⚡ Quick Summary
Published by Deeploy, this whitepaper presents a practical AI governance framework for organisations in regulated industries, with particular attention to the EU AI Act and related requirements. It distinguishes predictive, generative, and agentic AI; compares open-weight and closed-weight models; and frames governance across three lifecycle stages: ideation, building, and operationalising. It also outlines the AI Act’s four risk levels, organisational roles including provider and deployer, and a timeline of stated implementation dates through August 2028.
The proposed mechanism combines an organisational Artificial Intelligence Management System (AIMS) with use-case-level assessment and implementation. Its executive summary describes a control framework with eight categories and 40 specific controls, spanning governance operations, risk management, data governance, transparency, human oversight, operations, lifecycle management, and agentic AI governance. For agents that pursue goals across multiple steps and tools, the whitepaper adds eight controls covering registration, step-level tracing, intent documentation, intervention points, permission boundaries, multi-agent accountability, behavioural monitoring, and incident classification.
🧩 What’s Covered
The document progresses from AI concepts and regulation to implementation and specific controls:
- AI landscape: Defines predictive AI as forecasting from historical data, generative AI as creating new content, and agentic AI as goal-directed systems that can select tools and take sequences of actions. It sets out different governance emphases for each, including accuracy and fairness for predictive systems, content and behaviour for generative systems, and action and accountability for agents.
- Model sourcing and general-purpose AI: Contrasts truly open-source and open-weight approaches with closed-source systems, discussing transparency, dependency, security, data processing, and possible provider responsibilities. It explains that organisations using general-purpose AI remain responsible for their application design, users, risk assessment, and oversight.
- Lifecycle governance: Organises intervention into ideation, building, and operationalising. It associates these stages with early risk classification, data and ownership planning, bias and performance validation, documentation, security controls, monitoring, incident response, and version control.
- Regulation and standards: Summarises the EU AI Act’s risk-based structure, provider, deployer, and distributor roles, high-risk requirements, and stated implementation timeline. It also identifies intersections with GDPR, DSA, DMA, DORA, ISO 42001, AIUC-1, and selected non-EU approaches.
- AIMS and use-case implementation: Recommends clear ownership, an AI registry, documentation templates, AI-use policies, a risk assessment process, an incident response process, AI literacy, and CI/CD-integrated testing. It lists preliminary risk assessment, DPIA, FRIA, vendor assessment, and conformity assessment as potentially required assessments.
- Core controls: Describes controls for policies and roles; system registries, risk assessment and classification; data documentation and bias detection; explainability and user instructions; human monitoring and intervention; logging, performance, robustness and security; and version control, sign-off and technical documentation.
- Maturity, conformity and agents: Provides three maturity levels with priority actions, then addresses conformity assessment, CE marking and EU database registration for high-risk systems. The agentic chapter explains autonomy, tool use and multi-agent orchestration before specifying controls AG1 through AG8.
💡 Why it matters?
The whitepaper gives governance, compliance, legal, data, and technical teams a shared route from an inventory of AI use cases to controls and evidence. Its use-case approach helps distinguish obligations that depend on intended purpose and risk level rather than on the model alone. The links it draws between risk assessment, data governance, transparency, human oversight, logging, security, and lifecycle documentation support operational preparation for the AI Act requirements it describes.
Its agentic AI section is especially relevant where systems can access data, call APIs, alter records, or trigger workflows. It shifts attention from reviewing a final output to documenting permissions, tracing intermediate actions, monitoring behaviour against intended scope, and placing human approvals before consequential actions.
❓ What’s Missing
The document is a practical overview rather than a complete legal analysis or implementation manual. It names policy elements, documentation types, assessments, controls, and maturity actions, but does not supply completed templates, detailed testing procedures, technical reference architectures, or a worked end-to-end assessment for a real deployment. Its treatment of GDPR, other EU instruments, and approaches in the UK, US, China, and Singapore is introductory. It also presents several claims about implementation timelines and standards without reproducing their underlying legal or technical sources. The stated number of controls requires clarification: the executive summary refers to 40 specific controls, while the maturity assessment refers to implementing all 32 controls in Chapter 4.
👥 Best For
Best suited to AI governance leads establishing an AIMS, compliance and legal teams mapping AI Act-facing processes, and data or engineering teams operationalising registries, documentation, monitoring, and lifecycle controls. It is particularly relevant to teams deploying agentic systems with tool access, external actions, or multi-agent workflows.
📄 Source Details
AI Governance & Control Framework is a 48-page English whitepaper published by Deeploy. It is Version 3.0, dated August 2026, and names Maarten Stolk, Tim Kleinloog, Ellen Mik, Markus Heid, and Georgia Keegan as authors. The document contains a chapter on Deeploy and lists the organisation’s Utrecht address, but no HTTP(S) URL for the PDF itself is printed.