AI Governance — EU AI Act Comp... Note

AI Governance — EU AI Act Compliance, Risk Assessment, and Audit Logging

The final step in building a complete and functioning AI system is to establish an organizational infrastructure to ensure the safe operation of AI over time. This involves implementing technical safety measures such as blocking malicious input and evaluating the quality of the system. Additionally, organizational and regulatory safety measures are necessary, including governance, risk management, and audit logging. The EU AI Act, which came into force in August 2024, requires AI systems to be classified into three risk tiers: prohibited, high risk, and limited risk. The RAG system is classified as limited risk, which requires transparency obligations and disclosure to users that they are interacting with AI. To comply with the EU AI Act, an AI system inventory is necessary to centrally manage all AI systems in use across the organization. A risk assessment module is also required to quantitatively assess AI system risk and provide recommendations for mitigations. Furthermore, an audit logging module is necessary to record all operations of AI systems and comply with EU AI Act Article 12. The audit logger class records all AI operations to a JSONL file and provides methods for logging events, retrieving recent events, and generating compliance reports. Overall, establishing a robust organizational infrastructure is crucial for ensuring the safe and responsible operation of AI systems. The EU AI Act provides a framework for compliance, and implementing the necessary measures can help organizations ensure that their AI systems are transparent, explainable, and fair. By prioritizing organizational and regulatory safety, organizations can build trust with their users and stakeholders, and ensure that their AI systems are used for the benefit of society.