EU AI Act governance — model inventory, risk tiering, and post-market evidence.
The EU AI Act applies whether you build models or just use them. Lojycal turns risk classification, model inventory, post-market monitoring and serious-incident reporting into a live, signed governance stream — so a board question on Friday isn't a six-week spreadsheet exercise.
What the EU AI Act actually demands
Regulation (EU) 2024/1689 has been in force since 1 August 2024. Phased applicability, but the obligations on prohibited uses (Feb 2025), GPAI (Aug 2025) and high-risk systems (Aug 2026) are already shaping procurement and engineering decisions today.
AI inventory by risk tier
Every AI system in use — built or bought — classified as prohibited, high-risk, limited-risk or minimal-risk, with deployer/provider role assigned.
Documented risk & quality management
High-risk systems require a risk management system, data governance, technical documentation, logging, transparency, human oversight, accuracy/robustness/cybersecurity.
Post-market monitoring
Continuous monitoring of how AI systems perform in the field, with serious-incident reporting to national authorities within strict deadlines.
GPAI model obligations
General-purpose AI providers must keep technical documentation, train-data summaries, copyright policies — and systemic-risk providers face additional model-evaluation and incident-reporting duties.
The Lojycal AI governance engine
Four connected workspaces produce every artefact your DPO, your AI governance committee, or a national authority will ask for.
AI system register
Every model, agent and AI feature in use — provider/deployer role, risk tier, business owner, last-review date. Connected to procurement and SaaS inventory.
Trust Center → AI Inventory
Risk & quality records
For each high-risk system: risk management plan, data-governance notes, technical documentation, logging configuration, human-oversight design — signed and versioned.
Trust Center + Workflows
Post-market telemetry
Usage, error rates, drift, override frequency and override outcomes captured into a WORM ledger. Drift past threshold opens a review automatically.
Audit Log + AI Telemetry
Serious-incident reporting
Incident classification against Article 73 criteria, draft notifications pre-populated for the national market surveillance authority.
Incident Ledger
AI Act obligations → Lojycal controls
Lojycal automatically produces evidence for the operational obligations under Title III and the GPAI chapter. A sampled view:
| AI Act area | Example obligation | Lojycal source |
|---|---|---|
| Title II — Prohibited | Art. 5 — Avoid prohibited practices in deployment | AI Inventory → Tier Gate |
| Title III — Risk mgmt | Art. 9 — Risk management system | Trust Center → Risk |
| Title III — Data | Art. 10 — Data and data governance | Data Governance Workspace |
| Title III — Technical doc | Art. 11 — Technical documentation | AI System Register |
| Title III — Logging | Art. 12 — Record-keeping (automatic logging) | Audit Log + AI Telemetry |
| Title III — Oversight | Art. 14 — Human oversight | Workflows + Dual-control |
| Title III — Post-market | Art. 72 — Post-market monitoring plan | AI Telemetry + Reviews |
| Title III — Incident | Art. 73 — Reporting of serious incidents | Incident Ledger → Report Builder |
| GPAI | Art. 53 — Documentation & copyright policy | AI System Register |
Sampled — not exhaustive. The AI Act applies in phases; coverage maps to obligations applicable on each date.
Governance the board can read, the authority can verify
AI governance fails the same way ICT governance fails: documents drift from systems. The model the team actually uses isn't the model in the inventory; the oversight described in the policy isn't the oversight in the UI.
Lojycal closes that gap. Every model added, every tier change, every override, every drift event writes a WORM audit-log entry. The Trust Center bundles selected windows into a signed Evidence Pack — JSON, CSV and PDF, with a detached HMAC signature using a per-organisation key — that a national market surveillance authority or your insurer can verify independently.
From AI inventory to Article-73-ready — a 90-day path
Teams that wait for August 2026 will start from a blank page. Teams that start now have three quarters of post-market evidence by the time high-risk obligations bite.
- Days 0–30
Phase 1 — Inventory & tier
Discover every AI system in use across SaaS, internal apps and shadow tools. Classify by risk tier, assign provider/deployer role, identify the high-risk subset.
- Days 31–60
Phase 2 — High-risk artefacts
For each high-risk system, produce the risk-management record, data-governance notes, technical documentation, logging design and human-oversight design. Connect telemetry.
- Days 61–90
Phase 3 — Post-market & incident rehearsal
Operate the post-market monitoring loop. Run a serious-incident tabletop and rehearse the Article 73 notification flow end-to-end.
EU AI Act automation — common questions
What is EU AI Act automation?
EU AI Act automation is the practice of generating the AI system inventory, risk-tier classification, high-risk technical documentation, post-market telemetry and serious-incident reports directly from live operational systems — instead of producing them manually before each board review. Lojycal automates the inventory, the risk record, the post-market ledger and the Article 73 report builder end-to-end.
We only use AI — we don't build it. Does this still apply?
Yes. The AI Act distinguishes 'providers' (who build or place an AI system on the market) from 'deployers' (who use it under their authority). Deployers of high-risk systems have their own obligations under Article 26 — including human oversight, monitoring of system operation, and informing affected persons. Lojycal classifies both roles automatically per AI system.
What about GPAI (general-purpose AI) models like the ones behind ChatGPT or Claude?
Providers of GPAI models have obligations under Articles 53–55 applicable from August 2025: technical documentation, train-data summaries, copyright policies, and — for systemic-risk providers — model evaluation, adversarial testing and incident reporting. Lojycal's GPAI module produces the documentation pack and tracks systemic-risk designations.
How do you handle Article 73 serious-incident reporting?
Detected events flow from AI telemetry, SIEM and human-oversight overrides into the incident ledger. Lojycal classifies against Article 73 criteria (death, serious damage to health, serious infringement of fundamental rights, critical-infrastructure disruption, serious damage to property/environment) and surfaces incidents that cross the reporting threshold. The notification draft is pre-populated for the national market surveillance authority.
Which dates matter?
Prohibited uses applied from 2 February 2025. GPAI obligations from 2 August 2025. The majority of high-risk obligations apply from 2 August 2026, with certain Annex I product safety integrations extending to 2 August 2027. Lojycal's tier gate reflects current applicability per article.
How does the AI Act overlap with GDPR?
Substantially. Most high-risk AI systems process personal data, so GDPR data-minimisation, lawful-basis, DPIA and DSAR obligations apply on top of AI Act technical-documentation and human-oversight duties. Lojycal links each AI system to its GDPR Record of Processing entry so the same data governance work covers both.
Treat AI like any other regulated system — with one signed source of truth.
Every model. Every tier change. Every post-market signal. Every override. One ledger, ready for the regulator.
