The EU Artificial Intelligence Act as an Enterprise Governance Challenge
Abstract
The European Union Artificial Intelligence Act establishes a uniform, risk-based legal framework forartificial intelligence systems and general-purpose AI models. Its practical implementation, however,cannot be reduced to a legal interpretation exercise or delegated exclusively to information technology.Organizations may acquire different legal roles across the AI value chain; the same technology may beprohibited, high-risk, transparency-regulated, or minimally regulated depending on its intendedpurpose, context, modification, and effect. This paper analyzes the Act as amended through 27 July2026 and proposes an enterprise governance framework that converts legal classification intoaccountable operational practice. The framework begins with discovery of AI use, determination oflegal role, and risk classification; it then assigns ownership, implements lifecycle controls, and verifiescontinuing effectiveness. The analysis shows that leadership, operations, procurement, humanresources, legal and compliance, quality, cybersecurity, and internal assurance each possessinformation or authority necessary for compliance. ISO/IEC 42001 is evaluated as a usefulorganizational architecture for this work, while its voluntary and non-equivalent relationship to statutoryconformity is preserved. The paper concludes that the AI Act is risk-based in legal design but must bemanagement-system-based in organizational implementation. Keywords: European Union Artificial Intelligence Act; EU AI Act; AI governance; ISO/IEC 42001; artificial intelligence management system; high-risk AI; AI literacy; regulatory compliance; conformity assessment; organizational accountability.
// Source
Authors: Celso Alvarado Martinez
Institutions: Cloud Computing Center, 123 Certification (Canada)