# Governance Report — Integration assistance (MIIOS X)

_HumanOSE — governance preparation, assurance support and audit-ready evidence. No legal compliance certification._

**Product:** HumanOSE  
**Use Case:** uc\_miios\_001 (v1)  
**Source system:** miios-x  
**Language:** EN  
**Data mode:** synthetic  
**Generated at:** 2026-09-04T07:43:39.264Z  
**Report status:** Provisionally classified  
**Integrity hash:** 2175fccca9bfdd3f…  

> This report is based exclusively on synthetic data (pilot operation). No real personal data.

> This report does not certify legal compliance.

## Executive summary

Classification and hints on synthetic integration metadata — no live MIIOS, no PII.

- **Intended purpose:** Human-reviewed integration hints — no automatic system coupling.
- **Preliminary risk class:** Limited risk — review transparency obligations
- **Human oversight required:** No
- **Governance Readiness:** 1/2 Controls with evidence/reviewed

> Governance Readiness denotes the degree of preparation (evidence in place/reviewed) — it does not certify conformity.

## Use case profile

- **Intended purpose:** Human-reviewed integration hints — no automatic system coupling.
- **Affected groups of persons:** —
- **Data sources:** integrationsmetadaten\_synthetisch
- **AI function:** classification, recommendation
- **Potential impact:** operativ
- **Jurisdiction:** eu-de
- **Source system:** miios-x
- **Lifecycle state:** Provisionally classified

## Risk assessment (preliminary)

- **Preliminary risk class:** Limited risk — review transparency obligations
- **Confidence of the assessment:** high
- **Ruleset:** v0.1.0
- **Human review required:** No

> The risk classification is preliminary and does not replace a legal assessment.

### Reasoning (rule reference)

- R-LIM-TRANSPARENCY-01 — Generative or recommending AI function — transparency and labeling obligations must be reviewed.

### Recommended risk mitigations

- Label AI-generated content as such; escalation to a human is possible at any time.

### Uncertainty of the assessment

Rule set v0.1 works with internal review heuristics on the EU AI Act, GDPR, Swiss DSG and the UK context. The assessment depends on the completeness of the registry entries and does not replace a legal review.

## Policy & control overview

> The control status documents the review of the evidence — it does not certify conformity.

| Control | Reference | Status | Evidence |
|---|---|---|---|
| Transparency & labeling | EU AI Act Art. 13 / 50 | Evidence attached | 1 |
| AI literacy of those involved | EU AI Act Art. 4 | Open | 0 |

### Open gaps

- AI literacy of those involved

## Human oversight

- **Responsible human:** Oversight assignment pending — a final responsible human must be named before approval.
- **Reviewer:** —

> Human responsibility remains mandatory; AI does not make automatic decisions about persons.

### Review history

No review decisions recorded yet.

## Evidence summary

- **Evidence chain status:** invalid (suspected tampering)
- **Number of evidence events:** 45
- **Verification passed:** No

> Simulated anchoring (PageCipher integration pending) — marked as a simulation.

| # | Timestamp | Actor | Action | Hash |
|---|---|---|---|---|
| 818 | 2026-09-04T06:42:27.362Z | actor\_system\_humanose | governance\_report\_generated | 037b52aacc64… |
| 824 | 2026-09-04T06:44:03.766Z | actor\_system\_humanose | governance\_report\_generated | 63b61486359f… |
| 844 | 2026-09-04T06:47:30.947Z | actor\_system\_humanose | governance\_report\_generated | 142ac5eb69c0… |
| 1098 | 2026-09-04T07:40:21.648Z | actor\_system\_humanose | governance\_report\_generated | 6286099846f7… |
| 1124 | 2026-09-04T07:41:29.245Z | actor\_system\_humanose | governance\_report\_generated | 39566fceadd7… |
| 1136 | 2026-09-04T07:41:32.286Z | actor\_system\_humanose | governance\_report\_generated | 63903e91c32d… |
| 1146 | 2026-09-04T07:42:05.041Z | actor\_system\_humanose | governance\_report\_generated | afb7195ad6e4… |
| 1148 | 2026-09-04T07:42:41.663Z | actor\_system\_humanose | governance\_report\_generated | 5cf920cda3b8… |
| 1152 | 2026-09-04T07:42:43.356Z | actor\_system\_humanose | governance\_report\_generated | 1bf8914ddd21… |
| 1154 | 2026-09-04T07:42:47.207Z | actor\_system\_humanose | governance\_report\_generated | 34eb2a0233c7… |
| 1156 | 2026-09-04T07:42:47.711Z | actor\_system\_humanose | governance\_report\_generated | 1af17b456822… |
| 1158 | 2026-09-04T07:43:07.246Z | actor\_system\_humanose | governance\_report\_generated | 66c497e387ff… |
| 1160 | 2026-09-04T07:43:08.000Z | actor\_system\_humanose | governance\_report\_generated | 3a71f9c652ab… |
| 1162 | 2026-09-04T07:43:38.272Z | actor\_system\_humanose | governance\_report\_generated | 127e25183611… |

### PageCipher anchor status

- **PageCipher integration status:** Active (HTTP integration with PageCipher)
- **PageCipher anchor status:** 39/45 Anchored
- **PageCipher anchor reference:** pagecipher:8d152a155d83d8fa52653917d71511a1
- **Last anchoring attempt:** 2026-09-04T07:43:38.277Z

> The PageCipher anchor proves the integrity and provenance of the evidence — it does not certify legal compliance.

## Open risks & gaps

- 1 open controls without evidence

## Legal notices (disclaimer)

- This report does not certify legal compliance.
- The risk classification is preliminary and does not replace a legal assessment.
- The legal assessment may require a specialized legal review.
- This report serves governance and compliance preparation on an evidence basis. It does not constitute legal advice, certification, or a conformity attestation.
- Human responsibility remains mandatory; AI does not make automatic decisions about persons.

## Appendix

### Control catalog

| Control | Source | Reference |
|---|---|---|
| Check for prohibited practices | eu\_ai\_act | EU AI Act Art. 5 |
| Risk management system | eu\_ai\_act | EU AI Act Art. 9 |
| Data governance | eu\_ai\_act | EU AI Act Art. 10 |
| Technical documentation (Annex IV-like) | eu\_ai\_act | EU AI Act Art. 11 / Annex IV |
| Record-keeping / logging | eu\_ai\_act | EU AI Act Art. 12 |
| Transparency & labeling | eu\_ai\_act | EU AI Act Art. 13 / 50 |
| Human oversight | eu\_ai\_act | EU AI Act Art. 14 |
| Accuracy, robustness, cybersecurity | eu\_ai\_act | EU AI Act Art. 15 |
| Lawfulness of processing | gdpr | DSGVO Art. 6 |
| Data minimization | gdpr | DSGVO Art. 5(1c) |
| Data protection impact assessment (DPIA) | gdpr | DSGVO Art. 35 |
| Data subject rights | gdpr | DSGVO Art. 12–22 |
| Bias monitoring | internal\_policy | SysTec Policy AI-BIAS-01 |
| AI literacy of those involved | ai\_literacy | EU AI Act Art. 4 |
| Access control | security | ISO 27001 A.9 (Referenz) |
| Audit/evidence chain | audit | SysTec Evidence Standard (ADR-003) |

### Generation metadata

- **Generated at:** 2026-09-04T07:43:39.264Z
- **Version:** 0.1.0
- **Language coverage:** 100 %
- **Number of evidence events:** 1163
