EU AI Act
Evidence for reviewing your AI use
When reviewing AI systems, organisations need to trace applicable requirements, responsibilities and relevant events. On integrated paths, NomOS records applied policies, responsibilities and decisions while the work happens, so the evidence does not have to be rebuilt before an audit.
Context: a practitioner's perspective, not legal advice. Which obligations apply depends on the AI system, its purpose and your role as provider or deployer.
What the AI Act requires, in brief.
The AI Act classifies AI systems by risk. The most extensive requirements apply to high-risk systems: among them risk management, data governance, technical documentation, automatic event recording (Art. 12), human oversight and transparency. Further requirements address AI literacy and transparency for specified AI systems and content.
Why record-keeping is more than technical logging: Art. 12 EU AI Act in practice. Primary source: Regulation (EU) 2024/1689 on EUR-Lex.
What NomOS contributes in daily operations.
- Configured records capture agreed events on integrated paths. Coverage, signing and retention are defined for the installation. The records can be exported for review and can support record-keeping and traceability where Art. 12 applies to your system.
- The applicable policy set per room records policies with their version and validity. Technical enforcement depends on the integrated execution path.
- Approval paths involve responsible people when an action requires human oversight: escalate instead of silently executing, with a documented decision.
- Owners and roles per room capture responsibility for impact-graph content and time-limited exceptions.
Whether the AI Act applies to a particular system depends on its purpose, risk classification and the role of your organisation. NomOS provides operational evidence; the legal assessment remains your responsibility.
What stays with you.
NomOS replaces neither the classification of your AI systems nor the further duties of providers and deployers, such as risk management, conformity assessment or legal advice. NomOS contributes policies and records for the integrated paths. Whether the captured information covers your requirements is part of the installation review.
What this looks like per sector, from FINMA to MDR: AI governance for regulated industries.
Test it on two live workflows.
During the 30-day pilot, we apply NomOS to two workflows from your day-to-day operations and review the resulting evidence with you.