"Governance" sounds like paperwork you do after the fun part. It isn't. It's a classifier: given what your system does and who it touches, the law and your risk framework tell you which obligations attach — and getting the tier wrong is how a shipped product becomes an unshippable one. This page lets you run that classifier on your own system.
The EU AI Act doesn't regulate "AI" as one thing. It sorts systems into four tiers by risk, and the obligations scale with the tier: minimal-risk systems are essentially free, limited-risk ones owe transparency, high-risk ones carry heavy engineering and documentation duties, and a short list of uses is simply banned. The tier isn't about how clever the model is — it's about what it decides and about whom.
Tick what describes your system and watch where it lands. The tier is always the highest one any single answer triggers — one high-risk use case pulls the whole system up:
Two things people get wrong. First, most systems are minimal-risk — a spam filter or a recommender owes almost nothing, and treating it like a high-risk system is its own kind of failure (wasted quarters). Second, the transparency tier is easy to forget: if a user could mistake your system for a human, or you generate synthetic media, you must say so — that's a real obligation with a low bar to meet and a high cost to miss.
The EU Act tells you what you owe; the NIST AI Risk Management Framework is how a team actually runs risk day to day. It's four functions, and the crucial part is that it's a loop, not a checklist you complete once. Govern sets the culture and accountability that the other three run inside; you Map context and risks, Measure them, then Manage — and new information sends you back around. Step through it:
All of this stays abstract until it's written down, and the standard place to write it is a model card — a one-page datasheet shipped with the model. Intended use and out-of-scope uses; the training data and its known gaps; performance broken down by subgroup, not just an aggregate; limitations and ethical considerations. It's the document an auditor, a customer, and the engineer who inherits this in a year all read first. A high-risk EU AI Act system essentially requires this content; every system benefits from it.
Second opinion (the topic is taught here — these corroborate and are the official sources): EU AI Act Explorer · NIST AI Risk Management Framework · Google — Model Cards.