AI Governance: Why Your Company Is Already Breaking the Law (and How to Fix It)
The headline said that the European Union had postponed its AI law to 2027.
Your company has been breaking it since February 2025.
Both things are true, and that is exactly where the problem and the widespread confusion within the business landscape lie. Over the last summer, the media was filled with reassuring headlines about the Digital Omnibus, in force since July 27, which postponed the strictest obligations for high-risk Artificial Intelligence systems. December 2027 was set for Annex III systems and August 2028 for those integrated into products.
The relief was palpable. However, that part of the regulation is barely used by any SME. What did not move from its place was the general application date of the regulation: August 2, 2026, at which point the surveillance authorities will have full powers.
But there is an even more urgent detail that has gone unnoticed by most executives and IT managers: Article 4.
Article 4: The obligation that is already in force
Article 4 of the AI Act (EU Artificial Intelligence Act) has been in force since February 2025 and affects every company that uses Artificial Intelligence in its daily processes. And most importantly: with no size threshold. It doesn't matter if you are a multinational with 10,000 employees or a 15-person agency.
If someone on your staff uses ChatGPT to write emails, CopilotAI CopilotAI Assistant integrated into work tools to code, or a modern CRM with a predictive scoring system, the law requires you to ensure that this person has the appropriate «AI literacy». That is, the employee must know what risks the tool they handle entails. And your company must be able to prove it.
Proving it doesn't mean having good intentions; it means having paper. It means having auditable documentation that supports that your company has control over the technology it uses.
The real problem is not regulatory, it's operational chaos
This is where we must address an unpopular reality: most SMEs do not have a purely regulatory problem. They have a governance problem that is already costing them money, time, and reputation long before any inspector appears at the door.
The adoption of AI in companies has occurred from the bottom up. It is the employees who have introduced these tools to be more productive, creating what in cybersecurity is known as Shadow IT (or in this case, Shadow AIShadow AIUnauthorized use of AI tools within organizations). This creates scenarios of high operational risk:
- Duplicated and uncontrolled tools: You have AI tools contracted by three different departments (Marketing, Sales and HR) paying for duplicate licenses without anyone in management being aware of it.
- Hallucinations that cost customers: Commercial quotes drafted automatically with data, rates or promises that the language model (LLMLLM (Large Language Model)Large language model, the foundation of today's chatbots) made up.
- BiasAlgorithmic BiasWhen AI reproduces or amplifies biases present in the data and legal issues in Human Resources: Résumés screened automatically with opaque criteria that no one in the company can reconstruct or justify in the face of a discrimination complaint.
What is AI Governance and how is it applied?
Governing Artificial Intelligence does not mean halting your company's technological innovation. Governing AI is, simply, deciding in writing what can be done, with what data it can be done and who signs off on that responsibility.
In a company of 50 people, a solid governance plan does not require a new department. It fits into four key documents, the assignment of a named individual as the person responsible, and a quarterly review of an hour and a half.
The 4 essential documents of your AI Governance
To comply with the law and protect your business, you need to structure your governance around these four documentary pillars:
- Inventory of AI systems: An up-to-date record of all AI tools (free and paid) used in the company, which department uses them and for what specific purpose.
- Training plan by role: A software developer does not need to know the same about AI as a human resources profile. You must document what training each role has received about the risks of their tools (thus complying with Article 4).
- Activity and audit logs: Logs or documents that record when tools have been evaluated, what incidents have occurred and how they have been resolved.
- Corporate usage instructions (AI Policies): A clear guide for employees on what company data can be entered into a public model (such as ChatGPT) and which is strictly prohibited for confidentiality reasons.
The role of AESIA and the risk of sanctions
It is essential to remember that on August 2 last year, AESIA (the Spanish Agency for the Supervision of Artificial Intelligence) gained new powers to inspect and sanction. Despite this, the vast majority of Spanish SMEs do not even have their tool inventory in place.
What is expensive is not setting up this governance system today. The truly expensive and paralyzing thing is trying to set it up in the middle of the night the day a request from the administration arrives or when a corporate client demands an AI audit to sign a contract.
AI Governance implementation flow
Below, we show you a basic workflow to implement governance in your company:
Frequently Asked Questions (FAQ) about the AI Act and Governance
To optimize your understanding of this complex landscape, we have compiled the most common questions we receive from executives and IT managers:
When does the EU AI Act come into force for SMEs?
Although the obligations for high-risk systems are deferred to the end of 2027, the general application is in August 2026. However, Article 4, which requires AI literacy of employees, has been in force since February 2025 for any company that uses AI, regardless of its size.
What is Shadow AI and why is it dangerous?
Shadow AI occurs when employees use Artificial Intelligence tools (such as public LLMs, image generators, or assistants) without the explicit knowledge or approval of the IT department or management. It is dangerous because it exposes the company to leaks of confidential data, intellectual property violations, and security breaches.
Do I need to hire a full-time expert for AI governanceAI GovernanceRegulatory and management framework for the responsible use of AI?
Not necessarily. In most SMEs, AI governance can be managed by assigning responsibility to an existing management or operations role (such as the IT manager or the DPO), supported by external consultants to establish the initial framework and carry out the quarterly reviews.
What is the inventory of AI systems?
It is a living document that lists all AI-based applications used in the company.
It must include the tool name, the provider, the purpose of use, the responsible department and the associated risk level according to the AI Act classification.
What happens if an employee enters customer data into ChatGPT?
If you don't have a clear usage policy and an appropriate data processing agreement with the AI provider, entering personal or confidential customer data into a public model constitutes a serious breach of the GDPR and confidentiality policies, exposing the company to million-euro fines.
Conclusion: The self-assessment you must do today
At this point, the question you must ask yourself as a business leader is simple and direct: Do you have your AI tool inventory done and documented, or are you discovering it right now as you read this article?
Artificial Intelligence is the greatest productivity accelerator of our era, but without control, it is an endless source of legal and operational risks. Don't let a lack of organization hold back your competitiveness or expose you to unnecessary penalties.
Is your company prepared?
If you answered "no" to the question about the inventory, or if you have doubts about how to start organizing these four essential documents, it's time to act. If you need to create a solid governance plan, contact us today by writing to info@netretina.ai. We'll help you design an AI strategy that is secure, cost-effective and 100% aligned with European regulations.






