Risk classification
Each AI system needs role and risk assessment before obligations can be assigned, including high-risk screening where the deployment context requires it.
The EU AI Act, Regulation (EU) 2024/1689, introduces a risk-based framework for AI systems and general-purpose AI models. Vianordis handles AI governance as an evidence problem: disclose AI use, classify risk, log the lifecycle, retain model provenance, keep human oversight, and connect AI controls with GDPR obligations.
The regulation entered into force on 1 August 2024. Prohibitions on certain AI practices and AI-literacy requirements started to apply on 2 February 2025. Rules for general-purpose AI models, governance, confidentiality, and penalties started to apply on 2 August 2025.
The regulation becomes broadly applicable on 2 August 2026, with later high-risk dates for specific areas, including 2 December 2027 for certain high-risk uses and 2 August 2028 for systems embedded into regulated products. Organizations should therefore treat AI governance as a running program, not a one-time policy document.
Each AI system needs role and risk assessment before obligations can be assigned, including high-risk screening where the deployment context requires it.
Users must know when they are interacting with AI, and synthetic or AI-generated output must be identifiable where the regulation requires it.
AI activity must be logged with enough detail to review use periods, inputs or references, model versions, tool actions, guardrail outcomes, errors, and anomalies.
Sensitive AI workflows need meaningful approval, intervention, override, and accountability points instead of silent automated final action.
For consequential workflows, the organization needs decision grounding: which data, memory, knowledge source, model, policy, or tool influenced the output.
Architecture, data flows, risk controls, logging, monitoring, oversight, and evidence must be maintained in a form that can support audit and legal review.
Supported governed interactions can record timestamp, locale, notice version, tenant, and session context. Coverage must be confirmed per application.
Provider, model, version, routing, persona, prompt assembly, and guardrail fields exist for supported paths; completeness and retention require runtime-specific evidence.
Supported input and output decisions can retain rule identifiers and outcomes. This does not prove guardrail effectiveness or complete application coverage.
Supported consequential actions can require approval or rejection with actor and timestamp evidence. Signature method and assurance level are application-specific.
Supported interactions, tool calls, lifecycle events, permissions, and security events can produce durable records; coverage, integrity, retention, and administrator boundaries require evidence.
Legal basis, consent, rights, retention, transfers, and breach monitoring must be mapped for the customer role, data, application, and intended use.
AI Act readiness depends on context: provider, deployer, importer, distributor, product manufacturer, and user obligations differ. Vianordis therefore starts with inventory, classification, data-flow mapping, role assignment, and system boundaries.
Supported governed workflows are designed to fail visibly when a required evidence write fails. This behaviour must be validated for the specific application and action path.
This gives technical, security, compliance, and DPO teams a shared record of AI use: what happened, which controls applied, who approved it, which model was used, and which data-protection duties were connected.
Talk to Vianordis about inventory, governed AI access, audit trails, human approval, private inference, and sovereign AI deployment patterns.