Adopting Artificial Intelligence is no longer merely a technology decision. As the AI Act progressively applies, it has also become a decision about governance, risk, accountability and the ability to execute.

Many organisations still treat Artificial Intelligence as a succession of experiments: a tool purchased by one function, a pilot promoted by another, features activated by suppliers and informal uses that rarely reach management’s attention.
The problem is not experimentation.
It is the absence of a model that makes it possible to decide where AI creates value, which risks are acceptable, who is accountable and what conditions must be in place before moving forward.
That is why the European Union Artificial Intelligence Regulation — the AI Act — should not be understood as simply another compliance obligation. It should be used as a catalyst to build a permanent management capability: an AI Governance Plan.
The AI Act is already changing business decisions
It is often referred to as the “AI Directive”, but the AI Act is legally Regulation (EU) 2024/1689. As a regulation, it applies directly in Member States, although its provisions become applicable in stages.
- Since February 2025, the provisions on prohibited practices and AI literacy have applied.
- Since August 2025, governance rules and obligations relating to general-purpose AI models have applied.
- Since August 2026, transparency rules apply and enforcement of the applicable provisions has begun.
- In 2027 and 2028, additional obligations relating to certain high-risk uses and products become applicable.
The official implementation timeline is progressive. But organisations cannot wait until the final deadline to prepare.
The specific obligations depend on the company’s role, the nature of the system, the context of use and its risk level. The first management responsibility is therefore to know what AI actually exists in the organisation and how it is being used.
The regulatory deadline is not the real starting point
A company may approve an AI use policy and still be unable to answer basic questions.
- Which AI systems and capabilities are already in use?
- What data are being sent to external platforms?
- Which decisions about employees, customers or operations are influenced by AI?
- Which suppliers embed AI in contracted services?
- Who can authorise, suspend or review an initiative?
- What evidence shows how the decision was made?
If these answers do not exist, the problem comes before compliance.
It is a problem of visibility, criteria and ownership.
From an isolated policy to an AI Governance Plan
An AI Governance Plan turns principles and obligations into executable decisions, responsibilities, controls and priorities.
It is not simply an acceptable use policy. Nor is it a technology inventory or an isolated legal opinion.
| Without an AI Governance Plan | With an AI Governance Plan |
|---|---|
| Scattered initiatives and limited visibility | Shared inventory and explicit priorities |
| Tool-centred decisions | Decisions centred on value, risk and feasibility |
| Implicit responsibilities | Defined roles, forums and approval criteria |
| Compliance checked at the end | Risk and compliance integrated from the outset |
| Knowledge scattered across projects | Traceability and decision memory |
The plan should be proportionate to the company’s size, context and risk profile. But it needs to connect strategy, business, technology, data, security, human resources, procurement, risk and compliance.
What an AI Governance Plan should include
The objective is not to create more bureaucracy. It is to make clear the conditions required to move forward with confidence.
1. Inventory of systems and use cases
Identify purchased tools, features embedded in software, internal developments, suppliers and informal uses. Without an inventory, there is no consistent basis for assessing value, risk or compliance.
2. Classification and context of use
Understand the organisation’s role in each system, the purpose of the use, the people potentially affected, the data involved and the level of risk. Not every initiative requires the same process.
3. Decision model and responsibilities
Define who proposes, assesses, approves, monitors and can suspend a system. Governance exists only when ownership is explicit and proportionate to the impact of the decision.
4. Principles, controls and evidence
Turn transparency, human oversight, data quality, robustness, security, privacy and non-discrimination into verifiable criteria. A principle without control and evidence remains merely an intention.
5. Lifecycle and supplier management
Manage selection, development, testing, deployment, monitoring, change and retirement. Contracts, technical documentation, data use, security and supplier limitations must inform the decision.
6. AI literacy, metrics and continuous improvement
Equip directors, business teams, technology, human resources, procurement, legal and users according to their responsibilities. Measure value, incidents, residual risk and the validity of assumptions over time.
Governance should not mean obstruction
An overly burdensome model may lead teams to avoid formal processes and continue experimenting out of sight.
An overly permissive model increases fragmentation, supplier dependency and exposure to risk.
The objective is to create a proportionate process. Simple, low-risk cases should move quickly. Sensitive situations should receive a deeper assessment, involving the relevant functions.
Good governance is not there to prevent adoption.
It exists to enable the organisation to move forward with greater confidence, consistency and speed.
From the AI Act to AI Drive: turning obligation into execution
It is precisely in this shift from obligation to execution that aiteris AI Drive creates value.
AI Drive does not begin with the question “where can we use AI?”. It begins by understanding where AI creates real value, with what data, which risks, which architecture and which governance model.
The methodology gives the project structure and creates continuity between strategy, risk and execution.
At the end, the organisation has a maturity assessment, a prioritised inventory of use cases, feasibility assessments, a risk map, AI governance principles and an executable adoption roadmap.
Not merely a reading of the regulation.
With the capability to decide and move forward.
An AI Governance Plan is a management capability
The AI Act makes governance more urgent. But its relevance extends beyond compliance.
An organisation that knows its systems, establishes criteria, assigns responsibilities and preserves the logic behind decisions can reduce risk while accelerating the initiatives that create the greatest value.
An AI Governance Plan should therefore be understood as a permanent management capability.
It is not the document that completes preparation for the AI Act.
It is the mechanism that enables the organisation to keep adopting AI in a safe, responsible and results-oriented way.
The objective is not merely to be prepared for an obligation. It is to be prepared to make better decisions about AI, continuously.
Frequently asked questions
Does the AI Act apply to every company?
The framework depends on the company’s role, the type of system and the context of use. Even when an organisation does not develop AI models, it may have responsibilities as a deployer or user of systems supplied by third parties. Each case must be assessed on its own merits.
Is an AI use policy enough?
No. The policy is important, but it needs to be supported by an inventory, classification, responsibilities, approval processes, controls, training, monitoring and evidence mechanisms. Otherwise, it remains disconnected from actual adoption.
Who should lead AI governance?
Responsibility should not be isolated in technology or legal. The model should involve senior management, business, technology, data, security, human resources, procurement, risk and compliance, with clearly defined ownership and decision rights.
How does AI Drive support AI Act readiness?
AI Drive connects compliance with strategy and execution. It assesses maturity, inventories and prioritises use cases, analyses feasibility and risk, defines the AI governance model and builds an executable roadmap tailored to the organisation’s reality.
FROM OBLIGATION TO EXECUTION
Build an AI Governance Plan tailored to your organisation
AI Drive turns AI ambition into priorities, governance and execution — with a diagnosis, criteria, responsibilities and a clear roadmap.
accelerating what matters.