Feature 5 of 6 · AI governance
AI properly recorded Register, classification, documents.
The EU AI Act applies independently of NIS2. Many organisations already use AI without knowing exactly where. This is where you start.

What it is about
The first AI Act obligations already apply, such as AI literacy for staff and the ban on certain practices. More follow. Without an overview of the systems in use, neither the classification nor the right documentation can be settled.
What you do with it
- Build a register of your AI systems, with purpose, provider and owners.
- Have each system classified under the AI Act.
- See which documents are required per role and risk class.
- Build a management system for AI with ISO/IEC 42001.
What you get out of it
- A reliable overview of which AI is used where.
- Clear next steps instead of general uncertainty.
Part of these steps
Where the requirements come from
- AI Act Art. 4: AI literacy
- AI Act Art. 5: prohibited practices
- AI Act Art. 6 and Annex III: classification as high-risk AI
- AI Act Art. 50: transparency obligations
- ISO/IEC 42001: artificial intelligence management system
The references show where the requirements come from. They do not replace a legal assessment.
See it with your own questions.
In half an hour we show you what this feature looks like in your day-to-day work. Or check first where you stand with the quick check.
