AI GOVERNANCE · AI ACT · GDPR

Governing AI is not about slowing it down. It is about knowing how far it can go.

Innoquo turns regulation and the real risk of each AI system into controls that work: what it may do, which data it can use, who authorises its actions and what evidence remains afterwards.

So your company can move forward with AI without operating blind.

REGULATORY BASELINE REVIEWED · 25.08.2026 · EU

THE REAL RISK

More AI capability does not mean losing control.

Not every action carries the same impact. Consulting information, sending an email, creating an invoice or deleting an account require different permissions and controls.

That is why we define autonomy action by action: what the AI may do, within which limits, and when a person must intervene.

Innoquo Autonomy Scale

The same model can sit at different levels depending on the action — control is assigned per action, not per agent. Impact is classified separately.

AUTONOMY

IMPACT

A4 · Low impact

Act within limits

Executes bounded, reversible and supervised actions.

  • Scoped credentials
  • Stop path defined

REGULATORY STATUS

August 2026: we are no longer talking about a future law.

From 2 August 2026, most of the AI Act already applies and authorities have begun supervising active obligations.

  1. 02.02.2025Prohibited practices and AI literacy — organisations must adopt measures to foster AI literacy for people who use or operate these systems.
  2. 02.08.2025Obligations for general-purpose model providers.
  3. NOW · 02.08.2026Application of most provisions, transparency obligations and start of supervision.
  4. 02.12.2026End of transitional period for marking and detection for certain systems placed on the market before 2 August 2026.
  5. 02.12.2027Certain high-risk systems under Annex III.
  6. 02.08.2028High-risk systems embedded in regulated products.

Use the official EU AI Act checker ↗ — currently available in English; informative orientation, not a definitive legal conclusion.

TRANSPARENCY ALREADY APPLIES

Four situations that may trigger transparency obligations.

Direct interaction with people

When a system is designed to interact directly with people, they must be clearly informed that they are interacting with AI, unless this is obvious from the context.

The Commission requires that the information appears from the start of the first interaction and in a clear, accessible form.

Generated or manipulated content

Certain providers must incorporate technical mechanisms that allow synthetic content to be detected.

Biometrics and emotions

People exposed to emotion-recognition or biometric categorisation systems must be informed when applicable.

Deepfakes and public-interest text

Certain manipulated content and public-interest publications require clear disclosure, with specific exceptions and conditions.

Not every situation triggers the same obligation. It depends on the system, the content, the company's role and how it is used.

Consult the official Article 50 guidelines ↗

DECISION → CONTROL → EVIDENCE

A prepared company can answer six questions without improvising.

  1. Which systems use AI?An up-to-date inventory exists, with a named owner for each system.
  2. What may they be used for?Intended purpose, allowed users and explicitly excluded uses are defined.
  3. Which data and providers are involved?What information is processed, where it is stored, who can access it and for how long.
  4. Which actions can they execute?Every tool, permission, limit and approval is documented.
  5. Who keeps control?Responsible people can review, reject, stop or reverse actions when needed.
  6. What can be demonstrated?Tests, records, metrics, incidents and evidence linked to the live system version.

If these answers do not exist — or live across documents, vendors and teams — the system is not truly governed yet.

Innoquo AI Readiness Review

You arrive with scattered systems. You leave with a verifiable map.

We review the AI systems your organisation uses or is preparing and turn the current situation into five concrete deliverables.

01

AI system register

Purpose, owner, users, data, providers, markets and status.

02

Roles and obligations map

Each organisation's role, obligations that require analysis and internal owners responsible for addressing them.

03

Actions and control matrix

Data, tools, permissions, approvals, limits and stop capability.

04

Gap and evidence map

What exists, what is missing, what can be demonstrated and what needs validation.

05

Prioritised action plan

Actions organised by risk, impact, owner and next decision.

FROM REVIEW TO PRODUCTION

If a control is missing, we can implement it.

  1. 01

    Inform

    Notices, labels and user experiences adapted to the system and channel.

  2. 02

    Limit

    Identity, permissions, authorised tools, approvals and operational limits.

  3. 03

    Test

    Real cases, exceptions, isolation, security, reversibility and recovery.

  4. 04

    Observe

    Logs, metrics, alerts, incidents, changes and post-launch review.

We do not stop at identifying the gap. We can design, implement and operate the technical measure required.

Innoquo AI Regulatory Radar · 2026 Guide

The law changes. You receive only what requires a decision.

A clear signal when a deadline shifts, a new obligation appears or an official guide changes what your company should prepare.

  • Practical AI Act Guide — English
  • Prioritised regulatory alerts
  • Checklists and working templates

Read the web version without subscribing →

We send the guide to this email only. No newsletter subscription is required.

Optional · regulatory updates