Regulatory readiness map · Evidence operating model

EU AI Act readiness

High-risk AI obligations create a proof burden.

Guardian helps risk, compliance, AI governance, and ML platform teams preserve the operational evidence behind high-risk AI systems, without replacing legal review or conformity assessment.

Readiness SprintProductPost-market monitoring

Proof burden memo

Policies are not enough

The EU AI Act does not only ask for policies. It asks teams to show how systems were governed, monitored, reviewed, documented, and corrected over time. Most readiness gaps appear after deployment — when monitoring, incident handling, and evidence maintenance are not yet part of day-to-day operations.

Preserve what happened. Reconstruct what matters. Export what you can defend.

Guardian is the evidence operating model for that work — linking operational signals, human oversight, policy mapping, a traceable evidence trail, and export-ready records above the tools you already run.

Obligation → evidence map

Readiness register

Illustrative map for one in-scope system. Counsel confirms your specific obligations.

EU AI Act readiness map · MAP-001REF · GRD-EUA-MAP
Obligation areaWhat teams may need to showEvidence Guardian helps preserveSource systemsReadiness state
Risk managementRisk measures, review triggers, follow-upThreshold events, risk reviews, escalationsMonitoring, ticketingLinked
Data governanceData quality, lineage, governance decisionsQuality metrics, drift signals, notesMLOps, data platformActive
Technical documentationSystem description tied to productionVersioned docs linked to runs and changesModel registry, change logsOpen
Logging and traceabilityWho did what, when, on which outputTimestamped intake, custody trailAPI intake, webhooksLinked
Human oversightOversight procedures and interventionsReviewer sign-off, escalation historyReview workflow, incidentsActive
Accuracy, robustness, and cybersecurityPerformance and resilience in operationMetrics, robustness tests, security eventsObservability, security toolingOpen
Post-market monitoringOngoing behaviour after deploymentBaselines, alert history, review outcomesMonitoring, Guardian dossierVerified
Serious incident evidenceDocumentation when serious incidents occurIncident register, remediation, notificationTicketing, incident workflowActive

8 obligation areas · illustrative · not a legal checklist

Evidence operating model

What Guardian preserves

Six record types that form the dossier for one in-scope system — not a dashboard screenshot.

IDRecordWhat it holdsStatus
EVP-01AI System RecordIn-scope system identity, owners, and operating contextCore
EVP-02Version RecordModel, policy, and configuration versions linked to productionCore
EVP-03Evidence EventsCaptured signals with source, timestamp, and normalized payloadActive
EVP-04Human ReviewOversight actions, sign-off, and reviewer identityActive
EVP-05Incident + Corrective ActionOpen items, root cause, remediation, and resolution trailLinked
EVP-06Register-backed Export + RetentionPoint-in-time evidence packet with retention boundaryVerified

Supporting objects

Policies · Owners · Source Connectors — linked across every record type above.

From obligation to dossier

Evidence workflow

IDStepOutput
MAP-01Identify obligationObligation area mapped to in-scope system
MAP-02Map evidence sourceSource systems and intake channels registered
MAP-03Capture operational signalEvent received with timestamp and source ID
MAP-04Link owner and policyCustody handler and policy reference attached
MAP-05Review and preserve custodyReview actions and transfers recorded
MAP-06Export evidence packetReconstructable bundle for review

Scope boundaries

What Guardian does not do

  • Guardian does not provide legal advice.
  • Guardian does not decide whether a system is legally high-risk.
  • Guardian does not certify compliance.
  • Guardian does not replace conformity assessment.
  • Guardian does not replace existing MLOps, monitoring, ticketing, GRC, or legal tools.

Common questions

EU AI Act essentials

What is the EU AI Act?
Regulation (EU) 2024/1689 — the EU framework for AI systems, including requirements for systems that may be high-risk. It creates ongoing obligations around risk management, documentation, logging, oversight, and post-market monitoring. This page describes operational evidence readiness, not legal advice.
Which AI systems may be high-risk?
Annex III lists categories that may be treated as high-risk — including employment, credit, healthcare, education, and critical infrastructure. Whether your system qualifies depends on facts and role; counsel should confirm classification.
Does Guardian make us compliant?
No. Guardian helps teams preserve operational evidence that can support EU AI Act readiness and auditability workflows. Legal compliance is a separate determination requiring qualified review.
What evidence should teams prepare?
Typically: risk measures, data governance records, technical documentation, logging, oversight procedures, post-deployment monitoring baselines, and incident trails — maintained continuously, not assembled only when review begins.
How does Guardian support EU AI Act readiness?
By linking production signals, incidents, oversight actions, and exportable records in one governed dossier above the monitoring you already run — designed for teams preparing for high-risk AI obligations.
Why start with one system?
One in-scope system is easier to approve, faster to operationalise, and the only way to build a credible evidence baseline before scaling. Most readiness gaps appear after go-live, when evidence fragments across tools and teams.

Guardian supports evidence readiness and auditability workflows. It does not provide legal advice, determine legal classification, certify compliance, or replace sector-specific conformity assessment.

Start with one system

Build a first evidence baseline through the Readiness Sprint, then run the operating model in Guardian.

Readiness mapFAQ