Skip to main content
Intelligence

ai

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

arXiv: Computers and SocietyInternationalHigh confidence1 min

What changed

Research has identified significant technical gaps in the application of the EU AI Act's (Regulation 2024/1689) technical obligations (Articles 8-15) when applied to generative AI systems, which were originally drafted for predictive AI. These gaps encompass critical areas such as non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness. A 'Governance-as-Code' (GaC) framework has been developed, featuring 43 machine-checkable acceptance criteria across six compliance modules, designed to integrate into CI/CD pipelines to generate Article-indexed audit evidence and address these identified challenges.

Why it matters

This research highlights a critical challenge in applying existing AI regulation to rapidly evolving generative AI technologies, revealing the need for more nuanced technical interpretations and implementation strategies. Addressing these gaps is crucial for organizations developing and deploying generative AI to ensure compliance, mitigate risks, and maintain public trust, thereby safeguarding market access and operational continuity in regulated jurisdictions.

What to watch

The EU AI Act's Articles 8-15, designed for predictive AI, present seven technical gaps when applied to generative AI systems.

Forward consideration, not a verified fact.

Reported by arXiv: Computers and Society, International. The document itself is not reproduced here.

Read the original publication