re-ai-gov Join the waiting list

Responsible AI Governance

What you literally get in hand after the scan

Do you recognize this: someone in the finance department uses an AI tool to write reports, nobody in IT knows it exists, and if something goes wrong it's not clear who will be held accountable. Or: the tool on the IT list has long since been replaced by something employees found themselves, that works faster, and feeds on company data without anyone having looked at it. That is not a registration problem. That is a responsibility problem that only becomes visible at the moment it's too late to arrange calmly.

This page describes what is on the table once that picture is complete: not as a promise, but as a list of components.

What comes out per component

The scan does not deliver a single document, but a series of components that connect to one another.

First of all, an overview of applications, built up via a survey tool that goes out to departments and employees and is supplemented through guided desk research. That overview contains not only what IT knows, but also what has grown outside of it: the applications nobody formally approved, with whom they are used and for what.

Next follows, per application, a classification: which role the organization plays in it (provider or user) and which risk level applies. That classification comes from the aiacta datasets, not from an on-the-spot estimate. Based on that, a timeline emerges: what is an obligation now, and what can be planned for later. This makes visible where urgency belongs and where it does not.

Then there is a governance framework, worked out as a set of templates. Those templates are made to connect with the organization's existing risk structure, so that a second process does not need to emerge alongside the first. Added to that is a board report, summarized on one page, meant to share the essence of the situation without everyone having to go through the underlying material.

Finally, there is a subscription to a horizon scanner, to track what changes over time: new applications, new regulations, shifts in risk. What is correct at the moment of the scan may be outdated again a few months later; the subscription is the answer to that, not a one-time report.

Exactly how these components come about, from survey to template, is set out on how it works; those who want to see what the final results look like in substance will find that on outcomes.

Why every outcome is traceable

The data comes from two sources. The overview of applications comes from what the organization itself enters via the survey tool, supplemented with desk research that makes visible what the overview is based on. The classification of role, risk and obligation comes from the aiacta datasets: structured information about the AI Act, not from a separate assessment. This means every outcome can be traced back to where it comes from, and that nothing in the report rests on a substantiated estimate that cannot also be found in the source. Those who want to know how those datasets are built and maintained can read about it in the knowledge base.

What it is not

Three things fall outside what this scan does, and that is deliberate.

It is not an AI Act compliance tool. For register, classification and literacy according to the AI Act, aiacta.eu is the home; that boundary does not shift. This scan uses the datasets from that home, but does not replace it.

It is not proof of a completed trajectory. The scan structures what exists at the moment of execution; it does not show a track record and does not claim experience with previously completed trajectories. What the scan delivers is a snapshot of the current situation, not a track record.

It is not a second process alongside the existing structure. The templates are made to be inserted into what already exists in terms of risk management or compliance, not to start living a life of their own alongside it. Whether that fitting-in goes smoothly in practice depends on how that existing structure is built — the scan itself cannot guarantee that.

What you can decide with it

With the overview, the classification, the timeline and the templates on the table, a decision point arises about the next step. Some organizations take on the register, templates and timeline themselves, and arrange literacy via the aiacta seats. Others look for a partner for the design of the oversight process and the embedding into the existing risk structure. Yet others outsource the entire governance trajectory to a partner, with the scan as the file on which that trajectory starts. Which route is appropriate depends on the size of the organization, the complexity of the applications found and the capacity available internally — that is a consideration the organization makes itself, not something the scan prescribes.

The button to start the scan is currently on a waiting list; those who sign up will be notified as soon as the tool becomes available.

AI governance only gains meaning once it is clear which tasks, hours and systems are concretely involved. That translation, from application to workload, is made insightful by the work scan of FTE TO AI (ftetoai.com).

Andrewde assistent van de Responsible AI Scan

Vraag maar. Governance begint bij weten wat er draait — ook wat niemand heeft goedgekeurd.

Answers come from this site’s knowledge base. Not tailored advice, and not a scan of your company.