Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems
Rudrendu Kumar Paul, Sourav Nandy
Abstract
The EU AI Act (Regulation 2024/1689) imposes technical obligations on high-risk AI providers, yet Articles 8-15 were drafted for predictive AI and leave seven technical gaps when applied to generative systems, spanning non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness. We deliver Governance-as-Code (GaC), a framework of 43 machine-checkable acceptance criteria across six compliance modules that run in a CI/CD pipeline and emit Article-indexed audit evidence, and we show the actual Rego policy code rather than merely describing it. Our central commitment is that the Act's open-textured standards ("appropriate levels," "possible biases") become declared, auditable numbers: robustness thresholds are derived from the provider's documented baseline and a state-of-the-art floor, and framing bias is collapsed into eight measurable proxies tested by counterfactual demographic probing. We also correct who owes what, since under Article 25 and Chapter V a downstream deployer relies on the upstream provider's Article 53 training-data summary and documents only the layers it controls, so GaC verifies that summary rather than demanding per-sample documentation the deployer never had. We validate on two enterprise deployments, a high-risk advisory chatbot and a limited-risk content generator, benchmarking against a manual expert audit rather than documentation artifacts that were never designed to enforce compliance. GaC reproduces all of the manual audit's findings, including three penalty-triggering violations, while cutting audit labor by roughly 75%.
Create a lesson
Related papers
Harnessing Generative UI for Education: Tailored Learning Interactives
Alisa Kovshov, Anisha Choudhury, Anna Iurchenko et al.
When Does the Public Become Suspicious of Bots? Demand-Side Evidence from Botometer Query Logs
Tuğrulcan Elmas
Welfare-Opaque Income: Taxation under AI-Agent Delegation
Yukun Zhang, Kemu Xu, Yishen Chen
Detecting Deceptive Recruitment: A Signal-theoretic Machine Learning Framework for Early Identification of Labour Exploitation
Sajid Siraj, Mahnaz Hosseinzadeh, Amin Vafadarnikjoo et al.
Who Decides? Agency and Legitimacy in Digital Educational Systems
Eriam Schaffter, Ahmed Bounekkar
Funding the runners-up beats a golden ticket
Haining Wang