Logiciel Solutions Contact Us
Success Stories Tech News Investors Contact Us
whitepaper

Production AI Under Regulation.

Compliance programmes are built to reach a signature. The duties that decide whether a regulated AI system stays lawful are the ones that only begin once it is answering real traffic: monitoring that has to keep running, logs that have to keep accumulating, declared performance that has to keep holding, incidents timed from the moment somebody understood, and a modification rule that a routine model upgrade can trip. None of it carries a completion date, and none of it can be produced afterwards by anyone who did not capture it while the system ran.

In depth

The Duties With No Completion Date Begin The Day Traffic Does.

01

Nothing in the high-risk regime ends at approval.

The technical file gets signed, the assessment closes and the team treats the work as delivered, while the heavier half of the Act sits on the other side of go-live. Articles 12, 15, 72 and 73 describe things a system does while it is running, not things a project produced before it shipped. Read them as operating requirements with a legal consequence attached rather than paperwork with an engineering footnote.

In shortRead them as operating requirements with a legal con…
02

Post-market monitoring is a time series, and the plan is its cover page.

Article 72 asks a provider to collect, document and analyse performance data across the operational life of the system, so what an assessor eventually reads is the series itself: input drift, quality against the metrics you declared, override and escalation rates, complaint volume, and a note of what each reading changed. The usual failure is structural rather than lazy, since monitoring is funded as a launch task, the dashboard ships, and two quarters later no threshold has been tuned and nobody can say what March looked like. A monitoring system with no named owner and no record of action taken reads on paper exactly like no monitoring at all.

In shortA monitoring system with no named owner and no recor…
03

A model upgrade can reopen conformity on a Thursday afternoon.

Substantial modification triggers a fresh conformity assessment, and Article 25 lets a deployer who changes the intended purpose become the provider of a system it bought, yet swapping a base model, retraining on new data, widening the decision scope or granting one more tool all look like ordinary engineering inside a pull request. This is the duty with no natural owner, since legal is not in the release path and the engineer bumping a version number has no reason to think about Article 43. The remedy is procedural rather than technical, and it amounts to one mandatory question in the release template plus a named person allowed to hold the merge on the answer.

In shortThe remedy is procedural rather than technical, and…
The detail

Three Duties That Only A Running System Can Discharge.

Each of these is satisfied by something the system produces while it serves traffic, or it is not satisfied at all. They are also the three that look finished on launch day, which is precisely why they are the ones an audit finds wide open two years later.

Zone · 01

Records across the lifetime

Article 12 wants events recorded automatically over the lifetime of a system, and Article 17 puts their retention inside the quality management system. Two things go wrong reliably. A window sized against storage cost in 2026 decides what still exists in 2028, and the record holds sensitive input, so it needs a classification, an access rule and a lawful basis of its own.

Zone · 02

Accuracy after a year

Article 15 asks for accuracy, robustness and cybersecurity across the lifecycle rather than at the moment of assessment, which is a stronger demand than it sounds. Declared metrics sit in the instructions for use while live traffic drifts away from the distribution they were measured on, and the declaration quietly stops being true while the documentation stays signed and valid.

Zone · 03

Timed from awareness

Article 73 runs from the point a causal link is established, and from awareness before that, which makes awareness the field nobody writes down. The trigger is as likely to be a complaint, a journalist or your own evaluation run as an alert, so the question put to you later is always who first understood what had happened, and when.

By the numbers

The figures that make it a board-level conversation.

2 Aug 2025
serious incident reporting live for providers of general-purpose models with systemic risk
72 hours
to notify a personal data breach, counted from awareness rather than from confirmation
1 field
in the release template, between a modification you assessed and one an auditor finds later
Inside the report

What you'll take away.

01

Step 1 - Give every monitoring signal a named owner

Settle what this system is measured on in production, what an out-of-range reading triggers and who reads the numbers weekly. The dated note of what each reading changed is the part an assessor asks for.

02

Step 2 - Make the log wide enough to explain a decision

Model and version, the resolved prompt, retrieved context with document identifiers, every tool call and its result, the output returned, and the human decision that followed it.

03

Step 3 - Put the conformity question in the release template

One mandatory field asking whether this change touches intended purpose, model version, training data, decision scope or the action set, with a yes routed to a reviewer who can hold the merge.

04

Step 4 - Bind each deployed version to the run that cleared it

A dated record tying the live version to its evaluation results, prompt and model pinned together so a rollback restores both, the logging configuration in force, and whoever approved it.

Questions

Frequently asked.

Which AI Act duties actually start when a system goes live?

The ones weighted after entry into service: post-market monitoring under Article 72, automatic logging under Articles 12 and 17, accuracy, robustness and cybersecurity held across the lifecycle under Article 15, and serious incident reporting under Article 73. Not one of them has a point at which it is finished.

Is a monitoring plan enough to satisfy Article 72?

No. The plan is a document and the duty is the data behind it, collected, documented and analysed across the operational life of the system. What gets requested is the series: drift, quality against declared metrics, override rates, complaint volume, and a record of what each signal changed and who acted on it.

Can a routine retrain really reopen conformity?

Yes, and this is the version of the rule teams walk into rather than choose. A substantial modification needs a fresh assessment, and changing the base model, the training data, the decision scope or the action set are all candidates. None of them announces itself as a regulatory event inside a pull request.

When does an incident clock start, and from what?

From awareness, which is the timestamp nobody captures. Article 73 reporting runs from establishing a causal link, the GDPR gives 72 hours from awareness of a breach, NIS2 wants an early warning inside 24 hours, and DORA an initial notification four hours after classification. One event, four different starting guns.

Nothing has gone wrong yet, so where should we start?

Switch on the two records nobody can produce later: full trace and event capture with retention set against the longest duty the system carries, and a monitoring series with tuned thresholds and someone reading it every week. Each covers only the stretch since it started, so a quarter of delay is a quarter you will never have.

How does this differ from your engineering reference for production systems?

Read this one for what the law asks of a system already in service, and that one for the machinery that answers it. Production AI: An Engineering Reference covers evaluation, release gating, rollback, drift, cost and end-of-life as operational controls. The duties here are the reason several of those controls stop being optional.

Who is this report written for?

Heads of engineering, CISOs and heads of risk who own a system that is already serving traffic. It assumes the approval work is behind you and asks the harder question, which is what your release process and your telemetry would show if somebody examined both of them this quarter.

Get the whitepaper

Have it emailed to you.

Drop your details and we'll send Production AI Under Regulation straight to your inbox - no spam, unsubscribe anytime.

Download whitepaper
Next step

Go-live is where the obligation starts, not where the project ends.

Bring one system already serving traffic and we will map the duties running against it today, the evidence it currently produces by itself, and the gaps that no amount of later effort can close. Two hours with engineers. SECTION 7 - FAQ - 5 to 8 questions

Book a production review