AI governance · 12 min read
EU AI Act Implementation Roadmap for Companies | NUMEDIA
Compliance becomes manageable when it is treated as an operating model: named owners, a complete inventory, repeatable decisions, embedded controls and evidence created during normal work.

Start with accountability, not a policy document
A policy cannot classify systems, approve exceptions or respond to incidents. Establish an executive sponsor, an operational AI owner and a cross-functional review group spanning legal, privacy, security, procurement, HR and the business.
Define who may approve a use case, who can stop it and who maintains the evidence. This decision architecture prevents compliance from becoming an end-of-project legal review.
- Executive sponsor owns risk appetite and resources
- System owner remains accountable for outcomes
- Control owners verify privacy, security and human oversight
- Users know when and how to escalate
Months 1–3: inventory and triage
Create one intake route for every AI use case, including embedded features in SaaS products and employee experiments. Record purpose, users, affected people, model and vendor, data categories, outputs, integrations and existing controls.
Apply an initial risk triage quickly. Flag prohibited practices, potential high-risk use cases, transparency duties and material GDPR implications for specialist review.
- Known production systems
- Pilots and proofs of concept
- Shadow AI and employee tools
- Third-party products with embedded AI
Months 4–6: controls and documentation
Translate each obligation into an operational control with an owner, trigger, evidence and review frequency. Controls should cover data governance, instructions for use, logging, human oversight, accuracy, robustness, cybersecurity and transparency where applicable.
Keep a decision record showing why the classification was reached and what information was available. A short, reproducible rationale is more valuable than an unsupported label.
Months 7–9: integrate the lifecycle
Embed AI review into procurement, security assessment, privacy review, product development and change management. A system must be reassessed when its purpose, model, data, users or autonomy changes.
Train people by role. General awareness is useful, but system owners, reviewers, developers and frontline users need different practical capabilities.
Months 10–12: test and operate
Run a tabletop incident, sample evidence from several systems and test whether a reviewer can reconstruct the approval decision. Close gaps before expanding the portfolio.
Report a compact management view: inventory coverage, unresolved high-risk cases, overdue controls, incidents, training completion and systems approaching material change.
Frequently asked questions
Does every AI system require the same documentation?
No. Documentation should be proportionate to the system's role and risk, while the inventory and classification rationale should cover every use case.
Who should lead EU AI Act implementation?
A senior sponsor should own the program, while an operational owner coordinates legal, privacy, security, procurement and business control owners.
Can an existing GDPR program cover the AI Act?
It provides useful foundations, but the AI Act adds system classification, transparency, human oversight, technical performance and lifecycle obligations that require dedicated controls.