Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems
cs.CY, cs.AI
Submitted: 2026-09-17
Updated: 2026-09-17
Comments: Accepted at the AI4Law Workshop, ICML 2026. Camera-ready version
License: http://creativecommons.org/licenses/by/4.0/
The gist: The EU AI Act (Regulation 2024/1689) imposes technical obligations on high-risk AI providers, yet Articles 8-15 were drafted for predictive AI and leave seven technical gaps when applied to
Terminology
Abstract
The EU AI Act (Regulation 2024/1689) imposes technical obligations on high-risk AI providers, yet Articles 8-15 were drafted for predictive AI and leave seven technical gaps when applied to generative systems, spanning non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness. We deliver Governance-as-Code (GaC), a framework of 43 machine-checkable acceptance criteria across six compliance modules that run in a CI/CD pipeline and emit Article-indexed audit evidence, and we show the actual Rego policy code rather than merely describing it. Our central commitment is that the Act's open-textured standards ("appropriate levels," "possible biases") become declared, auditable numbers: robustness thresholds are derived from the provider's documented baseline and a state-of-the-art floor, and framing bias is collapsed into eight measurable proxies tested by counterfactual demographic probing. We also correct who owes what, since under Article 25 and Chapter V a downstream deployer relies on the upstream provider's Article 53 training-data summary and documents only the layers it controls, so GaC verifies that summary rather than demanding per-sample documentation the deployer never had. We validate on two enterprise deployments, a high-risk advisory chatbot and a limited-risk content generator, benchmarking against a manual expert audit rather than documentation artifacts that were never designed to enforce compliance. GaC reproduces all of the manual audit's findings, including three penalty-triggering violations, while cutting audit labor by roughly 75%.
Sources
- On the Opportunities and Risks of Foundation Models
- Assessing High-Risk AI Systems under the EU AI Act: From Legal Requirements to Technical Verification
- Bathtubs, Boundaries, and Sandboxes: AI Regulatory Learning under Legal Uncertainty
- BOLD: Dataset and Metrics for Measuring Biases in Open-Ended Language Generation
- Not what you've signed up for: Compromising Real-World LLM-Integrated Applications with Indirect Prompt Injection
- Runtime Governance for AI Agents: Policies on Paths
- Holistic Evaluation of Language Models
- Computational Compliance for AI Regulation: Blueprint for a New Research Domain
- Model Cards for Model Reporting
- Towards Assuring EU AI Act Compliance and Adversarial Robustness of LLMs
- Governance-as-a-Service: A Multi-Agent Framework for AI System Compliance and Policy Enforcement
- Robustness and Cybersecurity in the EU Artificial Intelligence Act
- AI Cards: Towards an Applied Framework for Machine-Readable AI and Risk Documentation Inspired by the EU AI Act
- A Robust Governance for the AI Act: AI Office, AI Board, Scientific Panel, and National Authorities
- Demystifying the Draft EU Artificial Intelligence Act
Related papers
- Reasoning Enhances Robustness to Prompt Injection in LLM-Based Consensus
- Generative AI Purpose-built for Social and Mental Health: A Real-World Pilot
- PersonaMem-v3: Toward Omni-Platform Personal Intelligence for Holistic User Understanding, Recommendation, and Agentic Tasks
- What is an intelligent system?
- AI University: An LLM-Powered Learning Assistant for Engineering---A Finite Element Method Case Study
- Generative AI Use in Entrepreneurship: An Integrative Review and an Empowerment-Entrapment Framework