Risk classification
Each AI system needs role and risk assessment before obligations can be assigned, including high-risk screening where the deployment context requires it.
The EU AI Act, Regulation (EU) 2024/1689, introduces a risk-based framework for AI systems and general-purpose AI models. Vianordis handles AI governance as an evidence problem: disclose AI use, classify risk, log the lifecycle, retain model provenance, keep human oversight, and connect AI controls with GDPR obligations.
The regulation entered into force on 1 August 2024. Prohibitions on certain AI practices and AI-literacy requirements started to apply on 2 February 2025. Rules for general-purpose AI models, governance, confidentiality, and penalties started to apply on 2 August 2025.
The regulation becomes broadly applicable on 2 August 2026, with later high-risk dates for specific areas, including 2 December 2027 for certain high-risk uses and 2 August 2028 for systems embedded into regulated products. Organizations should therefore treat AI governance as a running program, not a one-time policy document.
Each AI system needs role and risk assessment before obligations can be assigned, including high-risk screening where the deployment context requires it.
Users must know when they are interacting with AI, and synthetic or AI-generated output must be identifiable where the regulation requires it.
AI activity must be logged with enough detail to review use periods, inputs or references, model versions, tool actions, guardrail outcomes, errors, and anomalies.
Sensitive AI workflows need meaningful approval, intervention, override, and accountability points instead of silent automated final action.
For consequential workflows, the organization needs decision grounding: which data, memory, knowledge source, model, policy, or tool influenced the output.
Architecture, data flows, risk controls, logging, monitoring, oversight, and evidence must be maintained in a form that can support audit and legal review.
Each governed interaction can record that AI disclosure was shown, including timestamp, locale, notice version, tenant, and session context.
Provider, model, model version, key provenance, routing path, persona version, prompt assembly version, and guardrail configuration are retained with the interaction record.
Input and output guardrail decisions are persisted with rule identifiers, allow or block decisions, and links to the interaction they governed.
Actions on a user's behalf can require recorded approval, rejection, signer identity, timestamp, and cryptographic signature evidence.
AI interactions, tool calls, lifecycle events, permission decisions, and security events are handled as durable compliance records rather than transient logs.
AI governance is linked to legal basis, consent, data-subject rights, retention, transfer records, and breach monitoring where personal data is involved.
AI Act readiness depends on context: provider, deployer, importer, distributor, product manufacturer, and user obligations differ. Vianordis therefore starts with inventory, classification, data-flow mapping, role assignment, and system boundaries.
The implemented model treats auditability as the backbone. If a governed compliance write fails, the action is designed to fail loudly instead of continuing without evidence.
This gives technical, security, compliance, and DPO teams a shared record of AI use: what happened, which controls applied, who approved it, which model was used, and which data-protection duties were connected.
Talk to Vianordis about inventory, governed AI access, audit trails, human approval, private inference, and sovereign AI deployment patterns.