Back to blogGeneral

AI Governance: Why Your Company Is Already Breaking the Law

Discover why the postponement of the AI Act is a myth, the risks of operational chaos, and how to implement a robust governance plan in your company.

N
NAiOS.net Team
12 de agosto de 20267 min read
Compartir:
AI: Create a modern and professional image for a corporate website focused on AI governance. The design
In this article
  1. Article 4: The obligation that is already in force
  2. The real problem is not regulatory, it's operational chaos
  3. What is AI Governance and how is it applied?
  4. The role of AESIA and the risk of sanctions
  5. Frequently Asked Questions (FAQ) about the AI Act and Governance
  6. Conclusion: The self-assessment you must do today

AI Governance: Why Your Company Is Already Breaking the Law (and How to Fix It)

The headline said that the European Union had postponed its AI law to 2027.

Your company has been breaking it since February 2025.

Both things are true, and that is exactly where the problem and the widespread confusion within the business landscape lie. Over the last summer, the media was filled with reassuring headlines about the Digital Omnibus, in force since July 27, which postponed the strictest obligations for high-risk Artificial Intelligence systems. December 2027 was set for Annex III systems and August 2028 for those integrated into products.

The relief was palpable. However, that part of the regulation is barely used by any SME. What did not move from its place was the general application date of the regulation: August 2, 2026, at which point the surveillance authorities will have full powers.

But there is an even more urgent detail that has gone unnoticed by most executives and IT managers: Article 4.

Article 4: The obligation that is already in force

Article 4 of the AI ActAI Act (EU AI Act)Regulation (EU) 2024/1689: the first comprehensive law on artificial intelligence, with obligations based on risk level (EU Artificial Intelligence Act) has been in force since February 2025 and affects every company that uses Artificial Intelligence in its daily processes. And most importantly: with no size threshold. It doesn't matter if you are a multinational with 10,000 employees or a 15-person agency.

If someone on your staff uses ChatGPT to write emails, CopilotAI CopilotAI Assistant integrated into work tools to code, or a modern CRM with a predictive scoring system, the law requires you to ensure that this person has the appropriate «AI literacy». That is, the employee must know what risks the tool they handle entails. And your company must be able to prove it.

Proving it doesn't mean having good intentions; it means having paper. It means having auditable documentation that supports that your company has control over the technology it uses.

The real problem is not regulatory, it's operational chaos

This is where we must address an unpopular reality: most SMEs do not have a purely regulatory problem. They have a governance problem that is already costing them money, time, and reputation long before any inspector appears at the door.

The adoption of AI in companies has occurred from the bottom up. It is the employees who have introduced these tools to be more productive, creating what in cybersecurity is known as Shadow IT (or in this case, Shadow AIShadow AIUnauthorized use of AI tools within organizations). This creates scenarios of high operational risk:

  • Duplicated and uncontrolled tools: You have AI tools contracted by three different departments (Marketing, Sales and HR) paying for duplicate licenses without anyone in management being aware of it.
  • Hallucinations that cost customers: Commercial quotes drafted automatically with data, rates or promises that the language model (LLMLLM (Large Language Model)Large language model, the foundation of today's chatbots) made up.
  • BiasAlgorithmic BiasWhen AI reproduces or amplifies biases present in the data and legal issues in Human Resources: Résumés screened automatically with opaque criteria that no one in the company can reconstruct or justify in the face of a discrimination complaint.

What is AI Governance and how is it applied?

Governing Artificial Intelligence does not mean halting your company's technological innovation. Governing AI is, simply, deciding in writing what can be done, with what data it can be done and who signs off on that responsibility.

In a company of 50 people, a solid governance plan does not require a new department. It fits into four key documents, the assignment of a named individual as the person responsible, and a quarterly review of an hour and a half.

The 4 essential documents of your AI Governance

To comply with the law and protect your business, you need to structure your governance around these four documentary pillars:

  1. Inventory of AI systems: An up-to-date record of all AI tools (free and paid) used in the company, which department uses them and for what specific purpose.
  2. Training plan by role: A software developer does not need to know the same about AI as a human resources profile. You must document what training each role has received about the risks of their tools (thus complying with Article 4).
  3. Activity and audit logs: Logs or documents that record when tools have been evaluated, what incidents have occurred and how they have been resolved.
  4. Corporate usage instructions (AI Policies): A clear guide for employees on what company data can be entered into a public model (such as ChatGPT) and which is strictly prohibited for confidentiality reasons.

The role of AESIA and the risk of sanctions

It is essential to remember that on August 2 last year, AESIA (the Spanish Agency for the Supervision of Artificial Intelligence) gained new powers to inspect and sanction. Despite this, the vast majority of Spanish SMEs do not even have their tool inventory in place.

What is expensive is not setting up this governance system today. The truly expensive and paralyzing thing is trying to set it up in the middle of the night the day a request from the administration arrives or when a corporate client demands an AI audit to sign a contract.

AI Governance implementation flow

Below, we show you a basic workflow to implement governance in your company:

Initial Audit: Discover Shadow AI

Create Inventory of AI Tools

Risk Assessment and Data Privacy

Drafting Usage and Governance Policies

Execute Role-Based Training Plan

Quarterly Review and Documentation Update

Initial Audit: Discover Shadow AI

Create Inventory of AI Tools

Risk Assessment and Data Privacy

Drafting Usage and Governance Policies

Execute Role-Based Training Plan

Quarterly Review and Documentation Update

Frequently Asked Questions (FAQ) about the AI Act and Governance

To optimize your understanding of this complex landscape, we have compiled the most common questions we receive from executives and IT managers:

When does the EU AI Act come into force for SMEs?
Although the obligations for high-risk systems are deferred to the end of 2027, the general application is in August 2026. However, Article 4, which requires AI literacy of employees, has been in force since February 2025 for any company that uses AI, regardless of its size.

What is Shadow AI and why is it dangerous?
Shadow AI occurs when employees use Artificial Intelligence tools (such as public LLMs, image generators, or assistants) without the explicit knowledge or approval of the IT department or management. It is dangerous because it exposes the company to leaks of confidential data, intellectual property violations, and security breaches.

Do I need to hire a full-time expert for AI governanceAI GovernanceRegulatory and management framework for the responsible use of AI?
Not necessarily. In most SMEs, AI governance can be managed by assigning responsibility to an existing management or operations role (such as the IT manager or the DPO), supported by external consultants to establish the initial framework and carry out the quarterly reviews.

What is the inventory of AI systems?
It is a living document that lists all AI-based applications used in the company. It must include the tool name, the provider, the purpose of use, the responsible department and the associated risk level according to the AI Act classification.

What happens if an employee enters customer data into ChatGPT?
If you don't have a clear usage policy and an appropriate data processing agreement with the AI provider, entering personal or confidential customer data into a public model constitutes a serious breach of the GDPR and confidentiality policies, exposing the company to million-euro fines.

Conclusion: The self-assessment you must do today

At this point, the question you must ask yourself as a business leader is simple and direct: Do you have your AI tool inventory done and documented, or are you discovering it right now as you read this article?

Artificial Intelligence is the greatest productivity accelerator of our era, but without control, it is an endless source of legal and operational risks. Don't let a lack of organization hold back your competitiveness or expose you to unnecessary penalties.

Is your company prepared?
If you answered "no" to the question about the inventory, or if you have doubts about how to start organizing these four essential documents, it's time to act. If you need to create a solid governance plan, contact us today by writing to info@netretina.ai. We'll help you design an AI strategy that is secure, cost-effective and 100% aligned with European regulations.

Hashtags to share:

#NAiOS #IA #General #CRM #Sales #Marketing #SME #ArtificialIntelligence

Compartir:

Related articles

Soporte en 2026: un departamento entero, no un buzón
Naios Functions

Support in 2026: an entire department, not a mailbox

A mailbox stores messages; a department knows the status of each request, who is handling it, and who can see it. Support, included in any NAiOS instance, unifies form, email, Talk and chat into a single inbox, sets in advance who sees what, connects your platform with the NAiOS hub and lets AI do the triage while a person decides.

5 de octubre de 2026
Read more
NAiOS, explicado hoy: el chat con IA que ya incluye lo que tu empresa paga por separado
Naios Functions

NAiOS, explained today: the AI chat that already includes what your business pays for separately

What NAiOS is today: a multi-model AI chat and, with the same account, the native suites that a company pays for separately (office tools, email, meetings, customers, invoicing, accounting, people, training...). Table of which subscription covers each module, nine use cases by sector, the agents layer with a person in front, what NAiOS is not and how it is paid for.

4 de octubre de 2026
Read more
Habilidades: instrucciones que el chat aplica solo
Naios Functions

Skills: instructions that the chat applies on its own

New NAiOS module: 52 installable skills in ten categories, in open SKILL.md format and in six languages. They apply on their own when the request fits or with a slash in the chat, companies publish their own for the whole team and agents wear them. And how NAiOS Labs built it in one day: request, concept, harness, build, test and plating.

3 de octubre de 2026
Read more
El agente multiplica lo que ya sabes, y también lo que no sabes
Digital Transformation

The agent multiplies what you already know, and also what you don't know

One person with a coding agent closed 47 commits in a day. The figure is not the important thing: what matters is that writing code has stopped being the bottleneck and that the agent amplifies, with the same good appearance, both the judgement and the gaps of the person directing it. What to ask for, what it can touch, how far it goes, how we do it and why it applies equally to agents that do not write code.

2 de octubre de 2026
Read more
De la factura en PDF al pago: el gasto entra solo y tú solo lo confirmas
Naios Functions

From the PDF invoice to payment: the expense enters on its own and you just confirm it

Upload the supplier's PDF invoice and the AI proposes the expense with the PDF next to it; you correct and confirm. Invoices in dollars at the ECB exchange rate, EU suppliers with reverse charge, the two payment gateway fees, partial payments and instalment plans, payment methods, Treasury matching each charge, and the historical data from the previous software imported in an afternoon. Everything that has entered the NAiOS ERP this week.

27 de septiembre de 2026
Read more

Did you enjoy this article?

Discover more content on our blog.

View all posts