01 / Source and scope
Who acts, and what changes?
Principal and authority origin
Provider or deployer of an AI system. Provider and deployer governance obligations.
Consequential action
Operate a system that may fall into a regulated risk category.
02 / Action-time control
Make the requested effect testable.
Applicability depends on system classification, role and staged commencement; not every agent is high risk. Determine classification first, then bind human oversight and logging controls where required.
OriginProvider and deployer governance obligations
RequestOperate a system that may fall into a regulated risk category
DecisionEvaluate and enforce before effect
03 / Evidence and responsibility
Permission, execution, and outcome are separate.
Classification rationale, instructions, oversight intervention and logs.
ProofGrid can contribute control evidence, but cannot classify a system or guarantee AI Act compliance.
Primary source