Académie / AIGP — AI Governance

AIGP Annex · Governance · Cours

AI Governance: roles, risk, framework

Beyond Article 10: the full map of actors, risk levels, and governance frameworks — the world of AIGP certification.

3 sections

1Actors and risk levels

The AI Act distinguishes several actors along the chain: provider (places on the market), deployer (uses), importer, distributor. Obligations differ by role — Article 10 targets only the provider, but a deployer has its own duties (human oversight, information…).

It also classifies systems by risk level:

Unacceptable
Prohibited
Social scoring, manipulation… banned.
High
Annex III
Employment, credit, education… heavy obligations (incl. art. 10).
Limited
Transparency
Chatbots, deepfakes: disclose that it's AI.
Minimal
Free
Anti-spam, games… no specific obligation.

2Risk management frameworks

Governance relies on structured frameworks. The NIST AI RMF proposes four functions in a loop:

  • Govern — culture, roles, policies;
  • Map — context and identified risks;
  • Measure — evaluate, test, measure;
  • Manage — prioritize, address, monitor.

And cross-cutting responsible AI principles: fairness, transparency, accountability, robustness, human oversight, privacy protection.

Human oversight refers to humans' ability to understand, supervise and, if needed, interrupt or correct the system — neither manually validating every prediction, nor removing all automation.

Governing beyond the obligation. Even without being strictly required to, an organization has an interest in governing its AI: managing risks (reputation, legal, security), anticipating regulatory changes, earning customer trust. It is a continuous, organizational mechanism — not a one-off deliverable like a file.

3Obligations and lifecycle

Proportionate regulation

The AI Act scales requirements to the risk level: light for minimal, demanding for high risk, prohibited for unacceptable. Some practices are restricted or banned depending on context — for example emotion recognition in the workplace.

What the provider owes (high risk)

Beyond Article 10 on data, the provider must put in place:

  • a risk management system;
  • technical documentation demonstrating compliance;
  • logging of events;
  • the required transparency (e.g. disclosing that content is AI-generated);
  • post-market monitoring and the reporting of serious incidents.

The importer and the distributor, for their part, verify that the provider is compliant (conformity, documentation) before the system enters the EU market. And governance covers the whole lifecycle — through to the system's decommissioning / withdrawal.

Two roles, two responsibilities. The provider carries the design and compliance; the deployer carries the compliant use (human oversight, following the instructions for use, informing individuals). Distinguishing them clearly avoids misallocating responsibilities — and a deployer that substantially modifies the system switches to provider.