With the August 2 deadline, artificial intelligence ceases to be an innovation issue and becomes a governance issue in Europe (read our story on the AI Act). Business leaders become accountable for AI uses that have spread throughout their organizations without having been deliberately introduced by them.
By Alexandre Lazarègue, Attorney at the Paris Bar, specializing in digital law
On August 2, a new phase of the European Artificial Intelligence Regulation comes into force. Many companies see it as just another layer of regulation, following the GDPR. That misses the essential point.
Transparency obligations and the sanctions regime become applicable, while the provisions relating to high-risk systems have been postponed. But the fundamental change is not regulatory in nature: it is managerial. From that date onward, artificial intelligence ceases to be an innovation or productivity issue and becomes a governance issue for which business leaders must answer.
Since the arrival of ChatGPT, AI adoption has taken place at an unprecedented pace, and most often from the bottom up. It was not decided in any executive committee. Here, an employee opened an account. There, a team subscribed to a paid plan. Elsewhere, a software vendor quietly introduced an AI feature through an update. Within a few months, artificial intelligence had entered legal departments, human resources, sales teams, IT departments, and every support function—often without an internal policy, and sometimes without senior management having a clear view of its extent.
Experimentation allowed this disorder. The era of governance will not.
Few Companies Know What They Are Actually Using
The question most business leaders ask is whether their company is affected by the AI Act. It is a legitimate question, but it is not the first one. The first question is: which artificial intelligence systems are actually being used within the company?
This is where the real obstacle lies. Few companies today are capable of producing a comprehensive map of their AI usage. How many AI-enabled applications are employees using? Which suppliers are involved upstream, sometimes without the user’s own knowledge? Which processes influence a commercial decision, a recruitment process, or a financial analysis?
These basic questions often remain unanswered. Yet it will become increasingly difficult to claim that one did not know what was being used within one’s own company.
Compliance Begins Before the Law
The AI Act is often approached as a technical legal text. In practice, the difficulty is not understanding the regulation; it is regaining control over uses that have spread rapidly and in a decentralized manner.
Drafting an internal policy or assessing the risk level of an AI system first requires knowing which tools are in circulation, how they work, what data they process, and which decisions they contribute to. The first step toward compliance is therefore less legal than organizational.
The GDPR had already created this distinction. In 2018, companies that began by inventorying their data processing activities built coherent compliance programs; the others accumulated documentation without gaining control over their actual practices. The same divide is now emerging with artificial intelligence.
Who Takes Responsibility?
The governance of these issues is also shifting. Artificial intelligence is no longer solely the responsibility of the IT department: it now involves the legal department, the Data Protection Officer (DPO), information security, business units, and, from now on, senior management.
Indeed, the consequences of AI systems extend far beyond technical considerations. They affect data protection, fundamental rights, intellectual property, cybersecurity, employment relationships, and the company’s civil liability. Few organizations today have governance structures capable of addressing this level of cross-functional complexity.
The question is no longer who deploys the tool, but who assumes responsibility for it.
Mapping AI as a Management Tool
Yet the AI Act is not merely a compliance exercise. The work it requires—identifying AI uses, clarifying responsibilities, documenting processes—produces benefits that extend far beyond regulatory compliance.
A company that knows which tools are being used, what data they process, and who supervises them can make decisions quickly: it can assess a new tool in a matter of days rather than weeks, respond immediately to a client’s questions about data processing, and make informed technology investment decisions. What is often perceived as a preliminary formality becomes a genuine management instrument.
Moreover, this requirement will not come solely from regulators. Clients, investors, insurers, and business partners will gradually ask the same questions, just as they already do regarding cybersecurity and data protection. Being able to explain how artificial intelligence is used will, in the coming years, become an essential component of the trust an organization inspires.
Where to Begin
August 2, 2026, does not hinder innovation. It marks the beginning of a period in which innovation is governed rather than simply allowed to spread.
The starting point lies in four questions, not in an internal policy running dozens of pages: Where is artificial intelligence being used? What data is entrusted to it? Which decisions does it influence? Who supervises it?
These questions are as much about strategy as they are about law. That may well be the AI Act’s most lasting contribution: transforming artificial intelligence, beyond being a powerful technology, into a matter of corporate governance.







