AI projects scattered across product teams with no central register. No risk classification per workload. Training data classification absent. Model attestation produced ad-hoc when teams remember. Lineage from training data to deployed model invisible. Compliance is reactive — produces artefacts when regulators ask. No mapping from workload to EU AI Act tier.
Typical concerns
- ·No defensible answer to "what AI workloads do we have?"
- ·EU AI Act risk classification not applied
- ·Model attestation absent or ad-hoc
- ·Lineage from training data to model invisible
- ·No named owner of AI compliance
Capability gaps
- ·Central AI workload register
- ·EU AI Act tier classification per workload
- ·Training data classification and lineage (Purview)
- ·Model attestation cadence with reusable templates
- ·AI workload posture in Defender for Cloud