Do not start with a policy template
A production AI system is governed through behaviour: who can access it, which models and data it can use, what it may output or execute, when a person must intervene and what record survives. A useful AI Act workstream therefore begins with an inventory and system boundary, then maps the legal interpretation to controls.
As of August 2026, Regulation (EU) 2026/1744 is in force. It moves the Chapter III Sections 1–3 high-risk requirements to 2 December 2027 for Annex III systems and 2 August 2028 for Annex I product systems. Those dates do not eliminate duties already in application or the need to design evidence early.
A five-column control record
- Obligation: the exact provision and counsel-approved interpretation.
- System behaviour: what the architecture must permit, prevent or record.
- Owner: the person accountable for operation and exceptions.
- Evidence: a log, test, approval, version, record or exported report.
- Review: trigger, frequency and acceptance threshold.
This structure exposes the difference between a policy statement and an enforced control. “Human oversight exists” is not enough; the system needs a defined intervention point, authorised role, usable interface, recorded decision and failure path.
Build one evidence path
Reuse the same identifiers across inventory, risk decision, model version, evaluation, approval and incident records. That makes a later audit an export problem rather than a reconstruction exercise. It also supports GDPR, security and sector reviews without building a separate evidence system for each rulebook.
Primary sources
Regulation (EU) 2026/1744 · Regulation (EU) 2024/1689. This note is engineering information, not legal advice.