By Martin Davies
Organizations across every industry are embracing AI at speed, with many investing heavily in integrating the technology into their operations. Gartner estimates that cumulative worldwide spending on AI will have reached $2 trillion by the end of 2026.
However, while many companies are full steam ahead on AI, the governance needed to keep that adoption safe is not keeping pace. The slow-moving nature of the regulatory world struggles to keep up with this rapidly evolving technology. Although the EU AI Act applies in phases, with some requirements already in place, many commencing in August 2026, and some later in 2027, high levels of AI risk exposure already exist today – particularly as autonomous systems become more capable and more deeply embedded in everyday operations.
Organizations should not wait for regulatory direction before taking action on AI governance. Reactive compliance will be costly, disruptive, and difficult to retrofit. The businesses that lead in 2026 will be those that lay the groundwork for responsible, transparent, AI use to build trust and resilience before regulation forces their hand.
Why waiting for regulation is risky
AI is evolving far faster than the regulations intended to govern it. One of the biggest challenges is that organizations still lack clarity on what will count as ‘high-risk AI’.
While the EU has given details of what it means by high-risk AI, defining these as AI systems that negatively affect safety or fundamental rights, it has also confirmed that these will be broken down into two groups:
1) AI systems that are used in products falling under the EU’s product safety legislation. This includes toys, aviation, cars, medical devices and lifts.
2) AI systems falling into specific areas that will have to be registered in an EU database:
- Biometric identification and categorization
- Management and operation of critical infrastructure
- Education and vocational training
- Employment, worker management and access to self-employment
- Access to and enjoyment of essential private services and public services and benefits
- Law enforcement
- Migration, asylum and border control management
- Assistance in legal interpretation and application of the law.
However, many businesses are waiting for concrete external guidance on classifying the AI they are already using, meaning that many will struggle to get ready for the AI Act’s provisions coming into effect.
It is a familiar pattern we have seen repeated with the GDPR, NIS2, and many others. However, the rapid speed of AI presents a different and more difficult situation. A year is a long time for such a rapidly-developing technology, and AI systems could look completely different by the time the Act takes full effect.
Boards will feel growing pressure as accountability shifts
Adopting the core provisions of the EU AI Act early will help embed the governance mechanisms that will apply to AI technologies.
A growing focus on individual accountability is already reshaping the regulatory landscape. We have seen this with NIS2, where directors and members of management bodies may face personal accountability measures, subject to national implementation. AI regulation is expected to follow a similar path.
In my experience, boards rarely act until there is a clear consequence for inaction, and the first major AI-related incident will almost certainly sharpen scrutiny at the leadership level.
The challenge is that traditional oversight models were never built for autonomous systems capable of making independent decisions. Without documented governance, clear audit trails, and timely reporting, leaders have no credible way to show they understand the risks or have exercised proper oversight.
As regulation tightens, expectations will move from periodic reviews to continuous visibility – and accountability will sit firmly with those at the top.
Transparency and ethical data practices are differentiators
Trust is one of the most decisive factors in how organizations choose their partners, suppliers, and technology providers. Customers now expect evidence that the systems that they rely on are developed and deployed responsibly. That expectation only grows when AI is involved, particularly where models make or influence decisions that affect people, operations, or sensitive data.
This is why transparency around how AI systems are trained, tested, and monitored is becoming a critical differentiator. Clear documentation, ethical data practices, and strong guardrails are not just compliance measures – they are signals of maturity in a market where information asymmetry has long favoured providers.
Organizations that can explain their AI clearly, demonstrate control, and show responsible use will be far better positioned to earn trust. As regulation advances, transparency and accountability will sit at the heart of that trust. Those who embrace these principles early will stand out long before they are formally required.
Practical steps that organizations can take for AI compliance
Preparing for the EU AI Act does not require full regulatory clarity. What matters is building a solid governance foundation that can evolve as guidance matures. Organizations already using AI, whether for internal support or in products and services, can start by putting clear oversight in place and keeping humans involved in any system capable of making or acting on decisions. This distinction is crucial, as the risks linked to a generative assistant are very different from those associated with an autonomous model that could push code or approve transactions.
Documenting how models are trained, what data they process, and the limitations of their outputs is another essential step. This should be supported by regular risk assessments that evolve alongside the technology. Many organizations still struggle with incident tracking and reporting, so establishing repeatable workflows now will be vital once the Act introduces stricter requirements.
Continuous monitoring will also play a central role. Automated evidence collection, model-behaviour tracking, and centralised documentation cut the burden of annual audits and give leaders the real-time visibility that they need to make informed decisions. A cross-functional approach – involving security, compliance, product, legal, and operations – ensures governance becomes part of day-to-day practice rather than a last-minute addition.
Why proactive compliance is a resilience strategy, not a regulatory chore
Governance, risk, and compliance have long been viewed as a cost, but that perception is rapidly changing. Organizations that can demonstrate responsible practice almost always gain an advantage, especially when customers are choosing between similar services. Strong governance builds confidence, reduces uncertainty, and strengthens resilience by ensuring that issues are identified before they escalate.
In an AI-driven environment, proactive compliance becomes even more valuable. Real-time visibility, clear documentation, and continuous oversight help organizations respond quickly to emerging risks while showing stakeholders that safety and accountability are central to how they operate. Far from slowing innovation, responsible governance provides the stability that enables it.
The author
Martin Davies is Senior Audit Alliance Manager at Drata






