AI Leadership Ends Where AI Governance Begins
Understanding artificial intelligence and being able to evidence how it is governed are two different positions. The first is a leadership capability. The second is a legal one, and the national market surveillance authorities across the European Union began supervising and enforcing the EU AI Act on 2 August 2026.
The eight executive briefings in this series close the leadership gap: what AI does to decision quality, where accountability lands, and which questions a board should be asking before it approves anything. They stop deliberately short of the compliance work, because that work is documentary. It is done article by article, and it is judged on records rather than on intent.
The two obligations already in force
- Article 4 — AI literacy. The EU AI Act requires providers and deployers to take measures to support the development of AI literacy of their staff and of other persons dealing with the operation and use of their AI systems on their behalf. It has applied since 2 February 2025. Regulation (EU) 2026/1744 replaced the wording on 27 July 2026: no specific level of literacy has to be guaranteed. Measures still have to be taken. The EU AI Act prescribes no course, no certificate and no format for the record, which leaves the burden of showing what was done sitting entirely on the organisation’s own documentation. A completion list says little about whether the measures suited the roles involved. The reasoning behind who needed what, and why, is the part that carries.
- Article 50 — transparency. People must be told when they are interacting with an AI system. AI-generated content must be marked so that it can be detected. Deepfakes must be disclosed, and AI-generated text published to inform the public on matters of public interest must be labelled where it has not had human review or editorial control. These duties have applied since 2 August 2026. One transition remains: providers of generative systems already on the market before that date have until 2 December 2026 to meet the machine-readable marking duty in Article 50(2). Failure is fineable up to EUR 15 million or 3% of total worldwide annual turnover under Article 99(4), with proportionality taken into account for small and medium-sized enterprises and small mid-cap companies.
The obligations the EU AI Act defers — high-risk systems listed in Annex III on 2 December 2027, AI built into regulated products on 2 August 2028 — are the ones carrying the longest evidence files behind them. Deferral is not a reason to wait.
Who answers for it
The Chief Executive carries the organisational position. The record itself is usually owned by the Chief Technology Officer or the Chief Data Officer and reviewed by the General Counsel. Where no one is named, the exposure does not disappear. It collects at board level.
Where the work gets done
ExecLevel AI is an EU AI Act compliance platform built for exactly this handover: the point at which an executive who understands the technology has to produce a file that stands up to a regulator. It runs the assessment, records the reasoning, and produces the evidence pack — article by article, system by system.
The practical first step is an inventory of every AI system the organisation provides or uses, with its role recorded against each one. Most of what follows in the EU AI Act keys off that list.