· Mohamed Ben Haddou · AI readiness · 7 min read
Are you AI-ready? Part 4 — Governance & AI Act: the deadline is no longer in the future
Since 2 August 2026, the bulk of the EU AI Act applies. Most mid-market organisations still have no inventory of their AI systems — which means their exposure is unnamed, not absent. The fourth dimension of AI readiness: the register, the risk classifications, what deployers actually owe, and why governance done right is a rhythm rather than a scramble.

Fourth of six articles on the dimensions of the Mentis READY Framework. Part 1 covered deciding what AI is for, Part 2 whether your data is ready, Part 3 where it will run. This one is about the dimension with dates attached.
The question with a date on it
Every dimension in this series describes something that makes AI programmes succeed or fail. This one is different in a single respect: it also describes something the law now requires, on a timetable that has largely already run out.
The EU AI Act entered into force in August 2024. Its prohibitions and the AI-literacy obligation have applied since February 2025. The rules for general-purpose AI models followed in August 2025. And since 2 August 2026, the bulk of the regulation applies — including the obligations for high-risk systems and the transparency rules for AI that interacts with people. One extension remains, to 2027, for high-risk AI embedded in products that are already covered by EU product-safety regimes.
Against that timetable, here is the sentence we still hear most often in first conversations: “we’re aware of the AI Act, but we haven’t done an inventory yet.” On the scorecard, that is level 2 of 5 — and it describes organisations that are otherwise well run. Exposure you have not named is not exposure you avoided. It is exposure you carry, unpriced.
What AI governance actually means
Not a committee, and not a 40-page policy nobody reads. Four concrete things exist and are maintained:
- An inventory. Every AI system in use or planned — including the AI features inside SaaS tools, which is where most of the surprises live.
- A classification. Each system placed in the AI Act’s categories: prohibited, high-risk, limited-risk (transparency obligations), or minimal-risk. Most systems land in the last category; the point is being able to show why.
- A policy people have actually seen. What employees may use, with what data, with what checks — published, communicated, and short enough to be read.
- Assigned oversight. For each system that touches decisions about people, a named human who can intervene, and a record of AI-assisted decisions that would survive an auditor’s visit.
The five maturity levels of Governance & AI Act
| Level | What it looks like in practice |
|---|---|
| 1 · Ad hoc | “We didn’t know it applied to us.” No inventory, no policy; oversight not addressed. |
| 2 · Experimenting | Aware of the Act, but no inventory; verbal guidance instead of a policy; oversight ad hoc, depends on the team. |
| 3 · Structured | A partial inventory; a drafted policy not yet adopted; oversight defined for some systems. |
| 4 · Managed | An inventory with risk classifications; a published, communicated policy; oversight defined for all AI-assisted decisions. |
| 5 · Optimised | A maintained register with gaps tracked and oversight assigned; policy enforced with training and audits; decisions documented, tested, auditable. |
Three questions that tell you where you are
These are the three the scorecard asks for this dimension.
Do you know which of your current or planned systems fall under the EU AI Act? The honest range runs from “we didn’t know it applied to us” to “a maintained register”. The middle answer — a partial inventory — is where most organisations that have started sit, and the usual gap is the same: the AI nobody bought deliberately. CV screening inside the HR suite, scoring inside the CRM, transcription inside the meeting tool. The Act does not care that the feature came bundled.
Does an AI usage policy exist? “Verbal guidance only” is the most common answer and the least defensible one: it means the rules exist exactly until the person who gives the guidance is on holiday. A one-page policy adopted this quarter beats a comprehensive one planned for next year.
Human oversight and documentation of AI-assisted decisions? This is the question that separates paper compliance from the real thing. “Defined for some systems” is honest progress. The target is narrow and concrete: for every decision about a person that AI touches — hiring, credit, eligibility, pricing — a named human who can override, and a trail showing they could.
Provider or deployer — know which one you are
The Act’s heaviest obligations fall on providers — the organisations that develop AI systems and place them on the market. Most mid-market organisations are deployers: they use AI systems built by others. That is the better side of the line to be on, but it is not the exempt side. For a high-risk system, a deployer must, among other things:
- use the system according to the provider’s instructions — which presumes someone has read them;
- assign human oversight to people with the competence and authority to exercise it;
- ensure input data is relevant and representative for the purpose;
- keep the logs the system generates, and monitor operation;
- inform people affected where the Act requires it — and, for some deployers such as public bodies and providers of essential services, complete a fundamental-rights impact assessment before first use.
Two boundary cases matter. First, a deployer who substantially modifies a high-risk system, or puts their name on it, can become a provider — with the full obligations that follow. Second, “we only use vendors” does not transfer accountability: choosing, configuring and operating the system is yours.
The penalty regime is not decorative: up to €35 million or 7 % of worldwide turnover for prohibited practices, up to €15 million or 3 % for most other violations. Mid-market organisations are unlikely to be the first enforcement targets — but they are very likely to be asked about compliance by the large clients, insurers and auditors who are.
Governance as a rhythm, not a scramble
The organisations that handle this well share one habit: they treat the register as a living document with an owner, not a one-off project. New tools get classified on the way in, not discovered in an audit. The policy gets a yearly review. Oversight assignments survive reorganisations because they are attached to roles, not names. That rhythm is precisely the part that fits badly in a project budget and well in a standing responsibility — it is a governance-shaped job, not a governance-shaped deliverable. (It is also, not coincidentally, the core of what a fractional AI lead owns.)
What to do in the next 30 days
If you recognise yourself at level 1 to 3:
- Run the inventory workshop. One afternoon, the right people from IT, HR, finance and operations, one question: where does AI already touch our work? Include every SaaS feature. The list is always longer than expected.
- Classify against the Act’s categories. For most systems this takes minutes; the handful that plausibly land in high-risk — recruitment, credit, essential services, education — get a proper look. Write down the reasoning, not just the verdict.
- Adopt the one-page policy. Approved tools, forbidden data, required checks, who to ask. Publish it, say it out loud in a team meeting, done.
- Assign oversight by role. For each system that touches decisions about people: who can override, and where the record lives.
Do that and the question “are we compliant?” gets the only good answer available: “here is the register, here is what is classified, here is what remains — and here is who owns it.”
Where this sits in the bigger picture
Governance & AI Act compliance is the fourth of six dimensions. Next: People & Operating Model — who owns AI, what skills exist, and why a committee of enthusiasts is not an operating model. Then Security & Trust closes the series. Together they produce the maturity radar at the heart of the AI Readiness Assessment, our four-week, fixed-price diagnostic for mid-market organisations in regulated sectors — including the AI Act exposure register and gap analysis as standard deliverables.
Want your own reading? The free AI Readiness Scorecard asks the three governance questions above — and fifteen more across the other dimensions — and gives you your maturity radar in four minutes. No account, no sales call attached; if you want a second opinion on your results, leave an email and we will write back within a business day.
Mohamed Ben Haddou is the founder of Mentis Consulting (Brussels, ULB spin-off, since 2005) and an Independent AI Expert for the European Commission.
