Skip to main content
Promotional banner for the pentest readiness checklist
AI Governance Checklist: Aligning with the EU's General-Purpose AI CodeRegulatory Compliance
5 min readFor Risk Managers

AI Governance Checklist: Aligning with the EU's General-Purpose AI Code

Why You Need This Checklist

The European Commission's General-Purpose AI Code of Practice, released on July 10, 2025, isn't mandatory yet. However, treating it as a roadmap now can prepare your organization for future regulatory demands.

This checklist breaks down the Code's three core sections, transparency, copyright, and safety and security, into actionable steps. Use it to audit your AI operations, identify gaps, and document proactive risk management. If your organization develops, deploys, or relies on general-purpose AI systems (like image recognition, speech processing, or translation), this checklist is for you.

Prerequisites

Before diving in:

  • Define your AI inventory. List all general-purpose AI systems your organization uses or develops, including both in-house models and third-party services.
  • Assign ownership. Identify who owns each AI system, such as product managers or IT leads, to provide necessary technical details.
  • Gather existing documentation. Collect design documents, vendor contracts, data processing agreements, security assessments, and energy consumption records.
  • Establish a cross-functional review team. Include legal experts for copyright issues, information security for safety controls, and technical leads for transparency documentation.

The Checklist

Transparency

Technical Documentation

  • Maintain up-to-date technical documentation for each AI system, detailing:
    • Design (architecture, model type, training methodology)
    • Functionality (inference methods, decision logic)
    • Energy consumption metrics (if measurable; otherwise, plan to capture this)
  • Review and update documents quarterly or when significant changes occur
  • Store documentation in a centralized, version-controlled repository accessible to compliance, legal, and audit teams

Transparency Commitments

  • Document data sources for each AI model
  • Identify third-party datasets, APIs, or pre-trained models used
  • Create a transparency statement for each system, explaining its purpose, capabilities, and limitations in plain language
  • Establish a process to disclose AI-generated content to users when required

Copyright

Content Source Verification

  • Audit training data sources for copyright status:
    • Public domain materials (verify copyright expiration)
    • Licensed content (confirm license terms permit AI training)
    • User-generated content (review terms of service and consent)
    • Scraped web content (assess legal risk and consider removal)
  • Document the provenance of all training datasets
  • Establish a process to respond to copyright holder objections or opt-out requests

Licensing and Attribution

  • Review vendor contracts for AI services to confirm indemnification against copyright claims
  • Consult legal counsel on fair use arguments and licensing strategies for in-house AI development
  • Create an attribution log for any copyrighted materials used under license
  • Implement a copyright compliance review before deploying new AI models

Safety and Security

Cybersecurity Controls

  • Conduct a cybersecurity risk assessment for each AI system:
    • Identify attack vectors (adversarial inputs, data poisoning, model theft)
    • Assess data exposure risks (training data leakage, inference attacks)
    • Evaluate access controls and authentication mechanisms
  • Monitor for anomalous AI behavior (unexpected outputs, performance degradation)
  • Establish incident response procedures for AI-related information security events
  • Apply encryption to AI model files and training datasets at rest and in transit

Impact Assessment

  • Evaluate the societal and operational impact of each high-impact AI system:
    • Potential for bias or discrimination
    • Effect on employment or decision-making processes
    • Environmental impact (energy consumption, carbon footprint)
  • Document mitigation measures for identified risks
  • Establish a review cadence (at least annually) to reassess impact as usage scales

Organizational Commitments

  • Commit to ongoing AI risk monitoring and reporting to senior leadership
  • Establish clear accountability for AI governance (assign an AI risk owner)
  • Implement technical safeguards against misuse or unintended harm
  • Provide training to employees who develop, deploy, or interact with AI systems
  • Create a mechanism for users to report AI-related concerns or harms
  • Conduct regular third-party audits or assessments of high-impact AI systems
  • Maintain a public-facing AI ethics statement or responsible AI policy
  • Engage with stakeholders (customers, employees, regulators) on AI practices
  • Participate in industry forums or standards development for AI governance
  • Plan for the decommissioning or retirement of AI systems, including data deletion

Customizing the Checklist

Tailor to Your AI Footprint

If you primarily use third-party AI services, focus on vendor due diligence: request transparency documentation, copyright indemnification, and security certifications. If you develop AI in-house, emphasize technical documentation and copyright audits.

Adjust for Risk Appetite

High-impact AI systems (those affecting critical decisions or processing sensitive data) need deeper scrutiny. Apply the full checklist to these systems. For lower-risk applications, you might consolidate documentation or reduce review frequency.

Align with Existing Frameworks

Integrate this checklist with your current risk management or compliance programs. Add AI-specific entries to your Cybersecurity Risk Register or include AI governance policies in your policy attestation process. Avoid creating a separate AI governance structure.

Adapt Terminology

Replace "general-purpose AI" with categories relevant to your organization, like machine learning models or natural language processing tools. Use language your technical teams understand.

Validation Steps

Internal Review

  • Schedule a walkthrough with AI system owners. Confirm they can produce the required documentation. Identify gaps.
  • Test your documentation against a hypothetical regulatory inquiry: Could you explain, within 48 hours, how a specific AI system was trained, what copyrighted materials it used, and what security controls protect it?

External Benchmarking

  • Compare your practices to the Code of Practice text itself. Note where your documentation exceeds or falls short of the guidance.
  • If you operate in the EU or serve EU customers, consult with legal counsel on whether the Code's non-mandatory status will shift as the EU AI Act matures.

Audit Readiness

  • Share this checklist with your internal audit function. Ask them to validate that the evidence you've gathered would satisfy an external auditor or regulator.
  • Conduct a tabletop exercise: simulate a copyright claim or a Information Security Incident involving an AI system. Walk through your response using the documentation this checklist produces.

Continuous Improvement

  • Set a quarterly review cycle. AI systems evolve rapidly; your governance documentation must keep pace.
  • Monitor regulatory developments. The Code of Practice may become mandatory, or new obligations may emerge. Update this checklist accordingly.

The Code isn't enforceable today. But organizations that wait for enforcement before building AI governance will scramble under pressure. Use this checklist to get ahead of the curve.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like