Companies using AI systems often don’t know which risk class they fall into or which documentation is needed. The mapping is done by hand and has to be redone for every new system.
DataGovern
Five examples of the work DataGovern's agents do on your documents and business processes.
EU AI Act readiness
AI system classification and technical documentation ready before the high-risk obligations apply.
DataGovern keeps the inventory of AI systems and proposes each one’s risk class, which a person confirms. From the inventory it generates the Annex IV technical documentation and the deployer checklist, ready to validate. The FRIA is linked to the systems and the deadlines stay tracked.
What it is
The EU AI Act classifies AI systems by risk level and gives each class different obligations. It applies generally from 2 August 2026. Obligations for high-risk systems start on 2 December 2027, and on 2 August 2028 for those embedded in already regulated products.
References
Regulation (EU) 2024/1689 (AI Act), Art. 26, Art. 27 and Annex IV; Regulation (EU) 2026/1744 for the high-risk dates.
What DataGovern surfaces
NIS2 Compliance Manager
Security measures, posture and 24/72h notifications in one register.
Measures and response plans sit in separate documents. When an incident hits, the deadlines arrive before the evidence.
DataGovern keeps the Article 21 measures register with posture by area and flags gaps against the requirements. When an incident occurs it guides the notification within the 24/72h windows, with evidence ready for the competent authority.
What it is
NIS2 extends cybersecurity obligations to many SMEs in essential and important sectors. It requires technical and organisational measures, risk management and notification of significant incidents: early warning within 24 hours, notification within 72.
References
Directive (EU) 2022/2555 (NIS2), Art. 21; Italian Legislative Decree 138/2024.
What DataGovern surfaces
DataGovern covers the documentary side of NIS2. For attack surface and vulnerabilities there is CyberAgent.
GDPR and data subject requests
Records of processing, DPIAs and data subject requests in one place.
Records in Excel, DPIAs in separate documents, requests handled by email. Deadlines are checked by hand.
DataGovern keeps the records of processing and guided DPIAs with a second person’s opinion. Each data subject request has its deadline and a guided process: identity check, collection, OMISSIS redaction of third parties and a reply letter. Only the designated contact, the DPO and the request’s owner can see it.
What it is
The GDPR requires you to document processing, assess high-risk processing with a DPIA and answer data subject requests within one month, extendable where the law allows.
References
Regulation (EU) 2016/679 (GDPR), Arts. 12, 15-22, 30 and 35.
What DataGovern surfaces
Cross-regulation gap analysis
One remediation plan for GDPR, NIS2, AI Act, CRA and DORA.
Each regulation is handled on its own, with duplicated work and views that don’t connect.
The gap analysis cross-checks the five regulations on their shared requirements. The agent proposes actions and a person confirms each gap. Every confirmed gap becomes a task with an owner and a deadline in the unified remediation plan.
What it is
GDPR, NIS2, AI Act, CRA and DORA often ask for similar measures on risk, security and documentation. CRA and DORA apply only to those in scope: the compliance overview shows their applicability.
References
Regulation (EU) 2016/679 (GDPR); Directive (EU) 2022/2555 (NIS2); Regulation (EU) 2024/1689 (AI Act); Regulation (EU) 2024/2847 (CRA); Regulation (EU) 2022/2554 (DORA).
What DataGovern surfaces
Company brain and decision register
Plain-language questions on documents already indexed, with the source cited.
Anyone looking for a procedure or the reason behind a choice opens files by hand, asks around or redoes the work.
In the Assistant you ask in plain language and the answer cites the document and the passage. Everyone sees only what they can read at the source. The decision register turns decisions into citable sources, visible only to the office they belong to.
What it is
A company’s knowledge sits across shared folders, file servers, mail and repositories. The index DataGovern builds for compliance makes it searchable.
References
Regulation (EU) 2016/679 (GDPR), Art. 5 (data minimisation) and Art. 32 (security of processing).
What DataGovern surfaces
To govern interactions with any LLM, local or remote, there is Admina Enterprise.
DataGovern runs on-premise with open-weight LLMs: compliance data stays in your organisation and approval stays with your team.
