AI governance

AI governance and the EU AI Act: what your leadership team must decide now

By Elodie Hughes · August 10, 2026 · 8 min read
Leadership team setting up AI governance under the EU AI Act

Since August 2, 2026, the EU AI Act has teeth: the supervisory authorities are in post and fines are possible. The question that reaches the leadership team is no longer whether to engage, it is who decides what, and what can we prove. The problem: on this exact topic, boards are on their own. Search "AI governance AI Act" and you get law firms. Nobody tells you concretely what a leadership team has to decide. Here is that framework.

First, what actually applies (and what was postponed)

Two symmetric mistakes circulate. "Everything lands on August 2": false. "It's all postponed, I do nothing": also false. The digital omnibus adopted in June 2026 pushed the heavy part, the sensitive uses (HR, credit, insurance, education), to December 2, 2027. But transparency on chatbots and generated content, the duty to train staff, prohibited practices and the activation of sanctions all apply now. The detail is in our piece on what the AI Act still requires.

The 4 risk tiers, the image to give the board

The AI Act sorts every AI use into one of four tiers of a pyramid. Think road rules. Tier 1, the forbidden: running a red light, never, for anyone (reading employees' emotions, social-credit-style scoring of people, scraping faces for facial recognition). Tier 2, the sensitive: driving a heavy truck, allowed but with a special licence and a technical inspection; the law calls it high risk, and for a normal company the main entry point is HR. Tier 3, transparency: the turn signal, do what you like but announce it (your chatbot says it is an AI, your realistic generated content is flagged). Tier 4, the free: drive normally. A typical audit in a services SME finds zero or one forbidden use, one to three sensitive ones, and everything else between transparency and free. Governance is knowing which tier each of your uses falls into.

The 4 moves your board must make

1. The inventory. List every AI tool in the company, including the AI hidden in your software (Copilot in Microsoft 365, scoring modules in the CRM or HR system) and your teams' undeclared usage. Roughly one employee in two uses AI tools without their employer's approval (BlackFog study, January 2026). Without this inventory, nothing else is possible.

2. The sorting. Place each use in one of the four tiers. That turns a vague anxiety into a short list of watch points, usually one or two sensitive tools, often on the HR side.

3. The visible, right now. Show on your chatbots that they are bots, flag your realistic generated content. These transparency duties have applied since August 2, 2026, with no grandfather clause: a chatbot installed in 2024 must introduce itself today.

4. Training, and its proof. Article 4 requires training measures proportionate to each role, since February 2025. No automatic fine on this point, but in a control or an incident, the absence of training counts against you. Keep a written trace: who was trained, when, on what. We detailed the obligation on our AI training and the AI Act page.

Who steers: the AI lead and the register

An AI lead is not mandatory, but with no pilot, compliance is nobody's job. Often the DPO, the IT director, a board member or the CEO. Their first tool: a register, a simple spreadsheet to start, listing the tools, their tier, who was trained, the exchanges with vendors. And a principle the GDPR already set: no heavy decision (hiring, firing, credit) can be taken by a machine alone, a human decides.

The real risk is not the fine

On paper, up to 15 million euros or 3% of worldwide turnover for a transparency breach, 35 million or 7% for a prohibited practice. In practice, the first landmark sanctions are expected during 2027 on emblematic cases. The immediate risk is elsewhere: the competitor who reports your silent chatbot, the union that flags your HR tool, the tender lost for lack of proof of compliance. That is why AI governance is a leadership-team topic, not a file you delegate to IT.

This is exactly the work we do with committees in the half-day executive committee session and in the AI Governance Program for boards: map, decide, document. We ran it on our own products first, files in hand. Since 2025, over 300 leaders trained, including at McDonald's, Danone and Nestle Waters.

Want to align your committee and set your AI governance framework in one session? A 20-minute call is enough to scope it.

Get in touch →

Frequently asked questions

Is AI governance mandatory under the EU AI Act?

The AI Act does not impose a specific org chart, but it creates duties (transparency, training, a framework for sensitive uses) that someone must own. With no lead and no register, a company can neither prove compliance nor react to a control. Governance is therefore the practical consequence of the law, even if the word governance is not a checkbox in it.

Do we need to appoint an AI lead?

It is not a legal obligation, but it is strongly advised: with no pilot, AI compliance is nobody's job. It is often the DPO, the IT director, a board member or the CEO. Their role: keep the register of tools, coordinate training and vendor exchanges, and be the point of contact in a control.

Where does board-level AI governance start?

With an inventory of the company's AI tools, including the AI hidden in software and teams' undeclared usage. Then sort each use into one of the AI Act's four risk tiers, fix the visible items (chatbots, generated content), launch training and keep written proof. A spreadsheet is enough to start the register.

Does the AI Act postponement to 2027 remove the need for governance?

No. Only sensitive uses (HR, credit, insurance, education) are postponed to December 2027. Transparency, staff training and prohibited practices already apply. And preparing sensitive uses takes months (vendor contract, human in the loop, works-council consultation), which is why you structure governance now.