EU AI Act Automation

EU AI Act governance — model inventory, risk tiering, and post-market evidence.

The EU AI Act applies whether you build models or just use them. Lojycal turns risk classification, model inventory, post-market monitoring and serious-incident reporting into a live, signed governance stream — so a board question on Friday isn't a six-week spreadsheet exercise.

What the EU AI Act actually demands

Regulation (EU) 2024/1689 has been in force since 1 August 2024. Phased applicability, but the obligations on prohibited uses (Feb 2025), GPAI (Aug 2025) and high-risk systems (Aug 2026) are already shaping procurement and engineering decisions today.

  • AI inventory by risk tier

    Every AI system in use — built or bought — classified as prohibited, high-risk, limited-risk or minimal-risk, with deployer/provider role assigned.

  • Documented risk & quality management

    High-risk systems require a risk management system, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity.

  • Post-market monitoring

    Continuous monitoring of how AI systems perform in the field, with serious-incident reporting to national authorities within strict deadlines.

  • GPAI model obligations

    General-purpose AI providers must keep technical documentation, train-data summaries, copyright policies — and systemic-risk providers face additional model-evaluation and incident-reporting duties.

The Lojycal AI governance engine

Four connected workspaces produce every artefact your DPO, your AI governance committee, or a national authority will ask for.

AI system register

Every model, agent and AI feature in use — provider/deployer role, risk tier, business owner, last-review date. Connected to procurement and SaaS inventory.

Trust Center → AI Inventory

Risk & quality records

For each high-risk system: risk management plan, data-governance notes, technical documentation, logging configuration, human-oversight design — signed and versioned.

Trust Center + Workflows

Post-market telemetry

Usage, error rates, drift, override frequency and override outcomes captured into a WORM ledger. Drift past threshold opens a review automatically.

Audit Log + AI Telemetry

Serious-incident reporting

Incident classification against Article 73 criteria, draft notifications pre-populated for the national market surveillance authority.

Incident Ledger

AI Act obligations → Lojycal controls

Lojycal automatically produces evidence for the operational obligations under Title III and the GPAI chapter. A sampled view:

AI Act areaExample obligationLojycal source
Title II — ProhibitedArt. 5 — Avoid prohibited practices in deploymentAI Inventory → Tier Gate
Title III — Risk mgmtArt. 9 — Risk management systemTrust Center → Risk
Title III — DataArt. 10 — Data and data governanceData Governance Workspace
Title III — Technical docArt. 11 — Technical documentationAI System Register
Title III — LoggingArt. 12 — Record-keeping (automatic logging)Audit Log + AI Telemetry
Title III — OversightArt. 14 — Human oversightWorkflows + Dual-control
Title III — Post-marketArt. 72 — Post-market monitoring planAI Telemetry + Reviews
Title III — IncidentArt. 73 — Reporting of serious incidentsIncident Ledger → Report Builder
GPAIArt. 53 — Documentation & copyright policyAI System Register

Sampled — not exhaustive. The AI Act applies in phases; coverage maps to obligations applicable on each date.

Governance the board can read, the authority can verify

AI governance fails the same way ICT governance fails: documents drift from systems. The model the team actually uses isn't the model in the inventory; the oversight described in the policy isn't the oversight in the UI.

Lojycal closes that gap. Every model added, every tier change, every override, every drift event writes a WORM audit-log entry. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-organisation key — that a national market surveillance authority or your insurer can verify independently.

From AI inventory to Article-73-ready — a 90-day path

Teams that wait for August 2026 will start from a blank page. Teams that start now have three quarters of post-market evidence by the time high-risk obligations bite.

  1. Days 0–30

    Phase 1 — Inventory & tier

    Discover every AI system in use across SaaS, internal apps and shadow tools. Classify by risk tier, assign provider/deployer role, identify the high-risk subset.

  2. Days 31–60

    Phase 2 — High-risk artefacts

    For each high-risk system, produce the risk-management record, data-governance notes, technical documentation, logging design and human-oversight design. Connect telemetry.

  3. Days 61–90

    Phase 3 — Post-market & incident rehearsal

    Operate the post-market monitoring loop. Run a serious-incident tabletop and rehearse the Article 73 notification flow end-to-end.

EU AI Act automation — common questions

What is EU AI Act automation?

EU AI Act automation is the practice of generating the AI system inventory, risk-tier classification, high-risk technical documentation, post-market telemetry and serious-incident reports directly from live operational systems — instead of producing them manually before each board review. Lojycal automates the inventory, the risk record, the post-market ledger and the Article 73 report builder end-to-end.

We only use AI — we don't build it. Does this still apply?

Yes. The AI Act distinguishes 'providers' (who build or place an AI system on the market) from 'deployers' (who use it under their authority). Deployers of high-risk systems have their own obligations under Article 26 — including human oversight, monitoring of system operation, and informing affected persons. Lojycal classifies both roles automatically per AI system.

What about GPAI (general-purpose AI) models like the ones behind ChatGPT or Claude?

Providers of GPAI models have obligations under Articles 53–55 applicable from August 2025: technical documentation, train-data summaries, copyright policies, and — for systemic-risk providers — model evaluation, adversarial testing and incident reporting. Lojycal's GPAI module produces the documentation pack and tracks systemic-risk designations.

How do you handle Article 73 serious-incident reporting?

Detected events flow from AI telemetry, SIEM and human-oversight overrides into the incident ledger. Lojycal classifies against Article 73 criteria (death, serious damage to health, serious infringement of fundamental rights, critical-infrastructure disruption, serious damage to property/environment) and surfaces incidents that cross the reporting threshold. The notification draft is pre-populated for the national market surveillance authority.

Which dates matter?

Prohibited uses applied from 2 February 2025. GPAI obligations from 2 August 2025. The majority of high-risk obligations apply from 2 August 2026, with certain Annex I product safety integrations extending to 2 August 2027. Lojycal's tier gate reflects current applicability per article.

How does the AI Act overlap with GDPR?

Substantially. Most high-risk AI systems process personal data, so GDPR data-minimisation, lawful-basis, DPIA and DSAR obligations apply on top of AI Act technical-documentation and human-oversight duties. Lojycal links each AI system to its GDPR Record of Processing entry so the same data governance work covers both.

Treat AI like any other regulated system — with one signed source of truth.

Every model. Every tier change. Every post-market signal. Every override. One ledger, ready for the regulator.