AI governance as a layer in the workflow
Governance literally means steering: the rules and responsibilities by which your company uses AI. In many organisations this exists as a policy PDF on a shared drive and is not lived. PHÖNIX instead anchors the rules as checkpoints in the process itself, at the point where the work happens.
One example: instead of a policy that prescribes labelling of AI-generated text, the approval step before sending contains a check that cannot be passed without the label. The process itself keeps watch, not a binder.
What applies, and since when. (Last updated: 8 August 2026)
- The transparency obligations under Art. 50 of the AI Act (Regulation (EU) 2024/1689) have applied since 2 August 2026. Among other things, people must be able to recognise when they are interacting with an AI or looking at AI-generated content.
- The obligations for high-risk systems have been postponed to 2 December 2027 (Digital Omnibus, agreement of 6 May 2026).
- The GDPR applies in any case and independently of this, as soon as personal data is processed, including by AI tools.
None of these deadlines is a reason to panic, and panic is not used for selling here either. They are a reason to know your own inventory. All statements dated, details and sources on the knowledge page. No sentence on this page is legal advice.
What gets set up.
- Inventory of AI deployments: which tools work where, with which data, in which role. Without this list, no obligation can be assigned.
- Roles and approvals: who may use which AI for what, who releases results, who bears responsibility.
- Evidence keeping: records are created within the process instead of being gathered afterwards.
- Incident handling: a procedure for the day something goes wrong: report, contain, document, fix.
All of this is built into your existing processes as work steps. This is a set-up that stays, not a consulting visit.
The layer is kept up to date.
Regulation moves, as the postponement of the high-risk obligations shows. PHÖNIX monitors the legal position and updates the installed layer when obligations change: inventory, checkpoints and evidence are adjusted before a change hits you. You do not have to read the regulation yourself, and the record that updates were made stays with you. Rhythm and scope of this arrangement are agreed per case.
Frequently asked questions.
Are we even affected by the EU AI Act?
That depends on your role and your deployments, not on your industry alone. Whoever only uses AI systems has different obligations than whoever develops them or offers them under their own name. The first reliable answer comes from the inventory: which systems, which role, which risk class. That is exactly where the set-up begins.
Is an AI policy not enough?
A policy is a start, but it proves nothing. Obligations such as transparency and evidence keeping require that what is on paper actually happens in the process. A policy without checkpoints in the process is, in the decisive moment, exactly that: paper.
What is mandatory by when?
The dated deadlines are above in the legal-position section and in more detail in the deadline table on the knowledge page. Which of them affect your organisation follows from the inventory. Blanket answers without a look at the inventory would be guesswork.
What does the ongoing arrangement cost?
There is no public price, because rhythm and scope differ per case. Both are agreed in writing before the arrangement begins, and it can be terminated at any time within the agreed notice periods.