Risk-based inventory
Record systems, purposes, roles, data types, risk classes, providers and deployment. Without a reliable inventory, reviews and accountability remain incomplete.
Logging and traceability
The European Commission lists logging, technical documentation and human oversight among the core requirements for high-risk systems. The control layer should generate this evidence from operations.
Human oversight
Critical decisions need defined approvals, escalations and accountable people. Not every agent action should execute autonomously.
Technical policy enforcement
Policies must be evaluated before model access and action execution. Data class, region, model approval and risk level become part of every request.
CODE S translates governance requirements into identity, routing, policies, approvals and audit evidence.
Source: European Commission, “AI Act”, last updated 3 August 2026. Official EU source.