Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.
What AI governance does the EU AI Act require?
Updated
Articles 4, 14 and 26 of Regulation (EU) 2024/1689 set AI-literacy, high-risk human-oversight and deployer duties, only if they apply. ISO/IEC 42001:2023 is a standard, not a legal substitute for the Act. Not legal advice. This page does not determine that YOU have to stand up an AI management system.
AI governance requirements, last verified 9 September 2026 against Articles 3(56), 4, 14, 17, 26 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024). ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI literacy Q&A are Commission materials — guidance, not the regulation. Regulation (EU) 2026/1744 is an amending regulation; it does not rewrite Article 113(a) for Chapters I and II. This page is not legal advice, not a filing, not a determination that YOU have to stand up an AI management system, and does not start a clock.
This is Articles 4, 14 and 26, not YOUR AI management system
Audience: a CISO, compliance lead, or product owner walking Regulation (EU) 2024/1689 on organisational AI governance. This page is not legal advice. It does not start a clock. Reading it does not start a clock. Mapping a row is not a determination that the Act applies, that YOU are a provider or a deployer, or that YOU have to stand up an AI management system. This page does not file with the AI Office.
The AI Act is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. Article 4 is AI literacy. Article 14 is human oversight of high-risk AI systems. Article 26 is high-risk deployer duties. Article 17 is the high-risk provider quality-management system. ISO/IEC 42001:2023 is a standard. NIST AI RMF 1.0 is guidance. They are not the same kind of text. The EU AI Act overview on this site is the pillar page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. Last verified 9 September 2026. Not legal advice.
- Statute versus standard versus guidance: Articles 3(56), 4, 14, 17, 26 and 113 of 2024/1689 are legal requirements only if they apply. ISO/IEC 42001:2023 is a management-system standard, not a legal substitute for the Act. NIST AI RMF 1.0 is guidance, not law. Commission AI Act pages and AI literacy Q&A are Commission materials — guidance, not the regulation. This page quotes which kind of text it is relying on.
- The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. A dedicated AI-ownership-accountability, model-evaluation-requirements, and how-shipreadymetrics-supports-ai-governance guide is not on this site yet. Naming them is not a link.
- This page does not invent a 2 August 2026 start date for Article 4. Article 113(a) of 2024/1689 applies Chapters I and II from 2 February 2025. Article 4 sits in Chapter I. Article 113(b) applies Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 from 2 August 2025, with the exception of Article 101. Chapter VII is Union-level governance (Board, AI Office), not YOUR AI management system. Article 113(c) Annex I product-embedded high-risk is 2 August 2027, not 2026. This page does not invent a 2 August 2026 date for Annex I.
What original Article 4 actually says
Last verified 9 September 2026 against Article 4 and Article 3(56) of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). These are legal requirements of the original regulation, only if they apply. This page does not apply them to YOU. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| AI literacy — Article 3(56) | Authentic Article 3(56): 'AI literacy' means skills, knowledge and understanding that allow providers, deployers and affected persons, taking into account their respective rights and obligations in the context of this Regulation, to make an informed deployment of AI systems, as well as to gain awareness about the opportunities and risks of AI and possible harm it can cause. | Article 3(56) of 2024/1689. Legal requirement of the definition. This page does not find that YOUR staff lack AI literacy. | 9 September 2026 |
| Original Article 4 of 2024/1689 | Authentic original Article 4: Providers and deployers of AI systems shall take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons on whom the AI systems are to be used. | Article 4 of 2024/1689. Legal requirement, only if it applies. Article 113(a) applies Chapters I and II from 2 February 2025. This page does not run YOUR literacy programme. | 9 September 2026 |
| When Article 4 applies | Article 113(a): Chapters I and II shall apply from 2 February 2025. Chapter I includes Article 4. Article 4 did not start on 2 August 2026. This page does not invent a 2 August 2026 start date for Article 4. | Articles 4 and 113(a) of 2024/1689. Legal requirements of the original regulation. 2026/1744 is an amending regulation. It does not rewrite Article 113(a) for Chapters I and II. Counsel reads any authentic operative amendment. | 9 September 2026 |
Article 113(a) is 2 February 2025 for literacy, not 2 August 2026
Last verified 9 September 2026 against Article 113 of Regulation (EU) 2024/1689 on EUR-Lex (OJ L 2024/1689, 12.7.2024). Article 113(a): Chapters I and II shall apply from 2 February 2025. Chapter I is general provisions, including Article 4 AI literacy. Chapter II is prohibited AI practices. Those duties did not start on 2 August 2026. This page does not move that date.
Article 14 sits in Chapter III Section 2 (requirements for high-risk AI systems). Article 17 and Article 26 sit in Chapter III Section 3 (obligations of providers and deployers of high-risk AI systems and other parties). The original Article 113 second paragraph applies the rest of the Regulation from 2 August 2026. Article 113(c) keeps Article 6(1) and the corresponding obligations — Annex I product-embedded high-risk — on 2 August 2027, not 2 August 2026. Those dates are not one number.
Article 113(b): Chapter III Section 4, Chapter V, Chapter VII and Chapter XII and Article 78 shall apply from 2 August 2025, with the exception of Article 101. Chapter V is GPAI. Chapter VII is Union-level governance. Chapter III Section 4 is notifying authorities and notified bodies. None of those limbs is YOUR ISO 42001 AI management system. This page does not invent a 2 August 2026 start date for GPAI. Regulation (EU) 2026/1744 is an amending regulation. It does not rewrite Article 113(a) for Chapters I and II, and it does not rewrite Article 113(b) for Chapter V. Counsel reads the authentic operative article of any amendment. This page does not apply 2026/1744 to YOU. Not legal advice.
Article 14 — high-risk human oversight as written
Each row is a duty as Article 14 of 2024/1689 states it for high-risk AI systems. Mapping a row is not a finding that it binds YOU, and is not a classification that YOUR system is high-risk. Walk the checklist questions below with counsel. Last verified 9 September 2026. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 14(1) | High-risk AI systems shall be designed and developed in such a way, including with appropriate human-machine interface tools, that they can be effectively overseen by natural persons during the period in which they are in use. | Article 14(1) of 2024/1689. Legal requirement, only if it applies. This page does not design YOUR interface. | 9 September 2026 |
| Article 14(2) | Human oversight shall aim to prevent or minimise the risks to health, safety or fundamental rights that may emerge when a high-risk AI system is used in accordance with its intended purpose or under conditions of reasonably foreseeable misuse, in particular where such risks persist despite the application of other requirements set out in this Section. | Article 14(2) of 2024/1689. Legal requirement, only if it applies. | 9 September 2026 |
| Article 14(3) | The oversight measures shall be commensurate with the risks, level of autonomy and context of use of the high-risk AI system, and shall be ensured through either one or both of the following types of measures: (a) measures identified and built, when technically feasible, into the high-risk AI system by the provider before it is placed on the market or put into service; (b) measures identified by the provider before placing the high-risk AI system on the market or putting it into service and that are appropriate to be implemented by the deployer. | Article 14(3) of 2024/1689. Legal requirement, only if it applies. This page does not pick YOUR (a) or (b) measures. | 9 September 2026 |
| Article 14(4)(a)–(e) | The high-risk AI system shall be provided to the deployer in such a way that natural persons to whom human oversight is assigned are enabled, as appropriate and proportionate: (a) to properly understand the relevant capacities and limitations of the high-risk AI system and be able to duly monitor its operation, including in view of detecting and addressing anomalies, dysfunctions and unexpected performance; (b) to remain aware of the possible tendency of automatically relying or over-relying on the output produced by a high-risk AI system (automation bias), in particular for high-risk AI systems used to provide information or recommendations for decisions to be taken by natural persons; (c) to correctly interpret the high-risk AI system's output, taking into account in particular the characteristics of the system and the interpretation tools and methods available; (d) to decide, in any particular situation, not to use the high-risk AI system or otherwise disregard, override or reverse the output of the high-risk AI system; (e) to intervene in the operation of the high-risk AI system or interrupt the system through a 'stop' button or a similar procedure that allows the system to come to a halt in a safe state. | Article 14(4) of 2024/1689. Legal requirement, only if it applies. This page does not assign YOUR overseers and does not install a stop control. | 9 September 2026 |
| Article 14(5) | For high-risk AI systems referred to in point 1(a) of Annex III, the measures referred to in paragraph 3 shall be such as to ensure that, in addition, no action or decision is taken by the deployer on the basis of the identification resulting from the system unless that identification has been separately verified and confirmed by at least two natural persons with the necessary competence, training and authority. The requirement for a separate verification by at least two natural persons shall not apply to high-risk AI systems used for the purposes of law enforcement, migration, border control or asylum, where Union or national law considers the application of this requirement to be disproportionate. | Article 14(5) of 2024/1689. Legal requirement, only if it applies. This page does not classify YOUR system under Annex III point 1(a). | 9 September 2026 |
Article 26 — high-risk deployer governance duties as written
Article 14 is a design-and-development requirement for high-risk systems. Article 26(2) is the deployer duty to assign human oversight to natural persons. They are different articles. Mapping a row is not a finding that it binds YOU, and is not a classification that YOU are a deployer. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. Last verified 9 September 2026. Not legal advice.
| Point | What the cited text says | Kind of text | Last verified |
|---|---|---|---|
| Article 26(1) | Deployers of high-risk AI systems shall take appropriate technical and organisational measures to ensure they use such systems in accordance with the instructions for use accompanying the systems. | Article 26(1) of 2024/1689. Legal requirement, only if it applies. This page does not write YOUR instructions-for-use file. | 9 September 2026 |
| Article 26(2) | Deployers shall assign human oversight to natural persons who have the necessary competence, training and authority, as well as the necessary support. | Article 26(2) of 2024/1689. Legal requirement, only if it applies. Distinct from Article 14 design measures. This page does not assign YOUR overseers. | 9 September 2026 |
| Article 26(4) | To the extent the deployer exercises control over the input data on the basis of which the system produces an output, that deployer shall ensure that input data is relevant and sufficiently representative in view of the intended purpose of the high-risk AI system. | Article 26(4) of 2024/1689. Legal requirement, only if it applies. This page does not assess YOUR input data. | 9 September 2026 |
| Article 26(5) | Deployers shall monitor the operation of the high-risk AI system on the basis of the instructions for use and, where relevant, inform providers in accordance with Article 72. Where deployers have reason to consider that use in accordance with the instructions may result in that AI system presenting a risk within the meaning of Article 79(1), they shall, without undue delay, inform the provider or distributor and the relevant market surveillance authority, and shall suspend the use of that system. | Article 26(5) of 2024/1689. Legal requirement, only if it applies. This page does not start a clock and does not file that notice. | 9 September 2026 |
| Article 26(6) | Deployers of high-risk AI systems shall keep the logs automatically generated by that high-risk AI system to the extent such logs are under their control, for a period appropriate to the intended purpose of the high-risk AI system, of at least six months, unless provided otherwise in applicable Union or national law, in particular in Union law on the protection of personal data. | Article 26(6) of 2024/1689. Legal requirement, only if it applies. This product does not keep YOUR Article 26 logs. | 9 September 2026 |
| Article 26(7) | Workplace information to workers' representatives and affected workers before putting into service or using a high-risk AI system at the workplace. | Article 26(7) of 2024/1689. Legal requirement, only if it applies. This page does not send YOUR workplace notice. | 9 September 2026 |
ISO/IEC 42001:2023 operationalizes an AIMS — it does not discharge the Act
ISO/IEC 42001:2023 is the international standard for an AI management system (AIMS). It is a standard, not Regulation (EU) 2024/1689. Running an ISO 42001 programme is not a determination that the Act is met. Certification to ISO 42001 is not CE marking, not an Article 43 conformity assessment, and not a notified-body certificate under the Act. Last verified 9 September 2026. Not legal advice.
The ISO 42001 framework guide on this site is the education page under frameworks. An ISO 42001 versus EU AI Act comparison is not on this site yet. Naming it is not a link. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page.
| Element | What the standard is | Kind of text | Last verified |
|---|---|---|---|
| What it is | ISO/IEC 42001:2023 specifies requirements for establishing, implementing, maintaining and continually improving an AI management system. It is certifiable by an accredited certification body. That is a standard's certification cycle, not an AI Act conformity assessment. | ISO/IEC 42001:2023. Best practice / standard, not a legal substitute for the Act. This page does not determine that YOU have to stand up an AIMS. | 9 September 2026 |
| Clauses 4 to 10 | Context, leadership, planning, support, operation, performance evaluation, improvement — the Plan-Do-Check-Act management-system skeleton shared with ISO 27001. | ISO/IEC 42001:2023. Standard, not the regulation. Distinct from Article 17 of 2024/1689, which is a legal quality-management-system duty for providers of high-risk AI systems, only if it applies. | 9 September 2026 |
| Annex A control areas | Policies related to AI; internal organisation; resources for AI systems; assessing impacts of AI systems; AI system life cycle; data for AI systems; information for interested parties; use of AI systems; third-party and customer relationships. An organisation records applicability in a Statement of Applicability. | ISO/IEC 42001:2023 Annex A. Standard, not the regulation. This page does not write YOUR Statement of Applicability. | 9 September 2026 |
| Article 17 of 2024/1689 — distinct legal QMS | Providers of high-risk AI systems shall put a quality management system in place that ensures compliance with this Regulation. That system shall be documented in a systematic and orderly manner in the form of written policies, procedures and instructions. Article 16(c) points at Article 17. | Articles 16(c) and 17 of 2024/1689. Legal requirement, only if it applies. An ISO 42001 certificate does not discharge Article 17. This product does not keep YOUR Article 17 file. | 9 September 2026 |
NIST AI RMF is guidance, not law
NIST AI 100-1, Artificial Intelligence Risk Management Framework (AI RMF 1.0), January 2023, is US National Institute of Standards and Technology guidance. It is voluntary. It is not Regulation (EU) 2024/1689. It is not ISO/IEC 42001:2023. Mapping a Govern, Map, Measure, or Manage function is not a finding that the Act is met. Last verified 9 September 2026. Not legal advice.
Legal requirement versus standard versus ShipReady recommendation
The table below labels each text. Do not treat a standard as the article, do not treat guidance as the article, and do not treat a product surface as a determination. Last verified 9 September 2026. Not legal advice.
| Text | What it is | What this page does not do |
|---|---|---|
| Regulation (EU) 2024/1689 Articles 3(56), 4, 14, 17, 26, 113 | Legal requirement — the regulation, only if it applies. Article 4 from 2 February 2025 under Article 113(a). Article 14 and Article 26 sit on the original 2 August 2026 residual, except Article 6(1) corresponding obligations on 2 August 2027 under Article 113(c). Chapter V GPAI from 2 August 2025 under Article 113(b), except Article 101. | Does not determine that YOU have to stand up an AIMS. Does not date Article 4 from 2 August 2026. Does not invent a 2 August 2026 date for Annex I. |
| Regulation (EU) 2026/1744 — Digital Omnibus on AI | An amending regulation. It does not rewrite Article 113(a) for Chapters I and II. It does not rewrite Article 113(b) for Chapter V. | Does not treat an amending-regulation recital as moving Article 4 literacy to 2 August 2026. Article 113(c) Annex I remains 2 August 2027 in the original regulation. |
| ISO/IEC 42001:2023 | Best practice / standard. An AI management system standard. Not a legal substitute for the Act. | Does not treat an ISO 42001 certificate as discharging Article 4, Article 14, Article 17, or Article 26. |
| NIST AI RMF 1.0 (NIST AI 100-1, January 2023) | Guidance, not law. Voluntary US agency framework. | Does not treat a Govern/Map/Measure/Manage function as an AI Act duty. |
| European Commission AI Act page and AI literacy Q&A | Commission materials. Guidance, not the regulation. | Does not treat a Commission Q&A as rewriting Article 4 or Article 113(a). |
| This product's AI-governance surface | ShipReady recommendation: an inventory and posture the organisation recorded. Not a legal determination. | Does not discharge Article 4, Article 14, or Article 26. A named human still owns the assessment. |
What to do now
As of last verification on 9 September 2026, Article 4 AI literacy has applied since 2 February 2025 under Article 113(a). High-risk Chapter III Section 2 and Section 3 duties, including Article 14 and Article 26, sit on the original 2 August 2026 residual, except Article 6(1) corresponding obligations on 2 August 2027 under Article 113(c). The list below is operational preparation. It is not a determination that YOU have to stand up an AI management system. Walk it with counsel.
- Ask counsel whether Article 4 applies to YOU as a provider or a deployer of AI systems. This page does not run that test. Marking eu_ai_act in an obligation map is not that determination and is not a governance determination.
- If counsel finds a high-risk AI system, walk Article 14 design measures and Article 26(2) assignment of human oversight as separate articles. This product does not assign YOUR overseers.
- Do not treat ISO/IEC 42001:2023 as discharging the Act. An AIMS can operationalize governance. It is a standard, not a legal substitute. The ISO 42001 framework guide on this site is the education page under frameworks.
- The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. A dedicated AI-ownership-accountability, model-evaluation-requirements, and how-shipreadymetrics-supports-ai-governance guide is not on this site yet. Naming them is not a link.
Checklist
This is a question list, not a determination that YOU have to stand up an AIMS, and not a filing. Walk it with counsel. The EU AI Act overview on this site is the pillar page.
- Does the Act apply to YOU at all? Articles 2 and 3. This page does not run that test.
- Does Article 4 AI literacy apply? Article 113(a) is 2 February 2025, not 2 August 2026. This page does not run YOUR literacy programme.
- If high-risk, which Article 14 points, if any? This page does not pick YOUR points and does not classify YOUR system.
- If a high-risk deployer, which Article 26 points, if any, including Article 26(2) assignment of human oversight? This page does not assign YOUR overseers.
- If a high-risk provider, Article 17 QMS is a legal requirement, only if it applies. An ISO 42001 certificate does not discharge it.
- Does ISO/IEC 42001:2023 discharge the Act? No. It is a standard, not a legal substitute.
- Article 113(c) Annex I is 2 August 2027, not 2026. Document the assessment, including a not-in-scope and not-an-AIMS-required decision. This page does not keep YOUR file.
Where this shows up in ShipReady Metrics
The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). It is not in INTERNAL_TESTER_ONLY_FRAMEWORKS. The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.
If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture. The AI risk register lives with that AI-governance surface. That inventory does not determine that YOU have to stand up an AI management system, does not discharge Article 4, Article 14, or Article 26, and does not file with the AI Office or a market-surveillance authority. Marking in-scope is not a governance determination and not auto-filing. A named human still owns the assessment.
This product does not run an Article 4 literacy programme, does not assign Article 14 or Article 26(2) overseers, does not keep Article 26 logs, does not keep an Article 17 quality-management-system file, does not issue ISO 42001 certificates, does not file with the AI Office, and does not issue certifications. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking eu_ai_act in-scope is not a determination that you have to stand up an AIMS.
This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.
Primary sources (last verified 9 September 2026)
Every regulatory or guidance claim on this page is taken from one of these. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.
Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 3(56), 4, 14, 17, 26 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. Regulation (EU) 2026/1744 is an amending regulation; it does not rewrite Article 113(a) for Chapters I and II. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. The European Commission's AI Act page and AI literacy Q&A are Commission materials, not the regulation. These are not a complete world list. Not legal advice.
The EU AI Act overview on this site is the pillar page. The requirements-in-force-2026 guide on this site is the Article 113 dates page. The GPAI-requirements guide on this site is the Article 53 baseline page. The GPAI-systemic-risk guide on this site is the Article 51–55 page. The provider-vs-deployer guide on this site is the Articles 3, 16, 25 and 26 page. The EU AI Act framework guide on this site is the education page under frameworks. The ISO 42001 framework guide on this site is live. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. A dedicated AI-ownership-accountability, model-evaluation-requirements, and how-shipreadymetrics-supports-ai-governance guide is not on this site yet. Naming them is not a link.
Frequently asked questions
Is this legal advice?
No. It is a dated map of AI-governance duties distilled from Regulation (EU) 2024/1689 Articles 4, 14 and 26, with ISO/IEC 42001:2023 labelled as a standard and NIST AI RMF labelled as guidance, not the regulation. Whether those articles apply to YOU, and whether YOU have to stand up an AI management system, is a legal question for counsel on your facts. This page does not start a clock and does not file with the AI Office.
Does ISO 42001 discharge the EU AI Act?
No. ISO/IEC 42001:2023 is a voluntary management-system standard. The AI Act is Regulation (EU) 2024/1689. Running an ISO 42001 programme, or holding an ISO 42001 certificate, is not a determination that Article 4, Article 14, Article 17, or Article 26 is met. An ISO 42001 certificate is not CE marking and not an Article 43 conformity assessment. Last verified 9 September 2026.
Does this page require us to stand up an AIMS?
No. This page does not determine that YOU have to stand up an AI management system. Mapping a row is not a finding that the Act applies, that Article 4, Article 14, or Article 26 binds YOU, or that ISO/IEC 42001:2023 is required. Counsel applies those texts to YOUR facts. Last verified 9 September 2026.
Does ShipReady's AI governance surface discharge Art. 4 / Art. 14 / Art. 26?
No. Signed-in app → Compliance → AI governance holds the AI inventory and AI-governance posture the organisation recorded. That surface does not run an Article 4 literacy programme, does not assign Article 14 or Article 26(2) overseers, and does not discharge those articles. A named human still owns the assessment. Marking eu_ai_act in-scope is not a governance determination and not auto-filing.
Did Article 4 AI literacy start on 2 August 2026?
No. Article 113(a) of Regulation (EU) 2024/1689 applies Chapters I and II from 2 February 2025. Chapter I includes Article 4. That is not 2 August 2026. Article 113(c) Annex I product-embedded high-risk is 2 August 2027, not 2026. Last verified 9 September 2026.
Does marking eu_ai_act in-scope stand up an AIMS?
No. Marking the bundled framework key eu_ai_act in-scope on the obligation map is not a determination that you have to stand up an AI management system, is not a finding that Article 4, Article 14, or Article 26 applies, and is not auto-filing. Counsel applies those articles to YOUR facts. A named human still owns the assessment.
Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.