EU AI Act: what leaders need to know
Few pieces of regulation have generated as much misunderstanding as the European AI Act. In the boardrooms we sit in, it occupies an odd place: everyone has heard of it, almost no one knows what it concretely requires of their organisation, and most file it mentally under "legal problem, deal with it later". That filing decision is what ends up costing money.
The regulation, adopted in March 2024, phases in through 2027. It sorts AI systems into four risk tiers. Uses deemed unacceptable risk — social scoring, subliminal manipulation, certain forms of biometric identification — are banned outright. High-risk systems, those touching recruitment, credit, health, education or justice, carry heavy obligations: technical documentation, risk management, data quality, human oversight, registration in a European database. Limited-risk systems such as chatbots or generated content carry a transparency duty: the user must know they are dealing with a machine. Everything else is minimal risk and attracts no specific obligation.
The architecture looks simple. It becomes considerably less so the moment you apply it to a real organisation.
The first trap is believing compliance is decided at the level of the tool. It is decided at the level of the use. The same language model, used to summarise meeting notes, sits in minimal risk; used to shortlist job applications, it moves to high risk with every obligation that follows. It is not the technology that is classified, it is what you do with it. An organisation that rolls out a conversational assistant company-wide without governing its uses does not, in truth, know which category it falls into — and that uncertainty is itself a risk.
The second trap is the calendar. Many executives hear "2027" and conclude they have time. But the deadline that matters is not the one for entry into force: it is the one for bringing systems already in production into compliance. Reconstructing the technical documentation of a model deployed two years ago, tracing the provenance of its training data, demonstrating that human oversight existed by design — all of that is vastly more expensive after the fact than at design time. Compliance debt behaves like technical debt: it accrues quietly and falls due at the worst possible moment.
The case below describes no company in particular: it assembles observations gathered across several organisations. A services company has spent eighteen months deploying a series of off-the-shelf AI tools: a writing assistant for the sales teams, a recommendation engine for customer service, a CV-screening aid for HR. Each rollout was driven by the business unit concerned, with no central coordination. Asked about its exposure to the AI Act, the executive team discovers three things. First, that the third tool falls under high risk and that none of the corresponding obligations were anticipated. Second, that no one in the organisation holds a map of the AI systems in service — it takes several weeks to rebuild one. Third, that the contracts signed with vendors say nothing about supplying the technical documentation the regulation demands, which leaves the company poorly placed to obtain it.
None of those three findings is a legal matter. They are governance failures.
This is where our reading of the subject departs from a law firm's. The AI Act is not best handled as a compliance exercise, but as a question of organisational design. At KAIROS Impulse we start such engagements by mapping actual usage before analysing the text: which systems are running, who deployed them, on what data, for what decisions, with what level of human oversight. That map almost always surfaces blind spots — tools adopted locally, features switched on by default inside office suites, experiments that quietly became permanent. The regulatory work proper only begins afterwards, and it moves far faster, because it applies to a known perimeter.
There is a common objection to this approach, and it deserves to be taken seriously: compliance supposedly slows innovation. Our experience suggests the opposite, on one condition. An organisation that knows exactly where its high-risk systems sit can move much faster on everything else, because it no longer needs to apply blanket caution to every new initiative. Regulatory uncertainty is a far stronger brake than regulation itself. It is the organisations that do not know where they stand that stall their own projects out of prudence.
The human dimension of this subject is underrated too. The human-oversight requirement at the heart of the high-risk regime is not a box to tick: it assumes someone is able to understand the machine's decision, challenge its output and answer for it. That takes skills, allocated time and genuine authority. Decorative oversight — an operator rubber-stamping recommendations they have no means of evaluating — satisfies neither the spirit nor the letter of the regulation, and exposes the organisation far more than it protects it.
If you take away only three questions for your next board meeting, make them these. First, do we hold a current inventory of the AI systems running in this organisation, including those that never passed through IT? Second, which of those systems take part in decisions about people — hiring, evaluation, access to a service, pricing? Third, for those systems, could we produce today the documentation, the data lineage and the evidence of human oversight the regulation requires? If any of those answers is uncertain, the issue is not a legal one. It is strategic, and it belongs on the executive agenda.
Comments
Be the first to comment on this article.
The KAIROS Brief
Get our monthly read on AI.