⚡ Quick Summary
Published by PwC, this slide deck was prepared for Data Day 2025 under the title "How to boost innovation through effective AI Governance?", subtitled "Harnessing the EU AI Act". It explains what the regulation requires and proposes an operating approach for implementing AI governance.
The deck sets out the EU AI Act timeline from entry into force in August 2024 and the phased application of obligations through to product-based high-risk systems in August 2027, cites fines of up to EUR 40 million or 7% of annual turnover, and describes conformity assessment along the AI value chain from hardware provider and model provider to retailer and users. It maps the Act's scope, roles and four risk classes – prohibited, high risk, GPAI and AI with transparency obligations – with the requirements attached to each, including seven high-risk requirements and an article-by-article lifecycle view (Art. 9, 10, 11, 12, 13, 14, 15, 17, 43, 49).
Its deliverable is an implementation model: AI portfolio management with a central inventory and registration process, controls defined, implemented, evaluated and monitored across the lifecycle, and an accountability structure of governance bodies and AI roles, closing with five key takeaways.
🧩 What’s Covered
- EU AI Act timeline and penalties: entry into force in August 2024, then prohibited AI systems after 6 months, codes of practice after 9 months, sanctions after 12 months, GPAI regulation after 12 months (24 months if already on the market), all other aspects such as high risk after 24 months and product-based high-risk systems after 36 months; fines of up to EUR 40 million or 7% of annual turnover; conformity assessment along the entire AI value chain from hardware provider to users.
- Scope, roles and risk classification: territory (AI systems in the Union, including providers established in a third country), application state (placed on the market or put into service, not AI-focused R&D, testing or development), AI systems defined by Article 3(1), four risk classes, and roles including provider, deployer, distributor, importer, authorised representative and GPAI provider.
- The four risk classes and their requirements: definitions of prohibited systems (subliminal manipulation, certain real-time biometric recognition in public spaces, social-behaviour scoring), high-risk systems, GPAI with and without systemic risk, and systems with transparency obligations, each with its requirement list, such as risk management system, data governance, technical documentation, record keeping, transparency, human oversight and accuracy, robustness and cybersecurity.
- Lifecycle management mapped to articles: data management and governance (Art. 10), transparency and explainability (Art. 13, 52), design, development and testing procedures (Art. 17), logging, recording and traceability (Art. 11, 12, 20), accuracy and cybersecurity (Art. 15), oversight and monitoring (Art. 14, 61), conformity, technical documentation and CE marking (Art. 11, 43, 49), registration and reporting (Art. 60, 62), risk classification, impact assessment (Art. 29a) and risk management (Art. 9), and organisation (Art. 17).
- AI portfolio management: a use-case registration process and a centralised AI portfolio inventory system with Responsible AI metrics, controls and lifecycle status dashboards; risks identified and classified against the EU AI Act; control creation according to SOX AI and ISO 42001; continuous documentation, metadata and audit trails; incident management; and named artefacts such as risk assessments, third-party contracts, test reports, Statement of Applicability, ethics standard, risk catalog and training and awareness plan.
- Control cycle: control definition, implementation, evaluation and monitoring, addressing regulatory conformity, risk governance, creation of trust and standardization, with AI system monitoring for deployers and post-market surveillance for providers.
- Operating model and accountability: governance bodies (Data & AI Governance Body, Data & AI Office, Data & AI Oversight Committee), roles (AI Coordinator, AI Manager, Data Owner, Data Steward, Data Custodian, Data Engineer, Data Scientist, ML Engineer), service units and subsidiaries, and the split of responsibility between provider (software development process) and deployer (procurement process).
- Key takeaways: five closing recommendations on standards and controls, an AI inventory with an underlying meta model, a risk-based lifecycle approach with entry gates, defined accountabilities and awareness.
💡 Why it matters?
Organisations that place AI systems on the EU market or use them in the Union face obligations that phase in between 2025 and 2027, with fines cited at up to EUR 40 million or 7% of annual turnover. The deck translates the Act's risk classes and articles into governance mechanics that can be assigned and audited: a registered AI inventory, lifecycle controls, defined entry gates for new use cases and named accountabilities. It also links the Act's requirements to ISO 42001 and SOX AI controls, so compliance, risk and internal audit functions can align existing control frameworks with the regulatory timeline instead of building a parallel programme.
❓ What’s Missing
The deck stays at presentation level: no control templates, meta-model fields, risk-scoring method or worked examples are shown, so the operational detail behind the inventory, controls and entry gates must be developed separately. Risk classification thresholds and the Article 29a impact assessment are named but not explained, and enforcement bodies, penalties per infringement tier and post-market surveillance duties are not covered. Only the EU AI Act is treated; no other regimes or standards are mapped. The material is tied to the Act's original phase-in dates and to references to ISO 42001 and SOX AI controls.
👥 Best For
AI governance and compliance leads in enterprises that develop or deploy AI in the EU and need a structure for phasing obligations into lifecycle controls; risk, internal audit and GRC teams aligning the Act with ISO 42001 and SOX AI controls; and operating-model designers defining AI roles, governance bodies and portfolio registration processes.
📄 Source Details
How to boost innovation through effective AI Governance? carries the printed cover line "Data Day 2025 Harnessing the EU AI Act". Published by PwC; the cover is dated November 2024, slides 3 to 10 carry an "April 2025" header and the final slide carries "© 2025 PwC". Vivien Bender (Manager, PwC Frankfurt | Risk & Reg TPR) is named on the closing slide. 11 pages, English, no series or reference number. "pwc.com" is printed on the final slide but is not a link to this document. Text extraction covered all 11 pages.