Know your estate
Discover and register every AI system and general-purpose model in use, with owner, intended purpose, lifecycle stage and the role you play — provider, deployer, importer or distributor.
EU AI Act · Regulation (EU) 2024/1689
ai-governance.be is a single system of record for operationalising the EU AI Act. Inventory every AI system and model, classify its risk, assemble the technical documentation, run the conformity assessment, and keep evidence audit-ready — with the controls wired into the MLOps and DevOps pipelines you already run.
No spam. One launch email and occasional product notes. Unsubscribe anytime.
The AI Act treats compliance as a continuous process, not a one-off certificate. ai-governance.be is built around that lifecycle — from the first use-case intake to post-market monitoring and serious-incident reporting — so the evidence is produced as a by-product of building and running AI, not as a parallel paper exercise.
Discover and register every AI system and general-purpose model in use, with owner, intended purpose, lifecycle stage and the role you play — provider, deployer, importer or distributor.
A guided assessment maps each system to its AI Act risk tier — prohibited, high-risk (Annex III), limited or minimal — and records the reasoning and sign-off behind the call.
Generate technical documentation, capture logs and oversight decisions, and keep a versioned evidence vault that stays ready for auditors, market-surveillance authorities and notified bodies.
Each capability maps to a specific obligation in Regulation (EU) 2024/1689, so you can trace any requirement to the control that satisfies it.
A living catalogue of AI systems and GPAI models, with intended purpose, data sources, deployment context and accountable roles.
Decision-tree assessment against Articles 5 and 6 and Annex III, with an auditable record of inputs, outcome and sign-off.
Continuous risk identification, evaluation and mitigation aligned to Article 9, linked to each high-risk system.
Document training, validation and testing data practices, bias examination and quality criteria under Article 10.
Assemble and maintain the Annex IV / Article 11 file from structured inputs, exportable as a single dossier.
Capture automatically generated event logs and retention evidence to meet Article 12.
Define and record oversight measures, roles and intervention points required by Article 14.
Record the metrics, testing and resilience measures that evidence Article 15 before release and over time.
Manage user-facing disclosures and AI-generated content marking under Articles 13 and 50.
Track the route to conformity, the EU declaration of conformity and CE marking, including notified-body interactions and EU-database registration.
Model documentation, downstream information, copyright policy and training-content summaries for Articles 53–55, with systemic-risk extras.
Run the monitoring plan under Article 72 and manage serious-incident reporting under Article 73.
Most organisations already run an AI delivery process: a use case is proposed, data is prepared, models are trained and evaluated, something is deployed, and it is monitored in production. The AI Act adds an obligation to almost every one of those stages. ai-governance.be places its controls on the process you already have, so responsibility is clear and evidence accumulates as the work moves forward.
| Lifecycle stage | What the AI Act asks for | Captured in ai-governance.be |
|---|---|---|
| Use-case intake & design | Screen for prohibited practices (Art. 5); determine the risk tier (Art. 6, Annex III); fix the intended purpose. | An intake form opens the project record, runs the classification, and captures the intended purpose and a dated sign-off before build work starts. |
| Data preparation | Data governance and quality: relevance, representativeness, bias examination, documented provenance (Art. 10). | Dataset datasheets, bias-check results and lineage links pulled from your data catalogue or feature store, attached to the system record. |
| Training & experimentation | Operate the risk management system (Art. 9); keep records that make results traceable. | Run metadata, model versions and metrics imported from your experiment tracker and linked to open risk items and mitigations. |
| Validation & pre-deployment | Evidence accuracy, robustness and cybersecurity (Art. 15); design human oversight (Art. 14); complete the technical documentation (Art. 11 / Annex IV). | The tech-doc dossier is assembled from structured inputs; a release checklist gate blocks promotion until required evidence and oversight design are in place. |
| Deployment & release | Complete the conformity assessment, draw up the EU declaration of conformity, apply CE marking, register the system in the EU database. | A pipeline status check confirms readiness; the declaration is generated from the record and the registration reference is stored with it. |
| Production & monitoring | Post-market monitoring (Art. 72); keep automatic logs (Art. 12); report serious incidents within the deadlines (Art. 73). | Monitoring metrics and alerts are ingested from your observability stack; drift or failures open an incident workflow with the reporting clock and templates. |
| Change & retirement | Re-assess after a substantial modification; keep documentation for 10 years; decommission cleanly. | Version diffs flag when a change is substantial and re-open the assessment; the evidence vault retains superseded versions. |
ai-governance.be connects to model registries and experiment trackers — MLflow, Azure Machine Learning, Amazon SageMaker, Vertex AI, Databricks — and reads model versions, datasets, parameters and evaluation metrics through their APIs.
Compliance becomes a check in the pipeline you already run — GitHub Actions, GitLab CI, Azure DevOps, Jenkins — rather than a separate approval outside the toolchain.
The effect is shift-left compliance: classification and documentation gaps are caught at design and release time, inside the developer's workflow, instead of surfacing during an audit.
Dates reflect Regulation (EU) 2024/1689 as published in the Official Journal. This site is informational and is not legal advice.
The Act binds providers, deployers, importers and distributors of AI systems, plus providers of general-purpose AI models. It applies extraterritorially: an organisation established outside the EU is in scope if it places an AI system or GPAI model on the EU market, or if the output of its system is used in the EU. Obligations are heaviest for providers of high-risk AI systems.
Two routes. First, AI used as a safety component of a product covered by EU harmonised legislation in Annex I (for example medical devices or machinery). Second, AI used in one of the Annex III areas: biometrics, critical infrastructure, education, employment and worker management, access to essential private and public services, law enforcement, migration and border control, and administration of justice. High-risk systems must meet the requirements in Articles 8 to 15 before being placed on the market.
The Regulation entered into force on 1 August 2024 and applies in phases. 2 February 2025: prohibited practices and AI literacy. 2 August 2025: obligations for general-purpose AI models and the governance and penalties framework. 2 August 2026: the bulk of the Act, including high-risk systems under Annex III. 2 August 2027: high-risk obligations for AI as a safety component of products under Annex I.
A provider develops an AI system or GPAI model, or has one developed, and places it on the market or puts it into service under its own name or trademark. A deployer uses an AI system under its own authority in a professional context. Providers carry the design-time obligations such as conformity assessment and technical documentation; deployers carry use-time obligations such as human oversight, monitoring and, in some cases, a fundamental-rights impact assessment. A deployer that substantially modifies a high-risk system, or puts its own name on it, can become a provider.
Under Articles 53 to 55, every GPAI model provider must keep up-to-date technical documentation, provide information to downstream providers who build on the model, put in place a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training. Models presenting systemic risk have extra duties: model evaluation and adversarial testing, systemic-risk assessment and mitigation, serious-incident tracking and reporting, and adequate cybersecurity.
Fines are tiered. Breaching the prohibited-practices rules can cost up to 35 million euro or 7% of total worldwide annual turnover, whichever is higher. Breaching most other obligations can cost up to 15 million euro or 3% of turnover. Supplying incorrect, incomplete or misleading information to authorities can cost up to 7.5 million euro or 1% of turnover. For SMEs and start-ups the lower of the fixed amount or the percentage applies.
Yes. It connects to model registries and experiment trackers such as MLflow, Azure Machine Learning, Amazon SageMaker, Vertex AI and Databricks to populate the AI system inventory automatically, and it exposes a compliance status check for CI/CD pipelines such as GitHub Actions, GitLab CI and Azure DevOps so a release can be gated when required documentation or sign-off is missing. Obligations sync to issue trackers like Jira and Azure Boards.
No. ai-governance.be is a compliance-management tool and this website is informational only. It helps you organise, evidence and track your obligations, but it does not replace advice from a qualified lawyer or a conformity assessment by a notified body.
We're onboarding a first group of design partners — AI providers, deployers and compliance teams in the EU. Leave your email and we'll be in touch with early access and product updates.