Most organizations already have AI in operation, usually without having decided to. A colleague pastes customer data into a chatbot, marketing generates images with an image model, support runs a tool that automatically classifies cases. AI governance is about taking back control of this: moving from unreflective diffusion to conscious, documented choices. In addition, the EU AI Regulation (Regulation (EU) 2024/1689, adopted 13 June 2024) makes parts of this law. This article is about the internal procedures, not about repeating the law line by line.
What the law actually requires already
A common misconception is that the AI Regulation is something that "takes effect in 2027". That's not true. Two parts apply even thenFebruary 2, 2025: the prohibitions against certain AI uses (Article 5) and the requirement toAI skills(Article 4). Article 4 is worth reading verbatim, as it governs your routines directly:
"Suppliers and providers of AI systems shall take steps to ensure, to the best of their ability, an adequate level of AI knowledge of their staff and other persons managing the operation and use of AI systems on their behalf, taking into account their technical knowledge, experience, education and training and the context in which the AI systems are to be used..."
The heavier requirements for high-risk systems (Articles 9-17 for suppliers, Article 26 for those who use the systems) were postponed in May 2026. In the so-called Digital Omnibus, the Council and the Parliament reached a preliminary agreement on 7 May 2026 to postpone the Annex III obligations (including AI in recruitment, credit assessment, training and biometrics) toDecember 2, 2027and Annex I systems until August 2, 2028. The bottom line for those of you implementing AI in-house: the competency and prohibition rules apply now, and the high-risk requirements are coming. Anyone who starts building routines only in 2027 will be hopelessly behind.
Step 1: Inventory your AI
No governance is possible without a list. The first step is therefore an AI inventory, a living record of all AI systems the organization uses, buys in or builds. For each system, note at least:
What does the system do?and in what process it is used.
Who owns it internally(a named person, not a department).
What data goes in, especially if it is personal information or trade secrets.
Supplier and where the data is processed(EU, US, "don't know" is a valid but worrying answer).
Does the system influence decisions about people(employment, credit, pricing, prioritization)?
In practice, most people find twice as many systems as they thought existed. Shadow AI, tools brought in without decision, are the rule rather than the exception. The inventory should be simple enough to actually update: a shared spreadsheet beats an unused governance platform every time.
Step 2: Risk class the systems
When the list is available, you grade each system. The AI regulation uses four levels that are an excellent mental model even internally:
Prohibited(Article 5): for example, social scoring, workplace emotion recognition and untargeted facial image scraping. If you find something like that, it should be stopped, not controlled.
High risk(Annex III): systems that affect people's access to jobs, credit, education or essential services. Here comes the heavy requirements for documentation, logging and human supervision.
Limited risk: chatbots and generated content, where the main requirement is transparency, that the user knows that it is talking to or seeing AI.
Minimal risk: spell check, spam filter and the like, where voluntary guidelines are sufficient.
Be honest in the grading. The temptation to dismiss a system as "not really AI" or "not making the decisions itself" is great, but a tool that ranks candidates for a recruiter affects the outcome even if a human formally pushes the button. The classification determines how much control each system requires and where you should spend your time.
Step 3: An AI policy that people can follow
An AI policy that no one reads is useless. It must be short, concrete and answer the questions employees actually have. Good policies cover:
Approved tools: a list of what may be used, and how to propose new ones.
Data limits: what must never be entered into external models (personal data, customer data, code under confidentiality).
Audit duty: AI output is a draft, not a conclusion. Whoever publishes or acts on it bears the responsibility.
Transparency: when and how you notice AI-generated content and AI-driven customer contact.
Reporting: where to turn in case of suspected error, bias or incident.
Tie the policy to existing procedures instead of creating a parallel regulatory framework. If you already have an information security policy and GDPR procedures, the AI policy should complement them, not compete with them. One page that people follow beats twenty pages that no one opens.
Step 4: Human oversight that matters
Human oversight is a core concept in the regulation, but it is easily watered down to a tick box. Real supervision requires three things: that a designated personcan understandwhat the system does,has authorityto oppose or turn it off, andactually have timeto review. An administrator who must approve 400 automatic decisions a day does not exercise supervision, he stamps.
Therefore, design supervision based on the risk. For a high-risk system, this may mean that outcomes are reviewed in selection, that deviations are escalated and that the decisions are logged so that they can be reviewed afterwards. It's less about a human touching every decision and more about there being a real, capable control point with a mandate to intervene.
Step 5: AI literacy
Article 4 makes competence a legal obligation, but the requirement is deliberately flexible and context-dependent, not a standardized course. Supervision and sanctions for Article 4 rest with national market surveillance authorities and apply from 2 August 2026. Build the skills in stock:
All employees: a basic understanding of what AI is, where your systems are used and the most important pitfalls (finding answers, bias, data leakage).
Those who use AI at work: role-specific training in the concrete tools and in the data limits of the policy.
Owner and decision maker: deeper knowledge of risk classification, supervision and the legal framework.
Document what you do, who participated and when. In a future review, it is the difference between being able to demonstrate "adequate measures to the best of our ability" and being left empty-handed.
Step 6: Anchor and keep it alive
Governance dies if it only exists in a document. Appoint an owner, preferably a small cross-functional group with legal, IT/security and operations, who owns the inventory, approves new systems and receives incident reports. Set a simple rhythm: review the registry quarterly, tune in to new tools on an ongoing basis, and update the policy when technology or regulations change. Also, since the Digital Omnibus is still under formal adoption in June 2026, you should keep an eye on the final dates before locking in schedules.
This is also where most organizations underestimate themselves: good AI governance is not a brake, it is what makes you dare to use AI seriously. When the boundaries are clear and responsibility is defined, AI stops being a diffuse risk and becomes a tool you can trust.
Get started without getting lost
Building AI governance from scratch is affordable, but it takes focus away from core business. At ZORC, we help companies take inventory of their AI systems, classify risk and develop policies and skills plans that are actually used in everyday life, preferably connected to your existing security and GDPR routines. If you want to know what a plan would look like for you, describe the need in ourquote calculatoror get in touch viacontactthen we'll take it from there.