← Insights

Transparency & accountability in practice

The AI Act in plain language: three accountability questions with a deadline

Those three are the AI Act in plain language.
dogoda

On 2 August 2026, the European AI Office moves from a body that can advise to one that can request. Information requests, mandated mitigations and model recalls become real operational tools from that date. Fines are possible under specific circumstances. This is not legal advice, and the distinction matters: the AI Office is not primarily a fine machine. It is a body that can now ask questions, require written answers, and act on the gaps it finds.

My read, and it is not a popular one: most organisations running AI systems in production right now are nowhere near ready to answer those questions. The systems exist. The accountability structure around them often does not. And the party doing the asking, from 2 August, is no longer a colleague you can put off until next quarter.

Three plain questions map the exposure: which model uses which data, who inside IT owns this AI system, and where is the human-in-the-loop that can override it. Those three are the AI Act in plain language. Walk through each one, and you have mapped your real position before anyone asks.

Which model uses which data

The Act’s obligations begin with an inventory. Before you can assess whether a system is high-risk under the Act’s annexes, you need to know what model you are running, on what data it was trained or fine-tuned, and what decisions it influences in production. For general-purpose AI models, the provider’s obligations are one layer; the operator’s obligations as a deployer are another, and they cannot be delegated to the vendor’s compliance documentation.

In practice, this question surfaces a gap that has nothing to do with the regulation itself. Many organisations adopted AI capabilities without building a clear picture of which systems are running which models on which data. The tooling moved faster than the documentation. That is not unusual, but it is the gap the Act will now expose: an information request from the AI Office requires a specific, accurate answer, not a best guess at what the vendor probably did.

Who inside IT owns this AI system

Operator accountability under the Act requires a named person, not a team and not a vendor. For each AI system a deployer runs, someone with a title and a job description needs to be able to say: I am responsible for this system’s operation, its outputs and our obligations around it.

This is where most governance discussions stall. The business unit that requested the system points at IT. IT points at the vendor. The vendor points at its terms of service. From 2 August, the party asking “who is accountable” will not accept any of those answers. The AI Act places operator obligations on the organisation that deploys the system, and those obligations require a named human being, not a process document.

A CIO or head of IT is the right default owner for systems that IT operates. For systems embedded in a specific business function, the accountable person needs both IT authority and business context: someone who can actually intervene, not just someone whose name is on a form.

Where is the human-in-the-loop that can override it

High-risk AI systems must have a meaningful human oversight capability. That means a real operational pathway: a named person who can review an output, pause the system or reject a recommendation before it affects a customer, a patient or an employment decision. Not a theoretical switch in the architecture documentation.

The practical test is whether the override works under pressure. If a system produces an unexpected output at an inconvenient time, is there a named person who knows they are the one responsible for catching it? If the answer is “it would go to the team,” the override is notional, not operational. The Act asks for the former.

The minimum viable version

Print the three questions. Take them to the AI system that would cause the most damage if it broke tomorrow: the one that would make the news, not the one currently in a pilot. Get a written answer to each from a named CIO or head of IT.

That written record, with a name attached, is the minimum viable version of an AI governance programme. The Commission’s AI Act framework pages sit at digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai and the GPAI guidelines at digital-strategy.ec.europa.eu/en/policies/guidelines-gpai-providers; both are worth a careful read, and neither is a substitute for legal advice on your specific systems.

Most organisations still have not done the minimum viable version. From 2 August, the cost of that gap becomes visible in a new way: the answer to “who is accountable” defaults to whoever is closest to the model when the information request arrives.

Happy to think this through with you.