Skip to main content

AI governance (EU AI Act)

Every agent, MCP server and LLM gateway on the platform now carries a governance record: a risk classification under the EU AI Act, the people accountable for it, links to its compliance documents, and a lifecycle state that runs beside its operational status. Together the records form a tenant-wide AI register. On top of that sit serious-incident tracking (Art. 73) and the Art. 50 transparency controls that the relay applies to agent replies. The platform’s job is to help you record and evidence what the Act asks of you: who decided what, when, on which answers, with which documents. It does not make you compliant, it does not take legal decisions for you, and it does not file anything with an authority. The tier it shows is derived from the answers your people give and sign.
Nothing on this page or in the product is legal advice. Article references are there so your compliance lead can check the reasoning, not to replace it.

What a governance record holds

Every change to a record (a classification, a new owner, an approved document, a state change) is written to the governance timeline and to the audit hash chain, so the history can be shown later and shown to be unaltered.

Where things live

The second signature on a high-risk classification is not in the Approvals queue. It is the Approve classification button on the system’s Classification page. The register’s Pending approval tile and the approvalPending flag tell you which systems are waiting for one.
Everything in the UI is also available through the API. Through the gateway the registry is under /registry, so the register is:

What you see on day one after upgrading

The upgrade creates the governance tables and the register; it does not classify anything or change how traffic flows. Expect this:
Nothing blocks traffic. The relay’s per-request check (tenant freeze, kill switch, authorisation, subscription, health) does not look at the risk tier, the governance state or readiness. An agent in Draft keeps serving exactly as it did before the upgrade. Governance only stops traffic through the kill switch: when someone suspends a system that is in service, or when a system in service is classified Prohibited. Both show to callers as Sink agent is frozen.
That makes the first weeks safe to work through at your own pace. It also means the register only describes reality once people have filled it in.

A suggested first week

1

Give people the right permissions

Decide who classifies (agent owners), who gives second signatures (a compliance lead or a second engineer), who edits the governance policy (a tenant administrator), and who exports evidence (anyone with audit read). See Permissions below.
2

Confirm or assign owners

In Govern › AI register, the Accountable owner column marks every inferred owner as Unconfirmed. Open each system’s Governance › Accountability page and either press Confirm owner or name someone else. Assign owners to LLM gateways, which have none. For anything you expect to be high-risk, add a deputy and at least one oversight person with an AI literacy date.
3

Classify, person-facing and decision-making systems first

Tick Unclassified only in the register and work down the list. Each classification takes a few minutes in the wizard on the system’s Classification page. A high-risk result needs a second person to approve it. MCP servers and gateways inherit the highest tier of the agents using them, so classify agents before their tools.
4

Review the governance policy

Open Manage › Governance policy. Keep the gates on Warn while you classify; switch high-risk tiers to Block once their records are complete, so a gap stops a new version from being registered instead of only warning about it. Adjust review intervals if your own process is stricter than the defaults.
5

Set up a regular check

The governance monitor templates (review due, orphaned owner, unclassified agent, stale attestation, incident report due) cannot be enabled in this release, so nothing reminds you of gaps. Put a recurring check in someone’s calendar instead: the register tiles and filters (Review overdue, Owner unconfirmed, Unclassified only, Reassessment pending) and the Incidents page tiles (Overdue, Due in 7 days, Awaiting confirmation). For high-risk agents, also create a monitor under Observe › Monitors whose filter names the agent: that is what the post-market monitoring obligation looks for. See Governance checks.
6

Turn on disclosure for person-facing agents

For every agent people talk to, open Classification › Transparency (Art. 50), turn the disclosure on and choose the text. Then check that each of your channel integrations actually shows the notice — see AI Disclosure Notice.
7

Check that notices reach people

Retirement notices to dependants and monitor alerts go through notification-service. Make sure it is enabled in your values file and that SMTP is configured — see Configuration.

Permissions

Governance uses the permissions you already have; there is no separate governance permission. For per-system actions the entity follows the subject: agent governance is checked against Registry, MCP server governance against MCP registry, and LLM gateway governance against LLM gateway. Tenant-wide pages:
There are no owner-only actions. Anyone with Write on the entity can classify, approve, assign or retire, whether or not they are the accountable owner. The platform enforces only person-level separation: the second signature on a classification, retirement or suspension lift must come from a different person from the one who asked, and the deputy owner must differ from the owner. The one place assignments restrict who can act is human review on high-risk agents in the relay — see Human oversight in the relay.
The Approvals menu item itself is shown to people with access to human review requests; to use its Governance tab they also need Registry Read, and Registry Write to decide.

Dates in the Act

For context only — your obligations depend on your role and systems, and the timetable has changed once already.
Track the latest guidance and legislative updates yourself. The platform does not change its behaviour by date: obligations show as applicable as soon as a system is classified into a tier that carries them.

What the platform does not do

  • Readiness is not enforced at runtime. Unmet obligations are checked only when someone registers a new agent version, reactivates an agent, publishes to the marketplace or puts a system into service. A system that later loses its owner, lets an attestation lapse or misses its review date keeps relaying.
  • Monitors and alerts never suspend anything. They tell people; a person decides.
  • Block mode refuses registry actions, never traffic. It stops a version being registered or a system being put into service; it does not stop requests to a system that is already running.
  • Documents are links, not uploads. The platform stores the URL, the metadata you enter and the SHA-256 you supply. It never fetches the document, so it cannot verify the hash or notice that the file changed.
  • No transitional (Art. 111) logic. The placed on the market date is recorded and exported, but it does not change the tier, the obligations or any deadline.
  • Marking is metadata. Synthetic content marking adds machine-readable metadata and response headers. It does not watermark text, images or audio, and does not embed a C2PA manifest in files.
  • Nothing is filed for you. Incident reports, EU database registration and declarations of conformity are made by you, outside the platform; the record holds your reference to them.
  • Suspension does not notify anyone. Dependants are told when a retirement is opened for a corrective reason and when it completes, not when a system is suspended.
  • Retention floors do not delete data. They are recorded commitments that hold evidence at least that long; they do not schedule deletion.

Next

Classification

Risk tiers, the wizard, second signatures and inherited tiers.

Governance record

Owners, oversight, documents, readiness and Art. 50 transparency.

Lifecycle and policy

States, suspension, retirement and the tenant governance policy.

Incidents and evidence

Serious incidents, the register, exports and the evidence pack.