Every few years a compliance deadline arrives that separates the organisations that took governance seriously from the ones that treated it as paperwork. The EU AI Act is that deadline for AI, and its teeth are close. From 2 August 2026, the obligations for high-risk AI systems become enforceable, and the penalties are not symbolic — up to €35 million or 7% of global annual turnover for the prohibited practices, €15 million or 3% for other violations. Even if you're not in the EU, if your systems touch EU users or markets, this reaches you. And here's the part that should worry a careful IT leader more than the fine: most organisations have no idea how much AI is already operating inside their walls. This is the playbook I'd work from, and it's shaped by twenty years of sitting on both sides of an audit.
1. The deadline nobody's quite ready for
The Act's structure matters for planning. It's risk-tiered: a small set of prohibited practices, a heavily-regulated "high-risk" category (biometric identification, critical infrastructure, employment decisions, essential services, and more), and lighter obligations below that. The high-risk obligations are what bite on 2 August. If your organisation uses AI anywhere near hiring, access to services, critical systems or similar, you are potentially in scope, and "we didn't realise the vendor's feature counted" will not be a defence. The first job isn't legal. It's an inventory: what AI is actually in use here, who put it there, and what it decides.
2. Shadow AI is your real exposure
That inventory almost always turns up more than anyone expected, because shadow AI is now one of the fastest-growing risks in enterprise IT. It's the same pattern as shadow IT a decade ago, only faster and quieter: staff paste company data into unsanctioned public AI tools to get their work done, business units wire up their own agents, a SaaS product ships an AI feature nobody reviewed. Each is a small, reasonable-seeming decision. Together they're an ungoverned surface where your data leaves, decisions get made, and you have no record of either. From an audit standpoint this is the classic nightmare — risk you're carrying but can't see, and therefore can't have accepted knowingly.
You cannot govern what you haven't inventoried, and you cannot pass an audit on controls you didn't know you needed. Before policy, before tooling, find out what AI is actually running in your estate.
3. ISO 42001: audit evidence for AI
This is where my CISA training turns into something practical. The EU AI Act tells you what you must achieve but, like most law, not the operational how. ISO/IEC 42001 fills that gap: it's the first global standard for an AI Management System — an auditable framework for establishing, running and continually improving how an organisation governs its AI. In plain terms, it gives you the thing an auditor (and a regulator) actually wants: structured, certifiable evidence. Policies, defined roles, monitoring records, an inventory, decision trails. It's ISO 27001's discipline pointed at AI. If you've ever built or been audited against a management system, the shape is familiar, and that familiarity is exactly why it's the sensible backbone for AI Act readiness rather than inventing governance from scratch.
One honest caveat, because I've watched certifications get oversold: an ISO 42001 certificate is not the same as EU AI Act compliance. It's the management system that makes compliance achievable and evidenceable. The certificate proves you run a disciplined process; it doesn't automatically prove any specific system meets the law. Treat it as the scaffolding, not the finished building.
4. The three-layer stack
Organisations keep treating these frameworks as competitors to choose between. They're not — they're complementary layers of one governance stack, and seeing that clearly saves a lot of wasted argument:
- NIST AI Risk Management Framework — the method. How to think about and manage AI risk. Voluntary, practical, a good on-ramp.
- ISO/IEC 42001 — the management system. The auditable, certifiable structure that operationalises the method and produces evidence.
- EU AI Act — the law. The binding legal requirements with the penalties attached.
Read together: use NIST to shape how you assess risk, run ISO 42001 as the system that keeps you doing it consistently and provably, and map both to the EU AI Act's specific obligations. That's a coherent program, not three competing initiatives fighting for the same budget.
5. Accepted versus ignored AI risk
CRISC taught me the distinction that matters most here, and it's the one that decides how the morning after an incident goes. There's a world of difference between an AI risk you've accepted — named, owned, with someone accountable who looked at the exposure and consciously decided to live with it — and one you've simply ignored, which is just a liability nobody's admitted to. A regulator, an auditor and a court all treat those two very differently. "We assessed this AI use, documented the risk, and a named owner accepted it within policy" is a defensible position. "We had no idea that was running" is not. Good AI governance isn't about eliminating every risk; it's about making sure every risk you carry was a decision, not an accident.
6. A 90-day start
If this feels large, it is — but the first ninety days are tractable and worth far more than a perfect plan you never start. First month: inventory. Find every AI system, feature and shadow tool in use, and who owns each. Second month: triage and policy. Sort the inventory by risk against the Act's tiers, write the plain-language acceptable-use policy, and stand up a named owner and a lightweight review for anything new. Third month: build the management-system spine — start aligning to ISO 42001, wire in your existing data-governance tooling, and turn the inventory into a living register with accepted-risk decisions recorded. You won't be finished. You'll be governing, with evidence, which is the whole point and the thing that turns a frightening deadline into a manageable program. If you're staring at the AI Act and don't know where the first cut is, tell me where you are and I'll point you at the first move.