Screen pilots, procurement and production systems for prohibited practices and create a clear stop-and-escalate path.
AI Governance & EU AI Act
A practical implementation guide for organizations operating in Germany and the EU. Turn the EU AI Act, GDPR and ISO/IEC 42001 into an operating model with clear ownership, AI inventories, risk decisions, lifecycle gates, evidence, monitoring and staff literacy.
What applies now
Operational priorities · 7 August 2026The AI Act is already an operational compliance topic. Several obligations now apply and are enforceable, while the 2026 Digital Omnibus gives organizations more time for key high-risk requirements. Use that time to build repeatable governance rather than postpone implementation.
Providers and deployers must take measures supporting AI literacy for relevant staff. Keep role-based training evidence.
Disclosure and content-transparency duties now apply, including specified AI interactions and generated/manipulated content.
Key requirements for Annex III and product-safety-linked high-risk systems now phase in later under the amended timetable.
Interactive governance tools
Assess · Track · ExploreUse these lightweight tools to explore likely governance needs and track whether the basics are in place. They are orientation aids, not legal determinations.
Quick AI use-case assessment
Answer four questions to get a practical governance signal and suggested next steps.
Governance essentials
Mark what your organization already has. Your progress is saved in this browser.
Find a topic quickly
AI governance operating model
Policy → decisions → evidenceGood AI governance connects executive accountability to everyday product, procurement, IT, privacy and risk workflows. The objective is consistent, proportionate and traceable decisions—not a separate bureaucracy for every low-risk tool.
Policy and risk appetite
Define allowed, restricted and prohibited uses; privacy and confidentiality rules; human oversight; transparency expectations; vendor requirements; incident escalation; and exception handling.
Decision rights
Assign an executive sponsor, AI governance lead, system owners, legal/privacy/security reviewers and a forum for material or ambiguous cases.
Govern from intake to retirement
Integrate registration, classification, impact assessment, testing, approval, monitoring, change management and retirement into existing workflows.
Evidence, monitoring and challenge
Maintain an AI inventory, assessment records, approvals, test results, training evidence, logs, incident records and periodic control testing.
Suggested governance responsibilities
| Role / forum | Primary purpose | Typical decisions |
|---|---|---|
| Executive sponsor | Set accountability, risk appetite and resources. | Approve AI policy, major residual risk and remediation funding. |
| AI governance committee | Resolve cross-functional, high-impact or unclear cases. | Approve sensitive pilots, high-risk systems, exceptions and control standards. |
| AI governance lead / office | Run the governance process and maintain standards. | Inventory quality, classification workflow, evidence standards and reporting. |
| System / use-case owner | Own purpose, controls, monitoring and changes. | Define oversight, accept operating conditions and escalate incidents. |
| Independent assurance | Test whether governance and controls actually work. | Audit, control testing, findings and remediation verification. |
Minimum AI inventory fields
Identity
System name, vendor/model, version, business owner, technical owner, status and deployment environment.
Purpose & impact
Intended purpose, users, affected people, decision significance, sector, geography and business process.
Legal classification
Provider/deployer/importer/distributor role, prohibited/high-risk assessment, Article 50 triggers and GPAI dependencies.
Data & controls
Personal/confidential data, retention, transfers, human oversight, access, testing, logging, security and monitoring.
Goals of the EU AI Act
Trust · Innovation · HarmonizationThe EU AI Act aims to create a common legal environment for AI across EU Member States while supporting safe and trustworthy AI development.
Safety and fundamental rights
AI systems should be safe for users and respect privacy, equality, non-discrimination, human dignity, and other fundamental rights.
Responsible adoption
The framework encourages responsible AI development across sectors while reducing legal fragmentation.
One EU framework
A unified regulatory environment helps organizations understand expectations across all EU Member States.
Safe
Systems should be assessed and managed so they do not create unacceptable risks for users.
Transparent
Users should understand when AI is being used and how it operates where transparency duties apply.
Traceable
Development and operation should be documented, logged, and auditable where required.
Non-discriminatory
AI systems should avoid biased or discriminatory outcomes and use appropriate data governance.
Environmentally responsible
Organizations should consider environmental impact in AI development and use.
EU AI Act risk hierarchy
Risk-based regulationThe higher the risk to people’s rights, safety, or livelihoods, the stronger the legal obligations.
Unacceptable
Examples: social scoring, manipulative uses, and certain biometric surveillance practices.
Requirement: banned.
High
Examples: hiring, education, critical infrastructure, law enforcement, migration, public benefits, and essential services.
Requirement: strict compliance, documentation, risk management, human oversight, and monitoring.
Limited
Examples: chatbots, deepfakes, and certain user-facing AI interactions.
Requirement: transparency obligations.
Minimal
Examples: spam filters, AI in games, and low-impact internal tools.
Requirement: no specific AI Act obligations, though other laws may still apply.
GDPR and AI
Personal data rules still applyThe AI Act does not replace GDPR. Whenever AI processes personal data, organizations generally need to comply with both frameworks.
Build protection in from day one
Data protection should be embedded into AI systems from the outset, not retrofitted later.
Collect only what is necessary
Use the minimum personal data needed and protect it with appropriate technical and organizational measures.
Document everything
Organizations must be able to demonstrate compliance through records, policies, assessments, and evidence of controls.
Lawful basis
AI systems need a valid legal basis before processing personal data, such as consent, contract, legal obligation, public task, vital interests, or legitimate interests.
Data minimization
Only data strictly necessary for the task should be collected, retained, or used for model inputs and outputs.
Human oversight
Humans should be able to review automated decisions that significantly affect individuals.
Define who may override, stop or escalate the system and what information they need to do so.
Key rights for individuals
Transparency and controlInformation about automated decision-making
Where GDPR rules on automated decision-making apply, individuals may be entitled to information about the logic involved, significance and envisaged consequences, together with relevant safeguards.
Right to be forgotten
Individuals can request deletion of personal data when legal conditions are met.
Data portability
Individuals may be able to move their data from one service provider to another in a structured, commonly used format.
Right to notification
People may need to be informed if a personal data breach creates relevant risks to their rights and freedoms.
Compliance terminology and responsibilities
Know the rolesAI governance requires clear ownership. Organizations should know whether they are developing, placing, importing, distributing, or deploying an AI system.
Provider
Entity that develops or places an AI system on the market under its own name or trademark.
Deployer
Person or organization using an AI system under its authority in business or public-sector operations.
GPAI
General-purpose AI models that can support a wide range of downstream tasks.
DPIA
Data Protection Impact Assessment, used to evaluate risks from personal data processing.
DPO
Data Protection Officer responsible for advising on and monitoring data protection compliance.
BDSG
Bundesdatenschutzgesetz, Germany’s Federal Data Protection Act.
Identify and classify AI systems
Inventory AI tools and map each one to the EU AI Act risk tier. Include internal, third-party, and embedded AI tools.
Conduct DPIAs where required
Run DPIAs when AI processing is likely to create high risks for individuals, especially with sensitive or large-scale data.
Implement TOMs
Establish technical and organizational measures such as access controls, encryption, logging, vulnerability management, and data leakage safeguards.
Mandate AI literacy
Train staff who use, procure, or manage AI tools so they understand risks, limitations, appropriate use, and escalation routes.
Assign governance owners
Define responsibilities across legal, privacy, security, procurement, HR, IT, business teams, and the DPO where applicable.
Govern the full AI lifecycle
Intake → retirementAttach governance to business gates that already exist. A material change to purpose, model, vendor, data, users, geography or automation level should be able to trigger re-assessment.
Register
Capture owner, tool/model, purpose, data and affected people.
Classify
AI Act role/risk, privacy, security, rights and sector risks.
Control
Define oversight, testing, logging, data and transparency controls.
Gate
Record reviewers, conditions, residual risk and decision.
Monitor
Track incidents, complaints, quality, misuse and changes.
Close
Remove access, handle retained data and archive evidence.
AI control & evidence library
Turn principles into checksA standard control library makes assessments faster and more consistent. Scale the depth by risk, role, data sensitivity and decision impact.
Purpose & scope
Approved purpose, excluded uses, target users/population, benefit, risk owner and re-assessment triggers.
Check purpose changes, excluded uses and accountable owner at each major change.
Data governance
Quality, provenance, representativeness, minimization, sensitive data, retention, deletion and training/fine-tuning rules.
Evidence can include source/provenance notes, retention rules, minimization decisions and dataset checks.
Human oversight
Reviewer authority, competence, intervention point, override capability, escalation route and workload.
Testing & validation
Accuracy, robustness, bias/fairness, harmful outputs, edge cases, prompt injection, security and acceptance criteria.
Set pre-release acceptance criteria and repeat tests after material model, data or workflow changes.
Transparency
User disclosures, instructions, limitations, AI-generated content marking and decision information where applicable.
Check user notices, chatbot disclosure, synthetic-content marking and decision information obligations.
Security
Access, secrets, endpoints, supply chain, data leakage, adversarial testing, vulnerabilities and secure configuration.
Include prompt injection, data leakage, access controls, secrets, integrations and supply-chain risks.
Vendor management
Documentation, data use, subprocessors, transfers, retention, security, incident notice, audit rights and model-change notices.
Track contracts, subprocessors, data use, retention, security commitments and model-change notification.
Monitoring
Quality, drift, override rate, complaints, incidents, harmful outputs, misuse, vendor/model changes and review cadence.
Define measurable signals such as incident count, quality, harmful outputs, override rate and complaints.
Evidence pack
Governance evidence
AI policy, committee charter, RACI, risk appetite, approval matrix and exception process.
System evidence
Inventory entry, classification rationale, technical/system documentation, test results and version history.
Assessment evidence
AI risk/impact assessment, DPIA, FRIA where applicable, security review and vendor due diligence.
Operational evidence
Monitoring reports, incidents, complaints, corrective actions, training records and re-assessments.
90-day governance roadmap
Practical starting sequenceDays 1–30 · Discover and stop obvious risk
Create the AI inventory, publish interim acceptable-use rules, identify prohibited/sensitive use cases, nominate owners and map major vendors/models.
Days 31–60 · Standardize assessments
Launch a common intake form, classification method, privacy/security/vendor review, role-based AI literacy and approval matrix.
Days 61–90 · Operationalize evidence
Set monitoring and change triggers, establish governance reporting, test incident escalation, document exceptions and prioritize high-risk readiness.
ISO 42001 & AI Governance
Certifiable frameworkISO/IEC 42001 is the world's first international standard for Artificial Intelligence Management Systems (AIMS). It provides a structured framework to govern AI risks, demonstrate accountability, and bridge the gap to regulatory requirements like the EU AI Act.
Management System
Establishes policies, roles, and processes to ensure AI is developed and used responsibly across the organization.
Continuous cycle
Operates on a Plan-Do-Check-Act lifecycle to continuously monitor AI performance, adapt to threats, and improve controls.
Evaluating risks
Requires organizations to conduct impact and risk assessments for AI systems to address bias, transparency, and fairness.
Lifecycle governance
Embeds oversight into every stage—from inception and design to deployment, monitoring, and eventual retirement.
Regulatory alignment
Serves as objective evidence of due diligence, helping organizations demonstrate readiness for the EU AI Act and GDPR.
Third-party oversight
Defines controls for managing compliance risks when using external AI solutions, cloud AI platforms, or third-party vendors.
Violations, fines, and enforcement
Maximum exposureMaximum fines depend on the law, violation type, and organization size. Treat these as headline maximums and confirm with legal counsel.
Major infringements, such as serious violations of basic processing principles or data subject rights.
Certain governance, recordkeeping, and security-related obligations.
Prohibited AI practices under the EU AI Act.
Many other AI Act obligations depending on the infringement.
Important EU AI Act milestones
Phased applicationEntry into force
The EU AI Act entered into force, starting the phased implementation timeline.
Prohibited practices and AI literacy
Rules on banned practices and AI literacy obligations began applying.
GPAI obligations begin
Obligations for general-purpose AI models start applying, with transition rules for some existing models.
Transparency and enforcement phase
Article 50 transparency duties apply. AI literacy supervision/enforcement and Commission enforcement powers for GPAI providers are active.
Annex III high-risk phase
Key high-risk requirements for systems classified under Article 6(2) / Annex III apply under the amended Digital Omnibus timetable.
Product-safety-linked high-risk phase
Key requirements for high-risk systems linked to regulated products under Article 6(1) / Annex I apply under the amended timetable.
AI training and copyright
TDM reservationsOrganizations should manage how their content may be used for text and data mining while recognizing that technical and legal reservations are not always universally respected by AI scrapers.
Crawler instructions
Can block specified crawlers from specified pages, but it is a technical instruction rather than a complete legal solution.
Machine-readable opt-out
A structured way to express reservations for text and data mining where supported.
Explicit rights reservation
Terms of use or legal notices can reserve rights against AI training, scraping, and unauthorized reuse.
Common governance questions
Practical FAQDo we need a committee review for every AI tool?
No. Use proportionality. Low-risk tools can follow a streamlined path, while high-impact, novel, ambiguous or sensitive use cases should receive deeper cross-functional review.
Can we rely only on a vendor's AI Act classification?
No. Vendor information is useful, but your own role and context of use can create deployer obligations, privacy risks or sector-specific requirements the vendor cannot fully assess for you.
Does ISO/IEC 42001 certification equal EU AI Act compliance?
No. It provides a management-system structure for responsible AI governance and continual improvement, but specific legal obligations still need to be mapped to your systems, roles and use cases.
Do internal and experimental AI tools belong in the inventory?
Yes. Internal tools can still process employee, customer, confidential or sensitive data and may create security, discrimination, decision or prohibited-use risks.
What should trigger re-assessment?
Consider a re-review when intended purpose, model/version, vendor, data, population, geography, automation level, integrations, performance, incidents or applicable law materially change.
Primary sources
Official materialUse this guide for operational orientation, then verify material decisions against the current consolidated legal text and official guidance.
- Regulation (EU) 2024/1689 — Artificial Intelligence Act (EUR-Lex)
- Regulation (EU) 2026/1744 — Digital Omnibus on AI (EUR-Lex)
- European Commission — Navigating the AI Act
- European Commission — AI literacy Q&A
- European Commission — Article 50 transparency Q&A
- ISO — ISO/IEC 42001:2023 AI management systems
Additional facts organizations should not miss
Practical governanceAI Act compliance is not only an IT issue
Legal, privacy, security, procurement, HR, operations, and business owners all need defined responsibilities.
Vendor AI tools still need review
Using a third-party AI system does not remove the need to assess contracts, data flows, risk tier, security, and user obligations.
Training data quality matters
Poor, biased, incomplete, or unrepresentative data can create discrimination, inaccuracy, and compliance problems.
Logs and documentation are evidence
Risk assessments, model cards, DPIAs, incident records, access logs, vendor due diligence, and monitoring reports help demonstrate accountability.
Human oversight must be meaningful
Reviewers need authority, training, time, and information to challenge AI outputs rather than rubber-stamp them.
Prompts and outputs can contain sensitive data
Prompts may contain personal data or confidential information. Outputs may become records that need retention, review, or deletion controls.