How IG Central Works with the EU AI Act
John Woolley
IG Central uses AI to classify documents against your taxonomy, extract structured metadata, detect personal and sensitive data, and apply the right retention and disposition rules. What makes it relevant to the AI Act is not that it uses AI, but how it uses it.
Human oversight is built into the flow, not added on top. Every classification carries a confidence score, and low-confidence work is routed automatically to a human review queue rather than being applied silently. Reviewers can approve, correct or override any decision the model made. The system is designed around the assumption that a person is the final authority, which is exactly the posture Article 14 expects
Nothing happens without a record. Every status change a document goes through produces an audit event, and those events are written using an outbox pattern that guarantees they are not lost even if a service crashes mid-process. Each processing run is recorded with a full timeline of what ran, in what order, and what it produced. When an auditor asks how a given document came to be classified, deleted or retained, the answer is a query, not an archaeology project
Every decision is traceable to its source. IG Central records the provenance of each result: which model produced it, which taxonomy and prompt content were in force, and which server handled it.
The model is pinned to a versioned prompt template, so you always know the exact configuration behind any historical decision. This is the technical documentation and record-keeping the Act asks for, generated as a by-product of normal operation.
The reasoning is visible. Rather than returning a bare label, the system captures and surfaces the classifier's reasoning alongside the result, so the people relying on it can understand and, where needed, challenge it. Transparency stops being a promise and becomes something a reviewer can read.
The system is designed to get better, accountably. Human corrections are not discarded. They are stored and fed back to the model as signal, so the same mistake is less likely next time, and the improvement itself is on the record. That gives you an evidence trail for the accuracy and robustness obligations, and a defensible story about how the system is maintained.
Data governance is the product, not a side effect. Retention policies, disposition actions, legal holds, sensitivity labelling and personal-data detection are first-class capabilities, resolved consistently for every document. The data that feeds your AI, and the data your AI produces, is itself under managed governance. That directly serves the Act's data governance duty, and it means the records the Act generates are managed to the same standard as everything else.
The point most vendors skip: where your data lives
The AI Act's data governance provisions are not only about quality. They are about control. IG Central is deployed as a single-tenant system, which means your documents, your classifications and your audit trail stay inside your own deployment. You are not shipping sensitive records into a shared multi-tenant model to be governed by someone else's controls. For a legal, financial or public-sector organisation weighing AI adoption against confidentiality obligations, that is often the deciding factor, and it is the difference between a governance story you can defend and one you have to take on trust.
Compliance is just the starting point, there is a version of AI Act readiness that is pure cost: consultants, documentation, and a compliance function running to catch up with tools it does not fully understand. There is a better version, where the same controls that satisfy the regulator also make the organisation faster and safer.
That is the governance dividend. The audit trail that proves oversight to an auditor is the same trail that lets you investigate an incident in minutes. The retention engine that satisfies a data governance requirement is the same engine that shrinks your storage bill and your breach exposure. The human-review loop that demonstrates oversight is the same loop that steadily lifts classification quality. Built well, AI governance is not a tax on using AI. It is what lets you use AI on the material that actually matters.
Where to start
You do not have to solve the whole Act to make progress. Start with the highest-value question a regulator, or your own board, will ask: for the AI decisions we already rely on, can we show what happened, why, and who was accountable. If the honest answer is no, that is the gap to close, and it is the gap IG Central was designed to close.

