AI governance sounds like a legal topic, but it is increasingly a management one. As the European regulatory framework moves forward, having control over what AI does in your company becomes a practical requirement, not a theoretical exercise.
What has changed in the European framework
The EU AI Act, in force since 2024, applies its rules in phases. Prohibited practices have applied since early 2025, and obligations for general-purpose models since August of that year. As for the most demanding obligations, those for high-risk systems, the timeline has been eased: the provisional agreement reached in May 2026 postponed application for stand-alone high-risk systems to December 2027, and for those embedded in regulated products to August 2028. In short, there is more time to prepare, but the direction is clear.
What this means for management
The postponement is no excuse to delay getting your house in order. It means you have a window to organise governance without a last-minute rush. And there are four fronts where control matters, regardless of deadlines.
The four fronts of control
Data. Know which information feeds which system and where it comes from. Without this map, any compliance question becomes a reconstruction nightmare.
Transparency. Know when content or a decision has been generated by AI, and be able to explain it. The European framework strengthens obligations to label artificially generated content.
Risk. Classify where AI makes or supports decisions that affect people, such as recruitment or credit, because that is where the rules are strictest.
Accountability. Define who answers when the system gets it wrong. Accountability cannot be delegated to the algorithm.
The advantage of organising early
Companies that treat governance as a system, rather than a race against a deadline, gain two things. They reduce the risk of fines, which can reach significant percentages of turnover. And they earn the trust of customers and partners, who increasingly ask how AI is used before they sign a deal.
The starting point
You don't need a dedicated legal team to get started. You need an inventory: which AI systems you use, with what data, for which decisions and who is responsible. That map is the foundation for everything else.
Want to understand where you are exposed and what to organise first? Take the AI Diagnostic.
Writes about applied AI, operations, GEO/SEO and how to turn companies into machines that keep running even when no one is watching.
