The AI Incident Database allows users to consult incidents and harms associated with artificial intelligence systems. In parallel, on 29 June 2026, the Consejo de la Unión Europea approved a revision of the timetable applicable to high-risk systems. The coexistence of these two facts does not prove a causal relationship. It does, however, leave a specific question for each organisation · what changes in your systems between one governance decision and the next.
The operational question of this criterion fits on one line · who governs what changes between meetings? Periodic review remains necessary, but may be insufficient when a provider modifies a model, a use case emerges or the operating context changes before the next session. The gap is not presumed: it is measured by comparing those changes with the actual capacity to detect and address them.
The timing gap · check it yourself
The exact cadence varies by provider, model and deployment method. To understand your own, it is useful to compare release notes and changes recorded by the providers you use with minutes, technical reviews and internal incidents from the same period. The difference is not a universal maturity index. It is evidence for deciding whether the review frequency, thresholds and assigned responsibilities are sufficient for the risk assumed.
The governing body does not need to meet for every minor change. It needs to define who monitors, which event requires an extraordinary review and who can restrict or suspend a use while it is being assessed. Criterion 09 develops that discipline. Here, what matters is identifying the distance between the formal schedule and operations.
Shadow AI · the scope the organisation did not declare
The most urgent phenomenon in auditing practice for certified systems has a technical name · Shadow AI. Sales teams drafting proposals with general-purpose models by uploading identifiable client information. Legal departments uploading confidential contracts to assisted review tools without a data processing agreement. Human resources assessing candidates with scoring from providers absent from the asset inventory. Finance operating its own predictive models without technical documentation or periodic revalidation.
The operational taxonomy distinguishes three types of AI asset · direct use of third-party tools, internally built prototypes, and AI embedded in providers’ products — the least visible of the three, because it arrives inside software already inventoried as something else.
Criterion 03 uses the term epistemic scope for the boundary between what an assessment covers and what it leaves out. Shadow AI is that boundary applied to artificial intelligence · an organisation can have a certified management system while maintaining AI uses outside the scope of the system, the inventory or the risk assessment. The certificate must be read against its specific scope, not as blanket coverage of all technology used.
Three dimensions that get confused
AI governance operates across three dimensions. The management system · policies, inventory, assigned responsibilities, records. Technical risk · bias, drift, explainability, robustness. Legal compliance · the obligations each jurisdiction brings into effect by date. Each dimension is audited differently and documented differently. The recurring field error is using one to conceal another · presenting the management system when asked about model drift, or the legal opinion when asked about the inventory.
The framework that already exists · read without overstatement
ISO/IEC 42001:2023 provides the certifiable framework for an AI management system: policies, objectives, processes, operation, evaluation and improvement of the responsible use of artificial intelligence systems. ISO/IEC 42005 provides guidance on AI system impact assessments. And the piece that completes the circuit brings the matter into the domain of this doctrine · ISO/IEC 42006 sets requirements for bodies that audit and certify AI management systems. The accreditation chain has reached artificial intelligence.
The existence of these standards does not demonstrate that an organisation has implemented them or that a certificate covers all its AI uses. To establish that, one must examine the management system’s scope, the applicable accreditation and operational evidence.
The European regulatory clock, as read on 29 June 2026, also has different dates. The prohibitions under Regulation (EU) 2024/1689 have applied since February 2025, and obligations for general-purpose models since August 2025. According to the revised timetable communicated by the Consejo, certain transparency obligations apply from 2 December 2026; the high-risk rules covered by the reform apply from 2 December 2027 or 2 August 2028, depending on the type of system. Each organisation must determine which role and date apply to it.
Human oversight · effective, nominal or absent
The phrase «there is a human in the loop» needs evidence. Defensible oversight identifies what the person reviews, with what information, against which criteria and with what authority to confirm, escalate or stop. The absence of a blocked decision does not in itself demonstrate that the control is nominal; it requires looking for other evidence of its exercise, such as escalations, corrections, documented disagreements or tests of the intervention mechanism.
Drift does not allow an identical recipe for all systems either. When its likelihood or impact is significant, the control needs metrics, thresholds, frequency and an assigned owner. Promising that a model will not change goes beyond what can be substantiated; stating how material changes are detected and addressed is auditable.
The criterion test
The test begins with the inventory. Compare the official register with purchases, integrations, software contracts, interviews and other lawful and proportionate traces. A penalty-free disclosure period can help recover unregistered uses, but it is a governance decision, not a requirement of a standard or a guarantee of completeness. Each discrepancy found must be classified by use case, data, assigned owner, scope and risk. The next step is to decide what to incorporate, what to restrict and what to withdraw.
Governance begins when exposure ceases to be anonymous. An identified use can have an assigned owner, review criteria and evidence. A use that remains outside the inventory cannot receive any of those controls.