What the Act Now Asks For
The EU AI Act has been rewritten, and the Commission has published draft guidelines for high-risk AI systems. For any organisation with EU operations or EU market exposure, the practical consequence is a clear standard of proof to prepare for.
High-risk classification brings concrete documentation and audit-trail obligations. The system is described in operation: how it processes inputs, where decisions are made, where human oversight sits and what record exists when something goes wrong. The question regulators ask goes beyond whether you have a governance policy. It is whether you can show how your AI operates inside your processes.
Teams that already have governance frameworks on paper are well placed, and the piece to add is the evidence layer beneath them. A policy describes what should happen, and an audit asks for the record of what did. Closing that gap starts with making it visible, and there is time to do it deliberately.
What Evidence Means Under the Act
High-risk obligations centre on one principle: a system you can describe in operation is a system you can evidence. Documentation under the Act is an account of how the system behaves in production, maintained over its lifecycle and available for inspection.
That makes the distinction between policy and evidence useful. A compliance policy states that human oversight exists. An auditable record shows where the human gate sits in the process, what information the human received, what they decided and when.
The same applies to the audit trail. Regulators and auditors want the executed record: the decision points, the data movements, the control checkpoints and the human interventions, captured as they happened. Most organisations have produced volumes of procedure documents and can build the operational record on top of them.
To produce evidence systematically rather than under audit pressure, the process itself is written down first: made explicit and connected to the obligations it carries. That is the work our method is built around, and it prepares you for everything an auditor will ask to see.
Where the Governance Gap Closes
IBM has warned that “the governance gap is widening as deployment speed outpaces control mechanisms.” The gap is a control gap, and a control needs something concrete to attach to.
When an AI system operates inside a written-down workflow, there is a surface for a control to sit on and a record for evidence to reference. The disclosure obligations that fall on a Compliance Manager and the control effectiveness questions that fall on a Risk Manager rely on the same foundation: an explicit process to evidence against. With that in place, the three lines of defence look at the same version of reality and can produce the proof an auditor expects.
Deployment speed then becomes an asset, because each new deployment lands in a process that is already understood.
The Evidence Layer
IGX360 Insights makes the process knowledge you hold explicit and visible. It works alongside your governance framework and your process repository, adding the evidence layer those frameworks assume.
Three capabilities do the work. The compliance lens maps each process step to the regulatory obligation it carries, so an obligation becomes a marker attached to a specific point in a live process. The evidence map and compliance lens link each control to a documented process record, so that “we maintain human oversight” can be followed to the gate, the decision and the timestamp. Provenance and confidence scoring then show where each record came from and how reliable it is.
The effect is to turn abstract obligation into demonstrable control. An auditor asking how a high-risk system operates receives the process, the obligations mapped against it and the records behind the controls.
To be precise: IGX360 Insights does not make you compliant and does not interpret the Act on your behalf. That remains the work of your legal and compliance functions. What it provides is the evidence they can rely on. Compliance is a judgement, and evidence is what the judgement rests on.
Be Ready to Show It
Regulators, auditors and your own board will ask what control exists over your AI. Organisations that answer with written-down processes and concrete records move faster, because they are working from what they already have.
A written-down process turns the AI Act into a structured pathway you can walk deliberately. A good question to take into your next planning session: can your process estate show how your AI operates today? Talk to IGX about the regulatory evidence your process estate can already show.