SearcharxivSearch

arXiv · 2609.20016

Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

Abstract

The EU AI Act (Regulation 2024/1689) imposes technical obligations on high-risk AI providers, yet Articles 8-15 were drafted for predictive AI and leave seven technical gaps when applied to generative systems, spanning non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness. We deliver Governance-as-Code (GaC), a framework of 43 machine-checkable acceptance criteria across six compliance modules that run in a CI/CD pipeline and emit Article-indexed audit evidence, and we show the actual Rego policy code rather than merely describing it. Our central commitment is that the Act's open-textured standards ("appropriate levels," "possible biases") become declared, auditable numbers: robustness thresholds are derived from the provider's documented baseline and a state-of-the-art floor, and framing bias is collapsed into eight measurable proxies tested by counterfactual demographic probing. We also correct who owes what, since under Article 25 and Chapter V a downstream deployer relies on the upstream provider's Article 53 training-data summary and documents only the layers it controls, so GaC verifies that summary rather than demanding per-sample documentation the deployer never had. We validate on two enterprise deployments, a high-risk advisory chatbot and a limited-risk content generator, benchmarking against a manual expert audit rather than documentation artifacts that were never designed to enforce compliance. GaC reproduces all of the manual audit's findings, including three penalty-triggering violations, while cutting audit labor by roughly 75%.

Explore related subjects

Keep this discovery

Explore connections, maps & timelines

BibTeXRIS

Rudrendu Kumar Paul, Sourav Nandy. 2026-09-17. Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems. https://arxiv.org/abs/2609.20016

Cite the original work for its findings. Save a collection to share your selection of sources.

KEEP EXPLORING

Related papers

A Brief AI Literacy Intervention Does Not Significantly Reduce Over-Reliance and Increases Under-Reliance on ChatGPT: A Randomized Study

In this study, we examined whether a brief AI literacy intervention influences high school students' reliance on recommendations from large language models (LLMs). In a randomized experiment, students were assigned to either a control group receiving a brief introduction to LLMs or an intervention group receiving additional information about how LLMs work, their limitations, and effective usage strategies. Participants then solved eight math puzzles with ChatGPT's advice, which was incorrect in half of the trials. Results indicated widespread over-reliance, with incorrect recommendations adopted in 52.1% of the trials. The intervention did not significantly reduce over-reliance. Instead, it led to an increase in under-reliance, as students were more likely to reject correct recommendations. These findings provide preliminary evidence that brief text-based interventions may be ineffective in fostering appropriate reliance. More comprehensive and interactive approaches may be required to meaningfully influence students' real-world reliance on LLMs.

cs.CY

Examining Community-Requested Fact-Checking: Request Alerts Are Associated with Greater Diversity and Visibility of Community Notes

Crowdsourced fact-checking systems such as Community Notes are increasingly used on social media platforms, yet concerns remain about which content receives scrutiny and how visible that scrutiny is. X allows users to request notes for specific posts. When sufficient requests accumulate, an alert is displayed, creating an interface cue that may guide contributor behavior. We present a quantitative, non-causal analysis comparing the diversity and visibility of community notes written for X posts with and without request alerts. We infer alert presence at note submission and analyze 10,432 alerted and 44,442 non-alerted English notes from 318 top writers. We find that, alerted notes are associated with greater individual-level topical diversity, but also with stronger collective concentration in the Politics category. Mixed-effects models estimate that alerted notes are 8.4-20.2 percentage points more likely to be modeled helpful and visible, though this visibility gain diminishes as topics diverge from writers' prior interests.

cs.CY

Scarcity and Predictive Uncertainty: Implications for Societal Resource Allocation

An emerging literature examines the critical question of when and how prediction can be useful in allocating scarce societal resources. We examine a novel variant of this question: What happens when predictive uncertainty differs systematically across the population? This can occur in several situations; for example, when machine learning models have significantly different accuracies across different demographics. We show that this uncertainty has serious implications for resource allocation when coupled with commonly used binary measures of societal benefit from allocation. We formulate a novel mathematical model of scarce resource allocation that accounts for heterogeneous predictive uncertainties and analyze implications for both the allocation mechanism and the realized population-level benefits. We find that when resources are very scarce, maximum marginal benefit (MMB) prioritization favors individuals with lower predictive uncertainty even at the identical underlying initial state. However, we observe a flip in prioritization when resources are abundant, targeting higher-uncertainty individuals. We illustrate the implications of our results on the PISA educational testing dataset. Our findings have meaningful ramifications for the distributional outcomes of prioritization policies in many domains touched by the theory of local justice, including the allocation of public education resources, medical triage, and homelessness services. They also reveal a new moral dilemma in the ethics of scarce resource allocation - is it just to allocate a resource to one person over another solely based on predictive uncertainty about their futures? We also assess efficiency losses under both MMB and the vulnerability-first (VF) prioritization. Our model predicts efficiency losses across all resource levels, but particularly in low-resource settings.

cs.CY