Foundry IX
[ Insight ] · Governance

The EU AI Act holds leadership accountable. Not your vendor

Portrait of Jon Hu Hindsgaul HansenJon Hu Hindsgaul Hansen · Partner, Foundry IX · 2 min read
Contract review on a desk
Contract review on a desk
Portrait of Jon Hu Hindsgaul HansenJon Hu Hindsgaul HansenPartner, Foundry IX
Governance · · 2 min read
Share

With the EU AI Act, part of the risk moves from vendor to customer. It isn't your vendor who has to answer for how AI is used in your business. It's you.

The clock is already running

The AI Act phases in over the coming years, and its logic is risk-based: the more consequential the system, the heavier the obligations. But the parts that touch every organisation arrive first. That includes the requirement that the people who work with AI understand it well enough to use it responsibly. That isn't a policy document; it's a competence question.

And the exposure isn't limited to the systems you bought deliberately. Most organisations already run on more AI than leadership knows about: tools employees adopted on their own, and features vendors switched on quietly. A governance answer that only covers the official projects covers a fraction of the actual usage.

What the regulation actually requires

It's leadership that must be able to account for three things:

  • How your AI systems are classified. And why.
  • What risks they carry for customers, employees and the business.
  • How those risks are handled in practice. With named owners.

None of this can be outsourced. A vendor can deliver documentation, but not accountability. The day a system makes a bad call, it isn't the vendor's name on the account.

Redacted document on screen
Compliance works when it's built into the workflow. Not audited in afterwards.

Governance has become a leadership discipline

AI governance is not a legal formality. It is a leadership discipline.

It requires leadership to understand its own AI applications well enough to stand behind them. Not at a technical level, but well enough to know where the systems are used, what they're allowed to do, and when a human needs to step in.

Where to start

The starting point is unglamorous: an inventory. Which systems make or shape decisions in your organisation today? Which of them touch customers, employees or money? Who owns each one? Most leadership teams can't answer those three questions. And answering them is 80 percent of the work the regulation asks for.

The good news: the requirements are manageable for those who approach them in a structured way. An honest risk picture and an action plan that holds up against the EU AI Act and GDPR is a bounded piece of work. Not a year-long project.