Operational guidance, not legal advice. This page distills named public sources (regulator guidance and industry practice). It is not a legal determination, not a notification decision, and not a substitute for your counsel, insurer, or a retained DFIR firm. Verify applicability and current deadlines for your facts and jurisdiction.

How does ShipReady Metrics support AI governance?

Updated

It holds an org-authored AI inventory, an AI risk register, an obligation map, policies, and collected evidence with a human review overlay. It does not determine that Regulation (EU) 2024/1689 applies to you. Not legal advice. Compliance is not bought with a subscription.

ShipReady Metrics AI-governance capability, last verified 10 September 2026 against Articles 4, 9, 11, 12, 14, 17, 26, 49, 53, 55, 71, 73 and 113 of Regulation (EU) 2024/1689 (OJ L 2024/1689, 12.7.2024) for the duties being mapped. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 is guidance, not law. This page is not legal advice, not a filing, and does not start a clock. It does not determine that the Act applies to YOU, that YOU are a provider or a deployer, or that YOUR system is high-risk. This product does not file with the AI Office, does not register in the EU database, does not issue certifications, and does not affix CE marks.

This is a capability map, not a compliance claim

Audience: an evaluator, compliance owner, or CISO deciding whether this product helps with AI governance and, more usefully, where it stops. This page is not legal advice. It does not start a clock. Nothing described here is a determination that the Act applies, that YOU are a provider or a deployer, or that YOUR system is high-risk. Every capability below is a ShipReadyMetrics capability; every duty named beside it is a legal requirement only if it applies to you.

The regulatory context is Regulation (EU) 2024/1689 of 13 June 2024, OJ L 2024/1689, 12.7.2024. ELI: http://data.europa.eu/eli/reg/2024/1689/oj. ISO/IEC 42001:2023 is a management-system standard, not a legal substitute for the Act. This page deliberately reads as a product map rather than a pitch: an AI-governance tool that oversells is worse than none, because it converts an unknown gap into a false pass. Last verified 10 September 2026. Not legal advice.

  • Four kinds of text appear on this page, and they are labelled: legal requirements of 2024/1689 (only if they apply); Commission and AI Office materials, which are guidance, not the regulation; ISO/IEC 42001:2023 and NIST AI RMF 1.0, which are a standard and guidance respectively, not law; and ShipReadyMetrics capability, which is a product description and never a legal determination.
  • Compliance is not bought with a subscription. No product on the market can make Article 9, Article 11, Article 14, or Article 26 true of an organisation, because those articles are about what the organisation actually does. A tool can make the state of that work visible, and can make gaps hard to ignore.
  • The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The how-shipreadymetrics-builds-ai-inventory guide on this site is the inventory page. The how-shipreadymetrics-tracks-ai-risk guide on this site is the risk-register page. The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the evidence page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

The surfaces, and what each one actually is

The path is: signed-in app → Compliance → AI governance. The AI inventory and the AI risk register both live there. The obligation map, the policies library, and evidence collection are shared compliance surfaces that the AI work feeds into. The cyber risk register lives under Security and is a different register. Last verified 10 September 2026. Not legal advice.

Product surfaces against duties (ShipReadyMetrics capability, not a conformity determination; not legal advice)
SurfaceWhat it doesDuty it relates toKind of text
AI inventoryAn org-authored register: an administrator records each AI system with its declared risk tier, declared use case, provider or deployer posture, external provider name, GPAI flags, accountable owner, and which governance artefacts exist. A declared tier is reconciled against the tier the declared use case implies, so an under-declared system is flagged for review. A blank use case reads as needing review, never as a guessed tier.Supports the knowledge that Articles 6, 9 to 15, 26 and 49 all presuppose, and ISO/IEC 42001:2023 register practice.ShipReadyMetrics capability. Not a classification under Article 6, not an Article 49 registration, and not a determination that the Act applies to YOU.
AI risk registerThe AI-specific risks an Article 9 or ISO/IEC 42001:2023 assessment would have to consider, each shown against whether the governance obligations that would mitigate it are met across the registered high-risk inventory. Where there is no coverage, the row reads not verified rather than mitigated.Relates to Article 9 for high-risk systems and Article 55 for systemic-risk GPAI models, only if they apply, and to ISO/IEC 42001:2023 risk practice.ShipReadyMetrics capability. Not an Article 9 risk-management system and not a finding that a risk is mitigated in law.
Obligation mapThe list of frameworks the organisation has marked in-scope for itself, including the bundled eu_ai_act key. That key's control-set is a starter subset, illustrative, to be tailored by a compliance owner.Relates to nothing in the Act directly. It is a self-declared scope statement.ShipReadyMetrics capability. Marking eu_ai_act in-scope is not applicability, is not a classification, and is not auto-filing.
Policies librarySomewhere for the AI policy, the responsible-use policy, and the surrounding documents to live, be owned, and be dated.Relates to Article 17 quality-management documentation and ISO/IEC 42001:2023 Annex A policies for AI, only if they apply.ShipReadyMetrics capability. Holding a policy is not an Article 17 quality-management system.
Evidence collection and the evidence-review overlayArtefacts the organisation supplies, plus a human review step: a reviewer can accept a manually supplied row as meeting a control. That acceptance is recorded as a human judgement with a reviewer attached.Relates to the documentation and record duties in Articles 11, 12, 17, 18 and 19, only if they apply.ShipReadyMetrics capability. Not a records-retention system of record, not forensic chain of custody, and not a regulator filing pack.
Exports, including a CycloneDX AI bill of materialsThe inventory and governance posture in machine-readable form, for any CycloneDX-consuming tool, plus document exports.Relates to nothing the Act mandates in that format. It is portability.ShipReadyMetrics capability. An AI-BOM export is not an Annex VIII submission and not an Annex IV dossier.
ShipReady PassportA shareable snapshot of recorded posture, aimed at a customer's diligence questionnaire rather than a regulator.Relates to commercial diligence practice, not to any article.ShipReadyMetrics capability. Not legal conformity, not a certificate, not CE marking.
AI-authored code reportingEngineering-side measurement of how much code is AI-authored, with an AI return-on-investment view and per-committer metering.Relates to engineering governance and secure-SDLC practice. No article of 2024/1689 requires it.ShipReadyMetrics capability and industry practice. Explicitly not an AI Act legal requirement. The how-shipreadymetrics-tracks-ai-generated-code guide on this site is that page.

What it does not do

This section exists because the honest limits are the part of a product map that decides whether the rest can be trusted. None of the following is on a roadmap qualifier — they are things this product does not do. Last verified 10 September 2026. Not legal advice.

  • It does not determine that Regulation (EU) 2024/1689 applies to you, that you are a provider or a deployer, or that any system of yours is high-risk. Those are legal questions for counsel on your facts.
  • It does not file with the AI Office, does not file with a market-surveillance authority, and does not start any reporting clock. Recording an incident is not an Article 73 report and is not an Article 55(1)(c) filing.
  • It does not register in the EU database referred to in Article 71, which the Commission sets up and maintains. The euDatabaseRegistered field records an attestation the organisation entered, never a filing.
  • It does not issue certifications, does not affix CE marks, is not a notified body, and does not perform an Article 43 conformity assessment. An ISO/IEC 42001:2023 certificate comes from an accredited certification body, not from a dashboard.
  • It does not discover every model your organisation uses. The inventory is org-authored. Shadow-AI signals can propose a system, but the risk tier of a proposal floors at minimal and the use case is left blank, so a human still classifies it.
  • It does not keep your statutory records for you, is not forensic chain of custody, and is not a regulator filing pack. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page.
  • It does not run an Article 4 AI literacy programme and does not assign Article 14 or Article 26(2) overseers. An owner field records who is accountable; it is not an oversight measure.
  • It does not give legal advice, and a green surface is not a legal opinion. A named human still owns the assessment.

Legal requirement versus guidance versus ShipReady capability

The table below labels each text so that a product claim is never read as a legal one. Last verified 10 September 2026. Not legal advice.

Statute versus standard versus guidance versus product (not a ranking; not legal advice; last verified 10 September 2026)
TextWhat it isWhat this page does not do
Regulation (EU) 2024/1689 Articles 9, 11, 12, 14, 17, 26 and 49Legal requirements — risk management, technical documentation, logging, human oversight, quality management, deployer duties, and registration, each only if it applies.Does not claim any product surface discharges them and does not determine that they bind YOU.
Regulation (EU) 2024/1689 Articles 53 and 55Legal requirements — the GPAI baseline and the systemic-risk track, in force from 2 August 2025 under Article 113(b), except Article 101.Does not designate YOUR model and does not file with the AI Office.
ISO/IEC 42001:2023Best practice / standard. An AI management system standard the product's surfaces can help operationalise. Not a legal substitute for the Act.Does not issue, imply, or substitute for an ISO 42001 certificate from an accredited certification body.
NIST AI RMF 1.0 (NIST AI 100-1, January 2023)Guidance, not law. Voluntary US agency framework.Does not treat a Govern, Map, Measure or Manage activity as an AI Act duty.
European Commission AI Act pages and AI Office materialsCommission materials. Guidance, not the regulation.Does not treat Commission material as rewriting an article or a date.
Every surface described on this pageShipReadyMetrics capability. A description of shipped behaviour over facts the organisation recorded.Not legal advice, not a conformity determination, not compliance-by-purchase. A named human still owns the assessment.

What to do now

As of last verification on 10 September 2026, the high-risk duties this page maps against sit on the Article 113 residual application of 2 August 2026, Chapter V GPAI duties have applied since 2 August 2025 under Article 113(b) except Article 101, and Article 113(c) keeps Article 6(1) and the corresponding obligations on 2 August 2027. The list below is operational preparation, not a determination that any of it binds YOU.

  • Evaluate the inventory first. Everything else in the product hangs off it, and an inventory nobody maintains makes every other surface confidently wrong.
  • Ask what each surface refuses to say. Not verified rather than a fabricated pass, needs review rather than a guessed tier, and a floored risk tier on a proposed system are the design decisions worth checking in any tool you evaluate.
  • Keep counsel in the loop on scope. Marking eu_ai_act in-scope is a statement the organisation makes about itself; it is not an applicability determination and no product can make it one.
  • The how-shipreadymetrics-builds-ai-inventory guide on this site is the inventory page, including its limits. The how-shipreadymetrics-tracks-ai-risk guide on this site is the risk-register page. The how-shipreadymetrics-produces-ai-governance-evidence guide on this site is the evidence page. The readiness-checklist guide on this site is the deadline-anchored Article 113 self-assessment page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Checklist

This is a question list for evaluating an AI-governance tool — this one included. It is not a determination that the Act applies to YOU. Walk the legal questions with counsel.

  • Does the tool claim to determine that the Act applies to you? If it does, that claim is wrong, whoever makes it.
  • Is the inventory org-authored or discovered? If a vendor claims full auto-discovery of every model in use, ask what happens to a model called through an unremarkable HTTPS request.
  • What does the tool say when it does not know? Not verified is an honest answer; a pass with no underlying facts is not.
  • Does a green control mean a legal duty is met? No. It means someone recorded something and, where a review overlay exists, that a human accepted it.
  • Does the tool file anything with a regulator? This one does not — no AI Office filing, no market-surveillance report, no EU database registration.
  • Does it issue certifications or CE marks? No. Certification comes from an accredited certification body, and CE marking follows a conformity assessment, not a dashboard.
  • Who is the named human accountable for each judgement the tool records? If the answer is the tool, that is the finding.
  • Document the evaluation, including what the tool cannot do. This page does not keep YOUR file.

Where this shows up in ShipReady Metrics

The bundled framework key eu_ai_act is customer-visible. Its version label is Regulation (EU) 2024/1689 high-risk obligations (starter subset). The control-set is a starter subset, illustrative, to be tailored by a compliance owner; not legal advice; not a conformity determination; not CE marking. Readiness is not compliance and not an EU-database registration.

If you already have a session: signed-in app → Compliance → AI governance holds the AI inventory and the AI risk register. The obligation map lists frameworks the organisation has marked in-scope, including eu_ai_act if that mark is set. Marking in-scope is not applicability. A named human still owns the assessment.

This product does not file with the AI Office, does not register in the EU database, does not issue certifications, does not affix CE marks, and is not a notified body. ShipReady Passport is a shareable posture snapshot, not legal conformity. The cyber risk register lives under Security and is a different register from the AI risk register.

This page does not document a public demo URL. There is no public EU AI Act demo path. This product does not start a clock.

Primary sources (last verified 10 September 2026)

Every regulatory or guidance claim on this page is taken from one of these. Product claims describe shipped behaviour. If a later revision of a source changes the rule, the date above is how you can see we have not re-checked yet.

Regulation (EU) 2024/1689 of 13 June 2024 (Artificial Intelligence Act), Articles 4, 6, 9, 11, 12, 14, 17, 26, 43, 47, 49, 53, 55, 71, 73 and 113, is a legal requirement only if it applies. Entry into force 1 August 2024. Article 113(a) 2 February 2025; Article 113(b) 2 August 2025 except Article 101; general application 2 August 2026; Article 113(c) Article 6(1) from 2 August 2027. ISO/IEC 42001:2023 is a management-system standard, not the regulation. NIST AI RMF 1.0 (NIST AI 100-1, January 2023) is guidance, not law. Commission AI Act pages and AI Office materials are Commission materials — guidance, not the regulation. These are not a complete world list. Not legal advice.

The EU AI Act overview on this site is the pillar page. The AI-governance-requirements guide on this site is the Articles 4, 14, 26 and ISO 42001 page. The AI-risk-management-requirements guide on this site is the Articles 9 and 55 page. The ai-inventory-requirements guide on this site is the Articles 49 and 71 and Annex VIII page. The evidence-retention-checklist guide on this site is the Articles 12, 18 and 19 retention-matrix page. The AI-audit-evidence guide on this site is the evidence-request-by-role page. A dedicated AI-cybersecurity-requirements and model-evaluation-requirements guide is not on this site yet. Naming them is not a link.

Frequently asked questions

Is this legal advice?

No. It is a dated description of shipped product behaviour, set beside the duties in Regulation (EU) 2024/1689 and ISO/IEC 42001:2023 that the behaviour relates to. Whether the Act applies to YOU, which role YOU hold, and whether any duty is met are legal questions for counsel on your facts. A product surface is never a legal determination, and this page does not start a clock.

Does buying ShipReady Metrics make us EU AI Act compliant?

No. Compliance is not bought with a subscription. Articles 9, 11, 14, 17 and 26 of Regulation (EU) 2024/1689 are about what an organisation actually does with its systems, and no tool can make them true. This product records facts the organisation entered, makes gaps visible, and refuses to report a pass where nothing was assessed. A named human still owns every judgement it holds.

Does ShipReady file with the AI Office or register in the EU database?

No. This product does not file with the AI Office, does not file with a market-surveillance authority, and does not register anything in the EU database referred to in Article 71 of Regulation (EU) 2024/1689, which the Commission sets up and maintains. Recording an incident is not an Article 73 report; recording an EU-database attestation is not a registration. It does not start a clock.

Does a green control mean the legal duty is met?

No. A control reads as met because the organisation recorded an artefact, or because a human reviewer accepted a manually supplied row. That is a recorded human judgement about the organisation's own facts. It is not a conformity determination, not CE marking, not an Article 43 conformity assessment, and not a legal opinion. Where nothing has been assessed, the surfaces read not verified rather than pass.

Does ShipReady replace ISO 42001 certification?

No. ISO/IEC 42001:2023 certification comes from an accredited certification body after an audit of an AI management system against the standard. This product can help operationalise parts of that management system, and can hold the records an auditor asks for. It does not issue certificates, is not a certification body, and holding it is not a certificate. Last verified 10 September 2026.

Published by ShipReady Metrics, an evidence-based technology and compliance intelligence platform. This guide is educational and vendor-neutral.