The EU AI Act reached final agreement in March 2024, making it the first comprehensive legal framework for artificial intelligence anywhere in the world. If you work in governance, compliance, or risk management and you have been following AI regulation with anything less than full attention, that changes now. This is no longer a proposed regulation or a consultation document. It is law, with a phased implementation timeline and enforcement mechanisms that include fines calibrated to make non-compliance genuinely costly.
I want to talk about what the AI Act requires and what it means practically for the governance and compliance professionals who are going to be asked to help organizations navigate it, because I think this represents one of the most significant expansions of the compliance professional’s scope in years.
The AI Act takes a risk-based approach that will be immediately familiar to anyone with a background in IT risk management. AI systems are categorized by the level of risk they present, with requirements scaled accordingly. Systems that are prohibited, that present unacceptable risk as defined by the regulation, are simply banned. High-risk systems are subject to substantial requirements around documentation, transparency, human oversight, data governance, and ongoing monitoring. Limited-risk systems face lighter transparency requirements. Minimal-risk systems can be deployed with minimal regulatory obligations.
The high-risk categories are defined specifically and include AI used in critical infrastructure, education, employment decisions, essential private and public services, law enforcement, migration and border management, and the administration of justice. These are not niche applications. They are categories where organizations across multiple sectors are either already deploying AI or actively planning to. If your organization operates in any of these areas, the compliance burden under the AI Act is substantial.
The technical documentation requirements for high-risk systems are particularly demanding. Organizations must maintain detailed documentation of the system’s purpose, training data characteristics, performance metrics, and testing results. They must implement a quality management system covering the full AI lifecycle. They must establish logging and record-keeping capabilities that support post-market monitoring. They must create and maintain instructions for use that allow deploying organizations to meet their own compliance obligations. These are not checkbox exercises. They require structured processes and dedicated resources.
Human oversight requirements are a specific area where the compliance professional’s perspective adds real value. The AI Act requires that high-risk systems be designed and deployed in ways that enable human oversight, including the ability to understand the system’s outputs, intervene in its operation, and refuse or override its decisions. Auditing whether oversight mechanisms are genuine or merely nominal, whether the humans designated to provide oversight actually have the knowledge and access to do so, is exactly the kind of gap assessment that audit professionals are trained to perform.
The enforcement structure creates financial incentives to take compliance seriously. Fines for violations of the most serious requirements can reach thirty-five million euros or seven percent of global annual turnover, whichever is higher. For the prohibited AI practices, the ceiling is thirty million euros or six percent of global turnover. These numbers are calibrated to matter to large organizations, not just to serve as symbolic penalties.
The implementation timeline gives organizations some runway but not unlimited time. Prohibited AI practices face the earliest compliance deadline. High-risk system requirements have a two-year implementation period from the regulation’s entry into force. Organizations that treat this as a 2026 problem to worry about in 2026 are going to find themselves behind when the deadlines arrive.
For compliance professionals building their AI governance expertise, the combination of the NIST AI RMF, ISACA’s AI governance guidance, and deep familiarity with the EU AI Act text creates a knowledge foundation that organizations are going to need. The full regulation text and official guidance materials are accessible through the European Commission’s AI policy page. Reading primary sources rather than summaries is worth the investment for the depth of understanding it provides.
The professionals who can translate EU AI Act requirements into practical compliance programs, who can assess where organizations stand against the high-risk system requirements, who can develop the documentation and oversight frameworks the regulation demands, are going to be in demand. That demand is going to materialize faster than most organizations are currently planning for. Getting ahead of it now is a career move that will look very deliberate in about eighteen months.
Kim Walsh is a CISSP and seasoned cybersecurity practitioner with deep, hands-on experience in enterprise security architecture, risk management, and compliance. She is passionate about bringing the next generation into the IT and AI space, actively mentoring young people who are just finding their footing in the field. As the mother of five kids, she has both the patience and the battle-tested communication skills to explain just about anything to just about anyone.
