AI Governance & Conformity · OpenChainGraph v0.4
AI Governance & Conformity for Financial Services
The governance layer for the AI systems themselves: EU AI Act high-risk conformity for financial AI (Annex III: credit scoring, insurance pricing, financial-standing) plus agentic AI governance and GPAI classification. Four new tools (ART-64–67) across 8 aig-* chains compose the existing AI-Act/model-risk point tools into a verifiable, hash-anchored conformity lifecycle: classify → provider conformity pack → deployer FRIA + monitoring → fairness → audit. Reflexive tie to the agent-economy runtime: the same agents that transact on that runtime are AI systems that must be governed today.
GPAI Arts 53-55 IN FORCE 2 Aug 2025
Art 5 prohibited practices IN FORCE 2 Aug 2025
Art 4 AI literacy IN FORCE 2 Feb 2025
Annex III high-risk · PREPARE-AHEAD 2 Dec 2027
Art 27 FRIA · PREPARE-AHEAD 2 Dec 2027
Digital Omnibus · verify formal adoption
EU AI Act Reg. 2024/1689
AI Governance
Colorado SB 21-169 · US Insurance Bias IN FORCE
NAIC AIS 2024 · US Insurer AI Readiness
IETF draft-sharif-agent-audit-trail-00
Cluster ③ ↔ Cluster Ⓐ cross-link: Art-239 BIFSG bias testing and the insurance-ai-bias-attestation chain bridge AI Governance (③) and Fair Lending & Adverse Action (Ⓐ). US-licensed insurers running credit-based algorithms face obligations under both Colorado SB 21-169 / Reg 10-1-1 and ECOA disparate-impact rules.
See Fair Lending guide →
✅ DO NOW: Four obligations are IN FORCE as of today (2026-06-20): GPAI/foundation-model obligations (Arts 53–55, including systemic-risk 10^25 FLOP, enforceable 2 Aug 2025, explicitly UNCHANGED by the Digital Omnibus). Art 5 prohibited AI practices (IN FORCE 2 Aug 2025, €35M/7%, the Act's highest penalty). Art 4 AI literacy for providers and deployers (IN FORCE 2 Feb 2025). DORA ICT risk (fully enforced 17 Jan 2025). If you provide or deploy a GPAI model or use AI in a way that could constitute a prohibited practice, action is required NOW.
⚠ PREPARE-AHEAD: Annex III high-risk obligations (Arts 9–15), Art 27 FRIA, and Art 72 post-market monitoring confirmed for 2 Dec 2027 by the Digital Omnibus (provisional agreement 7 May 2026). Verify formal-adoption status. The deferral takes legal effect only if the Omnibus is formally adopted/published before 2 Aug 2026; otherwise the original 2 Aug 2026 date applies. Start preparation now: 18 months of runway against confirmed obligations.
EDUCATIONAL: All outputs are decision-support drafts. Not legal conformity certificates. Verify all Article/Annex references against EU AI Act (Reg. 2024/1689) consolidated text at eur-lex.europa.eu/eli/reg/2024/1689/oj and current Digital Omnibus formal-adoption status.
Lifecycle vs point tools: the uniqueness fix. Five existing tools (art-05 + catalog 327/333/451/452) are standalone point assessments. This hub composes them into a hash-anchored conformity lifecycle: classify (ART-64) → provider Annex IV pack (ART-65) → deployer FRIA + monitoring (ART-66) → agentic-AI governance (ART-67) → fairness → audit. The reused tools become lifecycle stages; their reframe role is stated on every chain page. This is not a re-skin; it is the conformity lifecycle those point tools individually cannot provide.
These tools address obligations already enforceable. Start here regardless of the Annex III high-risk timeline.
Colorado SB 21-169 (in force since 2022) and NAIC AIS guidance (2024) apply now to US-licensed insurers using algorithmic decision-making. Annual Dec 1 attestation deadline.
Annex III high-risk conformity, Art 27 FRIA, and Art 72 post-market monitoring. Start now: 18 months of preparation runway against confirmed obligations.
Art 12(2) logging, Annex III obligation classification, and IETF AAT chain-linked audit trail validation. Start preparation now against confirmed 2027 enforcement.
The AI-Act supply chain from GPAI provider to market-surveillance authority.
Tier 1: AI assurance firms + notified bodies
The verifiers
Big Four AI assurance practices, specialist AI audit firms, and notified bodies that certify high-risk systems. Primary chains: ai-governance-conformity, ai-governance-audit-pack. An endorsed artifact becomes a conformity-evidence standard.
Tier 2: Banks & insurers (providers + deployers)
The primary buyer
Model-risk, compliance, and AI-governance teams at lenders and insurers running high-risk credit/insurance AI. Primary chains: ai-governance-conformity, ai-governance-fria-monitoring, ai-governance-fairness-bias, ai-governance-credit-ai-conformity, ai-governance-resilience-overlap.
Tier 3: GPAI + agentic-AI platforms
The upstream
Foundation-model and agentic-platform providers with GPAI/systemic obligations (in force now). Primary chain: ai-governance-gpai-agentic. The reflexive tie to the agent-economy runtime buyers.
Tier 4: AI governance + RegTech vendors
The embedders (M&A-relevant)
AI governance, model-risk, and compliance-automation vendors embedding aig-* chains as MCP tools. The fastest-growing adjacency (~40% CAGR AI governance TAM). A hash-anchored conformity-evidence layer is what AI-governance tooling lacks.
How the OCG artifact maps onto the record-keeping requirements of Art 12(2), ECOA Reg B §1002.12, ASC 815, and IETF AAT, field by field.