AI Act posture: operational β risk management (Article 9) and logging (Article 12) are live and producing audit-grade evidence.
Risk-management cadence and logging are operational. Next focus: turn on the human-oversight loop (Article 14) and at least one transparency primitive (Article 13).
This score corresponds to operational AI Act posture: Article 9 continuous risk-management cadence and Article 12 logging are live, with signed Decision Dossiers as the audit-grade event log. Deployer-grade (Articles 13 & 14) is one human-oversight loop and one transparency primitive away.
Article 12 requires automated logs of high-risk AI system events. Signed dossier volume is the operational evidence that logging is actually happening β not just documented.
Next move β 128 signed dossiers/month is operational. Next move is breadth: add at least one regulated workflow (treasury movement, healthcare authorization, or AI-agent tool call) so the dossier mix proves governance, not just retries.
Article 9 mandates a continuous risk management process across the AI system lifecycle. Coverage of high-blast-radius actions is the auditable surface that proves risk identification reaches the actions a regulator cares about.
Next move β ~17% high-blast-radius coverage is on the path. The next layer is regulated workflows that buyers ask about by name (treasury, refunds above a threshold, AI agent tool calls). Add them to the evaluator.
Article 16/17 require a documented quality-management system mapped to the system's purpose. Verified policy packs are the encoded conformity layer that a conformity assessment can reference by hash, not by PDF.
Next move β Policy coverage is Strong. Next move is contributing one customized pack back so prospects see attribution as a marketing-acquisition surface.
Article 14 requires effective oversight by natural persons during the period the AI system is in use. Approval pings are the measurable human-in-the-loop surface that satisfies oversight in production β not just in onboarding.
Next move β 18 approval pings/month is the start of an override loop. Each ping you don't route is a π-thread audit gap. Route at least one more decision type (vendor onboarding, refund, or contract change) through the same surface.
Article 13 + 61 require providers to make information available to deployers and to monitor performance after launch. Public verify links, audit rooms, and signed proof are the three primitives that make this practical instead of paperwork.
Next move β Missing: private signing keys. Each one removes a category of question a reviewer can ask. The cheapest next move is enabling private signing keys β minutes of work, an immediate posture lift.
Route more human overrides through Slack Approval Ping.
- Monthly dossiers
- 128
- High-blast-radius dossiers
- 22
- Verified policy packs
- 3
- Approval pings / month
- 18
- Audit room enabled
- Yes
- Public verify links
- Yes
- Private signing keys
- No