AI governance for engineers: controls that leave evidence.

For the people who write the pipeline, the service or the agent: where a governance rule becomes code, what each stage should record, and which obligation that record answers.

Who this is for.

You own the build, the deploy and the pager. Governance tends to reach you as tickets and questionnaires. This route turns it into things you already know how to ship: a policy file the pipeline reads, an eval that can fail the build, a registry the deploy writes to, a guardrail at the enforcement point and a record each of them emits. Read it in order; each step says what it gives you.

  • ML and data engineers
  • Platform and MLOps engineers
  • Application and agent developers
  • Security engineers
  • Site reliability engineers

On the learning path, start at Eval gate in CI, Observability with OpenTelemetry or Policy-as-code with OPA.

New to the field? Read AI governance explained: the definition, the frameworks and where engineering fits.

Three questions you bring.

Each one answered in brief here, and in full in the Body of Knowledge.

  1. What do I actually have to build?

    Five layers, in build order: see it, rule it, test it, contain it, prove it. A team of one builds a thin slice through all five: a registry the deploy writes to, one policy that blocks, one eval gate, an identity and a kill switch per agent, and a structured record from each.

  2. Which tests count as evidence?

    A test whose metrics and thresholds were fixed before the run, whose result is filed against the version it tested, and whose failure blocks the release. For high-risk systems the EU AI Act asks for testing against prior defined metrics and probabilistic thresholds (Art. 9(8)) 1.

  3. What must the running system record?

    Enough to reconstruct any decision: inputs, outputs, model and prompt versions, tool calls and approvals, as structured, timestamped events. A high-risk system must allow the automatic recording of events over its lifetime (Art. 12(1)), and its deployer keeps the logs it controls for at least six months (Art. 26(6)) 1.

Your route through the site.

In reading order: chapters at the section that matters, then the patterns, tools, templates, datasets and figures that turn them into work.

Start this week.

  1. Put one eval in CI that can fail the build, with its threshold in version control. Eval Gate in CI
  2. Have the deploy write a registry entry with an owner and a scope, and block deploys without one. AI system register entry
  3. Emit one structured evidence record per release: version, eval results, approver and date. Evidence record schema
  4. Key each record to an obligation id, so an auditor can query it. The obligation register
  5. Score your five layers with the self-check and pick one move. Maturity self-check

The obligations that matter most.

The duties a pipeline evidences directly: logging, testing, robustness, documentation, oversight by design, transparency, and the threat lists the evals run against.

Obligations for this route (Engineers), with status, date and evidence
Obligation Applies Evidence
EU AI Act Art. 12 record-keeping and logging AIGE-OBL-EUAIA-ART12 Deferred · Structured, signed logs; OpenTelemetry traces; tamper-evident event store
EU AI Act Art. 15 accuracy, robustness and cybersecurity AIGE-OBL-EUAIA-ART15 Deferred · Eval gate; adversarial red-team suite; robustness and security controls; regression evals
EU AI Act Art. 9 risk management system AIGE-OBL-EUAIA-ART9 Deferred · Risk register as code; threat models; linkage to FRIA and eval results
EU AI Act Art. 11 technical documentation (Annex IV) AIGE-OBL-EUAIA-ART11 Deferred · AIBOM (CycloneDX ML-BOM, SPDX 3.0 AI); auto-generated technical documentation; model cards
EU AI Act Art. 14 human oversight AIGE-OBL-EUAIA-ART14 Deferred · Human-in-the-loop checkpoints; kill switch; override and escalation paths
EU AI Act Art. 50 transparency for certain AI systems AIGE-OBL-EUAIA-ART50 In force · Content labelling and machine-readable marking (e.g. C2PA-style); chatbot disclosure banner
OWASP LLM · Top 10 for LLM Applications 2026 AIGE-OBL-OWASP-LLM Voluntary Prompt-injection and output-handling controls; eval gate
OWASP Agentic · Top 10 for Agentic Applications 2026 AIGE-OBL-OWASP-AGENTIC Voluntary Agent threat model; adversarial evals; runtime guardrails; kill switch
NIST AI RMF · MEASURE AIGE-OBL-NISTRMF-MEASURE Voluntary Eval gates; adversarial red-team suite; metrics per failure mode

Every obligation in the register

Sources

  1. [1] Regulation (EU) 2024/1689 (Artificial Intelligence Act), consolidated text of 27 July 2026 (Arts. 9(8), 12(1) and 26(6)). Publications Office of the EU (EUR-Lex). 2026-07-27. https://eur-lex.europa.eu/eli/reg/2024/1689/2026-07-27/eng (verified: primary)

Start at the top of the route.

Step 01 is The stack, layer by layer. Each step after it builds on the one before.