The AI Act for Board Members: What Every C-Level Executive Needs to Know to Keep the Company from Paying Millions

The AI Act for Board Members: What Every C-Level Executive Needs to Know to Keep the Company from Paying Millions

Responsibility for compliance with the AI Act doesn’t end with the IT department. It ends on the boardroom table.

Imagine this scenario: your company is fined a few percent of its global revenue for an AI system that management didn’t even know the company was operating. Does that sound unlikely? According to surveys, more than half of organizations don’t even have a basic overview of which AI tools are being used within their organization. And it is precisely this overview that is the responsibility of senior management—not the IT department.

Why the AI Act Is a Topic for Management, Not for IT

Most companies still view the AI Act as a “technical problem that developers will solve.” This is a dangerous misconception. Regulation (EU) 2024/1689 of the European Parliament and of the Council imposes obligations on the organization as a whole. With fines of up to 35 million euros or 7% of global annual turnover—which exceed even the penalties under the GDPR—this is a risk that belongs on the board’s agenda just as much as financial or legal risks.

The reason is simple. An AI system deployed by a company affects its customers, employees, and partners. It decides on hiring, granting loans, and setting service prices. If such decisions violate the rules, the responsibility lies not with the programmer who integrated the tool, but with the organization and its leadership. A board of directors that lacks oversight of the company’s AI systems bears responsibility for decisions it never consciously made.

This shift in perception is fundamental. AI is ceasing to be “a tool we use” and is becoming “a risk we manage.” And risk management is a classic leadership task.

Four Questions Every CEO Must Ask Themselves

You don’t need to understand neural networks. However, you must be able to answer four questions. If you answer “I don’t know” to any of them, you have a problem that needs to be addressed.

Do we have an overview of all AI systems in the company?

This is the foundation without which nothing else works. It’s not just about tools the company has consciously purchased as “AI solutions.” It also includes AI built into everyday software, third-party SaaS platforms, and tools that employees have started using on their own. It is precisely this “shadow AI” that represents the biggest blind spot. If a company doesn’t have an up-to-date inventory of its AI systems, management is managing risk blindly.

Do we know which risk category they fall into?

The AI Act classifies systems into four categories—unacceptable risk (prohibited practices), high risk, limited risk, and minimal risk. Each entails different obligations and different deadlines. The key point is that many companies operate high-risk systems without even realizing it—typically AI tools used in recruitment or employee evaluations. Without proper classification, a company doesn’t know what requirements it actually needs to meet.

Who in the company is responsible for the AI Act?

If the answer is “no one in particular” or “probably IT,” that’s a problem in itself. Responsibility must be assigned by name—there must be a person or team that approves the deployment of AI, monitors the systems, and reports to management. Diffused responsibility, in practice, means no responsibility at all.

Are We Ready for Key Terms?

While the obligations for high-risk systems were postponed from May 2026 to December 2027 and August 2028 under the so-called Digital Omnibus Agreement from May 2026 to December 2027 and August 2028, the transparency obligations under Article 50 remain in effect as of August 2, 2026, without change. This is the nearest deadline and applies to nearly every company that uses a chatbot or generates content using AI.

What Risks Do Company Leaders Face?

Financial fines are only part of the picture. Management must also consider other aspects of risk.

Reputational risk can be more costly in the long run than the fine itself. A case where a company uses AI in violation of the rules—for example, a discriminatory tool in recruitment—quickly becomes a media story and damages the brand in a way that is difficult to repair.

The risk to investors is growing. The market is paying increasing attention to how companies manage AI. There are signs that capital markets are beginning to factor in companies’ “AI maturity” when assessing risk. A board of directors that cannot demonstrate control over AI exposes itself to questions from both investors and auditors.

In regulated industries—banking, insurance, and healthcare—there is a growing risk from sector regulators, who monitor AI compliance alongside other requirements.

That is precisely why a demonstrable “due diligence” approach by management is the best defense. If a company can demonstrate that it took AI risk seriously and systematically mapped and managed it, its position during a potential audit or reputational crisis is incomparably stronger.

Getting Started: The Role of the Board of Directors in AI Governance

The role of management is not to understand the technology in detail. It is to ensure that processes are properly established. Specifically, the board of directors should oversee the implementation of an AI risk management system, clearly defined responsibilities, and regular reporting on the status of AI systems and their compliance with regulations.

In practice, this means making AI governance a standard item on the management agenda—just as cybersecurity and data protection are. It also means designating a responsible person with sufficient authority and ensuring that management receives clear information about risks in business terms, not in technical jargon.

This is exactly where we can help. From auditing the current state, through classifying AI systems, to setting up a governance structure and reporting at the board level—we’ll prepare your company so that management has AI risk under control and can demonstrate it. If you’d like to find out where your company stands, contact us for a no-obligation consultation.


Sources

  1. Regulation (EU) 2024/1689 (full text, EUR-Lex): https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. European Commission – AI Act (official framework): https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  3. WRITER – Enterprise AI Adoption 2026 (data findings on leadership readiness and risks): https://writer.com/blog/enterprise-ai-adoption-2026/
  4. Gibson Dunn – EU AI Act Omnibus Agreement (deadline extension, May 2026): https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/

This article is for informational purposes only and does not constitute legal advice.