Verifiable governance · not declared

Governing AI is not a document. It is a system you can verify.

Policy, register, human oversight, evidence. Every rule we write leaves a trace that an auditor — or you — can check. No façade seals.

Governance is what makes AI usable without fear.

01 · Why govern

Without direction, AI is not an abstract risk. It is a cost that accrues.

Tools used without tracking, company data in the hands of unapproved services, outputs never checked. This is shadow AI: when it matters — an audit, an incident, a client — your word is not enough.

  • Outputs used without checking → errors no one tracks.
  • Company data in unapproved tools → shadow AI.
  • AI Act obligations ignored → exposure to penalties.
  • No evidence → in an inspection, you can prove nothing.

The AI Act provides for penalties of up to €35 million or 7% of total worldwide annual turnover for prohibited practices (Art. 5); for the other obligations, penalties reach up to €15 million or 3% (Art. 99). SMEs are subject to the lower of the two amounts.

Reg. (EU) 2024/1689, Arts. 5 and 99 · Law No. 132 of 23 September 2025

02 · What governing means

Not a slogan. Five concrete pillars.

AI Act readiness · Art. 26

"Governing AI" stays an abstraction until it takes a verifiable form. Here are the five pillars we build on — each with its anchor to the AI Act and, above all, with the proof it leaves behind.

01 · Register

Register of systems

Every AI system used in the company, catalogued: purpose, owner, data, risk. Including shadow AI.

Art. 26

The proofRegister of systems, dated and with an assigned owner.

02 · Risk

Risk classification

Every use placed in its AI Act category, from prohibited uses to minimal risk, with the obligations that follow.

Arts. 5, 6, 50

The proofRisk-classification matrix per system.

03 · People

Human oversight

A competent person oversees the high-risk systems. AI proposes, the human decides.

Art. 14

The proofHuman-oversight points documented and assigned.

04 · Rules

Policy & roles

Who can use what, with which data, within which limits. Written and assigned, not implicit.

Art. 26

The proofWritten usage policy and role map.

05 · Evidence

Evidence & logs

Every decision leaves a retained trace: logs kept for at least six months, ready for an inspection.

Art. 26(6)

The proofLogs kept ≥ 6 months, ready for an audit.

03 · How we make it verifiable

Every control we write produces a proof you can verify.

In short: a rule does not stay on paper. It is applied in the process, leaves recorded evidence and passes to a person when a check is needed.

Rule

Definedwritten, not implicit

Application

In the processwhere the work happens

Evidence

Recordedtracked and retained

Oversight

The person decides

The verification chain

Six steps, from rule to audit readiness. Tap a step to see what it leaves behind.

  1. The usage rule, in writing.

    What it leaves: a written policy and assigned roles — not rules implicit in people's heads.

  2. The risk of each system.

    What it leaves: each system placed on prohibited / high-risk / transparency / minimal, with the obligations that follow (Arts. 5, 6, 50).

  3. The system in the register.

    What it leaves: an entry in the register of systems with purpose, owner, data and review date (Art. 26).

  4. With a competent person.

    What it leaves: human-oversight points defined on the high-risk systems. AI proposes, the person decides (Art. 14).

  5. The evidence, over time.

    What it leaves: logs kept for at least six months, ready for an inspection (Art. 26(6)).

  6. Ready for readiness and audit.

    What it leaves: documentation and controls aligned, ready for an ISO/IEC 42001 readiness or for an audit.

Why this concerns you even if you do not "develop" AI: anyone who uses an AI system in the course of their professional activity is a deployer (deployer/user). For high-risk systems, the deployer has specific obligations — including human oversight and the retention of logs (Art. 26).

Reg. (EU) 2024/1689, Arts. 14, 26 and 50

Every rule we write leaves a trace. No claim without its proof.

04 · AI Act & ISO 42001, no myth

What is law, what is voluntary, what we do not do.

Citable sources

The AI Act classifies systems into four levels: prohibited (Art. 5), high-risk (Art. 6 and Annex III), transparency obligations (Art. 50) and minimal risk. We identify where your system sits and which obligations follow.

  • Prohibited · Art. 5
  • High-risk · Art. 6, Annex III
  • Transparency · Art. 50
  • Minimal risk

Reg. (EU) 2024/1689, Arts. 5, 6, 50 and Annex III

Following the Digital Omnibus (adopted by the Council of the EU on 29 June 2026), the obligations for high-risk systems apply from 2 December 2027 (stand-alone systems, Annex III) and from 2 August 2028 (AI embedded in regulated products, Annex I).

Digital Omnibus, Council of the EU, 29 June 2026 · "as from" dates, an evolving framework

Myth vs reality

The myth

  • "The AI Act only concerns those who develop AI."
  • "You certify us to ISO 42001 yourselves."
  • "A single document and we're compliant."

The reality

  • It also concerns those who use it: you are a deployer (Art. 26).
  • No. Only an accredited body certifies it: we prepare the readiness.
  • You need a system with evidence maintained over time.

On ISO/IEC 42001 we are clear — and it is a mark of seriousness, not a limitation.

ISO/IEC 42001:2023 · voluntary standard, complementary to the AI Act

The sources, in detail

Every obligation we cite is traceable back to its official source. Our Regulations pages explain, for each rule, what the source says and how to read it for an SME.

05 · Governance in action

What well-made governance looks like.

Illustrative example

A simplified extract of how the register of systems we build with you looks: each system, its risk, the active controls.

Extract from the register of AI systems 4 systems · tracked
E-mail assistant (drafts)Limited risk
Commercial lead scoringHigh-risk
Document classifierMinimal risk
Website chatbotTransparency · Art. 50
Active controls
  • Human oversight of the high-risk system (Art. 14).
  • Logs kept for at least six months (Art. 26(6)).
  • Information to workers on the use of AI.
Next step

Define the real perimeter with an AI Entry Assessment. Govern

Illustrative example — real client data never appears on this site

06 · Proportionate governance

Rules tailored to an SME. Not to a multinational.

Governance must not weigh more than the problem it solves. We calibrate it to your reality — and to only the obligations that genuinely concern you.

Proportionate

Only the obligations that genuinely concern you: first we understand which, then we act.

Modular

Start from an assessment and grow only if you see value. No imposed corporate apparatus.

No lock-in

No mandated software: we govern what you already use, with technology neutrality.

Transferable

The team stays autonomous: governance must not depend on us to work.

The first step

Want to know which obligations genuinely concern you?

The starting point is the AI Entry Assessment: a map of systems, gap analysis on AI Act and ISO/IEC 42001, a prioritised roadmap. From there, every rule will have its proof.