> ## Documentation Index
> Fetch the complete documentation index at: https://docs.aigoframework.com/llms.txt
> Use this file to discover all available pages before exploring further.

# 07 AIGO EU AI Act Governance and Enforcement Mapping v0.1

# AIGO — EU AI Act Governance and Enforcement Mapping

## 1. Document Purpose

This document provides the AIGO mapping for the governance, supervision, enforcement, institutional cooperation, market-surveillance, regulatory-authority, and penalty framework established by Regulation (EU) 2024/1689, as amended by subsequent Union legislation including Regulation (EU) 2026/1744.

The mapping translates the EU AI Act governance architecture into AIGO mechanisms covering:

* European AI governance;
* European AI Office;
* European Artificial Intelligence Board;
* Scientific Panel;
* Advisory Forum;
* national competent authorities;
* market-surveillance authorities;
* notifying authorities;
* fundamental-rights protection authorities;
* regulatory cooperation;
* supervisory investigations;
* information requests;
* inspections;
* corrective measures;
* commitments;
* non-compliance findings;
* administrative fines;
* periodic penalty payments;
* complaints and regulatory interaction;
* confidentiality;
* evidence preservation;
* management escalation;
* incident response;
* regulatory change management;
* assurance; and
* continual improvement.

This document is an operational governance mapping. It does not confer statutory authority on an organization or its internal governance bodies, and it is not legal advice.

The European Commission currently describes the AI Act as operating through a two-tiered governance structure in which national competent authorities oversee and enforce rules concerning AI systems while the European AI Office governs and enforces GPAI obligations and certain other AI systems within its competence. The AI Board supports EU-wide coherence, while the Scientific Panel and Advisory Forum provide expert and stakeholder input.

***

## 2. Mapping Information

| Field                         | Value                                             |
| ----------------------------- | ------------------------------------------------- |
| Mapping                       | AIGO EU AI Act Governance and Enforcement Mapping |
| Version                       | 0.1                                               |
| Status                        | Draft                                             |
| Document Identifier           | `AIGO-MAP-EUAI-007`                               |
| Document Type                 | EU AI Act Mapping                                 |
| Mapping Package               | `AIGO-MAP-EUAI`                                   |
| Primary Legal Instrument      | Regulation (EU) 2024/1689                         |
| Current Amendment Baseline    | Regulation (EU) 2026/1744                         |
| Primary Governance Provisions | Articles 64–68 and related provisions             |
| Enforcement Provisions        | Articles 69–85 and Article 99, as amended         |
| Mapping Architecture          | `AIGO-MAP-EUAI-ARCH-001`                          |
| Registry                      | `00-AIGO-EU-AI-Act-Mapping-Registry-v0.1.json`    |

Regulation (EU) 2026/1744 was adopted on 8 July 2026, published on 24 July 2026, and entered into force on 27 July 2026. It substantially amended the supervisory and enforcement architecture, including new provisions addressing AI Office supervisory and enforcement powers.

***

# 3. Governance Principle

The AIGO governance model must preserve the distinction between:

```text theme={null}
EU / National Regulatory Authority
             ↓
Statutory Authority
             ↓
Supervision / Enforcement
```

and:

```text theme={null}
Organizational AIGO Governance
             ↓
Internal Accountability
             ↓
Implementation / Evidence / Assurance
```

An AIGO Governance Board, AI Governance Owner, Risk Committee, or similar internal body does **not** acquire the statutory powers of:

* the European AI Office;
* a national market-surveillance authority;
* a notifying authority;
* a fundamental-rights protection authority; or
* any other competent public authority.

***

# 4. Governance Architecture

The current EU AI Act governance architecture can be represented as:

```text theme={null}
                         European Commission
                                 │
                                 ▼
                         European AI Office
                                 │
                 ┌───────────────┼───────────────┐
                 ▼               ▼               ▼
              AI Board     Scientific Panel   Advisory Forum
                 │
                 ▼
       National Competent Authorities
                 │
        ┌────────┴─────────┐
        ▼                  ▼
Market-Surveillance   Notifying Authorities
Authorities
        │
        ▼
AI-System Providers / Deployers / Other Operators
```

The actual supervisory chain depends on the AI system, actor, sector, and applicable statutory provisions.

***

# 5. Regulatory Actor Model

AIGO should maintain a controlled distinction between:

```text theme={null}
EUROPEAN_COMMISSION
EUROPEAN_AI_OFFICE
EUROPEAN_AI_BOARD
SCIENTIFIC_PANEL
ADVISORY_FORUM
NATIONAL_COMPETENT_AUTHORITY
MARKET_SURVEILLANCE_AUTHORITY
NOTIFYING_AUTHORITY
FUNDAMENTAL_RIGHTS_PROTECTION_AUTHORITY
OTHER_SECTORAL_AUTHORITY
ORGANIZATION
PROVIDER
DEPLOYER
OTHER_OPERATOR
```

The organization should record the applicable external authority rather than using generic labels such as "regulator" where a more specific designation is available.

***

# 6. AIGO Regulatory-Authority Register

AIGO should maintain an internal register of relevant authorities.

Potential fields:

| Field              | Purpose                                                    |
| ------------------ | ---------------------------------------------------------- |
| Authority ID       | Unique identifier                                          |
| Authority Name     | Official name                                              |
| Country            | Jurisdiction                                               |
| Authority Type     | Market surveillance / notifying / rights authority / other |
| Scope              | Regulatory responsibility                                  |
| AI System Types    | Relevant systems                                           |
| Contact            | Controlled contact information                             |
| Notification Route | Applicable pathway                                         |
| Source             | Official legal / government source                         |
| Effective Date     | Authority status                                           |
| Last Reviewed      | Currency                                                   |

This register should be maintained separately from the EU AI Act mapping registry when operationally necessary.

***

# 7. National Competent Authorities

The Commission states that Member States designate and empower national competent authorities, including market-surveillance and notifying authorities, to supervise the implementation and application of the AI Act at national level.

AIGO should therefore determine:

* which Member State is relevant;
* which market-surveillance authority has competence;
* whether a notifying authority is relevant;
* whether a sectoral authority has additional responsibilities;
* whether a fundamental-rights authority should be involved.

***

# 8. Market-Surveillance Authorities

Market-surveillance authorities have responsibilities concerning supervision and enforcement of AI-system requirements, including prohibitions and high-risk AI rules.

AIGO should provide a regulatory interaction control capable of managing:

* authority identification;
* information requests;
* evidence production;
* investigation support;
* corrective actions;
* deadlines;
* communication;
* escalation;
* closure.

***

# 9. Notifying Authorities

Notifying authorities designate and supervise notified bodies involved in conformity assessment.

AIGO should distinguish:

```text theme={null}
Notifying Authority
        ↓
Notified Body
        ↓
Conformity Assessment
```

from:

```text theme={null}
Internal AIGO Assurance
```

These are separate governance mechanisms.

***

# 10. Fundamental-Rights Protection Authorities

The Commission identifies national authorities empowered to supervise or enforce Union-law obligations protecting fundamental rights as relevant participants in AI Act governance.

These authorities can receive information, including information concerning serious incidents, from market-surveillance authorities.

AIGO should therefore include a fundamental-rights escalation route.

Potential triggers include:

* discrimination;
* privacy violations;
* unlawful treatment;
* rights-impact incidents;
* serious impact on vulnerable groups;
* relevant high-risk AI findings.

***

# 11. European AI Office

The European AI Office is established within the European Commission and has central responsibilities for implementation and enforcement, including supervision of GPAI models and specified AI systems under Article 75.

AIGO should treat the AI Office as an external statutory authority.

The organization should maintain:

* AI Office relationship owner;
* regulatory correspondence;
* submissions;
* notices;
* requests;
* deadlines;
* responses;
* evidence.

***

# 12. AI Office Scope

The current amended framework gives the AI Office responsibility for certain GPAI obligations and, under specified conditions, certain AI systems.

The precise scope must be determined from the current legal text.

Regulation (EU) 2026/1744 introduced detailed provisions concerning AI Office supervision and enforcement powers, including Articles 75a, 75b, and 75c.

AIGO should therefore avoid treating "AI Office supervision" as applying identically to every AI system.

***

# 13. AI Office Supervisory Powers

Under the amended framework, the AI Office can exercise specified market-surveillance powers for the AI systems within its competence, including information requests, investigations, inspections, and other supervisory measures subject to legal safeguards.

AIGO should prepare organizations to manage:

* requests for information;
* requests for explanations;
* document retention requirements;
* inspection support;
* investigations;
* commitments;
* corrective actions;
* non-compliance findings.

***

# 14. AI Office Information Requests

AIGO should establish:

**Regulatory Information Request Control**

The control should manage:

```text theme={null}
Request Received
      ↓
Authenticity Verification
      ↓
Scope Analysis
      ↓
Legal / Compliance Review
      ↓
Evidence Collection
      ↓
Response Approval
      ↓
Submission
      ↓
Acknowledgment
      ↓
Follow-Up
```

The control should preserve the regulator's original request and the organization's response.

***

# 15. Information-Request Evidence

Evidence may include:

* request;
* authority identity;
* legal basis;
* scope determination;
* response;
* supporting documents;
* communications;
* submission acknowledgment;
* follow-up.

Sensitive information should be access-controlled.

***

# 16. Preservation Requirements

Where a competent authority requests data or documents, the organization should activate evidence-preservation procedures.

Potential actions include:

* preservation notice;
* retention hold;
* access restriction;
* evidence copying;
* integrity verification;
* chain-of-custody tracking.

The Document Integrity and Evidence frameworks should support these activities.

***

# 17. On-Site Inspections

Where legally required, organizations should have a controlled inspection-response process.

AIGO should support:

* inspection authorization verification;
* designated response team;
* authority liaison;
* evidence access;
* visitor/access records;
* secure communications;
* document preservation;
* management escalation;
* post-inspection remediation.

AIGO internal approval is not a prerequisite for a lawful regulatory inspection.

***

# 18. Investigation Management

Regulatory investigations should be tracked separately from ordinary internal incidents.

Recommended record:

```text theme={null}
Regulatory Investigation
      ↓
Authority
      ↓
Legal Basis
      ↓
Scope
      ↓
Evidence
      ↓
Responses
      ↓
Findings
      ↓
Corrective Measures
      ↓
Closure
```

The Incident and Assurance models can support this workflow.

***

# 19. Regulatory Commitments

The amended framework permits the AI Office to address certain proceedings through binding commitments.

AIGO should maintain a dedicated commitment record or use the Change / Improvement / Approval framework to preserve:

* commitment;
* legal basis;
* responsible owner;
* actions;
* deadlines;
* verification;
* evidence;
* closure.

A binding regulatory commitment must not be treated as an ordinary internal improvement recommendation.

***

# 20. Non-Compliance Findings

When an authority determines non-compliance, AIGO should create a controlled regulatory finding.

Recommended fields:

| Field              | Purpose                   |
| ------------------ | ------------------------- |
| Finding ID         | Unique identifier         |
| Authority          | Issuing authority         |
| Legal Provision    | Relevant requirement      |
| Affected AI System | Subject                   |
| Finding            | Description               |
| Severity           | Governance classification |
| Deadline           | Regulatory deadline       |
| Corrective Action  | Required response         |
| Owner              | Accountability            |
| Evidence           | Response evidence         |
| Status             | Lifecycle                 |
| Closure            | Verification              |

***

# 21. Corrective Measures

A regulatory finding should generate:

```text theme={null}
Regulatory Finding
      ↓
Risk Assessment
      ↓
Corrective Action
      ↓
Change
      ↓
Evidence
      ↓
Verification
      ↓
Assurance
      ↓
Regulatory Response
```

The regulatory authority's required corrective action remains authoritative.

An organization must not substitute its own internal interpretation for the authority's binding decision.

***

# 22. AI Office Periodic Penalty Payments

Under the amended Article 75c framework, the AI Office may impose periodic penalty payments in specified circumstances to compel compliance with investigations, information requests, inspections, corrective actions, commitments, or decisions. The amended provision sets an upper limit of 5% of average daily income or worldwide annual turnover in the preceding financial year per day, where applicable.

AIGO should therefore classify a periodic penalty-payment decision as a critical regulatory governance matter.

***

# 23. AI Office Administrative Fines

The amended framework applies administrative fines to specified infringements within the AI Office's supervisory competence.

AIGO should treat a regulatory fine as:

```text theme={null}
Regulatory Event
   ↓
Legal / Compliance Review
   ↓
Incident / Risk
   ↓
Corrective Action
   ↓
Change
   ↓
Assurance
   ↓
Management Review
```

A fine should not be closed merely because the payment was made.

The underlying governance issue should be addressed.

***

# 24. Article 99 Penalty Mapping

The master mapping should preserve the Article 99 penalty framework and applicable amended provisions.

AIGO should not hard-code penalty amounts into operational controls because:

* penalties depend on the relevant infringement;
* statutory amendments can change thresholds;
* organization characteristics can matter;
* supervisory competence can differ;
* the applicable law should control.

The legal source should remain authoritative.

***

# 25. Confidentiality and Regulatory Information

Regulatory interactions can contain:

* confidential business information;
* security information;
* personal data;
* model information;
* proprietary documentation.

AIGO should control access to:

* regulatory correspondence;
* investigation evidence;
* inspection records;
* authority submissions;
* legal advice;
* enforcement documents.

***

# 26. Procedural Rights

Organizations subject to enforcement should maintain procedural safeguards and legal-review processes.

AIGO should not attempt to define legal procedural rights independently of the applicable law.

Relevant governance mechanisms include:

* legal review;
* authority verification;
* response approval;
* evidence preservation;
* representation;
* deadline management.

***

# 27. Coordination With Other EU Law

The amended AI Act establishes coordination mechanisms involving other Union legal frameworks, including the Digital Services Act for certain very large online platforms/search engines and AI systems connected to them. The AI Office and national authorities must coordinate with relevant authorities and take account of principles such as proportionality and ne bis in idem.

AIGO should identify overlapping regulatory frameworks during applicability assessment.

***

# 28. AI Act and Digital Services Act

Where an AI system:

* is deployed on a very large online platform;
* is embedded in a very large online platform;
* is connected to a very large online search engine;

the organization should assess whether additional regulatory authorities and coordination mechanisms apply.

The AI Act mapping should not be treated as the sole regulatory map.

***

# 29. Sector-Specific Supervision

The 2026 amendments preserve certain sectoral supervisory responsibilities where specific sectoral supervision exists.

AIGO should therefore identify:

* sector;
* sector regulator;
* AI Act authority;
* conformity authority;
* data-protection authority;
* other relevant authorities.

A "single regulator" assumption should be avoided.

***

# 30. Union Institutions

AI systems placed on the market, put into service, or used by Union institutions, bodies, offices, or agencies are subject to a distinct supervisory framework involving the European Data Protection Supervisor under the applicable AI Act provisions.

This is relevant primarily to the applicable public-sector scope.

AIGO should preserve the distinction between:

```text theme={null}
National / General AI Act Supervision
```

and:

```text theme={null}
Union Institution Supervision
```

***

# 31. European Artificial Intelligence Board

The AI Board provides EU-level coordination and supports coherent implementation across Member States.

The Commission describes the AI Board as composed of representatives of EU Member States.

AIGO should monitor:

* AI Board recommendations;
* guidance;
* coordination positions;
* common objectives;
* subgroups;
* relevant implementation developments.

AI Board material should be labelled appropriately as guidance or coordination unless it has another legal status.

***

# 32. AI Board and AI Literacy

The amended Article 4 provides for AI Board recommendations supporting AI literacy and taking European competence frameworks into account.

AIGO should therefore connect:

```text theme={null}
AI Board Recommendation
      ↓
AI Literacy Mapping
      ↓
Organizational Learning Measures
```

***

# 33. AI Board and Regulatory Consistency

The AI Board should be treated as an important source for:

* harmonized interpretation;
* implementation coherence;
* guidance;
* common approaches.

AIGO regulatory monitoring should incorporate material Board outputs.

***

# 34. Scientific Panel

The Scientific Panel provides independent scientific expertise to support AI Act governance.

AIGO should consider Scientific Panel outputs as high-value implementation information.

The organization should distinguish:

```text theme={null}
Scientific Panel Opinion / Advice
```

from:

```text theme={null}
Binding Legal Requirement
```

***

# 35. Advisory Forum

The Advisory Forum represents stakeholder perspectives and provides advice to the AI Board and Commission.

AIGO may monitor relevant outputs, but should distinguish:

* stakeholder advice;
* Commission guidance;
* AI Board outputs;
* binding legal requirements.

***

# 36. Regulatory Governance Information Hierarchy

AIGO should use:

```text theme={null}
Binding EU Law
        ↓
Delegated / Implementing Acts
        ↓
Official Commission / AI Office Guidance
        ↓
AI Board Recommendations
        ↓
Scientific / Advisory Inputs
        ↓
AIGO Interpretation
        ↓
Organizational Policy
```

Lower-level material must not be represented as changing higher-level legal obligations.

***

# 37. Regulatory Change Management

AIGO should maintain a formal regulatory-change process.

Recommended flow:

```text theme={null}
Regulatory Change Detected
        ↓
Source Verification
        ↓
Affected Requirements
        ↓
Affected AI Systems
        ↓
Risk Impact
        ↓
Control Impact
        ↓
Evidence Impact
        ↓
Procedure / Template Impact
        ↓
Management Review
        ↓
Implementation
        ↓
Assurance
```

This should use the AIGO Change Management Schema.

***

# 38. Regulatory Watch

The organization should monitor:

* Regulation amendments;
* delegated acts;
* implementing acts;
* Commission guidance;
* AI Office publications;
* AI Board recommendations;
* authority designations;
* national implementation;
* enforcement developments;
* relevant standards;
* cross-regulatory developments.

The regulatory watch should preserve source and review date.

***

# 39. Authority Designation Monitoring

Because national competent authorities have an essential enforcement function, changes in authority designation should trigger review.

AIGO should maintain:

* authority register;
* jurisdiction;
* scope;
* effective date;
* official source.

The Commission provides a consolidated list of identified national authorities and continues to update the governance information.

***

# 40. Regulatory Contact Management

AIGO should maintain controlled contact information for:

* competent authority;
* regulatory liaison;
* legal counsel;
* responsible executive;
* technical contact;
* evidence coordinator.

Personal information should be controlled.

***

# 41. Regulatory Submission Control

**Control Name:** Regulatory Submission and Authority Interaction

**Objective:**

Ensure that mandatory regulatory submissions and authority communications are accurate, timely, authorized, traceable, and retained.

**Control Owner:**

AI Governance Owner / Legal & Compliance.

**Evidence:**

* source request;
* draft submission;
* review;
* approval;
* submission;
* acknowledgment;
* follow-up.

***

# 42. Regulatory Deadline Control

Regulatory deadlines should be tracked separately from ordinary internal deadlines.

Fields should include:

* authority;
* legal basis;
* start date;
* due date;
* responsible owner;
* status;
* extension request;
* submission date;
* acknowledgment.

Missed regulatory deadlines should trigger a high-severity incident or governance escalation.

***

# 43. Authority Communication Evidence

AIGO should preserve:

```text theme={null}
Original Authority Communication
Response
Supporting Documents
Submission Evidence
Authority Acknowledgment
Follow-Up
Decision
```

Evidence should be protected against unauthorized modification.

***

# 44. Regulatory Investigation Evidence

For investigations, AIGO should preserve:

* requested evidence;
* evidence supplied;
* source system;
* timestamps;
* versions;
* integrity metadata;
* communications;
* legal review;
* corrective actions.

The Evidence Schema should support appropriate regulatory evidence records.

***

# 45. Regulatory Incident

A regulatory event may be recorded as an Incident where it involves:

* suspected non-compliance;
* authority investigation;
* enforcement action;
* serious regulatory finding;
* missed statutory requirement.

The Incident record should link to:

* AI system;
* risk;
* authority;
* finding;
* evidence;
* change;
* improvement;
* assurance.

***

# 46. Regulatory Risk

AIGO should support a dedicated regulatory-risk category:

`REGULATORY_COMPLIANCE_RISK`

Potential sources include:

* new legal requirements;
* uncertain applicability;
* inadequate controls;
* evidence gaps;
* authority findings;
* missed deadlines;
* supplier non-compliance.

***

# 47. Regulatory Risk Assessment

A regulatory risk assessment should consider:

* legal exposure;
* affected AI systems;
* control maturity;
* evidence;
* probability;
* impact;
* authority interest;
* remediation;
* residual risk.

Legal risk ratings should be clearly distinguished from legal conclusions.

***

# 48. Enforcement Readiness

An organization should maintain an enforcement-readiness capability.

Potential capabilities:

* complete AI inventory;
* current applicability decisions;
* traceable evidence;
* current documentation;
* regulatory contact register;
* controlled submissions;
* incident management;
* authority-response process;
* legal escalation;
* management reporting.

***

# 49. Enforcement Readiness Assessment

A readiness assessment may evaluate:

```text theme={null}
Authority Identified
Applicability Established
Records Current
Evidence Available
Documentation Current
Incident Process Ready
Regulatory Response Process Ready
Management Escalation Ready
Retention Ready
```

***

# 50. Enforcement Evidence Pack

For material AI systems, organizations may maintain a controlled evidence pack containing:

* AI System Profile;
* classification;
* risk;
* controls;
* assessments;
* approvals;
* monitoring;
* incidents;
* changes;
* assurance;
* evidence;
* regulatory mapping.

This should be generated or assembled from authoritative records rather than maintained as an uncontrolled duplicate.

***

# 51. Regulatory Inspection Readiness

The organization should define:

* inspection lead;
* technical lead;
* legal lead;
* evidence lead;
* communications lead;
* executive sponsor.

The process should be tested periodically.

***

# 52. Enforcement Simulation

A future assurance exercise may simulate:

```text theme={null}
Regulatory Request
      ↓
Information Collection
      ↓
Evidence Review
      ↓
Legal Review
      ↓
Submission
      ↓
Authority Follow-Up
```

Simulation evidence can be retained as Assurance evidence.

***

# 53. Regulatory Corrective Action

Where enforcement identifies a gap:

```text theme={null}
Finding
  ↓
Risk
  ↓
Corrective Action
  ↓
Change
  ↓
Verification
  ↓
Evidence
  ↓
Assurance
```

The corrective action should remain open until the defined closure conditions are satisfied.

***

# 54. Regulatory Commitment Tracking

Regulatory commitments should be managed like controlled governance obligations.

Fields should include:

* commitment;
* authority;
* legal basis;
* date;
* owner;
* milestone;
* evidence;
* status;
* verification.

***

# 55. Regulatory Assurance

Assurance may evaluate:

* authority register;
* regulatory monitoring;
* applicability;
* submissions;
* evidence;
* deadline management;
* investigation response;
* corrective action.

For material regulatory matters, independent legal or compliance assurance may be appropriate.

***

# 56. Management Review

Management review should periodically consider:

* regulatory changes;
* authority changes;
* open regulatory issues;
* investigations;
* enforcement;
* fines;
* corrective actions;
* evidence gaps;
* upcoming deadlines;
* resource requirements.

Material enforcement activity should be escalated promptly rather than waiting for the next scheduled management review.

***

# 57. Regulatory Improvement

Repeated regulatory findings should drive improvement.

Examples:

* improve legal monitoring;
* improve applicability assessment;
* improve AI inventory;
* improve controls;
* improve evidence;
* improve authority-response procedures;
* improve supplier governance;
* improve training.

***

# 58. Governance and GPAI

The governance architecture should recognize the special role of the AI Office for GPAI.

Recommended chain:

```text theme={null}
GPAI Provider
      ↓
GPAI Classification
      ↓
Systemic-Risk Determination
      ↓
AI Office Interaction
      ↓
Evidence
      ↓
Monitoring
      ↓
Incident
      ↓
Corrective Action
```

The detailed GPAI mapping is maintained in:

`05-AIGO-EU-AI-Act-GPAI-Mapping-v0.1.md`

***

# 59. Governance and High-Risk AI

For high-risk AI, governance should identify:

* national authority;
* notifying authority where relevant;
* notified body where relevant;
* sector authority;
* fundamental-rights authority;
* legal/compliance owner.

The detailed high-risk mapping is maintained in:

`03-AIGO-EU-AI-Act-High-Risk-AI-Mapping-v0.1.md`

***

# 60. Governance and Prohibited Practices

For Article 5:

```text theme={null}
Potential Prohibited Use
      ↓
Internal Escalation
      ↓
Legal Review
      ↓
Authority Interaction if Required
```

An internal governance body cannot authorize a prohibited practice.

Detailed provisions remain in:

`02-AIGO-EU-AI-Act-Prohibited-AI-Practices-Mapping-v0.1.md`

***

# 61. Governance and Transparency

Article 50 transparency obligations may be enforced through national authorities.

AIGO should maintain the transparency evidence and monitoring required to demonstrate implementation.

Detailed mapping remains in:

`04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md`

***

# 62. Governance and AI Literacy

Article 4 supervision and enforcement are under national market-surveillance authorities, not the AI Office. The Commission states that national authorities begin supervision and enforcement from 2 August 2026.

AIGO should therefore direct Article 4 regulatory issues through the relevant national authority rather than assuming the AI Office is the enforcement body.

***

# 63. Authority-Cooperation Model

Where multiple authorities may be involved:

```text theme={null}
Primary Authority
      ↓
Relevant Sector Authority
      ↓
Fundamental-Rights Authority
      ↓
Data Protection Authority
      ↓
Other Applicable Authority
```

AIGO should preserve the legal competence of each authority.

***

# 64. Regulatory Coordination

The organization should designate one regulatory coordination owner to avoid inconsistent responses from different functions.

The coordination owner should not prevent legally required direct communications with competent authorities.

***

# 65. Regulatory Reporting Governance

Regulatory reporting should include:

* trigger;
* source;
* applicability;
* deadline;
* authority;
* content;
* reviewer;
* approver;
* submission;
* evidence;
* acknowledgment.

***

# 66. Regulatory Communication Security

Regulatory communications should use:

* approved channels;
* access controls;
* encryption where appropriate;
* document classification;
* secure evidence handling.

***

# 67. Governance and Evidence

Governance decisions should be traceable to regulatory sources.

Recommended chain:

```text theme={null}
Legal Requirement
      ↓
Applicability
      ↓
Governance Decision
      ↓
Control
      ↓
Evidence
      ↓
Assurance
```

***

# 68. Governance and Auditability

AIGO should maintain sufficient records to reconstruct:

* what requirement applied;
* when it applied;
* who made the decision;
* what evidence supported the decision;
* what control was used;
* what monitoring occurred;
* what changed.

***

# 69. Governance and Legal Advice

Legal advice should remain distinct from ordinary governance records where legally privileged.

AIGO should preserve necessary references to legal review without unnecessarily embedding privileged legal content in broadly accessible operational records.

***

# 70. Governance and Accountability

Each regulatory obligation should have:

* accountable owner;
* operational owner;
* compliance reviewer;
* evidence owner;
* assurance owner where applicable.

Roles should be represented in the Governance Schema.

***

# 71. Enforcement Readiness Control Matrix

| Governance Area          | AIGO Control                           | Primary Record         |
| ------------------------ | -------------------------------------- | ---------------------- |
| Authority identification | Regulatory Authority Register          | Governance             |
| Legal monitoring         | Regulatory Change Control              | Change                 |
| Applicability            | Regulatory Applicability Assessment    | Assessment             |
| Information requests     | Regulatory Information Request Control | Evidence               |
| Inspections              | Regulatory Inspection Response Control | Incident / Evidence    |
| Investigations           | Regulatory Investigation Control       | Incident               |
| Commitments              | Regulatory Commitment Control          | Improvement / Approval |
| Corrective measures      | Regulatory Corrective Action Control   | Change                 |
| Fines                    | Regulatory Enforcement Event Control   | Incident / Evidence    |
| Deadlines                | Regulatory Deadline Control            | Monitoring             |
| Evidence                 | Regulatory Evidence Control            | Evidence               |
| Assurance                | Regulatory Assurance Control           | Assurance              |
| Management               | Regulatory Management Review           | Management Review      |

***

# 72. Regulatory Traceability Chain

The minimum chain is:

```text theme={null}
EU AI Act Provision
        ↓
Competent Authority
        ↓
Applicability
        ↓
Organizational Requirement
        ↓
Control
        ↓
Evidence
        ↓
Monitoring
        ↓
Assurance
        ↓
Management Review
```

For enforcement:

```text theme={null}
Authority Finding
        ↓
Incident / Risk
        ↓
Corrective Action
        ↓
Change
        ↓
Verification
        ↓
Evidence
        ↓
Regulatory Response
        ↓
Assurance
```

***

# 73. Governance Findings

Potential AIGO findings include:

```text theme={null}
REGULATORY_AUTHORITY_UNRESOLVED
AUTHORITY_REGISTER_MISSING
REGULATORY_SCOPE_UNRESOLVED
REGULATORY_DEADLINE_MISSING
INFORMATION_REQUEST_UNCONTROLLED
REGULATORY_SUBMISSION_UNCONTROLLED
INSPECTION_RESPONSE_UNCONTROLLED
REGULATORY_INVESTIGATION_UNCONTROLLED
REGULATORY_COMMITMENT_UNCONTROLLED
REGULATORY_FINDING_UNCONTROLLED
CORRECTIVE_ACTION_UNCONTROLLED
REGULATORY_EVIDENCE_GAP
AUTHORITY_CONTACT_OUTDATED
REGULATORY_CHANGE_UNREVIEWED
ENFORCEMENT_READINESS_GAP
```

***

# 74. Critical Governance Findings

Potential critical findings include:

* competent authority unknown for a materially regulated AI system;
* statutory deadline missed;
* regulatory request not controlled;
* required submission not made;
* evidence subject to regulatory preservation not protected;
* enforcement finding without corrective action;
* regulatory commitment without owner;
* material regulatory change not assessed.

***

# 75. Governance Metrics

Potential management metrics include:

| Metric                    | Purpose                |
| ------------------------- | ---------------------- |
| Regulated AI Systems      | Scope                  |
| Authorities Identified    | Governance coverage    |
| Applicability Assessments | Coverage               |
| Open Regulatory Requests  | Current obligations    |
| Regulatory Deadlines      | Timeliness             |
| Open Investigations       | Exposure               |
| Open Findings             | Remediation            |
| Regulatory Commitments    | Compliance obligations |
| Critical Findings         | Risk                   |
| Overdue Actions           | Management attention   |
| Assurance Coverage        | Verification           |

These metrics should not be presented as legal compliance scores.

***

# 76. Regulatory Health

A future governance-health view may classify:

```text theme={null}
HEALTHY
HEALTHY_WITH_WARNINGS
DEGRADED
UNHEALTHY
NOT_READY
```

The Repository Health Checker may aggregate these results.

***

# 77. Regulatory Governance Assurance

Assurance should verify:

* authority mapping;
* regulatory-change monitoring;
* deadlines;
* submissions;
* evidence;
* investigations;
* corrective actions;
* management escalation.

***

# 78. Regulatory Governance and Repository Health

Repository health should identify:

* stale authority references;
* missing legal sources;
* outdated regulatory dates;
* broken links;
* outdated mapping;
* missing governance artifacts;
* unresolved enforcement findings.

***

# 79. Current Governance Baseline

The Commission's current governance page states that the AI Office and Member State authorities are responsible for implementing, supervising, and enforcing the AI Act, while the AI Board, Scientific Panel, and Advisory Forum steer and advise on governance.

The current consolidated legal framework must additionally be read with Regulation (EU) 2026/1744, which introduced more detailed AI Office supervision and enforcement powers and refined the relationship between the AI Office and national authorities.

***

# 80. Digital Omnibus Impact

The 2026 amendments materially affect governance and enforcement by:

* defining additional AI Office supervisory powers;
* specifying information-request powers;
* regulating inspections;
* introducing structured dialogue and commitments;
* establishing detailed AI Office non-compliance decisions;
* enabling AI Office fines and periodic penalty payments;
* clarifying cooperation with national authorities;
* refining supervision of certain AI systems;
* coordinating with other Union regulatory regimes.

AIGO governance and enforcement mappings must therefore be reviewed against the amended text, not the 2024 governance model alone.

***

# 81. Review Triggers

This mapping should be reviewed after:

* EU AI Act amendments;
* AI Office guidance;
* AI Board recommendations;
* national authority designation changes;
* enforcement guidance;
* new implementing acts;
* new delegated acts;
* relevant regulatory decisions;
* major court decisions;
* changes to sectoral supervision;
* changes to the Digital Services Act interaction.

***

# 82. Review Frequency

Minimum review frequency:

* annual;
* event-driven after regulatory changes;
* before major AIGO releases.

Event-driven review takes precedence.

***

# 83. Relationship to Other EU AI Act Mappings

| File                                                             | Relationship         |
| ---------------------------------------------------------------- | -------------------- |
| `01-AIGO-EU-AI-Act-Mapping-v0.1.md`                              | Master mapping       |
| `02-AIGO-EU-AI-Act-Prohibited-AI-Practices-Mapping-v0.1.md`      | Article 5            |
| `03-AIGO-EU-AI-Act-High-Risk-AI-Mapping-v0.1.md`                 | High-risk            |
| `04-AIGO-EU-AI-Act-Transparency-Mapping-v0.1.md`                 | Article 50           |
| `05-AIGO-EU-AI-Act-GPAI-Mapping-v0.1.md`                         | GPAI                 |
| `06-AIGO-EU-AI-Act-AI-Literacy-Mapping-v0.1.md`                  | Article 4            |
| `08-AIGO-EU-AI-Act-Conformity-and-Documentation-Mapping-v0.1.md` | Conformity           |
| `09-AIGO-EU-AI-Act-Rights-and-Remedies-Mapping-v0.1.md`          | Rights and remedies  |
| `10-AIGO-EU-AI-Act-Annexes-Mapping-v0.1.md`                      | Annexes              |
| `11-AIGO-EU-AI-Act-Applicability-and-Timeline-v0.1.md`           | Timeline             |
| `12-AIGO-EU-AI-Act-AIGO-Control-Mapping-v0.1.md`                 | Controls             |
| `13-AIGO-EU-AI-Act-Evidence-and-Assurance-Mapping-v0.1.md`       | Evidence / assurance |

***

# 84. Relationship to AIGO Schemas

| Regulatory Activity              | AIGO Schema       |
| -------------------------------- | ----------------- |
| Governance structure             | Governance        |
| AI system scope                  | AI System         |
| Applicability                    | Assessment        |
| Regulatory risk                  | Risk              |
| Regulatory control               | Control           |
| Authority decision               | Approval          |
| Deadline / regulatory monitoring | Monitoring        |
| Enforcement event                | Incident          |
| Regulatory response              | Change            |
| Assurance                        | Assurance         |
| Regulatory evidence              | Evidence          |
| Management escalation            | Management Review |
| Corrective action                | Improvement       |
| Final lifecycle action           | Retirement        |

The mapping does not require a dedicated regulatory-enforcement schema at this stage.

***

# 85. Relationship to AIGO Tools

The governance and enforcement mapping should eventually be supported by:

* Schema Validator;
* Reference Validator;
* Traceability Validator;
* Control Coverage Validator;
* Evidence Coverage Validator;
* Framework Consistency Checker;
* Document Integrity Checker;
* Repository Health Checker.

***

# 86. Validation Requirements

The mapping should satisfy:

### Authority Validation

Relevant authority is identified.

### Legal Source Validation

Authority powers and obligations trace to current law.

### Applicability Validation

Supervisory competence is determined.

### Timeline Validation

Effective dates and enforcement dates are current.

### Evidence Validation

Regulatory interactions can be evidenced.

### Traceability Validation

Requirement → authority → organization → control → evidence chain is complete.

### Consistency Validation

Authority names, roles, and terminology are consistent across AIGO.

### Change Validation

Regulatory amendments are incorporated.

***

# 87. Limitations

This mapping cannot independently determine:

* which authority will ultimately exercise jurisdiction in a specific factual case;
* whether a regulator's action is legally valid;
* whether a specific enforcement decision is correct;
* whether a fine will be imposed;
* whether internal governance satisfies all regulatory procedural requirements;
* whether a particular legal interpretation will prevail.

Those matters require current law, authority decisions, factual circumstances, and appropriate legal review.

***

# 88. Document Control

| Field                     | Value                                                              |
| ------------------------- | ------------------------------------------------------------------ |
| Document                  | AIGO EU AI Act Governance and Enforcement Mapping                  |
| Version                   | 0.1                                                                |
| Status                    | Draft                                                              |
| Document Identifier       | `AIGO-MAP-EUAI-007`                                                |
| Document Type             | EU AI Act Mapping                                                  |
| Primary Legal Source      | Governance and enforcement provisions of Regulation (EU) 2024/1689 |
| Amendment Baseline        | Regulation (EU) 2026/1744                                          |
| Owner                     |                                                                    |
| Legal/Compliance Reviewer |                                                                    |
| Governance Reviewer       |                                                                    |
| Framework Architect       |                                                                    |
| Approved By               |                                                                    |
| Effective Date            |                                                                    |
| Next Review Date          |                                                                    |

***

# 89. Document Status

**Document:** AIGO — EU AI Act Governance and Enforcement Mapping

**Version:** 0.1

**Status:** Draft

**Working Name:** AIGO

**Full Name:** AI Governance Operating Framework

**Document Identifier:** `AIGO-MAP-EUAI-007`

**Document Type:** EU AI Act Mapping

This document maps the EU AI Act governance and enforcement architecture to the AIGO AI Governance Operating Framework, including the European AI Office, AI Board, national competent authorities, market-surveillance authorities, notifying authorities, fundamental-rights authorities, regulatory interactions, investigations, corrective measures, commitments, enforcement decisions, penalties, evidence, assurance, management review, and continual improvement.

End of Document
