If the phrase means nothing to you, this page will make more sense in ninety seconds.
A stage gate is a scheduled decision point. Before a project can spend the next tranche of budget, it comes to a meeting and shows evidence that it is safe to continue. Most organisations run four to six of them across a project's life, under PRINCE2, MSP, a PMI-aligned lifecycle or a local variant of one of those.
A gate pack is the set of documents a project brings to that meeting. Your organisation almost certainly has one already. It asks for a business case, a design, a test report, a go-live checklist. It works, because ordinary projects produce deliverables that either meet a specification or do not.
An AI initiative does not produce that. It produces a system that is right most of the time. The gate pack you already own has no question that catches the difference, so the meeting looks at a working demonstration and approves it. Which is not the same as the system being ready.
This is the gate pack for that. Six gates, thirteen documents, and one rule that does most of the work: the threshold a system has to clear is agreed and signed before anyone sees the result.
Fifteen questions at the start decide the lane. Light, Standard or Full. This takes minutes and is free.
Each gate asks for two or three documents. They are short, and each one exists to prevent a specific failure, not to satisfy a policy.
A named person decides. An unsigned artefact does not clear its gate, and an authorisation carries an expiry date.
What you filled in becomes the technical file a regulator, auditor, underwriter or acquirer asks for. You do not write it twice.
The documents an AI initiative brings to each stage gate, and the evidence each one leaves behind.
Six gates, thirteen evidence artefacts and three proportionate lanes for running AI initiatives through the governance your organisation already has. Not a method. An overlay on PRINCE2, MSP or a PMI-aligned lifecycle, which produces your regulatory evidence as a by-product of running delivery rather than as a reconstruction eighteen months later.
Each gate maps to a decision point your process already has. Where your organisation already holds a gate at that point, add the artefacts to it rather than adding a gate. Six new gates in a process that already has five will be routed around within a quarter.
Is this worth governing, and at what weight?
Is the case sound and the data lawful to use?
Is it specified well enough to build?
Did it meet the threshold, or did the demonstration work?
Who is authorising this into production, and on what?
Did the benefit arrive, and is it still behaving?
Governance is proportionate or it is routed around. The triage instrument asks fifteen questions about a single AI initiative and returns its lane, the gates that apply, the evidence artefacts each gate needs, and the regulatory flags it raises. Nothing leaves your browser.
A completed initiative validates rather than being read, and assembles into an evidence bundle cross referenced to EU AI Act Annex IV headings and ISO/IEC 42001 clauses. The assembler catches six things a document review cannot.
The specimen is a general insurer's claims triage assistant, taken through all six gates on the Full lane. It shows a threshold set before evaluation, a subgroup threshold catching what the aggregate hid, an honest attribution note at the benefit review, and a benefit only partially realised with the initiative continued rather than declared a success.
Twenty-eight pages. Gate definitions with entry and exit criteria, thirteen artefact specifications, sign-off blocks, the regulatory crosswalk, and a mapping to PRINCE2, MSP and PMI.
Every artefact in machine readable form, with lane-conditional requirements. A completed initiative validates rather than being read.
Turns a completed initiative into an evidence bundle, cross referenced to Annex IV headings and ISO/IEC 42001 clauses, and refuses the bundles that would not survive a review.
All thirteen artefacts filled, plus the bundle the assembler produces from them. Break a field deliberately and watch which check catches it.
Licensed per team, not per reader. Twelve months of updates included, which matters because the EU AI Act timeline will move again before 2028. Adapt it internally as you like: rename the gates, move the lane thresholds, extend the crosswalk to your own control framework. Everything you produce with it is yours outright.
One programme, one delivery team. Card payment; the pack is sent to your inbox within two working days.
Unlimited internal programmes across one legal entity. Invoiced on thirty-day terms.
Organisation licence plus tailoring. Invoiced on thirty-day terms.
The pack makes the review credible. The review is what your board actually wants. An independent gate review reads one live initiative against the pack, reports what would and would not survive scrutiny, and produces a finding list your internal audit function will recognise.
No, and the difference is testable. A template pack gives you documents. This gives you documents plus a schema and an assembler that refuses a bundle where the thresholds were agreed after the evaluation, or the benefit was measured against a baseline that moved. Break a field in the worked case deliberately and watch which check catches it. That demonstration takes thirty seconds and settles the question.
Very little. Those platforms sell to the CISO, the Chief AI Officer, Legal and Compliance, and they govern the model. This is built for the PMO and the delivery function, and it governs the delivery. If you have a platform, this is what feeds it. If you do not, this is what a change budget can actually buy.
The Digital Omnibus deferred the standalone Annex III obligations to 2 December 2027 and product-embedded ones to 2 August 2028. It did not defer the Article 50 transparency obligations or the Article 4 AI literacy duty, which applied from 2 August 2026. Part of it is already live, and the deferral on the rest is preparation time rather than relief. Initiatives entering delivery now will still be running in December 2027.
The pack is framework-neutral. The worked case is an insurer because that is where the governance vocabulary is sharpest, but the gates map to PRINCE2, MSP and PMI lifecycles rather than to any sector rulebook. The model risk references are marked optional throughout.