Skip to content
LegAIchain

AI Act · 6 min

The AI Act is live: what boards must actually do now

LegAIchain

The EU AI Act's obligations are phasing in. The companies that treat it as a governance programme, not a one-off legal review, will move fastest.

The AI Act does not ask whether your company uses AI. It asks whether you can prove how, where and under what controls. As obligations phase in, the difference between a blocked deployment and a shipped one is governance that already exists.

Start with an inventory. Most organisations do not know how many AI systems they operate, who owns them, or which would classify as high-risk. Without that map, every other obligation is guesswork.

Classification drives everything else. A high-risk system carries conformity assessment, documentation, human oversight and post-market monitoring duties. A general-purpose model carries transparency and, above a threshold, systemic-risk obligations. Getting the classification right is the single highest-leverage decision.

Human oversight is not a checkbox, it is an operating model. Regulators will ask who can intervene, how, and whether they are trained and empowered to do so. Design it before you deploy, not after an incident.

The board's role is assurance, not implementation. Directors need a dashboard: which systems, what risk class, what obligations, who owns them, and where the gaps are. That is the deliverable we build first.

Más artículos

Empecemos a hablar

Cuéntanos qué estás construyendo.

Ya sea IA en producción, una estructura de tokens, una solicitud de licencia o una fábrica que se digitaliza, te ayudamos a construirlo sobre una base jurídica sólida.