Home/ Compliance/ EU AI Act Governance
European Union

Operational evidence for EU AI Act governance.

Connect high-risk AI obligations to runtime records, policy decisions, human oversight, and evidence workflows without treating infrastructure as a compliance certificate.

Applies to: Providers and deployers of AI used in or affecting people in the EU Status: Regulation (EU) 2024/1689; staged application through 2027 Reviewed: 31 July 2026

The implementation timeline matters now

The EU AI Act entered into force on 1 August 2024. Its requirements apply in stages, so teams should identify their role and risk category before selecting controls or evidence workflows.

2 February 2025

Prohibitions and AI literacy

Chapter I and Article 5 prohibited practices began applying, alongside Article 4 AI-literacy obligations.

2 August 2025

Governance and GPAI provisions

Several governance, general-purpose AI, notified-body, confidentiality, and penalty provisions began applying.

2 August 2026 and 2027

Main high-risk obligations

Most provisions apply from August 2026; Article 6(1) product-safety high-risk obligations apply from August 2027.

Map obligations to evidence, not slogans

The exact obligations depend on whether your organization is a provider, deployer, importer, or distributor and whether the system is prohibited, high-risk, transparency-regulated, or outside those categories.

EU AI Act areaWhat a team may need to demonstrateAxonFlow contribution
Article 9 risk managementKnown risks, controls, testing, residual-risk decisions, and change history.Policy enforcement and framework-oriented records can support a broader risk-management process.
Article 12 record keepingAutomatically generated logs appropriate to the system's intended purpose and risk.Governed request, policy, approval, and execution records with correlation context.
Article 13 transparencyCapabilities, limitations, input expectations, oversight measures, and log interpretation.Response metadata and runtime evidence can support documentation supplied to deployers.
Article 14 human oversightMeaningful ability to understand, intervene, override, or stop where required.Configured HITL queues and circuit-breaker workflows provide intervention points.
Article 15 accuracy, robustness, cybersecurityDefined metrics, testing, monitoring, resilience, and security controls.Operational records and licensed evidence workflows; model testing remains external.
Article 43 conformity assessmentApplicable assessment procedure and supporting technical evidence before placement or use.Enterprise workflow APIs can organize evidence; AxonFlow does not perform or certify conformity.

A practical runtime evidence path

1. Classify

Establish role and risk

Document intended purpose, affected people, prohibited-practice screening, high-risk category, and whether you are acting as provider or deployer.

2. Govern

Place controls at execution boundaries

Apply policies and human review before high-impact model or tool actions, then test failure and emergency-stop behavior.

3. Correlate

Connect decisions to outcomes

Carry correlation identifiers from governance decisions into model, gateway, and downstream system logs.

4. Review

Inspect evidence quality

Verify that records identify the policy, actor, model or tool, decision, timestamp, approval path, and downstream effect.

5. Export

Produce scoped evidence

Use the licensed compliance workflows for conformity, approval, policy-violation, and model-quality evidence where applicable.

6. Rehearse

Exercise intervention

Test reviewer escalation, circuit-breaker activation, rollback, and evidence preservation before production approval.

Important product boundaries

Evidence AxonFlow can produce

  • Request and policy-decision records
  • Human-review history and reviewer identity
  • Governed connector and model activity
  • Framework-oriented exports and workflow records in licensed editions

Evidence you must supply elsewhere

  • Legal classification and prohibited-practice analysis
  • Training-data governance and fundamental-rights assessments
  • Statistical accuracy, fairness, and bias testing
  • Formal conformity assessment, registration, and CE marking

Test the control path against a real workflow.

Use the Evaluation license to assess policy enforcement, human review, evidence records, and deployment boundaries before a regulated rollout.