{"id":188,"date":"2026-09-26T08:01:00","date_gmt":"2026-09-26T08:01:00","guid":{"rendered":"https:\/\/www.dobryakov.net\/blog\/188\/"},"modified":"2026-09-26T08:01:00","modified_gmt":"2026-09-26T08:01:00","slug":"ai-governance-regulation-standards","status":"publish","type":"post","link":"https:\/\/www.dobryakov.net\/blog\/188\/","title":{"rendered":"EU AI Act Compliance Is a Pipeline, Not a PDF"},"content":{"rendered":"<p>Kovcheg&#x27;s credit module drafts decisions on customer applications. Under the EU AI Act, this is not an &quot;assistant&quot; \u2014 it is a high-risk AI system. Creditworthiness assessment of individuals is explicitly named in Annex III, which moves the system into a different legal class: a mandatory risk management system, technical documentation, logs, human oversight, registration. In parallel, the text assistant generating replies to customers falls under Art. 50 \u2014 transparency for AI-generated content. One system, two different sets of obligations.<\/p>\n<p><!--more--><\/p>\n<p>This chapter covers the compliance plane: turning regulatory requirements from a PDF policy into automated gates and artifacts. Compliance assembled by hand ahead of an audit date is theater. Compliance generated by a pipeline from your live engineering planes is evidence.<\/p>\n<h2>The regulator&#x27;s timeline and the cost of delay<\/h2>\n<p>The stakes are explicit. Fines under Art. 99 come in three tiers: up to \u20ac35M or 7% of turnover for prohibited practices under Art. 5 (in force since 02 Aug 2025); up to \u20ac15M or 3% for high-risk violations; up to \u20ac7.5M or 1% for supplying incorrect information to a regulator. For SMEs, the lower figure applies.<\/p>\n<p>The timeline has shifted, but a delay is not a cancellation. Prohibitions and GPAI rules have applied since August 2025. The AI Office&#x27;s supervisory powers and Art. 50 transparency requirements hit on 02 Aug 2026. Stand-alone high-risk systems under Art. 6(2) and Annex III were pushed by the Digital\/AI Omnibus to 02 Dec 2027. Embedded high-risk systems under Annex I move to 02 Aug 2028.<\/p>\n<p>Pushing the deadline to 2027 or 2028 breeds complacency. A risk management system, technical documentation, and evaluation pipelines take years to build. If you start when the deadline looms, you are already late.<\/p>\n<p>ISO\/IEC 42001 (published Dec 2023) is a de facto requirement in EU B2B RFPs. It is not harmonized under the AI Act, meaning it does not grant presumption of conformity. It does provide certifiable evidence of governance. NIST AI RMF is voluntary, non-certifiable, and serves as a bridge to ISO 42001.<\/p>\n<h2>The architectural pattern: Compliance-by-Design<\/h2>\n<p>Use a Compliance-by-Design automated pipeline. Compliance is built into CI\/CD. Risk classification, the RMS, and content labeling are pipeline steps, not a manual audit prep exercise. Governance is expressed as policy-as-code. Evidence is auto-generated artifacts.<\/p>\n<h3>Step 1. Auto-classifying risk in CI\/CD<\/h3>\n<p>At registration or release, a system is tagged with an AI Act category: unacceptable, high-risk, limited, or minimal. The class determines which gates are mandatory. For Kovcheg, the credit module routes to high-risk, triggering the full gate set. The text assistant routes to limited, triggering Art. 50 transparency obligations.<\/p>\n<h3>Step 2. A Risk Management System for high-risk<\/h3>\n<p>Regular logging of risks and mitigations under Art. 9 is tied to the audit trail and evaluation reports. The RMS is a living process, not a one-off document you write and forget.<\/p>\n<h3>Step 3. C2PA watermarking for Art. 50<\/h3>\n<p>Generated content \u2014 text, image, audio \u2014 carries cryptographic Content Credentials plus provenance metadata. To defend against metadata stripping, you apply Durable Credentials: invisible watermarks and perceptual fingerprints, the SynthID approach. The Commission&#x27;s draft Code of Practice on Transparency cites C2PA as an example meeting all four Art. 50 criteria.<\/p>\n<h3>Step 4. Technical documentation as an artifact<\/h3>\n<p>The system dossier \u2014 covering data, model, evaluations, risks, and controls \u2014 is assembled automatically from your engineering artifacts at release time. It is not written after the fact by someone scrambling to meet an audit deadline.<\/p>\n<h3>Step 5. A single compliance matrix<\/h3>\n<p>One table links &quot;requirement \u2192 control (chapter) \u2192 evidence (artifact).&quot; It maps AI Act articles to ISO 42001 controls to your implemented engineering planes. This matrix is the core of the audit.<\/p>\n<h2>The engineering stack<\/h2>\n<table>\n<thead>\n<tr>\n<th>Layer<\/th>\n<th>Tool \/ Standard<\/th>\n<\/tr>\n<\/thead>\n<tbody>\n<tr>\n<td>Provenance \/ watermarking<\/td>\n<td>C2PA Content Credentials, Durable Content Credentials, SynthID, draft ISO 22144<\/td>\n<\/tr>\n<tr>\n<td>Policy-as-code<\/td>\n<td>OPA (Rego) \u2014 gates in CI\/CD<\/td>\n<\/tr>\n<tr>\n<td>Compliance automation<\/td>\n<td>AI system registry, technical documentation templates, RMS trackers<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<h2>Where it breaks<\/h2>\n<p>Building this pipeline exposes four failure modes you have to account for.<\/p>\n<p><strong>Watermarks get stripped.<\/strong> Paraphrasing text, screenshotting, or re-encoding kills the mark. Durable Credentials reduce this but do not eliminate it, and the weakness is especially acute for text. Do not promise a client an &quot;unremovable&quot; mark. Build the system to survive the mark being lost.<\/p>\n<p><strong>Risk classification is not binary.<\/strong> Borderline cases require legal interpretation. The automation sets a draft class, and a lawyer confirms it. Auto-classification speeds things up; it does not replace judgment.<\/p>\n<p><strong>ISO 42001 does not equal presumption of conformity.<\/strong> Certification helps a lot in RFPs and as evidence, but it does not automatically satisfy the AI Act because the standard is not harmonized under the regulation.<\/p>\n<p><strong>Compliance theater returns.<\/strong> The matrix exists, but the controls do not work in production. This is the exact gap from a PDF policy. You fix it by generating evidence automatically from live planes, not by taking screenshots of a dashboard that says everything is fine.<\/p>\n<h2>The lab: classify, map, and test provenance<\/h2>\n<p>Classify both faces of Kovcheg under the AI Act and build the requirement-to-control-to-evidence matrix, referencing the artifacts from the preceding chapters. Attach C2PA credentials to generated content and test their survivability under paraphrasing and screenshotting.<\/p>\n<p>The artifact you produce is a risk classification, a compliance matrix, and a provenance demo with an honest report on exactly where the mark gets stripped.<\/p>\n<h2>Maturity checklist<\/h2>\n<ul>\n<li><strong>L1<\/strong>: Systems are classified, a compliance owner is assigned.<\/li>\n<li><strong>L2<\/strong>: An RMS and technical documentation exist as release artifacts; C2PA is applied to output content.<\/li>\n<li><strong>L3<\/strong>: Policy-as-code gates run in CI\/CD; an AI Act-to-ISO 42001 matrix exists with live, auto-generated evidence; Durable Credentials are deployed; AIMS certification readiness is achieved.<\/li>\n<\/ul>\n<h2>Sources<\/h2>\n<ul>\n<li><a href=\"https:\/\/artificialintelligenceact.eu\/implementation-timeline\/\">EU AI Act \u2014 implementation timeline<\/a><\/li>\n<li><a href=\"https:\/\/artificialintelligenceact.eu\/article\/99\/\">Article 99: Penalties<\/a><\/li>\n<li><a href=\"https:\/\/c2paviewer.com\/articles\/eu-ai-act-content-credentials\">EU AI Act and C2PA: what Article 50 requires<\/a><\/li>\n<li><a href=\"https:\/\/www.eccouncil.org\/cybersecurity-exchange\/responsible-ai-governance\/eu-ai-act-nist-ai-rmf-and-iso-iec-42001-a-plain-english-comparison\/\">ISO 42001 vs NIST AI RMF vs EU AI Act (EC-Council)<\/a><\/li>\n<\/ul>\n<p>If your compliance strategy for the EU AI Act is a document someone updates by hand, you are building a binder for a fine.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Turning the EU AI Act and ISO 42001 into automated CI\/CD gates, risk classification, and cryptographic provenance \u2014 not a last-minute audit binder.<\/p>\n","protected":false},"author":0,"featured_media":187,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[147],"tags":[191,192,153,193,154],"class_list":["post-188","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-ai-governance","tag-c2pa","tag-compliance-automation","tag-eu-ai-act","tag-high-risk-ai","tag-iso-42001"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 4.9.10 - aioseo.com -->\n\t<meta name=\"description\" content=\"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/www.dobryakov.net\/blog\/188\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 4.9.10\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"Grigoriy Dobryakov - IT+AI Blog - Grigoriy Dobryakov&#039;s blog: management, development and testing\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"EU AI Act Compliance Is a Pipeline, Not a PDF\" \/>\n\t\t<meta property=\"og:description\" content=\"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/www.dobryakov.net\/blog\/188\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-09-26T08:01:00+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-09-26T08:01:00+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"EU AI Act Compliance Is a Pipeline, Not a PDF\" \/>\n\t\t<meta name=\"twitter:description\" content=\"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#blogposting\",\"name\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\",\"headline\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\",\"author\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ai-governance-regulation-standards.jpg\",\"width\":1200,\"height\":630,\"caption\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\"},\"datePublished\":\"2026-09-26T08:01:00+00:00\",\"dateModified\":\"2026-09-26T08:01:00+00:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#webpage\"},\"articleSection\":\"AI Governance, C2PA, compliance automation, eu-ai-act, high-risk AI, iso-42001\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"name\":\"AI Governance\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"position\":2,\"name\":\"AI Governance\",\"item\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#listItem\",\"name\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#listItem\",\"position\":3,\"name\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/category\\\/ai-governance\\\/#listItem\",\"name\":\"AI Governance\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\",\"name\":\"Grigoriy Dobryakov - IT+AI Blog\",\"description\":\"Grigoriy Dobryakov's blog: management, development and testing\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#webpage\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/\",\"name\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\",\"description\":\"How to turn EU AI Act and ISO 42001 requirements into automated CI\\\/CD gates, risk classification, and C2PA provenance artifacts.\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/author\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/wp-content\\\/uploads\\\/2026\\\/09\\\/ai-governance-regulation-standards.jpg\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#mainImage\",\"width\":1200,\"height\":630,\"caption\":\"EU AI Act Compliance Is a Pipeline, Not a PDF\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/188\\\/#mainImage\"},\"datePublished\":\"2026-09-26T08:01:00+00:00\",\"dateModified\":\"2026-09-26T08:01:00+00:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/\",\"name\":\"Grigoriy Dobryakov - IT+AI Blog\",\"description\":\"Grigoriy Dobryakov's blog: management, development and testing\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.dobryakov.net\\\/blog\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"EU AI Act Compliance Is a Pipeline, Not a PDF","description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.","canonical_url":"https:\/\/www.dobryakov.net\/blog\/188\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/www.dobryakov.net\/blog\/188\/#blogposting","name":"EU AI Act Compliance Is a Pipeline, Not a PDF","headline":"EU AI Act Compliance Is a Pipeline, Not a PDF","author":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"publisher":{"@id":"https:\/\/www.dobryakov.net\/blog\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/www.dobryakov.net\/blog\/wp-content\/uploads\/2026\/09\/ai-governance-regulation-standards.jpg","width":1200,"height":630,"caption":"EU AI Act Compliance Is a Pipeline, Not a PDF"},"datePublished":"2026-09-26T08:01:00+00:00","dateModified":"2026-09-26T08:01:00+00:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/www.dobryakov.net\/blog\/188\/#webpage"},"isPartOf":{"@id":"https:\/\/www.dobryakov.net\/blog\/188\/#webpage"},"articleSection":"AI Governance, C2PA, compliance automation, eu-ai-act, high-risk AI, iso-42001"},{"@type":"BreadcrumbList","@id":"https:\/\/www.dobryakov.net\/blog\/188\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog#listItem","position":1,"name":"Home","item":"https:\/\/www.dobryakov.net\/blog","nextItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","name":"AI Governance"}},{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","position":2,"name":"AI Governance","item":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/","nextItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/188\/#listItem","name":"EU AI Act Compliance Is a Pipeline, Not a PDF"},"previousItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/188\/#listItem","position":3,"name":"EU AI Act Compliance Is a Pipeline, Not a PDF","previousItem":{"@type":"ListItem","@id":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/#listItem","name":"AI Governance"}}]},{"@type":"Organization","@id":"https:\/\/www.dobryakov.net\/blog\/#organization","name":"Grigoriy Dobryakov - IT+AI Blog","description":"Grigoriy Dobryakov's blog: management, development and testing","url":"https:\/\/www.dobryakov.net\/blog\/"},{"@type":"WebPage","@id":"https:\/\/www.dobryakov.net\/blog\/188\/#webpage","url":"https:\/\/www.dobryakov.net\/blog\/188\/","name":"EU AI Act Compliance Is a Pipeline, Not a PDF","description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/www.dobryakov.net\/blog\/#website"},"breadcrumb":{"@id":"https:\/\/www.dobryakov.net\/blog\/188\/#breadcrumblist"},"author":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"creator":{"@id":"https:\/\/www.dobryakov.net\/blog\/author\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/www.dobryakov.net\/blog\/wp-content\/uploads\/2026\/09\/ai-governance-regulation-standards.jpg","@id":"https:\/\/www.dobryakov.net\/blog\/188\/#mainImage","width":1200,"height":630,"caption":"EU AI Act Compliance Is a Pipeline, Not a PDF"},"primaryImageOfPage":{"@id":"https:\/\/www.dobryakov.net\/blog\/188\/#mainImage"},"datePublished":"2026-09-26T08:01:00+00:00","dateModified":"2026-09-26T08:01:00+00:00"},{"@type":"WebSite","@id":"https:\/\/www.dobryakov.net\/blog\/#website","url":"https:\/\/www.dobryakov.net\/blog\/","name":"Grigoriy Dobryakov - IT+AI Blog","description":"Grigoriy Dobryakov's blog: management, development and testing","inLanguage":"en-US","publisher":{"@id":"https:\/\/www.dobryakov.net\/blog\/#organization"}}]},"og:locale":"en_US","og:site_name":"Grigoriy Dobryakov - IT+AI Blog - Grigoriy Dobryakov's blog: management, development and testing","og:type":"article","og:title":"EU AI Act Compliance Is a Pipeline, Not a PDF","og:description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.","og:url":"https:\/\/www.dobryakov.net\/blog\/188\/","article:published_time":"2026-09-26T08:01:00+00:00","article:modified_time":"2026-09-26T08:01:00+00:00","twitter:card":"summary_large_image","twitter:title":"EU AI Act Compliance Is a Pipeline, Not a PDF","twitter:description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts."},"aioseo_meta_data":{"post_id":"188","title":"EU AI Act Compliance Is a Pipeline, Not a PDF","description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.","keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":"EU AI Act Compliance Is a Pipeline, Not a PDF","og_description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.","og_object_type":"default","og_image_type":"default","og_image_custom_url":null,"og_image_custom_fields":null,"og_image_url":null,"og_image_width":null,"og_image_height":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_image_url":null,"twitter_title":"EU AI Act Compliance Is a Pipeline, Not a PDF","twitter_description":"How to turn EU AI Act and ISO 42001 requirements into automated CI\/CD gates, risk classification, and C2PA provenance artifacts.","schema_type":"default","schema_type_options":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"limit_modified_date":false,"ai":null,"breadcrumb_settings":null,"seo_analyzer_scan_date":null,"created":"2026-09-26 08:01:14","updated":"2026-09-26 08:01:14"},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.dobryakov.net\/blog\" title=\"Home\">Home<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\t<a href=\"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/\" title=\"AI Governance\">AI Governance<\/a>\n\t\t<\/span><span class=\"aioseo-breadcrumb-separator\">&raquo;<\/span><span class=\"aioseo-breadcrumb\">\n\t\t\tEU AI Act Compliance Is a Pipeline, Not a PDF\n\t\t<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/www.dobryakov.net\/blog"},{"label":"AI Governance","link":"https:\/\/www.dobryakov.net\/blog\/category\/ai-governance\/"},{"label":"EU AI Act Compliance Is a Pipeline, Not a PDF","link":"https:\/\/www.dobryakov.net\/blog\/188\/"}],"_links":{"self":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts\/188","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"replies":[{"embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/comments?post=188"}],"version-history":[{"count":0,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/posts\/188\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/media\/187"}],"wp:attachment":[{"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/media?parent=188"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/categories?post=188"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.dobryakov.net\/blog\/wp-json\/wp\/v2\/tags?post=188"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}