Risk-based inventory

Record systems, purposes, roles, data types, risk classes, providers and deployment. Without a reliable inventory, reviews and accountability remain incomplete.

Logging and traceability

The European Commission lists logging, technical documentation and human oversight among the core requirements for high-risk systems. The control layer should generate this evidence from operations.

Human oversight

Critical decisions need defined approvals, escalations and accountable people. Not every agent action should execute autonomously.

Technical policy enforcement

Policies must be evaluated before model access and action execution. Data class, region, model approval and risk level become part of every request.

From document to infrastructure

CODE S translates governance requirements into identity, routing, policies, approvals and audit evidence.

Source: European Commission, “AI Act”, last updated 3 August 2026. Official EU source.