Operationalizing the EU AI Act
The EU AI Act deadline moved. The operationalization work it was buying time for did not.
Under the EU AI Act's risk-based approach, Modulos allows organizations to define, categorize, and govern AI risks based on specified controls; while Vijil evaluates whether the agent meets the risk threshold, enforces controls to mitigate defined risks, and monitors whether the agent conforms to policy — flagging and providing remediation guidance when violations happen. Together, Modulos and Vijil enable a holistic and sustainable strategy for agentic risk governance under the EU AI Act.
The Digital Omnibus pushed the Annex III high-risk deadline out to 2 December 2027 — the eighteen months in between are a build window, not a grace period.
- GRC teams have the tools to define policies and compliance requirements but not to validate and verify AI systems for risk
- Compliance testing of AI agents is manual, and doesn't replicate production conditions
- Manual reviews don't yield quantifiable metrics for evidence of accuracy, robustness, and security at a system level
- EU AI Act penalties and deadlines demand continuous monitoring based on the nature and risks of the application
IN FORCE TODAY
2 Aug 2026
Article 50 transparency duties apply. Systems already on the market have until 2 December 2026 to retrofit content marking.
STANDARDS
Zero cited
EN 18286 (quality management) is approved and awaits Official Journal citation. prEN 18228 (risk management) is still in draft.
DEFERRED · WAS 2 AUG 2026
2 Dec 2027
Annex III high-risk provider obligations apply. The runway is for building — conformity work takes most of it.
DEFERRED · WAS 2 AUG 2027
2 Aug 2028
High-risk obligations for AI embedded in regulated products under Annex I, deferred by twelve months.
Policy definition and policy enforcement are one loop — not two teams working past each other.
GRC teams have the tools to define policy and compliance requirements, but not to validate or verify AI systems against them. Compliance testing of agents is manual, and it doesn't replicate production conditions. Manual review doesn't produce quantifiable evidence of accuracy, robustness, and security at a system level — and the EU AI Act's penalties and deadlines demand continuous monitoring calibrated to risk, which a point-in-time review can't deliver. Operationalizing compliance means closing that loop: the policy a governance team writes has to be the exact thing a system is tested against, and what happens in production has to flow straight back as evidence.
POLICY DEFINITION
Turn governance into something testable
- Define policies, controls, and risk tolerance per AI project — written as parameters a system can actually be tested against, not a document that sits in a shared drive.
- Frame compliance as a specific, answerable question per agent — is this safe, with acceptable risk? — instead of a general posture nobody can point to evidence for.
- Specify what evidence has to exist before an agent ships, and where it should come from, so evaluation has something concrete to produce against.
- Classify each system against the EU AI Act's four gates and keep the risk register and quality management system current as the system changes.
POLICY ENFORCEMENT
Turn governance into something testable
- Define policies, controls, and risk tolerance per AI project — written as parameters a system can actually be tested against, not a document that sits in a shared drive.
- Frame compliance as a specific, answerable question per agent — is this safe, with acceptable risk? — instead of a general posture nobody can point to evidence for.
- Specify what evidence has to exist before an agent ships, and where it should come from, so evaluation has something concrete to produce against.
- Classify each system against the EU AI Act's four gates and keep the risk register and quality management system current as the system changes.
.jpg)
Who It's For
One integration, three teams
who stop reconciling by hand.

Security & Risk Leaders
A closed loop, not a spreadsheet
- A real closed-loop process between policy definition and policy enforcement
- Quantitative, system-level assessment of agent compliance and resilience
- Materially reduced manual review burden

Compliance & Audit Teams
Evidence, not attestations
- Automated evidence collection through system-level evaluation, reusable across every framework a control serves
- Framework mapping — EU AI Act, harmonized standards, ISO/IEC 42001, NIST AI RMF — for the same underlying control
- A register that visibly iterates, which is what an auditor or notified body reads first

Engineering & ML Teams
Guardrails that fit the ship date
- Reliable, repeatable model and agent assessment against controls someone else has already defined
- Built-in guardrails specific to the compliance property they're meant to satisfy
- A head start against draft standards now, instead of a scramble against final ones in 2027
How Modulos Structures the Strategy
One control, one body of evidence,
several frameworks satisfied at once.
The Modulos platform organizes compliance into three concepts. Getting this right is what lets a single Vijil evaluation or guardrail event count as evidence more than once.
CONCEPT 1
Frameworks
The regimes in scope for a given system: the EU AI Act, its harmonized standards, ISO/IEC 42001, NIST AI RMF, and others an organization already answers to.
CONCEPT 2
Requirements
Each framework's own article-by-article structure, preserved rather than flattened — an Article 15 requirement stays legible as Article 15, even while it's linked to other frameworks' equivalents.
CONCEPT 3
Controls
The operational implementation. One control, backed by one body of evidence, can satisfy requirements across several frameworks at once — a single model-documentation control can serve the EU AI Act's technical-documentation duty, an ISO/IEC 42001 control, and a NIST AI RMF subcategory simultaneously.
of controls
on the Modulos platform serve two or more frameworks at once — and the efficiency it buys scales with how much the frameworks in scope overlap.
frameworks
served by the platform's single most-reused control — one evaluation, one evidence trail, nine compliance obligations closed.
standards
usable today: EN 18286 as a released template, and prEN 18228 in current-draft form — so the management-system build can start before Official Journal citation, not after.
The Integration
How the strategy becomes automated evidence.
Modulos' controls are only as good as the evidence behind them. Vijil is what generates that evidence continuously, instead of someone screenshotting a dashboard before an audit.

Policy flows down from governance; evidence flows back up through evaluation and enforcement.
VIJIL Discover
Find every agent
- Connects to source (development repos) and destination (production environments and cloud VPCs) to scan for agent signatures
- Surfaces a comprehensive inventory of candidate agents — the register that step one of the compliance sequence depends on
Define the strategy
- Classify the system against the four gates and register it, whichever way classification lands
- Establish the risk register (Art. 9) and quality management system (Art. 17), and specify what evidence each control needs
VIJIL DIAMOND
Generate the evidence
- Ingests Modulos' policies, risk contexts, and system categories, and translates them into executable test cases
- Scores 32 attributes of agent trust across 250,000+ built-in prompts plus bespoke tests, and returns metrics, logs, and a Trust Score as objective evidence — not a self-attestation
VIJIL DOME
Enforce and keep monitoring
- Deploys guardrails tuned to the control and its risk, filtering the agent's actual inputs and outputs at sub-100ms latency
- Feeds continuous telemetry back to Modulos — satisfying Article 72 post-market monitoring and ready for Article 73's incident-reporting clocks
Seven steps, ordered by deadline.
The first three are current obligations. The rest build toward the deferred dates, with the harmonized standards as scaffolding — and with Modulos and Vijil doing the work at each step.
What To Do Now
Inventory every AI system
List every system and model in use or development. Vijil Discover finds the agents nobody registered; Modulos is the register everything downstream depends on.
Run the four gates
Screen against the prohibitions, classify under Article 6 including the Article 6(3) filter, tag Article 50 duties, identify general-purpose models. Modulos runs the classification and documents it.
Meet the duties already in force
Article 50 disclosure and content marking, AI-literacy measures, GPAI obligations where the role applies. Vijil evaluates whether marking and disclosure are actually present in what the agent outputs.
Close the 2026 items
Retrofit content marking on systems placed before 2 August 2026, and screen generative systems against the two new prohibitions arriving 2 December 2026.
Build the management systems
Implement the quality and risk management pair against EN 18286 and prEN 18228. Modulos carries both as templates today; Vijil's evaluation runs supply the evidence each control needs, before a single standard is even cited.
Assess, declare, register
Run the conformity route, issue the declaration, affix CE marking, register before placement. Vijil Trust Reports feed directly into the Annex IV technical documentation file.
Bring product-embedded AI through
Annex I systems follow their sectoral conformity procedure with the EU AI Act's requirements integrated — the same Frameworks / Requirements / Controls model extends to cover it.
NEXT STEP
Three ways to move from strategy to proof.
Download the solution brief
The joint Vijil × Modulos solution data sheet: the reference architecture, key benefits by team, and use cases for AI model risk management and EU AI Act / NIST AI RMF readiness.
Watch the webinar
"Bridging the AI Agent Governance Gap: Putting Policies into Practice" — Kevin Schawinski (Modulos) and Vin Sharma (Vijil) walk through the governance-to-guardrails workflow end to end, live on LinkedIn.