Operationalizing the EU AI Act

The EU AI Act deadline moved. The operationalization work it was buying time for did not.

Under the EU AI Act's risk-based approach, Modulos allows organizations to define, categorize, and govern AI risks based on specified controls; while Vijil evaluates whether the agent meets the risk threshold, enforces controls to mitigate defined risks, and monitors whether the agent conforms to policy — flagging and providing remediation guidance when violations happen. Together, Modulos and Vijil enable a holistic and sustainable strategy for agentic risk governance under the EU AI Act.

The Digital Omnibus pushed the Annex III high-risk deadline out to 2 December 2027 — the eighteen months in between are a build window, not a grace period.

  • GRC teams have the tools to define policies and compliance requirements but not to validate and verify AI systems for risk
  • Compliance testing of AI agents is manual, and doesn't replicate production conditions
  • Manual reviews don't yield quantifiable metrics for evidence of accuracy, robustness, and security at a system level
  • EU AI Act penalties and deadlines demand continuous monitoring based on the nature and risks of the application
Download the solution brief
Watch the webinar

IN FORCE TODAY

2 Aug 2026

Article 50 transparency duties apply. Systems already on the market have until 2 December 2026 to retrofit content marking.

STANDARDS

Zero cited

EN 18286 (quality management) is approved and awaits Official Journal citation. prEN 18228 (risk management) is still in draft.

DEFERRED · WAS 2 AUG 2026

2 Dec 2027

Annex III high-risk provider obligations apply. The runway is for building — conformity work takes most of it.

DEFERRED · WAS 2 AUG 2027

2 Aug 2028

High-risk obligations for AI embedded in regulated products under Annex I, deferred by twelve months.

Policy definition and policy enforcement are one loop — not two teams working past each other.

GRC teams have the tools to define policy and compliance requirements, but not to validate or verify AI systems against them. Compliance testing of agents is manual, and it doesn't replicate production conditions. Manual review doesn't produce quantifiable evidence of accuracy, robustness, and security at a system level — and the EU AI Act's penalties and deadlines demand continuous monitoring calibrated to risk, which a point-in-time review can't deliver. Operationalizing compliance means closing that loop: the policy a governance team writes has to be the exact thing a system is tested against, and what happens in production has to flow straight back as evidence.

POLICY DEFINITION

Turn governance into something testable

  • Define policies, controls, and risk tolerance per AI project — written as parameters a system can actually be tested against, not a document that sits in a shared drive.
  • Frame compliance as a specific, answerable question per agent — is this safe, with acceptable risk? — instead of a general posture nobody can point to evidence for.
  • Specify what evidence has to exist before an agent ships, and where it should come from, so evaluation has something concrete to produce against.
  • Classify each system against the EU AI Act's four gates and keep the risk register and quality management system current as the system changes.

POLICY ENFORCEMENT

Turn governance into something testable

  • Define policies, controls, and risk tolerance per AI project — written as parameters a system can actually be tested against, not a document that sits in a shared drive.
  • Frame compliance as a specific, answerable question per agent — is this safe, with acceptable risk? — instead of a general posture nobody can point to evidence for.
  • Specify what evidence has to exist before an agent ships, and where it should come from, so evaluation has something concrete to produce against.
  • Classify each system against the EU AI Act's four gates and keep the risk register and quality management system current as the system changes.

Who It's For

One integration, three teams

who stop reconciling by hand.

Security & Risk Leaders

A closed loop, not a spreadsheet

  • A real closed-loop process between policy definition and policy enforcement
  • Quantitative, system-level assessment of agent compliance and resilience
  • Materially reduced manual review burden

Compliance & Audit Teams

Evidence, not attestations

  • Automated evidence collection through system-level evaluation, reusable across every framework a control serves
  • Framework mapping — EU AI Act, harmonized standards, ISO/IEC 42001, NIST AI RMF — for the same underlying control
  • A register that visibly iterates, which is what an auditor or notified body reads first

Engineering & ML Teams

Guardrails that fit the ship date

  • Reliable, repeatable model and agent assessment against controls someone else has already defined
  • Built-in guardrails specific to the compliance property they're meant to satisfy
  • A head start against draft standards now, instead of a scramble against final ones in 2027

How Modulos Structures the Strategy

One control, one body of evidence,

several frameworks satisfied at once.

The Modulos platform organizes compliance into three concepts. Getting this right is what lets a single Vijil evaluation or guardrail event count as evidence more than once.

CONCEPT 1

Frameworks

The regimes in scope for a given system: the EU AI Act, its harmonized standards, ISO/IEC 42001, NIST AI RMF, and others an organization already answers to.

CONCEPT 2

Requirements

Each framework's own article-by-article structure, preserved rather than flattened — an Article 15 requirement stays legible as Article 15, even while it's linked to other frameworks' equivalents.

CONCEPT 3

Controls

The operational implementation. One control, backed by one body of evidence, can satisfy requirements across several frameworks at once — a single model-documentation control can serve the EU AI Act's technical-documentation duty, an ISO/IEC 42001 control, and a NIST AI RMF subcategory simultaneously.

0

of controls

on the Modulos platform serve two or more frameworks at once — and the efficiency it buys scales with how much the frameworks in scope overlap.

0

frameworks

served by the platform's single most-reused control — one evaluation, one evidence trail, nine compliance obligations closed.

0

standards

usable today: EN 18286 as a released template, and prEN 18228 in current-draft form — so the management-system build can start before Official Journal citation, not after.

EU AI Act — released template
EN 18286 (quality mgmt, Art. 17) — released template
prEN 18228 (risk mgmt, Art. 9) — draft template
prEN 18282 (cybersecurity, Art. 15) — draft template
ISO/IEC 42001
NIST AI RMF

The Integration

How the strategy becomes automated evidence.

Modulos' controls are only as good as the evidence behind them. Vijil is what generates that evidence continuously, instead of someone screenshotting a dashboard before an audit.

Policy flows down from governance; evidence flows back up through evaluation and enforcement.

VIJIL Discover

Find every agent

  • Connects to source (development repos) and destination (production environments and cloud VPCs) to scan for agent signatures
  • Surfaces a comprehensive inventory of candidate agents — the register that step one of the compliance sequence depends on

Define the strategy

  • Classify the system against the four gates and register it, whichever way classification lands
  • Establish the risk register (Art. 9) and quality management system (Art. 17), and specify what evidence each control needs

VIJIL DIAMOND

Generate the evidence

  • Ingests Modulos' policies, risk contexts, and system categories, and translates them into executable test cases
  • Scores 32 attributes of agent trust across 250,000+ built-in prompts plus bespoke tests, and returns metrics, logs, and a Trust Score as objective evidence — not a self-attestation

VIJIL DOME

Enforce and keep monitoring

  • Deploys guardrails tuned to the control and its risk, filtering the agent's actual inputs and outputs at sub-100ms latency
  • Feeds continuous telemetry back to Modulos — satisfying Article 72 post-market monitoring and ready for Article 73's incident-reporting clocks

Seven steps, ordered by deadline.

The first three are current obligations. The rest build toward the deferred dates, with the harmonized standards as scaffolding — and with Modulos and Vijil doing the work at each step.

What To Do Now

01
Now

Inventory every AI system

List every system and model in use or development. Vijil Discover finds the agents nobody registered; Modulos is the register everything downstream depends on.

02
Now

Run the four gates

Screen against the prohibitions, classify under Article 6 including the Article 6(3) filter, tag Article 50 duties, identify general-purpose models. Modulos runs the classification and documents it.

03
Now

Meet the duties already in force

Article 50 disclosure and content marking, AI-literacy measures, GPAI obligations where the role applies. Vijil evaluates whether marking and disclosure are actually present in what the agent outputs.

04
By Dec 2026

Close the 2026 items

Retrofit content marking on systems placed before 2 August 2026, and screen generative systems against the two new prohibitions arriving 2 December 2026.

05
By Dec 2026

Build the management systems

Implement the quality and risk management pair against EN 18286 and prEN 18228. Modulos carries both as templates today; Vijil's evaluation runs supply the evidence each control needs, before a single standard is even cited.

06
By Dec 2026

Assess, declare, register

Run the conformity route, issue the declaration, affix CE marking, register before placement. Vijil Trust Reports feed directly into the Annex IV technical documentation file.

07
By Aug 2028

Bring product-embedded AI through

Annex I systems follow their sectoral conformity procedure with the EU AI Act's requirements integrated — the same Frameworks / Requirements / Controls model extends to cover it.

Governed AI is shippable AI.

Modulos builds the AI Governance Platform used by regulated organizations to run EU AI Act, harmonized-standard, and ISO/IEC 42001 compliance as one system of controls and evidence. Vijil is the enforcement and monitoring layer that keeps that system honest in production, agent by agent.

— Modulos AG, "The EU AI Act Guide," 2026 Edition

NEXT STEP

Three ways to move from strategy to proof.

01

Download the solution brief

The joint Vijil × Modulos solution data sheet: the reference architecture, key benefits by team, and use cases for AI model risk management and EU AI Act / NIST AI RMF readiness.

Download the data sheet
02

Watch the webinar

"Bridging the AI Agent Governance Gap: Putting Policies into Practice" — Kevin Schawinski (Modulos) and Vin Sharma (Vijil) walk through the governance-to-guardrails workflow end to end, live on LinkedIn.

Watch the webinar
03

Contact the team

Talk to the partnership team about operationalizing EU AI Act obligations for your AI agents — from compliance strategy to runtime enforcement and audit-ready evidence.

Talk to the team