Close Menu
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
More items
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
X (Twitter) LinkedIn
  • Home
  • Managing resilience
    • AI resilience
    • Business continuity
    • Business resilience
    • Climate resilience
    • C-suite and the board
    • DORA – the EU Digital Operational Resilience Act
    • Operational resilience
    • Organizational resilience
    • Supply chain resilience
    • Technology
  • Risk
    • Enterprise risk management
    • Operational risk
    • Threatscape
  • Cyber resilience
    • Cyber resilience updates
    • DORA – the EU Digital Operational Resilience Act
    • Product updates
Login
LinkedIn Bluesky
Resilience Forward
Subscribe Now
  • All News
  • Research
  • Jobs in Resilience
  • Resilience Resources
  • About Resilience Forward
Resilience Forward
You are at:Home»Managing resilience»C-suite and the board»Why organizations hoping to build trust and resilience cannot afford to wait for AI regulation (Page 2)
C-suite and the board

Why organizations hoping to build trust and resilience cannot afford to wait for AI regulation

January 12, 20266 Mins Read
The words AI Governance on an abstract background.

By Martin Davies

Organizations across every industry are embracing AI at speed, with many investing heavily in integrating the technology into their operations. Gartner estimates that cumulative worldwide spending on AI will have reached $2 trillion by the end of 2026.

However, while many companies are full steam ahead on AI, the governance needed to keep that adoption safe is not keeping pace. The slow-moving nature of the regulatory world struggles to keep up with this rapidly evolving technology. Although the EU AI Act applies in phases, with some requirements already in place, many commencing in August 2026, and some later in 2027, high levels of AI risk exposure already exist today – particularly as autonomous systems become more capable and more deeply embedded in everyday operations.

Organizations should not wait for regulatory direction before taking action on AI governance. Reactive compliance will be costly, disruptive, and difficult to retrofit. The businesses that lead in 2026 will be those that lay the groundwork for responsible, transparent, AI use to build trust and resilience before regulation forces their hand.

Why waiting for regulation is risky

AI is evolving far faster than the regulations intended to govern it. One of the biggest challenges is that organizations still lack clarity on what will count as ‘high-risk AI’.

While the EU has given details of what it means by high-risk AI, defining these as AI systems that negatively affect safety or fundamental rights, it has also confirmed that these will be broken down into two groups:

1) AI systems that are used in products falling under the EU’s product safety legislation. This includes toys, aviation, cars, medical devices and lifts.

2) AI systems falling into specific areas that will have to be registered in an EU database:

  • Biometric identification and categorization
  • Management and operation of critical infrastructure
  • Education and vocational training
  • Employment, worker management and access to self-employment
  • Access to and enjoyment of essential private services and public services and benefits
  • Law enforcement
  • Migration, asylum and border control management
  • Assistance in legal interpretation and application of the law.

However, many businesses are waiting for concrete external guidance on classifying the AI they are already using, meaning that many will struggle to get ready for the AI Act’s provisions coming into effect.

It is a familiar pattern we have seen repeated with the GDPR, NIS2, and many others. However, the rapid speed of AI presents a different and more difficult situation. A year is a long time for such a rapidly-developing technology, and AI systems could look completely different by the time the Act takes full effect.

Boards will feel growing pressure as accountability shifts

Adopting the core provisions of the EU AI Act early will help embed the governance mechanisms that will apply to AI technologies.

A growing focus on individual accountability is already reshaping the regulatory landscape. We have seen this with NIS2, where directors and members of management bodies may face personal accountability measures, subject to national implementation. AI regulation is expected to follow a similar path.

In my experience, boards rarely act until there is a clear consequence for inaction, and the first major AI-related incident will almost certainly sharpen scrutiny at the leadership level.

The challenge is that traditional oversight models were never built for autonomous systems capable of making independent decisions. Without documented governance, clear audit trails, and timely reporting, leaders have no credible way to show they understand the risks or have exercised proper oversight.

As regulation tightens, expectations will move from periodic reviews to continuous visibility – and accountability will sit firmly with those at the top.

Transparency and ethical data practices are differentiators

Trust is one of the most decisive factors in how organizations choose their partners, suppliers, and technology providers. Customers now expect evidence that the systems that they rely on are developed and deployed responsibly. That expectation only grows when AI is involved, particularly where models make or influence decisions that affect people, operations, or sensitive data.

This is why transparency around how AI systems are trained, tested, and monitored is becoming a critical differentiator. Clear documentation, ethical data practices, and strong guardrails are not just compliance measures – they are signals of maturity in a market where information asymmetry has long favoured providers.

Organizations that can explain their AI clearly, demonstrate control, and show responsible use will be far better positioned to earn trust. As regulation advances, transparency and accountability will sit at the heart of that trust. Those who embrace these principles early will stand out long before they are formally required.

Practical steps that organizations can take for AI compliance

Preparing for the EU AI Act does not require full regulatory clarity. What matters is building a solid governance foundation that can evolve as guidance matures. Organizations already using AI, whether for internal support or in products and services, can start by putting clear oversight in place and keeping humans involved in any system capable of making or acting on decisions. This distinction is crucial, as the risks linked to a generative assistant are very different from those associated with an autonomous model that could push code or approve transactions.

Documenting how models are trained, what data they process, and the limitations of their outputs is another essential step. This should be supported by regular risk assessments that evolve alongside the technology. Many organizations still struggle with incident tracking and reporting, so establishing repeatable workflows now will be vital once the Act introduces stricter requirements.

Continuous monitoring will also play a central role. Automated evidence collection, model-behaviour tracking, and centralised documentation cut the burden of annual audits and give leaders the real-time visibility that they need to make informed decisions. A cross-functional approach – involving security, compliance, product, legal, and operations – ensures governance becomes part of day-to-day practice rather than a last-minute addition.

Why proactive compliance is a resilience strategy, not a regulatory chore

Governance, risk, and compliance have long been viewed as a cost, but that perception is rapidly changing. Organizations that can demonstrate responsible practice almost always gain an advantage, especially when customers are choosing between similar services. Strong governance builds confidence, reduces uncertainty, and strengthens resilience by ensuring that issues are identified before they escalate.

In an AI-driven environment, proactive compliance becomes even more valuable. Real-time visibility, clear documentation, and continuous oversight help organizations respond quickly to emerging risks while showing stakeholders that safety and accountability are central to how they operate. Far from slowing innovation, responsible governance provides the stability that enables it.

The author

Martin Davies is Senior Audit Alliance Manager at Drata

Europe
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email WhatsApp
Previous ArticleFraud risk in 2026 – the year collaboration becomes more concrete
Next Article The Internet of Stranger Things: managing IoT risks

Related Posts

An exploding digital padlock illustrates the requirement for post-quantum cryptography.

Research breakthrough brings reliable quantum computers and Q-day closer to reality

September 10, 2026
A danger sign on a digital background.

New blob URL phishing technique evades detection by using legitimate Microsoft services

September 10, 2026
AI risks

Unmanaged AI workflows expose EMEA organizations to rising compliance and data risks

September 9, 2026
City skyline at sunset with bright light trails and a translucent blue smart-city grid overlay and GPS pins indicating locations.

AI world models: future possibilities for organizational resilience?

September 7, 2026
DRJ and BCI logos

DRJ and BCI publish guidance for governing, managing, and using AI in resilience

September 7, 2026
Decision making with over whelming information.

AI can find the vulnerability. Accountability still sits with your crisis leadership

September 7, 2026
Advertisement
Resilience First
This week's most read articles
Under pressure: An egg cracking under pressure applied by squeezing clamps form the sides.

Managing scenario testing for operational resilience

May 16, 2024
COSO logo

New COSO ERM guidance aims to help organizations with practical implementation

May 12, 2026
Close-up of a green-brown iris peering through a jagged tear in dark paper or wall material.

The blind spots in business continuity

September 2, 2026
Latest resources
AI enabled business processes concept.

Operational resilience in an AI-dependent enterprise

August 26, 2026
Load More

Subscribe to Updates

Get our Resilience Updates newsletter.

Most Popular Feature Articles
Three dark coloured light bulbs on a black background illustrate the concept of The Dark Triad in Crisis Management.

The Dark Triad in crisis management

Five stage crisis management framework

A five stage framework for a crisis management process

Blue interconnected gears and network nodes symbolizing automation and complex machinery.

Agent zero – the 2028 digital pandemic

Latest Reports
A futuristic red warning alert icon with glowing exclamation mark.

Cloud Security Alliance publishes Hugging Face Incident Initial Post-Mortem

A person hold a building door open for a person behind who is tailgating to get unauthorised access.

Security Culture: A Strategic Capability That Builds Resilience in a Volatile World

An identity icon with a map marker on it, indicating the concept of identity as a target for attackers. The icon is on a generic IT background predominantly in black and orange.

Identity-based approaches dominate initial access for ransomware attacks

A promo box for an article about resilience governance.
© 2026 Resilience Forward
  • About Resilience Forward
  • Newsletter
  • Newsfeed
  • Advertise
  • Call for Papers
  • Contact
  • Privacy Policy and Cookie Use
  • AI Use Policy

Type above and press Enter to search. Press Esc to cancel.

Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Manage Cookie Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behaviour or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
Ad Blocker Enabled!
Ad Blocker Enabled!
Our website is made possible by displaying online advertisements to our visitors. Please support us by disabling your Ad Blocker.

Sign In or Register

Welcome Back!

Login to your account below.

Lost password?