Governance-as-Code: Translating EU AI Act Technical Requirements into Executable Compliance Pipelines for Generative AI Systems

📅 2026-09-17
📈 Citations: 0
✨ Influential: 0
📄 PDF
🤖 AI Summary
本文针对欧盟AI法案在生成式AI系统中的技术缺口,提出了一种名为Governance-as-Code的框架,通过CI/CD管道实现自动化合规检查。
📝 Abstract
The EU AI Act (Regulation 2024/1689) imposes technical obligations on high-risk AI providers, yet Articles 8-15 were drafted for predictive AI and leave seven technical gaps when applied to generative systems, spanning non-deterministic data governance, training-data provenance, continuous conformity, human oversight, open-ended robustness, emergent risk, and generative fairness. We deliver Governance-as-Code (GaC), a framework of 43 machine-checkable acceptance criteria across six compliance modules that run in a CI/CD pipeline and emit Article-indexed audit evidence, and we show the actual Rego policy code rather than merely describing it. Our central commitment is that the Act's open-textured standards ("appropriate levels," "possible biases") become declared, auditable numbers: robustness thresholds are derived from the provider's documented baseline and a state-of-the-art floor, and framing bias is collapsed into eight measurable proxies tested by counterfactual demographic probing. We also correct who owes what, since under Article 25 and Chapter V a downstream deployer relies on the upstream provider's Article 53 training-data summary and documents only the layers it controls, so GaC verifies that summary rather than demanding per-sample documentation the deployer never had. We validate on two enterprise deployments, a high-risk advisory chatbot and a limited-risk content generator, benchmarking against a manual expert audit rather than documentation artifacts that were never designed to enforce compliance. GaC reproduces all of the manual audit's findings, including three penalty-triggering violations, while cutting audit labor by roughly 75%.
Problem

Research questions and friction points this paper is trying to address.

EU AI Act
generative AI systems
technical gaps
compliance
high-risk AI providers
Innovation

Methods, ideas, or system contributions that make the work stand out.

Governance-as-Code
Compliance Pipeline
Generative AI Systems
Machine-Checkable Criteria
Rego Policy Code
💼 Related Jobs
No related jobs found.
R
Rudrendu Kumar Paul
Boston University, Boston, MA, USA
S
Sourav Nandy
University of Texas at Austin, Austin, TX, USA