In September 2024, the European Union’s AI Office released the formal text of the AI Pact commitments — a voluntary framework inviting organisations worldwide to proactively adopt key principles of the EU AI Act before its transitional period ends.
The moment I read it, one thought came to mind: we’ve been building this since day one.
At OrdoNova, human oversight isn’t a compliance checkbox. It’s the architectural foundation. But the EU AI Pact matters enormously — not just for organisations operating in Europe, but for every enterprise serious about deploying AI responsibly. So let me walk through the full text of the commitments exactly as published, then share what each one means to us in practice.
What Is the EU AI Pact?
Before we get into the text, a brief frame: the EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. Most of its requirements apply at the end of a transitional period — meaning the law is real, but many deadlines haven’t hit yet. The AI Pact is the EU AI Office’s mechanism to close that gap. It asks organisations to voluntarily commit to the spirit of the law now, rather than scrambling later.
This is the right instinct. The companies that treat AI governance as a last-minute compliance exercise will fail — not just legally, but operationally. Governance baked in from the start is a competitive advantage. Governance bolted on after the fact is a liability.
Here is the complete official text of the AI Pact commitments, published by the EU AI Office in September 2024.
The Full EU AI Pact Commitment Text
Artificial Intelligence (AI) is a transformative technology with numerous beneficial effects. Yet, its advancement brings also potential risks. In light of this, the European Union has adopted the first-ever comprehensive legal framework on AI worldwide, the AI Act. The majority of rules of the AI Act (for example, some requirements on the high-risk AI systems) will apply at the end of a transitional period (i.e. the time between entry into force and date of applicability). In this context and within the framework of the AI Pact, the AI Office calls on all organisations to proactively work towards implementing some of the key provisions of the AI Act, with the aim of establishing best practices for mitigating the risks to health, safety and fundamental rights.
By taking part in this initiative, organisations agree to make three “core” commitments and may decide to strive to meet all the other commitments mentioned, or to select specific ones, depending on, for instance, their area of activity. Organisations may sign the core commitments and any other commitments they deem relevant at a first stage, and then sign further non-core commitments at a later stage.
The commitments are mostly focusing on transparency obligations and requirements for AI systems that are likely to classify as high-risk under the AI Act. Furthermore, depending on their position in the AI value chain, some organisations may not be able to meet themselves the commitments. In these cases, such organisations may also declare their intention to contribute to the best of their ability to the fulfilment of the commitments. When joining the initiative, organisations will have the opportunity to communicate to the general public, in general terms, how they intend to work towards the commitments in their specific context. The AI Pact encourages AI systems’ providers and deployers to commit to the pledges that are relevant to them, and to share their best practices, irrespective of whether these organisations are currently putting into service or placing into the EU market high-risk AI systems.
OrdoNova Observation
Note the phrase “irrespective of whether these organisations are currently putting into service high-risk AI systems.” The EU isn’t waiting for you to hit a risk threshold before asking you to govern. Neither should you. Governance is a practice, not a reaction.
The Three Core Commitments
Taking these considerations into account, for the period starting from the submission of the AI Pact commitments and ending with the entry into application of the relevant provisions of the AI Act, all organisations participating to this initiative agree to make best efforts to meet or contribute to the following “core” commitments:
- adopt an AI governance strategy to foster the uptake of AI in the organisation and work towards future compliance with the AI Act;
- carry out to the extent feasible a mapping of AI systems provided or deployed in areas that would be considered high-risk under the AI Act;
- promote awareness and AI literacy of their staff and other persons dealing with AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context the AI systems are to be used in, and considering the persons or groups of persons affected by the use of the AI systems.
OrdoNova Observation
Three commitments, and every single one is about humans — governance strategy (humans deciding policy), risk mapping (humans identifying exposure), and AI literacy (humans understanding the tools they operate). The EU is sending a clear signal: AI governance is fundamentally a human discipline. Technology is the instrument; accountability is always human. This is exactly why BotSpot was built with audit trails and role-based governance from day one — not as a feature, but as architecture.
Commitments for AI Developers
For organisations that develop AI systems, where relevant in light of future obligations, to the extent feasible:
- put in place processes to identify possible known and reasonably foreseeable risks to health, safety and fundamental rights that could follow from the use of relevant AI systems throughout their lifecycle;
- develop policies to ensure high-quality training, validation and testing datasets for relevant AI systems;
- when developing all or certain AI systems, implement logging features to allow traceability appropriate for the intended purpose of the system;
- inform deployers about how to appropriately use relevant AI systems, their capabilities, limitations and potential risks;
- implement concrete measures to ensure human oversight over the operation of high-risk AI systems as defined by the AI-Act;
- implement policies and processes aimed at mitigating risks associated with the use of relevant AI systems, in line with the relevant obligations and requirements envisaged in the AI Act, to the extent feasible;
- design AI systems intended to directly interact with individuals so that those are informed, as appropriate, that they are interacting with an AI system;
- design generative AI systems so that AI-generated content is marked and detectable as artificially generated or manipulated through technical solutions, such as watermarks and metadata identifiers;
- provide means for deployers to clearly and distinguishably label AI-generated content, including image, audio or video constituting deep fakes;
- provide means for deployers to clearly and distinguishably label AI-generated text published to inform the public on matters of public interest, unless the text has been subject to human review and a natural or legal person holds editorial responsibility for its publication.
OrdoNova Observation
Two items jump out. First: “implement concrete measures to ensure human oversight over the operation of high-risk AI systems.” The word “concrete” matters. Not aspirational policies. Not mission statements. Actual mechanisms — checkboxes, approval gates, audit logs, escalation paths. This is precisely what the Human-in-the-Loop controls in BotWorks enforce. Second: AI-generated content must be marked and detectable. This isn’t a nice-to-have. It’s rapidly becoming the global standard. More on what OrdoNova is building in response — below.
Commitments for AI Deployers
For organisations that deploy AI systems, where relevant in light of future obligations, to the extent feasible:
- carry out a mapping of known and reasonably foreseeable possible risks to fundamental rights of persons and groups of individuals that may be affected through the use of relevant AI systems;
- implement concrete measures to ensure human oversight over the operation of high-risk AI systems as defined by the AI-Act;
- clearly and distinguishably label AI generated content including image, audio or video constituting deep fakes;
- clearly and distinguishably label AI-generated text published to inform the public on matters of public interest, unless the text has been subject to human review and a natural or legal person holds editorial responsibility for its publication;
- ensure that individuals are informed, as appropriate, when they are directly interacting with an AI system;
- inform with clear and meaningful explanations individuals when a decision made about them is prepared, recommended or taken by relevant AI systems with an adverse impact on their health, safety or fundamental rights;
- when deploying relevant AI systems at the workplace, inform workers’ representatives and affected workers.
OrdoNova Observation
Every commitment here is about transparency to humans — employees, individuals, workers’ representatives. The EU is building a legal framework where AI cannot operate in the dark. Decisions affecting people must be explainable. Workers must be informed. Individuals must know when they’re interacting with an AI. For enterprise deployers, this changes the architecture of every customer-facing and employee-facing AI workflow. You can’t retrofit this. You have to design for it from the start.
The Reporting Obligation
The participating organisations consent to the AI Office publicly share the commitments they intend to meet and to report on the outcome of the implementation of these commitments twelve months after the publication of their commitments.
OrdoNova Observation
Voluntary commitments with a public report card, twelve months out. This is smart governance design. Accountability without enforcement tends to drift. Public reporting creates reputational stakes, which drives genuine implementation. The enterprises that treat this seriously will build real systems. The ones that sign the pact for the press release will face uncomfortable questions in twelve months. Choose accordingly.
OrdoNova’s Position: Human In the Loop Is Not a Feature. It’s a Principle.
Reading the EU AI Pact is, for us, a confirmation — not a course correction. Every commitment the EU AI Office is asking organisations to aspire toward is something we made foundational decisions about when we designed OrdoNova.
Here’s what “human in the loop” means at OrdoNova in concrete terms:
- Every agent action is logged. BotSpot maintains a full audit trail of every AI agent invocation — what was requested, what model responded, what decision was made, and which human had visibility or authority over that decision.
- High-risk actions require human approval gates. BotWorks allows organisations to designate workflow steps that cannot proceed without explicit human sign-off. The agent presents its recommendation. The human decides. The system enforces this — not optionally, by design.
- Roles and scopes govern agent permissions. No agent in BotSpot operates beyond its policy-defined scope. A compliance agent cannot take financial actions. A marketing agent cannot access HR data. The boundaries are enforced architecturally, not through trust.
- Everything is explainable. If an AI recommendation affected a business decision, a person can trace it back — step by step, input by output — in plain language. Not a black box summary. A full explanation.
What We’re Building Next: The AI Signature and the Human Review Gate
Inspired by the EU AI Pact’s call to mark AI-generated content, and consistent with our own belief that transparency is the foundation of trust, we are adding two new features to our platform roadmap:
1. The OrdoNova AI Signature
Every piece of content, every report, every analysis, and every communication generated by an OrdoNova AI agent will carry a visible AI Signature — a clear, standardised label indicating that the output was AI-generated. This is not a warning label. It’s a transparency label. We believe AI-generated work can be exceptional work. But the people receiving it deserve to know its provenance.
This blog post, for example, closes with our AI Signature. We’re starting the practice now, and building it into every AI-assisted output across the platform.
2. The Human Review Checkbox
Before any AI-generated output in BotSpot or BotWorks can be deployed — sent to a customer, submitted to a regulator, published on a website, or executed as a business action — a named human must confirm they have reviewed it. A checkbox. A name. A timestamp. Logged, auditable, and mandatory.
This isn’t bureaucracy. This is accountability made concrete. The EU AI Pact says “implement concrete measures to ensure human oversight.” We think the most concrete measure possible is a human being who cannot press “deploy” until they have confirmed they reviewed what the AI produced.
Humans control AI. Not the other way around. That’s not just our tagline — it’s the mechanism we’re building into every workflow.
A Note to Enterprise Leaders
The EU AI Pact is voluntary today. The AI Act’s full requirements are coming. And even before legal enforcement, the organisations adopting this framework now are building the competency, the culture, and the infrastructure that will make them genuinely AI-capable enterprises — not just AI-experimenting ones.
If you’re evaluating an enterprise AI platform, ask your vendor this question: “Where is the human in this workflow?”
If the answer is vague, that’s your answer.
We’d be glad to show you exactly where the human is in every OrdoNova workflow. It won’t take long to find them.
OrdoNova AI Transparency Label
🤖 Generated by AI · ✅ Reviewed by Human
This article was drafted with AI assistance and reviewed, edited, and approved by Dhaval Patel before publication. OrdoNova is committed to transparent disclosure on all AI-assisted content.