The Conversation Has Changed
For the past two years, much of the business conversation around the EU AI Act has been about preparation.
When will the Act apply?
Which systems will be considered high-risk?
What will organisations eventually need to do?
That phase is changing.
The EU AI Act entered into force on 1 August 2024 and introduced obligations through a phased implementation timetable. Prohibited AI practices and the original AI literacy provisions began applying in February 2025, while governance rules and obligations relating to general-purpose AI models followed in August 2025.
A much broader part of the framework became applicable on 2 August 2026, including important transparency requirements under Article 50.
At the same time, the regulatory framework itself has continued to evolve. The AI Omnibus, which entered into force in July 2026, simplified certain requirements and extended the implementation timetable for high-risk AI systems.
For businesses, this creates an important distinction.
The EU AI Act is now operational. But not every obligation applies to every organisation, every AI tool or every use case. The practical challenge is therefore no longer simply understanding the legislation. It is understanding where the organisation sits within it.
Start with the Use Case, Not the Technology
An organisation might say:
"We use artificial intelligence."
From a governance perspective, that tells us relatively little.
AI might be used to draft internal communications.
It might summarise meeting notes.
It might generate marketing content.
It might support customer service.
It might analyse CVs.
It might recommend candidates.
It might assist with employee performance decisions.
It might generate content presented directly to customers.
These uses do not necessarily create the same regulatory considerations.
The AI Act follows a risk-based framework. Certain practices are prohibited. Some AI systems are classified as high-risk because of their intended purpose and context. Other systems attract specific transparency obligations, while many common AI applications fall outside the high-risk categories.
This means organisations should resist the temptation to classify AI risk based simply on the name of the tool. The relevant question is:
What is the AI system being used to do?
The same underlying technology may support several different use cases within an organisation, each with a different risk profile. A generative AI assistant used to improve the wording of an internal email is very different from an AI system used to evaluate candidates during recruitment. Governance therefore needs to begin with use cases rather than software licences.
Know Whether You Are a Provider or a Deployer
One of the most important concepts in the AI Act is the distinction between organisations that provide AI systems and those that deploy them.
In simplified terms, a provider develops an AI system or general-purpose AI model, or has one developed, and places it on the market or puts it into service under its own name or trademark.
A deployer uses an AI system under its authority, except where the system is used in the course of a personal, non-professional activity.
Many businesses purchasing or subscribing to third-party AI tools will therefore primarily be deployers. That distinction matters because the obligations imposed on providers and deployers are not identical. But organisations should not assume that purchasing technology from an external vendor automatically resolves their governance responsibilities.
A business still needs to understand what system it is using, how it is being used and whether its own use triggers obligations. It should also be alert to circumstances in which modifying, rebranding or substantially changing an AI system could affect its regulatory role. The first governance question should therefore be:
What role do we play in relation to each AI system and use case?
Without answering that question, it is difficult to determine what should happen next.
Build an AI Inventory That Is Actually Useful
For many organisations, one of the most practical first steps is creating an AI inventory. This does not need to become a complex technical database. Its purpose is visibility. A useful inventory should allow the organisation to understand:
- Which AI systems are currently being used.
- What each system is being used for.
- Which function or team owns the use case.
- Whether the technology was procured centrally or adopted independently.
- Whether employees, customers or other individuals interact with the system.
- Whether personal or confidential information is processed.
- Whether AI-generated outputs influence decisions about individuals.
- Which third-party provider supplies the technology.
- Whether human review is part of the process.
This exercise often reveals something important. AI adoption does not always happen through a formal enterprise technology programme.
Employees may use generative AI tools independently. Marketing teams may adopt content-generation platforms. HR may purchase recruitment technology. Customer-service teams may introduce automated interaction tools. Developers may integrate AI models into products.
Without an inventory, organisations can end up governing the AI they know about while remaining unaware of the AI already embedded elsewhere in the business.
The objective should not be to prevent experimentation. It should be to make experimentation visible enough to govern responsibly.
Article 50 Makes Transparency Operational
One of the most immediate changes for businesses comes from Article 50.
The European Commission's guidance on AI transparency obligations confirms that these requirements apply from 2 August 2026.
The obligations differ depending on whether an organisation is the provider or deployer and on the type of AI involved.
Providers of certain AI systems intended to interact directly with individuals must ensure that people are informed that they are interacting with AI, unless this is obvious to a reasonably well-informed, observant and circumspect person in the circumstances.
Providers of systems generating synthetic audio, image, video or text content also face requirements relating to machine-readable marking and detectability of AI-generated or manipulated outputs, subject to the detailed conditions and exceptions in Article 50.
Deployers have their own obligations in particular circumstances.
These include disclosure requirements concerning deepfakes and certain AI-generated or manipulated text published to inform the public on matters of public interest. Deployers of emotion-recognition or biometric-categorisation systems also face transparency requirements towards affected individuals.
The practical lesson for businesses is not: "Label everything created using AI." The requirements are more specific than that.
Instead, organisations should identify which of their use cases fall within Article 50 and establish an appropriate disclosure or marking process where required. That requires coordination between technology, marketing, communications, legal and operational teams rather than treating AI transparency solely as an IT issue.
Not Every AI System Is High-Risk
The term "high-risk AI" is sometimes used very broadly in business discussions. Under the AI Act, however, it has a specific regulatory meaning.
Certain systems used in areas such as employment, education, essential services, biometrics, critical infrastructure, migration and law enforcement can fall within the high-risk framework, subject to the precise conditions established by the legislation.
Employment is particularly relevant for many organisations.
AI systems intended for use in recruitment or selection — for example, to place targeted job advertisements, analyse and filter applications or evaluate candidates — may fall within the high-risk category.
Systems intended to make decisions affecting the terms of employment, promotion or termination, allocate tasks based on individual behaviour or characteristics, or monitor and evaluate worker performance can also fall within the framework.
But the timetable matters.
Following the AI Omnibus, rules for high-risk systems within the relevant Annex III categories are scheduled to apply from 2 December 2027.
High-risk AI systems embedded in regulated products covered by Annex I have a later application date of 2 August 2028. This additional time should not be interpreted as a reason to ignore those systems until the deadline.
Organisations using AI in recruitment, employee management or other potentially high-risk areas should use the implementation period to understand the systems, establish ownership and prepare the necessary governance.
The advantage of starting early is that governance can be integrated into normal business processes rather than added hurriedly immediately before the requirements become applicable.
Human Oversight Needs to Be Real
One of the most common phrases in AI governance is "human in the loop." It sounds reassuring. But simply placing a person somewhere in a process does not automatically create meaningful human oversight.
If an AI system contributes to a consequential decision and the person responsible routinely accepts its recommendation without being able to assess or challenge the output, human oversight may exist formally while adding limited protection in practice.
Can they challenge the output?
Do they have enough information to recognise an unreasonable result?
Are they authorised to override the recommendation?
Do they understand the limitations of the system?
Do they know when escalation is required?
This becomes particularly important when AI influences decisions affecting people.
Even where a particular use case is not currently subject to the full high-risk framework, these are sensible governance questions.
The objective is not to distrust AI outputs automatically. It is to ensure that responsibility for consequential decisions does not disappear simply because technology has been introduced into the process.
AI Literacy Is About Capability, Not a Training Certificate
AI literacy has been another major area of discussion under the Act.
The original Article 4 framework placed an obligation on providers and deployers to take measures to ensure, to their best extent, a sufficient level of AI literacy among staff and others dealing with AI systems on their behalf.
The 2026 AI Omnibus simplified this framework, with the Commission and Member States taking a stronger role in promoting AI literacy.
For organisations, however, the underlying governance principle remains highly relevant. People using AI need enough understanding to use it appropriately. That does not mean every employee needs to understand machine-learning architecture.
Different roles require different levels of knowledge.
Someone using generative AI to help draft marketing copy may need to understand confidentiality, hallucination, intellectual-property considerations and the organisation's rules around AI-generated content.
A manager using AI-supported workforce analysis may need a stronger understanding of data quality, bias, interpretation and the limits of automated recommendations.
A technical team integrating AI into a customer-facing product may require much deeper knowledge of model behaviour, testing, transparency and regulatory responsibilities.
AI literacy should therefore be role- and use-case appropriate. A generic annual training module may create awareness. It does not necessarily create capability.
Vendor Governance Matters
Most organisations will not build every AI system they use. They will purchase technology, subscribe to platforms or integrate services supplied by external providers.
Vendor governance therefore becomes an important part of AI governance.
Before adopting an AI-enabled system, organisations should understand questions such as:
-What AI functionality is actually being provided?
-What is the intended purpose of the system?
-What data does the system process?
-Is customer or employee data used for model training?
-What documentation does the provider make available?
-What controls exist around security and access?
-How are outputs generated and monitored?
-What happens when the provider materially changes the AI functionality?
-What regulatory role does the vendor consider itself to have?
-What information will the organisation need from the vendor to fulfil its own obligations?
These questions should be proportionate to the risk.
A small productivity tool used for low-risk administrative tasks does not necessarily require the same due diligence as an AI system influencing recruitment decisions.
Good governance distinguishes between them.
Documentation Creates the Evidence Layer
AI governance can easily become dominated by policies.
Policies matter.
But a policy saying that AI must be used responsibly does not demonstrate how a particular system was assessed, why it was approved or what safeguards were implemented. This is where documentation becomes valuable. For material AI use cases, organisations should be able to reconstruct the basic governance journey:
What system are we using?
What is it being used for?
Who owns it?
What role do we play under the AI Act?
What risks were identified?
What controls were introduced?
Where is human oversight required?
What information or disclosures are provided to affected individuals?
When will the use case be reviewed again?
The level of documentation should reflect the significance of the use case.
The objective is not paperwork for its own sake. It is preserving enough evidence to demonstrate that AI adoption was deliberate rather than accidental.
SMEs Need Proportionate Governance
The AI Act can appear particularly daunting to smaller organisations.
Terms such as conformity assessment, technical documentation, fundamental-rights impact assessment and post-market monitoring can make AI governance sound like an exercise requiring a large compliance department.
For many SMEs, that is not the right starting point.
Most organisations should first establish a simple governance foundation:
Know what AI you use.
Understand what it does.
Identify who owns the use case.
Determine your regulatory role.
Classify the use according to its context and risk.
Apply appropriate controls.
Keep enough evidence to explain what you did.
More complex requirements can then be applied where the use case genuinely requires them.
Proportionality matters because excessive governance can create its own risk: employees may avoid formal processes altogether and use unapproved tools instead.
The objective should be to make responsible AI use easier than irresponsible AI use.
Governance Should Follow the AI Lifecycle
AI governance should also not end when a tool is approved.
Systems change.
Vendors update models.
Features are introduced.
Teams discover new uses for existing tools.
An AI system originally approved for one purpose may gradually be used for another.
This means governance needs to follow the lifecycle of the use case.
A practical model might look like:
Discover → Assess → Approve → Deploy → Monitor → Review
The review stage is particularly important.
A low-risk use case may become more consequential if the organisation starts using its outputs to influence decisions about employees or customers.
A vendor may introduce functionality that changes how personal information is processed.
A new regulatory requirement may become applicable.
Governance therefore needs to recognise that AI risk is not necessarily static.
What Businesses Should Be Doing Now
For organisations that have already begun using AI, the immediate priority should not be producing an enormous compliance manual. It should be establishing visibility and ownership.
Businesses should know where material AI use exists, which use cases interact with people, which may fall within transparency requirements and which could eventually fall within high-risk categories.
They should understand the distinction between provider and deployer responsibilities. They should review customer-facing and content-generation use cases against Article 50.
They should examine AI used in recruitment, workforce management and other consequential areas with particular care.
They should ensure employees understand the boundaries surrounding the AI tools they use.
And they should begin integrating AI considerations into procurement, information security, data governance and existing risk processes.
The strongest AI governance models are unlikely to operate as completely separate compliance structures. They will connect with governance mechanisms organisations already have.
Key Takeaways
-The EU AI Act is now operational, but obligations remain dependent on the organisation's role and the specific AI use case.
-AI governance should begin with understanding what the system does, not simply which technology vendor provides it.
-A practical AI inventory provides the visibility needed for proportionate governance.
-Article 50 transparency requirements have applied since 2 August 2026 and require businesses to identify the specific use cases to which disclosure or marking obligations apply.
-Not every AI application is high-risk; high-risk is a defined regulatory classification.
-Following the AI Omnibus, relevant Annex III high-risk requirements apply from 2 December 2027, while certain product-related high-risk requirements apply from 2 August 2028.
-Human oversight needs to involve genuine capability to understand, challenge and act on AI outputs.
-AI literacy should reflect the employee's role and the risks associated with the AI being used.
-Third-party AI does not eliminate the need for organisational governance.
-Effective AI governance should be proportionate, evidence-based and integrated into the lifecycle of AI use.
Conclusion
The EU AI Act has entered a different phase.
For businesses, the question is no longer whether AI regulation is coming.
It is how regulation should translate into everyday organisational practice.
That translation does not begin with a hundred-page AI policy.
It begins with visibility.
Which AI systems are being used?
For what purpose?
By whom?
Who is affected?
What regulatory role does the organisation play?
What level of risk does the use case create?
And what controls are proportionate to that risk?
Once those questions can be answered, governance becomes considerably more manageable.
Organisations can distinguish low-risk productivity uses from more consequential applications. They can apply transparency where it is required, strengthen oversight where decisions affect people and prepare systematically for future high-risk requirements.
The objective should not be to slow AI adoption. Nor should compliance become a parallel bureaucracy disconnected from how the organisation actually works. The more sustainable approach is to make governance part of AI adoption itself.
As artificial intelligence becomes embedded across business functions, organisations that build this capability early will be better positioned not only to meet regulatory requirements but also to understand where AI is creating value, where it introduces risk and where human judgement must remain central.
That is ultimately what operational AI governance should achieve:
not simply compliant AI, but AI that the organisation understands well enough to use responsibly.
References & Further Reading
- Regulation (EU) 2024/1689 — Artificial Intelligence Act
- European Commission — AI Act Regulatory Framework
- European Commission — AI Act Enforcement Framework
- European Commission — Guidelines on Article 50 Transparency Obligations
- European Commission — Navigating the AI Act
- European Commission — AI Pact
About ACEVO
ACEVO helps organisations translate regulatory and technological complexity into practical governance structures.
Our work spans compliance readiness, AI governance, workforce governance and digital solutions, with a focus on helping organisations build proportionate frameworks that can operate within real business environments.
As AI becomes increasingly embedded across everyday business processes, ACEVO supports organisations in moving from informal adoption towards structured, evidence-based governance — creating the visibility, accountability and controls required to use emerging technology responsibly while continuing to innovate.

