← Back
Blog

The EU AI Act Is Live. Most Boards Don’t Know What That Means for Them.

The Clock Is Already Ticking

Tales from the Hat — EU AI Act series, Part 1 of 3

Let’s be direct about something.

The EU AI Act is not a future problem. It’s not something to note on next year’s risk register, add to a governance committee agenda, or quietly hand to IT to sort out. It’s live, it has a compliance timeline, and the window to prepare properly is closing faster than most boards realise.

I’ve sat in enough board meetings and senior leadership sessions to know how this tends to go. A new regulation lands. Someone adds it to the horizon-scanning slide. It gets noted. A working group is suggested. And then the organisation carries on exactly as before, right up until the point where not having acted becomes very difficult to explain.

With the EU AI Act, that moment is arriving sooner than most boards are ready for.

What the Act Actually Does

The EU AI Act is the world’s first comprehensive legal framework for artificial intelligence. It came into force in August 2024, and its requirements are being phased in over a transition period that’s already under way.

It takes a risk-based approach, classifying AI systems into tiers — unacceptable risk, high risk, limited risk, minimal risk — and placing different obligations on organisations depending on where their AI use sits. The bit that catches most boards out: you don’t have to be building AI to be regulated by this Act. If your organisation uses or deploys AI systems, obligations apply to you.

In education, this matters enormously. AI is already embedded in learning management systems, admissions tools, plagiarism detection, HR processes, and student support platforms. Most institutions haven’t done a proper review of what they’re actually running, let alone worked out where it sits under the Act’s classification framework.

That gap is a governance gap. And governance gaps at board level have consequences.

What Boards Actually Need to Understand

Under the Act, high-risk AI systems — which include systems used in education and employment contexts — attract the most significant obligations: risk management, data governance, transparency, human oversight, and accuracy.

The institutions that will struggle most aren’t the ones using the most AI. They’re the ones using AI without knowing they’re using it, or without the governance infrastructure to show responsible deployment.

What the Act effectively requires is that an organisation can answer three questions with confidence:

What AI systems are we actually using or deploying? Most organisations can’t answer this comprehensively today. Shadow AI — staff and students using tools informally, without institutional knowledge or oversight — is widespread. A board can’t govern what it hasn’t mapped.

How have we classified and assessed the risk of those systems? The Act creates a legal obligation to understand the risk profile of your AI use. That takes a structured process, not a best guess.

What controls, oversight, and documentation do we have in place? For high-risk systems, the Act wants evidence. Not a policy document sitting in a shared drive. Evidence of active governance, human oversight, and ongoing monitoring.

The Timeline Most Organisations Are Ignoring

The Act’s transition periods mean different requirements land at different points. But the practical implication is the same either way: organisations that wait for full enforcement before starting to prepare will end up building governance infrastructure under pressure, with too little time, in the middle of regulatory scrutiny rather than ahead of it.

The organisations that navigate this well are the ones treating the transition period as preparation time, not as permission to delay.

The governance frameworks you build now aren’t just about compliance. They’re about being able to make decisions confidently when AI adoption accelerates. Which it will.

What This Means for Your Board Right Now

Boards carry a fiduciary responsibility to understand and manage material risks to their institution. AI regulation — with its potential for reputational damage, legal exposure, and operational disruption — is unambiguously a material risk for most organisations today.

That doesn’t mean boards need to become AI experts. It means asking the right questions, making sure the right frameworks exist, and holding leadership accountable for demonstrating that AI is being governed responsibly.

The right questions start here: do we actually know what AI is being used in this organisation? And do we have the governance infrastructure to manage it properly?

If the honest answer to either is no, or “we’re not sure” — that’s where to start.

Next in the series: what good AI governance actually looks like in practice, and the gaps I see most often when I’m in the room with boards and senior leadership teams.