Skip to main content
M516 Cyber Solutions

AI Governance

The EU AI Act: what regulated firms must do now

Felix · 16 August 2026 · 1 min read

The EU AI Act is phasing in obligations through 2026 and 2027. Here is a practical, evidence-first way to prepare without stalling delivery.

The EU AI Act is the first horizontal AI law with extraterritorial reach. If your models or AI-enabled services touch the EU market, the obligations apply regardless of where your engineering sits.

Start with an inventory you can defend

Most firms cannot answer the first question a supervisor asks: which AI systems are in use, by whom, and for what decision? Build a single register that captures purpose, data sources, model provider, human oversight, and the business owner. Without that register, every downstream control is an assertion rather than evidence.

Classify by risk, not by hype

The Act works in tiers: prohibited practices, high-risk systems, transparency obligations for general-purpose and generative systems, and minimal-risk uses. Classification drives cost. Treat classification as a documented, reviewable decision with named approvers.

Controls that carry the weight

  • Risk management across the AI lifecycle, not just at launch
  • Data governance and provenance for training and prompt data
  • Technical documentation and logging sufficient for reconstruction
  • Human oversight with real authority to stop or override
  • Accuracy, robustness and cybersecurity testing evidenced over time

Reuse what you already have

If you run ISO 27001, your risk assessment, supplier management and change control processes are already close. ISO/IEC 42001 maps AI-specific governance onto that management-system spine, and ISO/IEC 27701 covers the privacy overlay. Building a separate AI programme is usually the more expensive path.

Where firms slip

Shadow AI in productivity tools, vendor models embedded in SaaS features, and pilots that quietly reach production. All three fail the same test: no owner, no record, no evidence.

Governance you can prove starts with an inventory you can trust.

  • EU AI Act
  • AI governance
  • regulation

← All insights

Want this thinking applied to your supplier ecosystem?

A short, no-obligation discovery call to understand your risk profile and where to start.