The EU AI Act has left the waiting room
The grace period for the EU AI Act is over. If you're still treating this as a "future state" project or something for the legal team to fret over in Q4, you've already missed the window to fix your design.
Most firms are currently practicing compliance theatre. They've written an "AI Ethics Policy," checked a box on a vendor's self-assessment, and decided that's enough. It isn't. I've seen this movie before. Back in the early days of SOX, I watched executives think a signed memo from the CFO constituted a financial control. It didn't. When the auditors actually looked for evidence of a review, the whole house of cards collapsed.
The difference now is the price tag.
Look at Coupang. They just posted an operating loss of over $580 million after a privacy fine shock in South Korea. That isn't a cost of doing business; it's a catastrophic failure of control design. Meanwhile, telecom operators are staring down potential fines of up to 10 percent of their total revenue for security lapses. If you think the EU regulators will be softer on AI violations than they are on GDPR or privacy breaches, you're delusional.
The real question is: what does a failure here cost you at year-end? For a mid-sized firm, a high-risk AI classification error combined with a lack of human oversight isn't just a finding in a report. It's a material hit to the P&L that you can't explain away as a one-time event.
You'll hear the usual excuse: "Our vendors are compliant."
That is a dangerous position. A vendor's SOC 2 or ISO certificate tells you they have a process in place at their office, not that your specific implementation of their tool is functioning correctly within your environment. Reliance on a third-party attestation without performing your own control testing is just outsourcing your risk to someone who doesn't care if you get fined. You cannot outsource accountability.
The fallout won't stop at the CISO's desk.
The second-order effect here hits the auditors. The firms that rubber-stamped these AI deployments as "low risk" because they didn't want to spend the hours digging into the data lineage are going to find themselves in a very tight spot. When the first multi-million euro fine drops for a biased algorithmic decision, the regulator will ask who signed off on the risk assessment.
Stop looking for a way to make this "fit" into your existing framework.
AI requires a different set of controls, specifically around data quality and human-in-the-loop overrides, that most legacy frameworks don't cover. If you can't show me a log of who reviewed an AI output and why they approved it, you don't have a control. You have a hope.
I want to see the actual evidence of the "human oversight" required for high-risk systems. Most of you can't produce it because the process doesn't exist.
Check your registry and find every system using an LLM or automated decisioning. If the only control listed is "Vendor Agreement," start praying.