Legal Framework
Article 22(1) and Article 22(4) of the AI Act establish the core governance obligations for the board of a provider of a high-risk AI system. Article 22(1) mandates that providers establish a board responsible for ensuring compliance with the Regulation. Article 22(4) explicitly requires that the board's decision-making procedures and voting mechanisms are documented, formal, and structured to enable effective oversight of the AI system's compliance, including its conformity assessment. The law requires these internal governance structures to be robust and transparent to fulfill the board's accountability function.
Practical Application
The legal requirement for formalized procedures is interpreted as creating a demonstrable audit trail for board oversight. As established in case law such as Client Earth v. EFSA, necessity and proportionality are key principles; the board's documented procedures must be designed to ascertain the objectivity and integrity of the provider's operations, justifying its governance actions. Following the balancing logic seen in Dennekamp v. European Parliament, the board must ensure its procedures allow for the full application of all relevant legal obligations, without granting automatic priority to operational efficiency over fundamental compliance duties. Organizations must therefore implement and record clear protocols for how the board reviews, challenges, and approves key compliance decisions.
Key Considerations
- Document Formal Procedures: Implement and maintain written terms of reference for the board that detail specific voting thresholds, agenda-setting, information rights, and the process for escalating and resolving compliance concerns related to the high-risk AI system.
- Ensure Informed Oversight: Establish mechanisms to guarantee the board receives timely, comprehensive, and understandable information from management on all material compliance risks, conformity assessment results, and post-market monitoring findings to base its decisions on.
- Balance Competing Interests: Design decision-making protocols that proactively balance and document the consideration of competing requirements, such as transparency obligations versus the protection of confidential business information or personal data, as part of the board's deliberation process.