The European Union's Artificial Intelligence Act came into force in August 2024, establishing the first comprehensive regulatory framework for AI systems. It classifies AI by risk, assigns obligations to deployers and providers, and requires organizations to demonstrate governance, risk assessment and record-keeping. For organizations using AI systems that process data connected to EU individuals or markets, the Act creates new compliance obligations with enforcement mechanisms including fines and operational restrictions.
Why the AI Act Matters to Your Organization
The AI Act matters because it holds organizations accountable for the use of AI systems, not just their creation. If your organization deploys AI that affects people in the EU—whether in hiring, credit decisions, biometric identification, critical infrastructure or safety components—you may be subject to mandatory risk assessments, human oversight requirements and transparency obligations. Non-compliance can result in fines of up to €35 million or 7% of global annual turnover for the most serious violations, alongside reputational consequences and operational disruption.
The Act distinguishes between providers, who develop or supply AI systems, and deployers, who use them under their own authority. Many organizations assume compliance is the provider's responsibility. It is not. Deployers carry independent obligations, and gaps in governance or documentation become the deployer's liability regardless of vendor assurances.
The Risk Classification System
The AI Act assigns AI systems to four risk categories: unacceptable, high, limited and minimal. The classification determines the obligations that apply.
Unacceptable Risk
AI systems deemed to pose unacceptable risk are prohibited. This includes social scoring systems, certain real-time biometric identification in public spaces and AI that exploits vulnerabilities of specific groups. These systems cannot be deployed regardless of safeguards.
High-Risk AI Systems
High-risk AI systems are those used in areas where incorrect output could harm people's safety, rights or livelihoods. The Act defines high-risk systems in two ways: AI used as a safety component of products already subject to EU safety legislation, and AI used in specific domains listed in an annex. These domains include biometric identification, critical infrastructure management, education and vocational training, employment decisions, access to essential services (including creditworthiness assessment), law enforcement, migration and border control, and administration of justice.
High-risk systems trigger the most demanding obligations. Providers must establish risk management systems, maintain technical documentation, ensure data governance and quality, maintain logs, provide transparency and human oversight mechanisms, and achieve required levels of accuracy, robustness and cybersecurity. Deployers must use the system according to instructions, ensure human oversight, monitor for risks during operation and report serious incidents and malfunctions to providers and authorities.
Limited and Minimal Risk
AI systems with limited risk, such as chatbots or systems that generate or manipulate content, must meet transparency requirements so that users know they are interacting with AI or viewing AI-generated material. Minimal-risk systems, which represent the majority of AI applications in use today, face no specific obligations under the Act beyond general EU law.
Obligations for Deployers Versus Providers
The Act draws a clear line between providers and deployers. Providers place AI systems on the market or put them into service. They must ensure systems meet essential requirements before release, conduct conformity assessments, maintain documentation and register high-risk systems in an EU database. Deployers use AI systems under their own authority. They must ensure appropriate use, assign qualified personnel to oversight functions, monitor for risks in their operational context, maintain logs as specified and cooperate with authorities during investigations.
A deployer may become a provider under the Act if it substantially modifies a high-risk system or uses a general-purpose AI system in a way that makes it high-risk. In those cases, all provider obligations apply. This creates exposure for organizations that customize or integrate AI tools without recognizing the regulatory significance of the modification.
Providers cannot contract away deployer obligations through terms of service. Even where a vendor offers compliance support, the deployer remains accountable for monitoring, oversight, incident reporting and appropriate use in its specific context.
Who Is Accountable and What Adequate Ownership Looks Like
The AI Act creates accountability at the executive level. Organizations must designate personnel responsible for oversight of high-risk AI systems, ensure they have the authority and competence to intervene, and provide them with access to documentation and monitoring data. Adequate ownership requires three elements: clear assignment of accountability to a named executive or function, governance structures that connect AI risk decisions to enterprise risk management, and processes for ongoing monitoring, incident response and regulatory reporting.
In practice, AI Act compliance intersects legal, compliance, information security, technology and operational risk functions. No single department typically owns all the necessary decisions. General counsel can interpret obligations but cannot assess technical risk. IT can evaluate system behavior but may lack authority over deployment decisions in business units. Compliance can track regulatory deadlines but often lacks visibility into where AI is actually being used.
The gap is one of coordination and decision-making authority. Someone must determine what is in scope, make risk classification calls when they are ambiguous, decide what level of oversight is appropriate, define what constitutes a reportable incident and represent the organization's position to regulators. That role is executive in nature and requires both technical understanding and business judgment.
This is the accountability gap that [virtual CISO leadership](/vciso/) is designed to close. A vCISO provides executive ownership of the governance framework, coordinates across legal, technical and business functions, translates regulatory requirements into operational decisions and maintains the ongoing oversight structure that the Act requires.
The Connection to AI and Emerging Technology Governance
The AI Act is one driver among several for AI governance. Organizations also face obligations under sector-specific regulation, contractual requirements from customers and partners, and expectations from investors and boards. The NIST Cybersecurity Framework and NIST Privacy Framework provide voluntary structures for managing cybersecurity and privacy risk that can support AI governance, though neither was written specifically for AI systems.
Effective AI governance addresses risk across the lifecycle: vendor selection and due diligence, risk classification and impact assessment before deployment, oversight and monitoring during operation, incident response when systems behave unexpectedly, and documentation sufficient to demonstrate compliance during an audit or investigation. These activities require integration with enterprise risk management and information security programs, not parallel structures.
The challenge for leadership is that AI governance must be specific enough to meet regulatory obligations while remaining practical to implement and sustain. Generic policies do not satisfy the Act's requirements. Conversely, attempting to document every decision at the level of technical detail appropriate for a data science team creates overhead that obscures accountability. The right level is one where each decision has a clear owner, a documented rationale and a mechanism for review when circumstances change.
What Leadership Must Decide Now
Leadership must answer five questions to establish a defensible compliance position.
First, what AI systems is the organization deploying? This requires an inventory that includes not only systems developed in-house or purchased as AI products, but also AI embedded in SaaS platforms, decision-support tools, monitoring systems and third-party integrations. Many organizations discover that AI is more widespread than initially believed.
Second, which systems meet the definition of high-risk under the Act? Risk classification is not always straightforward. A system used in hiring is clearly high-risk if it ranks candidates, but what about a tool that schedules interviews or parses résumés for keywords? The classification depends on the role the system plays in the decision and the degree of human oversight in practice, not just in policy.
Third, who is accountable for each high-risk system? Accountability cannot be diffuse. For each system, someone must be named as responsible for ensuring compliance, monitoring performance and responding to incidents. That person must have the authority and resources to act.
Fourth, what oversight mechanisms are appropriate? The Act requires human oversight but does not prescribe the form. Leadership must decide what oversight looks like in practice: who reviews outputs, how often, under what circumstances they can intervene, and how those decisions are documented.
Fifth, what processes exist for incident reporting and regulatory engagement? When a system malfunctions or produces an incorrect output with consequences, the organization must recognize it, assess whether it meets the threshold for reporting, notify the appropriate authorities and document its response. These steps require coordination across functions and clarity about who has authority to make the call.
Practical Next Steps for Executives
Start with a scoping exercise. Identify the AI systems your organization deploys, determine which are subject to the Act based on EU nexus, and classify them by risk. This is not a project for IT alone; it requires input from business units, legal and compliance.
For each high-risk system, document the current state: who selected it, what due diligence was performed, what instructions the provider has given, who monitors it in operation, what logs are maintained and how incidents would be detected and reported. The gap between current state and regulatory requirements becomes your remediation roadmap.
Assign executive accountability. Designate a single individual responsible for AI governance, with authority to make classification decisions, approve or halt deployments and coordinate incident response. This role must be senior enough to convene the necessary functions and empowered to act without requiring consensus.
Establish governance processes that integrate with existing enterprise risk management. AI risk is not separate from operational, legal or information security risk. The processes for evaluating, approving and monitoring AI systems should fit within the governance structures the organization already uses for other technology and operational decisions.
If your organization lacks the internal capacity to lead this work, or if accountability has been unclear across functions, that is the problem a vCISO engagement is designed to solve. Heights Consulting Group provides the executive ownership required to establish AI governance, make the classification and oversight decisions the Act requires, and maintain the regulatory posture your board and counsel expect.
The EU AI Act does not permit a wait-and-see approach. The obligations are in force, enforcement mechanisms are active, and the consequences of non-compliance extend beyond fines to include operational restrictions and reputational harm. The question is not whether to comply, but who will own the decisions necessary to get there.
If you are prepared to assign accountability and need the strategic leadership to execute, Heights offers a confidential consultation to assess your current position, clarify the decisions your organization must make and determine whether vCISO leadership is the appropriate next step. This offer is made once, at the point where the decision to act is clear.
Sources
- Cybersecurity Framework | NIST , www.nist.gov
- Privacy and Security | Federal Trade Commission , www.ftc.gov
- Privacy Framework | NIST , www.nist.gov
Related service: AI and Emerging Technology Governance
Governance for how your organization adopts artificial intelligence: approved uses, data handling boundaries, review before deployment, and accountability for the output.