Governance-first AI: shipping under the EU AI Act and China's rules
For manufacturers selling into Europe and operating in China, governance is not paperwork you add at the end. Built in early, it is faster, not slower.

Manufacturers feel caught between two regimes: the EU AI Act's risk tiers and China's own framework for algorithms and data. The instinct is to treat compliance as a final gate. That is exactly what makes it slow and painful.
Classify the use case, not the company
Do not classify factory-floor AI from the technology label alone. Under the EU AI Act, intended purpose matters: a system may be high-risk when it serves as a safety component of a regulated product requiring third-party conformity assessment, or when its intended use falls within a listed high-risk area. Inspection assistance, production scheduling, employment decisions and safety control can therefore create different obligations. Confirm the classification for the actual use case and market.
Audit logs are a feature, not a cost
The same trace that satisfies an auditor also tells your operators why the model flagged a part. Build it once and it serves quality, debugging, and compliance at the same time. Governance that is wired in at the data layer is cheaper than governance bolted on after launch.
Keep data residency explicit, keep a human in the loop for decisions that carry real cost, and keep the model's reasoning legible to the people who depend on it. Do that and crossing borders becomes a checklist, not a rebuild.
Risk classification follows intended purpose
It is unsafe to classify an AI system from the words factory, vision or assistant alone. Under the EU AI Act, intended purpose and the role of the system matter. A tool may enter the high-risk category when it is a safety component of a regulated product requiring third-party conformity assessment, or when its intended use falls within a listed high-risk area. An inspection aid, an employment decision tool and a safety controller can therefore create very different obligations even inside the same company.
China also requires scope discipline. The Interim Measures for Generative AI Services apply to services providing generated content to the public in China, while internal research or application not offered to the public is treated differently under that instrument. Other cybersecurity, data, personal-information, algorithm and sector rules may still apply. The correct first step is a use-case and data-flow assessment, not a universal statement that a private system is exempt or compliant.
Govern the decision, data and change path
A practical governance record should answer three questions. What decision does the system influence, and who remains accountable? What data enters, where does it come from, and what boundary prevents unintended reuse? What changes can occur after approval, and who reviews them? These questions produce concrete controls: named owners, approved sources, access rules, evaluation evidence, version records and change gates.
One evidence trail can serve several teams
Quality wants to know why a part was flagged. Operations wants to know whether the workflow is slowing the line. IT wants to know which model and data source were active. Management wants to know who accepted the risk. A connected evidence trail can answer all four without creating separate copies of truth. That is why governance built into delivery is usually faster than governance performed as a document collection exercise before launch.
Use a living management review
Management review should look across the portfolio: which initiatives are active, which decisions they influence, which risks remain open, which controls lack evidence, and which incidents or user complaints require action. The review does not need to become a large committee. It needs a cadence, a decision owner and a record of what changed. Legal classification should be confirmed with qualified counsel for the relevant market; the operating system should make that advice executable.