Why prompt governance shows up in the Act at all
For agents in an Annex III high-risk use, the deploying organization carries duties that touch the prompt directly: risk management (Art. 9), logging (Art. 12), and accuracy / robustness (Art. 15). A prompt is part of the system these articles govern. If you cannot show what the agent was told and that a guardrail survived a change, you cannot evidence the control.
What versioning evidences
- Art. 9 (risk management) — a versioned prompt with a regression gate is a managed risk control, not an ad-hoc edit.
- Art. 12 (logging) — an exportable history shows what the agent was instructed, when it changed, and the regression result.
- Art. 15 (robustness) — a regression check proves a guardrail was not lost between versions.
What it does not prove
A versioned prompt is evidence of a control, not a conformity certificate. Conformity is the deployer's responsibility across the full system, and the mapping should be validated with qualified counsel — especially because the Digital Omnibus has delayed several high-risk obligations. Annex III extensions currently track toward 2 December 2027; verify the current effective date before committing a timeline.
Using it in practice
Keep prompts versioned and regression-gated, export the history alongside your conformity assessment, and point at the artifact — not at a claim — when asked how you govern prompt change. Treat the version history as living evidence, re-generated on every release.
Authoritative references
- EU AI Act (Reg. 2024/1689), Art. 9 / 12 / 15: https://eur-lex.europa.eu/eli/reg/2024/1689/oj
- AI Act explorer: https://artificialintelligenceact.eu/
- European Commission AI policy: https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai