Skip to main content

AI Governance

Parts of the EU AI Act already apply to your operation. Here is what needs to be in place.

AI literacy obligations under Article 4 have applied since 2 February 2025. High-risk system requirements follow on 2 December 2027, and the next compliance date is 2 December 2026. Most manufacturers have not yet mapped which of their systems are in scope. Three governance programmes cover different starting points. All three share the same goal: a documented, defensible AI operation.

30 minutes. No prep needed. We figure out fit together.

The regulatory reality in numbers

€35M
or 7% of global annual turnover: penalty ceiling for high-risk AI violations
EU AI Act, Article 99
42%
of Europeans currently lack sufficient digital skills for regulated AI contexts
ERT and McKinsey
23%
of organisations have mature AI governance in place
Deloitte and McKinsey 2026
Dec 2, 2027
High-risk AI system obligations (Annex III) become enforceable
EU AI Act as amended by the Digital Omnibus, 2026

What the EU AI Act requires, in plain English

The EU AI Act is a risk-based framework. It classifies AI systems into four tiers (Unacceptable, High-Risk, Limited, and Minimal) and assigns compliance obligations based on where a system falls.

The penalties for non-compliance at the high-risk tier reach €35 million or 7% of global annual turnover, whichever is higher. For other violations, €15 million or 3% of global turnover. These are the actual enforcement ranges, not ceiling figures for rare edge cases.

What the Act requires of organisations operating in-scope AI systems:

  • Register high-risk systems in the EU database
  • Conduct conformity assessments before deployment
  • Maintain technical documentation
  • Implement human oversight mechanisms
  • Take measures to support AI literacy across the organisation (Article 4)

That last requirement is Article 4. It has applied since 2 February 2025 and was not delayed by the Digital Omnibus. The June 2026 revision softened the wording: organisations must take measures to support AI literacy rather than guarantee a level. Any organisation deploying or operating AI systems still carries the obligation today.

According to ERT and McKinsey (industry benchmark), 42% of Europeans currently lack sufficient digital skills. The gap between that baseline and documented AI literacy in a regulated context is not small, and it is already your obligation to close it.

Does this apply to your organisation?

If your organisation deploys, procures, operates, or places on the market any AI system in the EU, the Act applies. This includes:

  • Manufacturers using AI in quality management, production planning, or supplier evaluation
  • Tier-1 and Tier-2 suppliers using AI-assisted tools in customer-facing or safety-relevant processes
  • Any organisation using AI tools that inform decisions about people: hiring, performance assessments, access controls

The risk tier of your systems determines your specific obligations. A predictive maintenance tool may fall in a different tier than a hiring support tool. Classification is the first step.

The Act also applies to organisations that did not build their AI tools. Deployers of third-party AI systems carry compliance obligations depending on how those systems are used. If your team uses AI tools bought off the shelf, that does not eliminate your exposure.

Gartner projects that 40% of agentic AI initiatives will be abandoned by 2027 (industry benchmark). Most will not fail because the technology stopped working. They will fail because the organisation cannot demonstrate what the system is doing, who is overseeing it, or what data it processes. Compliance documentation is what makes that demonstration possible.

Three programmes, three starting points

EU AI Act

Industrial AI Governance Diagnostic

For organisations that need to understand their compliance exposure quickly. Covers AI system inventory, risk tier classification, and an initial gap analysis against EU AI Act requirements.

Outcome:

A written assessment with prioritised compliance gaps and a recommended next step. Entry point for organisations that do not yet have a clear picture of their exposure.

EU AI Act + ISO 42001

Industrial AI Governance Readiness Programme

For organisations that have identified their exposure and need to act on it. Covers the full Diagnostic plus governance training, AI policy and documentation build, and a compliance roadmap.

Outcome:

Documented policies, a trained team, and a clear roadmap through the remaining requirements.

EU AI Act + ISO 42001 + TISAX

Automotive AI Compliance Readiness Programme

For Tier-1 and Tier-2 automotive suppliers operating under TISAX alongside the EU AI Act. Covers the full Readiness Programme plus TISAX alignment work.

Outcome:

Compliant with the EU AI Act, aligned with ISO 42001, and positioned for TISAX AI-related assessment requirements.

What the work actually involves

Every governance engagement builds toward the same five deliverables.

Assessment
AI system inventory and risk tier classification. What systems are in scope, what tier they fall into, and what that means for your specific obligations under the Act.
Gap Analysis
Where your current policies, documentation, and practices fall short of what the Act requires. Prioritised by risk tier and deadline proximity.
Governance Training
Your decision-making team and AI operators understand their obligations under the Act, what Article 4 requires of their role specifically, and what oversight mechanisms they are responsible for.
Documentation
AI usage policies, data governance records, technical documentation for in-scope systems, and human oversight procedures. Written to the standard the Act requires.
Roadmap
A sequenced plan through remaining compliance steps, with timeline and ownership.

The Diagnostic delivers the first two. The Readiness Programme delivers all five.

Know your risk tier in under 5 minutes

ACTS gives you a free risk tier classification and the beginning of a compliance gap picture before you speak to anyone. No email required for the initial result.

The ACTS result is a starting point, not a formal compliance assessment. The governance engagement uses your actual system inventory and operating context to build the full picture.

Not sure what the Act requires?

If you want to understand the EU AI Act before deciding whether you need a governance engagement, start with the plain-English guide.

The revised EU AI Act timeline: what needs to happen when

The Digital Omnibus (adopted June 2026) moved high-risk enforcement to 2 December 2027 for stand-alone systems and 2 August 2028 for AI embedded in products. Article 4 literacy obligations already apply. Plan from your current position using the delivery durations below.

Full Readiness Programme: 10 to 16 weeks

Includes the Diagnostic, documentation framework, training, and compliance roadmap. Compare this duration to your own compliance dates before committing to scope.

Governance Diagnostic: 4 to 6 weeks

Produces a written inventory, classification, and initial gap analysis. Any remediation work follows the diagnostic output.

Already in force

Article 4 AI literacy obligations have applied since 2 February 2025. Prohibited-practice rules apply since then too, with new prohibitions added on 2 December 2026. Classification and documented action are current obligations, not future ones.

A Governance Diagnostic typically takes 4 to 6 weeks from kickoff to written output. A full Readiness Programme runs 10 to 16 weeks, depending on the size of the AI system inventory and the complexity of the documentation gap. The discovery call establishes which programme fits your timeline and scope. It takes 30 minutes.

Start the compliance conversation now

According to Deloitte and McKinsey (2026, industry benchmark), only 23% of organisations have mature AI governance in place. At the same time, 74% are planning to deploy agentic AI within the next 2 years. That gap does not close by itself.

The governance call is 30 minutes. You describe your AI systems and current documentation state. We tell you which programme fits and what a realistic compliance timeline looks like from your current position.

Florin Cusmereanu, founder of AI Fluent

Florin Cusmereanu

Founder, AI Fluent

Florin Cușmereanu spent 12 years in Tier-1 automotive operations managing a EUR 70M annual die-cast portfolio across Europe, running supplier relationships and carrying quality accountability through OEM audit cycles across three continents. He moved to AI because the problems he had lived were exactly the ones most consultants couldn't diagnose from the outside. Every AI Fluent engagement is designed and delivered by Florin personally.

experience
12 years Tier-1 automotive
portfolio
EUR 70M annual die-cast
delivery
founder-led, every engagement

Start the compliance conversation now

30 minutes. No prep needed. Bring what you know.