Summer series note: prepared in advance — one thesis, built to be used. Regular multi-story format returns next week, along with me.
The Thesis
Every edition of this newsletter since May has ended in the same place by a different road: named owners, mapped systems, enforceable rules, reconstructable evidence. The transparency editions got there through Article 50. The supply-chain edition got there through a model vanishing overnight. The agentic editions got there through accountability, and this series got there through topology and perimeters. When every road ends at the same destination, the destination is an architecture. This finale draws it: the AI governance hub — governance implemented as a small set of running services rather than a binder of documents. The thesis is blunt: a policy that is not enforced by infrastructure is a hope, and evidence that is not generated automatically will not exist when asked for. Enterprises that treat the AI Act as a document-production exercise will produce documents; enterprises that treat it as an infrastructure pattern will produce compliance as a by-product of operation — and reuse the same infrastructure for every regime that follows.
The Pattern: Five Components
The hub is cloud-agnostic. Any mature platform can implement it; the components matter, not the logos.
1. The Registry — one inventory to rule them. A single system of record for every AI system, model, agent, and MCP server: what it is, who owns it, what data it touches, which obligations apply, which risk tier it sits in. This is the June system map and the July agent matrix made live — populated by pipeline hooks and discovery scans, not by quarterly spreadsheet archaeology. The registry answers the first question of every audit, information request, and buyer questionnaire: what do you run and who is accountable? One rule makes it real: nothing reaches production without a registry entry and a named owner. No entry, no deploy.
2. The Policy Plane — rules that block, not remind. Machine-enforced policy at the choke points the stack already has: the CI/CD pipeline (no deployment without registry entry, owner, and classification), the MCP gateway (tool-level authorisation, approval gates on consequential actions — Build Lab 2's four non-negotiables), and the identity layer (per-agent identities, no shared service accounts — the July lesson). The test of the policy plane is simple: pick a rule from your AI policy document and try to violate it. If nothing stops you, you have a wish, not a control.
3. The Evidence Pipeline — audit as a by-product. Every consequential event — agent action with authoriser, tool call at the gateway, model version change, disclosure served to a user, marking applied to generated content, oversight approval given or refused — flows to immutable, queryable storage with retention. This is Article 12's logging duty and the incident-reconstruction capability in one build. Design target: the "five questions" folder from Enforcement Eve assembles itself from queries, not from a week of email archaeology.
4. The Oversight Console — where humans actually supervise. Article 14 requires effective human oversight; the console is where "effective" becomes real: pending approvals for gated actions, drift and anomaly flags, kill switches per system and per agent, and the fallback runbooks (June's model-suspension scenario) one click from the operator. Oversight that lives in a wiki is oversight that fails at 2 a.m.; the console is the difference between a right to intervene and the ability to.
5. The Diligence Store — the paper trail with the outside world. Vendor and model records: Annex XII requests and responses, Code-of-Practice signatory status, identity-verification terms, contract clauses on government directives, fallback test results. Half of this newsletter's artifacts since June file here. When the next Fable-style suspension or verification-policy change lands, this store is where "are we exposed?" gets answered in minutes.
Your prompts are leaving out 80% of what you're thinking.
When you type a prompt, you summarize. When you speak one, you explain. Wispr Flow captures your full reasoning — constraints, edge cases, examples, tone — and turns it into clean, structured text you paste into ChatGPT, Claude, or any AI tool. The difference shows up immediately. More context in, fewer follow-ups out.
89% of messages sent with zero edits. Used by teams at OpenAI, Vercel, and Clay. Try Wispr Flow free — works on Mac, Windows, and iPhone.
The Worked Example: Azure
Vendor-neutral pattern, concrete example — Azure, because it is where much of European enterprise already lives. The mapping, one line per component: the Registry builds on Purview's data-governance catalog extended with an AI-system register (or a lightweight app over a governed database — the discipline matters more than the product); the Policy Plane combines Azure Policy for infrastructure rules, deployment gates in Azure DevOps/GitHub Actions, Entra ID for per-agent identities (its workload/agent identity model maps directly to the July requirements), and API Management fronting MCP servers as the gateway; the Evidence Pipeline lands events in Log Analytics/Azure Monitor with immutable storage tiers for retention; the Oversight Console is a thin custom layer — this is the piece you genuinely build — over Monitor workbooks, alerts, and approval flows; the Diligence Store is a governed SharePoint/Dataverse repository with retention labels. Nothing exotic: the estate most Azure enterprises already license, arranged around AI-specific choke points. The equivalent AWS or GCP sentence exists; the components translate one-for-one.
Two cautions from the sovereignty file: running the governance hub on a US hyperscaler is itself a dependency decision — the June/July editions apply to your control plane too, so keep the evidence exportable and the pattern portable. And no platform ships this assembled; every vendor will tell you their catalog is the registry. It isn't, until the no-entry-no-deploy rule makes it so.
What This Buys You
Regulatory readiness, by construction: the registry is your system map, the evidence pipeline is Article 12, the console is Article 14, the diligence store is your Annex XII record — and when the high-risk tier arrives in December 2027, conformity assessment becomes an export from systems that were running all along, not a project that starts that autumn. Commercial readiness, same build: the buyer questionnaires that now gate enterprise deals get answered from the registry and evidence pipeline in an afternoon. And a compounding asset: every future regime — sectoral guidance, the next directive, the first DPA decision on AI access — lands on infrastructure that already knows what you run, who owns it, and what it did last Tuesday.
The Playbook
Start with the registry — two weeks, not two quarters. A governed table with owner, classification, and obligations per system beats a perfect ontology shipping next year. Wire the no-entry-no-deploy rule into CI the same sprint.
Enforce one policy end-to-end before adding ten. The best first candidate: per-agent identity at the MCP gateway. It is checkable, it is the foundation everything else cites, and it converts July's essay into a control.
Point existing logs at one place. You are already logging; the gap is usually consolidation and retention, not instrumentation. The evidence pipeline is mostly plumbing you own.
Build the console thin. A pending-approvals view and a kill switch per system is a sprint, and it is 80% of Article 14's practical value. Resist the platform-purchase reflex until the thin version proves the workflow.
Assign the hub an owner and a budget line. Infrastructure without an owner decays into the binder it replaced. This is the governance hire the seven-to-one edition argued for — with a deliverable.
Artifact: Component → Obligation Map
Component | What it is | AI Act anchor | Also serves |
|---|---|---|---|
Registry | Live inventory: systems, models, agents, MCP servers; owner + classification | System map duty; classification evidence; (2027) Art 49 registration readiness | Buyer questionnaires; NIS2/DORA asset alignment |
Policy Plane | Machine-enforced rules at CI/CD, gateway, identity | Art 14 oversight gates; Art 9 risk controls | Security baseline; cost control |
Evidence Pipeline | Immutable event flow: actions, approvals, markings, versions | Art 12 logging & record-keeping; incident reconstruction | Forensics; buyer evidence |
Oversight Console | Approvals, anomalies, kill switches, runbooks | Art 14 effective human oversight | 2 a.m. incident response |
Diligence Store | Annex XII records, signatory status, contract clauses, fallback tests | Art 53(1)(b) downstream diligence | Vendor risk; continuity (model-suspension scenario) |
The maturity test, in one question: if a regulator's information request arrived Monday, how many of its answers would be queries rather than meetings? Count the meetings. That is your backlog.
That’s it for this week.
That closes the Summer Build Lab — patterns, perimeter, and now the hub that holds it together. Regular editions return next Thursday, with a full reply backlog and, knowing August, some news to catch up on. If you built anything from this series, reply and tell me what — those replies steer the autumn.
Until next Thursday, João
OnAbout.AI delivers strategic AI analysis to enterprise technology leaders. European governance lens. Vendor-agnostic. Actionable.
If this landed in your inbox from a forward — subscribe here to get the full picture every week.



