Skip to content

EU AI Act

The EU AI Act came into full effect in August 2026. GOVERN has built-in support for the key compliance obligations across all risk tiers.

Risk tier mapping

GOVERN uses the EU AI Act risk classification framework as its default inventory taxonomy:

GOVERN tierEU AI Act categoryExamples
ProhibitedProhibited AI practices (Article 5)Social scoring, real-time biometric surveillance
High-RiskHigh-risk AI systems (Annex III)Recruitment, credit scoring, law enforcement
Limited-RiskTransparency obligations (Article 50)Chatbots, deepfake generators
Minimal-RiskNo specific obligationsSpam filters, AI-powered games

Article coverage in GOVERN

ArticleRequirementGOVERN coverage
Article 9Risk management systemContinuous assessment + remediation workflows
Article 10Data governanceData lineage tracking (via SDK metadata)
Article 12Record-keepingImmutable audit trail, 7-year retention
Article 13TransparencyDisclosure enforcement via policy
Article 14Human oversightAlert routing + remediation approval workflows
Article 17Quality managementPolicy versioning + compliance reporting

Generating an Article 12 record

Go to Compliance → EU AI Act Report. Select the system and date range. GOVERN generates a structured report containing all assessment records, policy versions, violation log, and remediation history formatted for Article 12 submission.

Continuous compliance monitoring

GOVERN’s EU AI Act policy template automatically applies the appropriate scorer set for your system’s risk tier. It updates automatically when new guidance is issued.