AI workloads scattered across product teams with no central register. No risk classification per workload. Model attestation absent. Compliance reactive — produces governance artefacts in response to regulator questions rather than continuously. AI workload posture managed by AI engineering, not by Compliance.
Typical concerns
- ·No defensible answer to "what AI workloads do we have?"
- ·EU AI Act risk classification not applied
- ·Model cards and attestation absent
- ·Lineage from training data to deployed model invisible
- ·Compliance has no continuous evidence of AI governance posture
Capability gaps
- ·Central AI workload register
- ·Risk classification per workload (EU AI Act tiers)
- ·Purview lineage on AI training and grounding data
- ·Model attestation cadence
- ·Cross-functional cadence (Compliance + AI engineering + Legal)