When the EU AI Act became enforceable, the most common response I saw from leadership teams was to forward it to legal.
That instinct is understandable. It is also exactly backward.
The EU AI Act is not primarily a legal problem, but an operational one. And the organizations most exposed are those that genuinely do not know what AI is running inside their own walls.
Most Companies Can't See Their AI Risk
Most regulatory conversations focus on prohibited use cases. High-risk systems. Transparency requirements. Penalties for non-compliance. Those conversations matter, but they are downstream of a more fundamental problem.
Before a company can determine whether its use of AI is compliant, it has to know which AI it is using. And when I have watched organizations go through that inventory process, what they find consistently surprises them.
What a real AI inventory turns up:
- Shadow AI is everywhere. Employees using consumer AI tools for work tasks, outside any procurement or security review. Drafting documents, summarizing meetings, analyzing data, and answering customer queries.
- Teams are adopting tools independently. Individual teams that adopted AI solutions independently, with no central visibility. The marketing team is using one platform. The finance team is using another. The HR team is running a third.
- Sensitive data is leaving approved systems. Employees are uploading customer data, internal documents, or proprietary information into AI tools that were never vetted for data handling, privacy, or security.
- AI-generated decisions lack accountability. Outputs being used to make consequential decisions, with no record of how the AI reached them, what data it used, or who approved the process.
The problem in every one of these cases is the same. The behavior is not malicious. It is invisible. Invisible behavior cannot be governed.
Most Companies Are Somewhere Between Growth and Chaos
In my work with organizations building AI governance frameworks, I see the same pattern playing out repeatedly. There are four stages, and most companies today are stuck somewhere between the second and the third.
Stage 1: AI Experimentation
Leadership encourages AI adoption. The message is broadly permissive. Try things. See what works. Move fast. This stage feels productive because activity is high and the risks are not yet visible.
Stage 2: Proliferation
Dozens of tools appear across the organization. Different departments adopt different platforms. Usage expands faster than anyone is tracking. The organization is generating real productivity gains in pockets, alongside real risks that nobody has mapped.
Stage 3: Panic
Leadership realizes nobody has a complete picture of what is happening. A compliance question arises, a data incident surfaces, or a regulator requests documentation, and the organization discovers it cannot answer basic questions about its own AI use. This is where most companies currently sit.
Stage 4: Governance
Policies, inventories, controls, and monitoring are put in place. AI usage becomes visible, documented, and manageable. The organization can answer the questions regulators and customers will ask, and can make informed decisions about risk.
The gap between Stage 3 and Stage 4 is where the EU AI Act is applying pressure. Companies that have not moved through it deliberately will be forced to move through it reactively. Reactive is significantly more expensive.
Compliance Starts With Knowing What AI You Use
The EU AI Act is not asking companies to stop using AI. It is asking them to answer a question that responsible leadership should have been asking anyway: how do we govern intelligence inside the enterprise?
Answering that question requires four things that most organizations have not yet built:
- An inventory of AI systems in use, including tools adopted at the department level and tools employees are using individually without formal approval.
- A risk classification process that maps each system to the Act's risk categories and identifies which require formal documentation, human oversight, or specific technical safeguards.
- Data governance controls that establish clear rules about what data can be used with which tools, and enforce those rules in practice rather than just on paper.
- Audit trails for consequential decisions that allow the organization to reconstruct how an AI-assisted decision was reached, what inputs were used, and who was responsible for the outcome.
None of these is a primarily legal task. They require operational leadership, cross-functional coordination, and in most cases, a significant amount of remediation work on systems and processes that were never designed with governance in mind.
Every Month of Delay Increases the Cost
The EU AI Act did not create this problem. It revealed one that was already there.
Organizations that moved fast on AI adoption without building governance infrastructure did not make a technological error. They made a leadership error. The technology worked. The oversight did not keep pace with it.
Legal teams can interpret the regulation. They can map requirements to existing frameworks. They can advise on high-risk classifications and documentation standards.
What legal teams cannot do is inventory shadow AI across forty departments. They cannot establish data handling protocols for tools that procurement has never reviewed. They cannot build an audit-trail infrastructure for decisions already being made. Those are operational problems, and they require operational ownership.
The companies treating the EU AI Act compliance as a legal workstream will produce documentation. The companies treating it as an operational transformation will produce governance. Those are not the same outcome, and regulators are increasingly able to tell the difference.
Three Questions Leaders Need to Answer Now
There is a version of this story in which companies act now, and another in which they wait.
Companies that build governance now will move faster later. An organization with a clean AI inventory, documented risk classifications, and functioning oversight processes can adopt new tools quickly, with confidence. The governance infrastructure becomes a capability, not just a compliance cost.
Companies that wait will face a different arithmetic. Every month of uncontrolled AI proliferation is another month of shadow tools to inventory, unauthorized data flows to trace, and undocumented decisions to reconstruct. The longer the gap between Stage 2 and Stage 4, the more expensive the crossing becomes.
Three questions leadership should answer this quarter:
- Can you produce a complete inventory of AI tools currently in use across your organization, including tools adopted at the team or individual level without central approval?
- Do you know what data your employees are putting into AI systems that were not procured through your standard vendor review process?
- Can you reconstruct how any AI-assisted decision your organization made in the last six months was reached, what it was based on, and who was accountable for it?
If the answer to any of those is no, the compliance risk is not primarily regulatory, but operational. And it exists independently of whether a regulator ever asks.
The organizations that find out on their own terms will handle it. Those that find out when someone else asks the question will have significantly less room to maneuver.
This is only a preview.
The deeper insights, including how AI reshapes education, finance, leadership, cybersecurity, and communication, are inside Neil's Substack, where policymakers, founders, and Fortune 500 leaders get strategies they won't find anywhere else.
Read Disrupting the Box on Substack