Risk-based inventory

Document each AI system’s purpose, responsible roles, data types, risk class, provider and deployment environment. Without a reliable inventory, reviews and accountability processes remain incomplete.

Logging and traceability

For high-risk AI systems, the European Commission identifies logging, technical documentation and human oversight as core requirements. The control layer should capture the required operational evidence.

Human oversight

Critical decisions require defined approval and escalation paths with clear accountability. Not every agent action should be executed autonomously.

Technical policy enforcement

Each request must be evaluated against policies before a model is accessed or an action is executed. The evaluation should account for data classification, region, approved model and risk level.

From policy to infrastructure

CODE S implements governance requirements through identity controls, routing, policies, approvals and audit evidence.

Source: European Commission, “AI Act”, last updated 3 August 2026. Official EU source.