | Risk assessment, treatment and impact assessment all run |
| 4. Operate and report | Human oversight, monitoring and the incident chain | usually planned over 6–10 weeks | A rehearsal produces a report inside the statutory limit |
Deliverables
| Deliverable | Required by | Who maintains it afterwards |
|---|---|---|
| Role and classification record | Article 6, read with Annex III | AI governance owner |
| AI policy and accountability record | Article 17; ISO/IEC 42001:2023, 5.2 and 5.3 | Executive sponsor |
| Risk management system record | Article 9, iterative across the lifecycle 4 | Risk owner |
| Technical documentation | Article 11, content per Annex IV | Provider-side product owner |
| Fundamental rights impact assessment | Article 27, where its terms catch the deployer 5 | Deployer-side business owner |
| Human oversight assignment | Article 26(2) | Deployer-side business owner |
| AI literacy measures | Article 4 6 | People function |
Roles
| Role | Side | Accountable for |
|---|---|---|
| Executive sponsor | Organisation | Policy, resourcing, review |
| AI governance owner | Organisation | Inventory, classification, documentation, reporting |
| Business owner per system | Organisation | Human oversight and the impact assessment |
| Adviser | External | Method, classification and rehearsal design |
What the authority asks
Failure modes
Mapping
Clause titles 7 and function names 8 are as published.
| Obligation | AI Act | ISO/IEC 42001:2023 | NIST AI RMF |
|---|---|---|---|
| Set policy and assign authority | Art. 17 | 5.2 AI policy, 5.3 Roles, responsibilities and authorities | Govern 1, Govern 2 |
| Inventory and classify systems | Art. 6, Annex III | 4.4 AI management system | Map 2 |
| Assess and treat AI risk | Art. 9 | 8.2 AI risk assessment, 8.3 AI risk treatment | Measure 1, Manage 1 |
| Assess impact on people | Art. 27 | 8.4 AI system impact assessment | Map 5 |
| Document the system | Art. 11, Annex IV | 7.5 Documented information | Map 3 |
| Monitor after release | Art. 72 | 9.1 Monitoring, measurement, analysis and evaluation | Measure 3 |
| Correct, improve and report | Art. 20, Art. 73 9 | 10.2 Nonconformity and corrective action | Manage 4 |
Related
- EU AI Act for security governance — the obligations in briefing form.
- Governing AI and agents: who decides what — decision rights for agent estates.
- AI use-case triage form — the intake this inventory feeds.
References
- Regulation (EU) 2024/1689 (AI Act), OJ L, 2024/1689, 12.7.2024 10.
- Regulation (EU) 2026/1744 (Digital Omnibus on AI), OJ L, 2026/1744, 24.7.2026, amending Article 113 of the AI Act 11.
- ISO/IEC 42001:2023 — Artificial intelligence — Management system. ISO/IEC JTC 1/SC 42, 2023-12.
https://www.iso.org/standard/42001, accessed 2026-09-03. The annexes were not readable free of charge, so none is cited. - NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0). NIST, January 2023.
https://nvlpubs.nist.gov/nistpubs/ai/NIST.AI.100-1.pdf; Core names read onairc.nist.gov, accessed 2026-09-03.
Sources
- 1Regulation (EU) 2024/1689, Art. 6 and Annex III, CELEX 32024R1689 · verified 2026-09-03
- 2Regulation (EU) 2024/1689, Art. 113, CELEX 32024R1689 · verified 2026-09-03
- 3Regulation (EU) 2026/1744, Art. 1(40), CELEX 32026R1744 · verified 2026-09-03
- 4Regulation (EU) 2024/1689, Art. 9(1)–(2), CELEX 32024R1689 · verified 2026-09-03
- 5Regulation (EU) 2024/1689, Art. 27(1), CELEX 32024R1689 · verified 2026-09-03
- 6Regulation (EU) 2024/1689, Art. 4, CELEX 32024R1689 · verified 2026-09-03
- 7ISO OBP, ISO/IEC 42001:2023 clause titles 4 to 10 · verified 2026-09-03
- 8NIST AI 100-1, AI RMF Core, airc.nist.gov · verified 2026-09-03
- 9Regulation (EU) 2024/1689, Art. 73(2)–(4), CELEX 32024R1689 · verified 2026-09-03
- 10Regulation (EU) 2024/1689, full text, CELEX 32024R1689 · verified 2026-09-03
- 11Regulation (EU) 2026/1744, full text, CELEX 32026R1744 · verified 2026-09-03