Tales from the Hat — EU AI Act series, Part 2 of 3
In the first post in this series, I made the case for why the EU AI Act is a board-level issue that can’t be deferred. This one gets practical — because the honest truth is, awareness that governance matters is rarely the problem I see. The gap is between intention and implementation.
Most organisations fall into one of two camps.
The first has no AI governance framework at all. No policy, no process, no oversight structure. AI is being used — often extensively — and nobody has drawn a line around it. This is more common than it should be, and it’s meaningful regulatory and reputational exposure.
The second problem is subtler, and in some ways harder to fix. There’s a policy document. Someone wrote it, the board approved it, it went round on email. And then it sat in a shared drive and changed absolutely nothing about how AI actually gets used day to day. That’s governance as theatre, and the EU AI Act won’t be satisfied by it.
What the Act requires — and what actually protects an organisation — is governance that’s embedded. It shapes decisions, informs behaviour, and leaves an evidence trail that shows active oversight rather than a box ticked once and forgotten.
Four Things That Hold Embedded Governance Together
From what I’ve seen across the boards and institutions I’ve worked with, AI governance tends to stand or fall on four interconnected things. Skip any one of them and that’s usually where an organisation ends up exposed.
1. Knowing what you’re actually dealing with
Before you can govern AI, you need to know what AI you’ve got. Sounds obvious. Is almost never done properly.
A genuine risk and readiness picture maps every AI system in use across the organisation — including the ones that arrived through procurement without anyone asking the right questions, the tools staff are using informally, and the student-facing platforms with AI functionality nobody’s advertising. It places each system against the EU AI Act’s risk classification framework and produces a clear, prioritised view of what needs to change and in what order.
This is the foundation. Without it, everything else is built on assumptions.
2. A governance structure that actually makes decisions
AI governance needs structure — clear roles, defined responsibilities, decision-making pathways that don’t depend on the right person happening to ask the right question at the right time.
That structure has to operate at board level, not just within IT or operations. Boards need to approve AI policy with genuine understanding of what they’re approving, exercise oversight of high-risk AI use, and hold leadership accountable for the evidence that governance is actually working.
The policy suite behind this isn’t complicated, but it needs to be complete: an AI Acceptable Use Policy covering staff and students, an AI in Teaching and Assessment Policy addressing the specific complexities of the education context, an AI Procurement and Vendor Risk Policy that assesses new tools before they arrive rather than after, and an Ethical AI Principles document that grounds all of it in the institution’s values.
Each one is meant to shape behaviour. None of them should be a compliance exercise filed and forgotten.
3. Processes that embed governance in day-to-day operations
Policy without process is just aspiration. The framework only works if it changes what actually happens when someone wants to use a new AI tool, when a high-risk decision gets made, or when something goes wrong.
That means use-case approval workflows, so new AI applications go through structured assessment before deployment. Risk assessment templates that make it easy for staff to document and escalate concerns. And audit-ready assurance processes that generate the evidence trail the Act asks for.
This is where most frameworks fall short. The policy says the right things. The process to make those things actually happen doesn’t exist. And when a regulator or inspector asks for evidence of active oversight, there’s nothing to show them.
4. Staff who actually understand what’s expected of them
The final piece, and the one most directly tied to day-to-day risk, is people.
The biggest AI risk in most organisations isn’t malicious use. It’s well-intentioned staff using tools they don’t fully understand, with no framework to guide them, making decisions they don’t realise carry institutional weight. Student data going through unvetted tools. Assessment integrity compromised by AI use that falls outside policy. Personal data submitted to public AI platforms without a thought for GDPR.
Compliance training isn’t optional — it’s how the gap between “we have a policy” and “we’re an organisation that actually behaves like it” gets closed. And beyond compliance, practical AI skills create the conditions for responsible innovation, rather than blanket prohibition on one side or unmanaged risk on the other.
The Gap, in Plain Terms
When you actually map what’s going on inside most institutions, the same gaps turn up again and again: no comprehensive picture of AI in use across the organisation, policies that exist but aren’t embedded in process or behaviour, no clear board-level ownership of AI governance as its own responsibility, staff who don’t know what the policy says (let alone why it matters), and no evidence infrastructure to demonstrate compliance if anyone asks.
None of these are difficult to close. But they need deliberate effort, structured delivery, and a genuine commitment to embedding governance rather than just documenting it.
The organisations that navigate the EU AI Act well aren’t necessarily the ones with the most sophisticated AI programmes. They’re the ones that have built the infrastructure to govern AI responsibly, whatever form it takes.
The Test That Actually Matters
For boards and senior leaders, the practical test is this: if your institution were asked today to show its AI governance framework to a regulator, an inspector, or your own audit committee, what would you actually be able to produce?
A policy document is a start. Evidence of active oversight, structured risk assessment, embedded process, and trained staff is what the Act genuinely requires.
If there’s a gap between what you could produce today and that list, now — while the transition period is still running — is the time to close it.
Next in the series: what the preparation window actually looks like in practice, and what to do with it before it closes.