EU AI Act
A reference for relevant AI uses, including documentation, risk management, and human oversight where the Act’s high-risk provisions apply.
Applicability depends on your role, AI use, EU connection, and applicable provisions and dates.
Discuss an assessment AI GOVERNANCE, MADE OPERATIONAL
AI governance for insurers, lenders, and health organizations. Connect systems, owners, evidence, and action.
See where AI is used, who owns the decision, and what supports it.
This arrangement is too dense to keep labels separate at the current zoom. Showing the complete record list. Zoom in or narrow the scope to return to the graph.
Every matching record is available in this list, including records collapsed in the graph.
Accountability, controls, and evidence. In one view.
THE CONNECTED CAPABILITIES
From an AI use case to the decision it supports. Follow the people, obligations and evidence in between.
Explore the capability mapStart with purpose, ownership and dependencies—not just a list of model names.
Connect requirements to policies and controls, with a recorded rationale for each relationship.
Bring policies, controls, contracts, evidence and transactions into one navigable record.
Connect risk assessment to accountable review, conditions, exceptions and the next action.
Relate supplier commitments and open questions to the AI systems and decisions that depend on them.
Connect leadership reporting to the owners, evidence gaps and follow-up work underneath it.
The public workspace is an interactive demonstration. Production workflows are planned and scoped separately; no customer documents are ingested or monitored here.
See the phased roadmapTHE SYSTEM PROFILE
Choose an AI system. Open any facet to see the people, decisions and records behind it.
A human underwriter reviews the submission summary and retains the underwriting decision.
THE GUIDED ASSESSMENT
The planned assessment combines a scoped four-to-six-week engagement with twelve months of workspace access. Scope, availability and timing are confirmed in your proposal.
Agree the scope, identify stakeholders, and gather the starting inventory.
Document systems and ownership, assess risk, and connect controls to evidence.
Review observations, agree owners and next actions, and define the workspace handover.
THE OUTPUTS, NOT MORE STEPS
Systems, purposes, owners, model context and recorded risk considerations.
Open the working previewEXAMPLE OUTPUTBounded observations, supporting records and proposed review decisions.
Open the working previewEXAMPLE OUTPUTA leadership summary with a scoped registry and source appendix.
Open the working previewEXAMPLE OUTPUTAssigned work, status, priority, due dates and the evidence needed to close it.
Open the working previewThe intended outcome is an ongoing workspace with named owners and a maintained action register; secure customer access is planned.
INDUSTRY EXAMPLES
Start with the same connected record. Shape the assessment around the decisions, workflows, and people in your organization.
Document how AI supports insurance workflows, who reviews its output, and which evidence supports the controls. Connect internal systems and vendor relationships in the same inventory.
An insurer introduces a submission assistant while another team tests a claims model.
One inventory linking use cases to owners, review evidence, and outstanding vendor questions. Consider the NAIC AI Model Bulletin alongside relevant state insurance guidance.
Hypothetical workflows, not client case studies or measured outcomes.
A STARTING POINT FOR YOUR TEAM
A supplier review. An AI rollout. A leadership question. Choose the decision you need to make.
Explore all six solutionsA new AI program lead or a lean risk team
Procurement and third-party risk teams
Insurance, lending and health operations leaders with risk reviewers
Compliance, internal assurance and customer-facing trust teams
AI product owners, security teams and business sponsors
Executives, boards and governance committees
FRAMEWORK REFERENCES
Select relevant references when agreeing the assessment scope. These are reference points, not a claim of automated coverage or a determination of your obligations.
A reference for relevant AI uses, including documentation, risk management, and human oversight where the Act’s high-risk provisions apply.
Applicability depends on your role, AI use, EU connection, and applicable provisions and dates.
A voluntary framework for structuring AI risk discussions and governance practices across the lifecycle, adaptable to different organizations, sectors, and AI use cases.
Voluntary guidance, not a legal compliance determination or endorsement.
An international management system standard for organizing AI responsibilities, policies, risk processes, and continual improvement across organizations that develop, provide, or use AI.
Reference does not establish conformity or certification. Standard text is not reproduced here.
A model bulletin describing insurer AI governance expectations, including a written AI systems program, third-party oversight, consumer risk considerations, and documentation for regulatory review.
The model is not itself law or regulation. State adoption, wording, and applicability vary.
CLEAR WORKING BOUNDARIES
A useful governance record makes its boundaries as clear as its findings.
The public demonstration uses bundled example records. Customer source handling, storage and any AI processing will be agreed before a secure pilot begins.
The assessment documents observations and proposed actions. Your team reviews the findings and retains responsibility for decisions and risk acceptance.
Legal, accounting, actuarial, and certification questions belong with appropriately qualified professionals. Sector-specific applicability should be confirmed with qualified counsel.
START A CONVERSATION
Tell me what your organization is using, where ownership or evidence is unclear, and what you want the assessment to deliver.