Governance and regulatory evidence, answered in full.
The evidence a governance function, an auditor or a regulator will ask for, specified while you build rather than reconstructed afterwards.
- questions in this group, each answered in full
- 5
- pages the answers are written on, every one linked
- 1
- questions across the whole FAQ
- 316
5 questions on governance and regulatory evidence, answered by Tenhaw, a UK AI consultancy and AI delivery partner based in London. Nothing here is a summary: each answer is the exact text from the page that owns it, and every group links back to that page for the context around it.
AI governance and regulatory evidence
Answered on AI governance and regulatory evidence, and rendered here in the same words.
Read the page these answers live on →
When do the EU AI Act's high-risk obligations actually apply?
Later than the date most plans were written against, and the obligations themselves are unchanged. Article 113 originally set 2 August 2026 for stand-alone high-risk systems and 2 August 2027 for high-risk systems embedded in regulated products. The Digital Omnibus amendment, agreed between the Council and the Parliament in May 2026 and approved by the Parliament in June, moves those to 2 December 2027 and 2 August 2028 respectively. What has been in force since 2 February 2025 is the prohibited-practice list and the AI literacy duty, and the general-purpose model obligations have applied since 2 August 2025. For a high-risk system the obligations still include conformity assessment, technical documentation, risk management, data governance, human oversight, registration and post-market monitoring, so the practical implication has not moved either: a current inventory, a defensible classification of each system, and evidence generated by your process rather than assembled retrospectively. Tenhaw designs the operating model and delivery discipline that produce that evidence; we are not lawyers, formal legal interpretation should come from counsel, and you should check the dates against the Official Journal rather than against us.
The board wants an AI plan. What should actually be in it?
Five things, and they are all answerable in weeks rather than quarters. An inventory of the AI already running, including embedded vendor features and anything bought outside procurement, because a plan written before the count gets rewritten later. A classification of that inventory by consequence, so the board can see which systems carry real risk rather than a flat list. A named accountable individual per class of decision, which is the first thing a regulator tests and the first thing a board should. A sequence with dates, showing which processes go first and what evidence each one produces as a by-product of the work. And an honest statement of what you cannot yet evidence, because the plans that survive board scrutiny are the ones that name their own gaps before somebody else does. If a stalled pilot is what prompted the board to ask, say so, and say whether it stalled on evidence, on ownership or on the data underneath it, because those three need different money and different people.
Where do AI governance programmes usually go wrong?
Four places. The inventory takes far longer than planned because AI entered the organisation through tool purchases and embedded vendor features rather than one programme. Governance is written as policy rather than embedded in process, so evidence has to be reconstructed. Accountability does not resolve to a named person, which is the first thing a regulator tests. And second-line risk arrives to review a finished system rather than to co-design it, so their only available lever is to block.
How do you make agent decisions auditable?
By designing the audit trail into the workflow rather than adding logging afterwards: what the agent was asked, what it retrieved, which tools it called, what it decided, which human approved or overrode it, and against which version of the system. The test is whether you could reconstruct a specific decision from six months ago without asking anyone what happened.
Who is accountable when an AI agent makes a mistake?
A named individual, and that has to be established before deployment rather than after an incident. Under regimes such as SM&CR accountability cannot rest with a system. In practice this means mapping each class of agent decision to a person with matching authority, and defining explicitly which decisions require human approval based on how consequential and how reversible they are.
316 questions, grouped by subject
Every question answered anywhere on tenhaw.com sits in one of 39 groups. This is one of them.
Still have a question?
A 30-minute discovery call with James Rooney. Bring the question this page did not answer. You'll leave with a rough scope whether you engage us or not.
Most organisations start with a fixed-price Agent-Readiness Audit · £30k–£90k · 6–8 weeks