AI Governance in Practice: Preparing for the EU AI Act
Deepika Rao
Director, AI Governance, RippleCode
With the EU AI Act's obligations phasing in, enterprises deploying AI in or into Europe need governance that stands up to regulatory scrutiny. Most of what's required is simply good engineering discipline, formalized.
Know your risk tier
The Act classifies systems by risk. Most enterprise deployments — copilots, document processing, forecasting — fall into limited or minimal risk with transparency obligations. High-risk categories (hiring, credit, essential services) carry substantial requirements: risk management systems, data governance, human oversight, logging and conformity assessment.
The documentation backbone
- A model inventory: every AI system, its purpose, provider, risk tier and owner
- Data lineage for training and retrieval sources
- Evaluation results with defined acceptance criteria
- Human oversight procedures and escalation paths
- Incident logging and response procedures
Build governance into delivery, not around it
Bolted-on compliance fails. We embed governance artifacts into the delivery pipeline: evaluation suites run in CI, model cards generated from deployment metadata, audit logs captured by default. Compliance becomes a byproduct of shipping, not a quarterly scramble.
The upside nobody mentions
Clients with strong AI governance ship faster, not slower. Clear ownership, evaluation gates and documented behavior reduce the internal fear that stalls AI programs. Governance done right is an accelerant.