Skip to main content
1 min readKnowledge Resource

Knowledge Resource · Open access

Research Summary: Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

Original authors
Attribution requires verification
Original source
arXiv — Computers and Society
Summary & Analysis prepared by
Aziz Shuaib Ausi
Resource type
Research Summary / Knowledge Resource
Resource published on AZIZ OS
18 September 2026
Reading time
1 min
Publication type
Knowledge Resource
Availability
Open access
About this Summary & Analysis

AZIZ OS provides independently prepared summaries and analytical interpretations of externally published research and knowledge sources. The underlying works remain attributable to their original authors and rights holders. This resource is intended to improve accessibility and understanding and does not replace the original publication.

Checking access…

Research has identified significant technical gaps in the application of the EU AI Act's (Regulation 2024/1689) technical obligations (Articles 8-15) when applied to generative AI systems, which were originally drafted for predictive AI. These gaps encompass critical areas such as non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness. A 'Governance-as-Code' (GaC) framework has been developed, featuring 43 machine-checkable acceptance criteria across six compliance modules, designed to integrate into CI/CD pipelines to generate Article-indexed audit evidence and address these identified challenges.

Why it matters

This research highlights a critical challenge in applying existing AI regulation to rapidly evolving generative AI technologies, revealing the need for more nuanced technical interpretations and implementation strategies. Addressing these gaps is crucial for organizations developing and deploying generative AI to ensure compliance, mitigate risks, and maintain public trust, thereby safeguarding market access and operational continuity in regulated jurisdictions.

Key insights

  • The EU AI Act's Articles 8-15, designed for predictive AI, present seven technical gaps when applied to generative AI systems.
  • Specific gaps include challenges in non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness for generative AI.
  • A 'Governance-as-Code' (GaC) framework has been proposed to translate the Act's technical requirements into executable compliance pipelines.
  • The GaC framework includes 43 machine-checkable acceptance criteria organized into six compliance modules.
  • This framework is designed to run in a CI/CD pipeline and generate Article-indexed audit evidence, utilizing Rego policy code.
  • The core commitment of GaC is to operationalize the Act's open-textured standards, such as "appropriate levels" and "possible bias."

Source

arXiv — Computers and Society — https://arxiv.org/abs/2609.20016

Citation

Cite the original work (APA 7)

The original source is authoritative for this citation. Cite the source publication directly — this attribution is pending verification. Open the original source.

Verification

This is an authenticated AZIZ OS resource record.

Verification ID
ASA-EXE-2026-00717
Version
v1.0 · r0
Issued
18 September 2026
Resource prepared by
Aziz Shuaib Ausi
Resource status
Research Summary / Knowledge Resource
Underlying work
Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems
Original authors
Attribution requires verification
Original source
arXiv — Computers and Society
Provenance status
Attribution requires verification
Rights
Underlying publication rights remain with the respective copyright holder(s). Refer to the original source for authoritative publication and licensing information.

This verification confirms the AZIZ OS resource record and its documented provenance. It does not establish authorship of the underlying external work.

Verify this resource