Govern AI Before It Governs You.
The EU AI Act is live. AI systems are proliferating across enterprises at a pace regulators are scrambling to match. Most organisations have no governance framework — no risk classification, no model inventory, no audit trail, no accountability layer. Illumia builds structured AI governance programs aligned with the EU AI Act, NIST AI RMF, and ISO/IEC 42001 — so you can deploy AI with confidence, not liability.

What the Program Covers
Risk Classification
Classify every AI system against the EU AI Act's four-tier model — unacceptable, high-risk, limited-risk, and minimal-risk — with documented rationale and evidence.
Maintain a living register of every AI system in use, including third-party SaaS, embedded ML, and shadow-IT models — the foundation of every other control.
Bias & Fairness Auditing
Quantitative testing of model outputs across protected attributes — age, gender, ethnicity, geography — using statistical fairness metrics.
Pre-processing, in-processing, and post-processing remediation strategies, with documented trade-offs and sign-off from product and legal.
EU AI Act Alignment
Map your AI systems against the Act's obligations — risk management (Art. 9), data governance (Art. 10), transparency (Art. 13), human oversight (Art. 14), and post-market monitoring (Art. 72).
Produce the technical documentation package required by Annex IV for high-risk systems, with version control and audit trail.
Model Accountability
Standardised model cards (Mitchell et al.) and dataset datasheets (Gebru et al.) for every production model — disclosing training data, intended use, and known limitations.
Formal model approval gates with sign-off from data science, security, legal, and business owner — captured in a tamper-evident log.
AI Incident Response
Detection, triage, containment, and remediation procedures for model drift, harmful outputs, prompt injection, and data leakage incidents.
Pre-built notification templates for Article 73 serious incident reporting to national competent authorities within the 15-day window.
Data Governance for AI
Track lineage of every dataset used in training — source, licence, consent basis, retention, and deletion. Aligns with GDPR Article 5 and EU AI Act Article 10.
Policies for synthetic data generation, including disclosure obligations, evaluation against original distributions, and risk of memorisation.
Human Oversight
Define meaningful human-in-the-loop, human-on-the-loop, and human-in-command roles per use case — with override authority and competence requirements.
Targeted training for staff exercising oversight — covering automation bias, interpretation of model confidence, and escalation paths.
Vendor & Procurement
Questionnaires and contract clauses for AI vendors — model provenance, indemnities, audit rights, and EU AI Act obligation flow-down.
If you fine-tune or substantially modify a general-purpose AI model, you inherit provider obligations. We map where that line falls for your deployments.
Regulatory Reporting
Prepare and submit the registration package for high-risk AI systems to the EU AI database under Article 49.
Post-market monitoring plan, conformity assessment refresh cycle, and reporting cadence to align with both EU AI Act and ISO/IEC 42001 management system requirements.
The window to operate AI without a governance framework has closed. The EU AI Act applies extraterritorially — any organisation placing AI systems on the EU market or whose outputs are used in the EU is in scope. Illumia's program gives you a defensible position: classified risk, documented controls, auditable decisions. Whether you are deploying generative AI internally, embedding ML in customer products, or procuring AI from third-party vendors, the same governance layer applies.