By Dr. Freddie Seba © 2026 Freddie Seba. All rights reserved.
You do not need an office in Europe to be bound by Europe.
What the world’s first binding AI regulation governs — and what it leaves to your institution. Applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI
Governance as Leadership: The organizations that govern AI intentionally will lead. The ones that don’t will follow the consequences.
This series is not about compliance. It is about leadership. Every framework examined here surfaces the same question: not whether your institution is following the rules — but whether your leaders are governing the most consequential technological transformation of our time. Ungoverned: Applied Frameworks Under the Lens exists for leaders who understand the difference.
Previously: Anthropic, OpenAI, Google Gemini, NIST-CAISI. This week: EU AI Act. Coming next: China, Singapore, South Korea.
Constructive analysis — three questions, every installment, without exception.
Why this series — and why these frameworks
This series does not examine every AI governance framework. It examines the frameworks that together reveal the full shape of the governance challenge — and the full scope of what institutional leadership must build in response.
The selection logic is deliberate. It begins with the AI labs — Anthropic, OpenAI, Google — because that is where most institutions first encountered the governance gap: in the terms of service of tools already embedded in their workflows. It moves to U.S. federal bodies — NIST-CAISI — because understanding the voluntary, underfunded, and pending-authorization nature of federal AI standards is essential context for every institution that assumed federal governance was someone else’s responsibility.
It then moves outward — to the EU AI Act, China, Singapore, South Korea, and beyond — because AI governance is not a Western conversation, and leaders who govern only within the frameworks they already know will be ungoverned by the ones they do not. It will explore Canada — not because Canada has a framework, but because it does not, and the governance vacuum left by failed legislation is itself a governance lesson every institution needs to examine. It will explore the Gulf states — UAE, Saudi Arabia, Qatar — because some of the world’s most aggressive AI investment is happening in jurisdictions whose governance frameworks Western institutions have barely begun to examine.
The frameworks explored in this series are not the only ones that matter. They are the ones that, examined together, reveal the pattern. The framework governs the platform, the standard, the model, or the market. Only the institution governs the consequences. That pattern is what this series is for.
This is a living series. Frameworks are added as the global AI governance landscape evolves — and it is evolving faster than any publication schedule can fully anticipate.
Series roadmap — a living intellectual agenda
This roadmap reflects the series as currently envisioned. New frameworks will be added as countries, standards bodies, and sector organizations publish governance guidance. The sequence may evolve. The three questions never will.
Tier 1 — AI Labs: The governance gap begins here — in the terms of service, privacy policies, and platform decisions of the tools already embedded in institutional workflows.
- Anthropic — United States
- OpenAI — United States
- Google Gemini — United States
Tier 2 — Government & Standards Bodies: Federal and national frameworks that shape institutional expectations — and the gaps those frameworks deliberately or structurally leave ungoverned. 4. U.S. NIST-CAISI — United States 5. Canada AI Governance — North America 6. UK AI Governance — United Kingdom
Tier 3 — Binding Regulatory Frameworks: The binding laws and regulations that define legal compliance floors — and the institutional governance required to meet them, such as the EU AI Act — Europe.
Tier 4 — International Standards & Multilateral Bodies: The frameworks that aspire to global consensus — and the institutional gaps that consensus cannot close.
Tier 5 — Sector & Vertical Frameworks: Where global frameworks meet institutional reality — in education, financial services, and emerging economies, such as EDUCAUSE / Higher Education — United States, Federal Reserve — Financial Services, etc.
Tier 6 — Series Synthesis: What the frameworks — examined together — leave ungoverned. And what leadership must build in the space they leave behind. What the Frameworks Don’t Say
An ongoing series. Full roadmap and all published editions at freddieseba.com. New frameworks added as the global AI governance landscape evolves.
Question One — What was the framework designed to govern?
The EU AI Act — Regulation (EU) 2024/1689 — is the world’s first comprehensive binding legal framework for artificial intelligence. It entered into force on August 1, 2024, and operates on a phased implementation timeline revised through the Digital Omnibus provisional agreement reached May 7, 2026, formally adopted by the Council of the EU on June 29, 2026.
The Act governs AI through a four-tier risk classification system. Unacceptable risk systems — including social scoring, real-time biometric identification in public spaces, and emotion recognition in workplaces and educational institutions — are prohibited outright, with these prohibitions taking effect on February 2, 2025. Transparency obligations under Article 50 — requiring disclosure of AI interactions, labeling of synthetic content, and deepfake identification — took effect on August 2, 2026. High-risk AI system obligations — covering healthcare, education, employment, critical infrastructure, and law enforcement — have been formally deferred to December 2, 2027, for standalone Annex III systems, and to August 2, 2028, for AI embedded in regulated products, under the Digital Omnibus agreement.
The deferral is not a retreat from AI regulation. It is a sequencing correction. The technical standards required for high-risk AI conformity assessment were not yet ready. The institutions acknowledged that and moved the high-risk deadlines to dates when standards will actually exist. What they did not do is delay everything. August 2, 2026 remains a live enforcement date — transparency obligations are active, enforcement powers for the European AI Office and national market surveillance authorities are in place, and penalty tiers are operative. Maximum fines reach €35 million or 7% of global turnover — higher than GDPR.
The Act applies extraterritorially. It governs AI systems placed on the EU market. Comprehensively. Bindingly. At scale.
The updated EU AI Act enforcement timeline
February 2, 2025 — Prohibited practices in effect. Social scoring, real-time biometric identification, and emotion recognition in workplaces and schools are banned outright. Already enforceable.
August 2, 2025 — General-purpose AI model obligations active. Providers of models including GPT-4, Claude, and Gemini must comply. National competent authorities designated across member states.
August 2, 2026 — Transparency obligations under Article 50 fully active. Chatbot disclosure, AI content labeling, deepfake identification requirements operative. Enforcement powers for the European AI Office and national market surveillance authorities begin. This date is operative regardless of the Digital Omnibus deferral.
December 2, 2026 — New prohibition on AI systems generating non-consensual intimate imagery and CSAM enters force—watermarking of AI-generated content required for systems placed on market before August 2026.
December 2, 2027 — High-risk AI system obligations under Annex III — covering employment, education, healthcare, critical infrastructure, and law enforcement — fully enforceable. This is the deferred deadline under the Digital Omnibus.
August 2, 2028 — High-risk AI embedded in regulated products under Annex I must comply with the requirements.
Question Two — The Governance Gap: what falls outside the frame, and where leadership begins?
Institutional deployment readiness. And this is not only a European compliance issue — a point worth stating with precision before examining the gap itself.
The EU AI Act is extraterritorial. Under Article 2, any organization whose AI outputs are used in the EU is subject to the Act’s requirements — regardless of where it is incorporated. The Act’s extraterritorial reach extends further than GDPR’s: where GDPR requires intent to target EU individuals, the AI Act triggers when AI system output is used in the Union — a lower and broader threshold. A U.S. hospital system whose clinical AI tools serve European patients, a university whose learning platform reaches EU students, or a corporation whose AI-assisted decisions affect EU employees — all may be inside the scope of this regulation, whether or not they have completed a compliance assessment. Non-EU providers of high-risk systems must additionally designate an authorized representative established in the EU under Article 22.
The Act governs what AI systems must do and what providers and deployers must demonstrate to be legally compliant. What it cannot do is build the institutional governance processes your organization needs to classify its AI systems, complete conformity assessments, assign human oversight roles, maintain technical documentation, and respond to incidents in practice. That work belongs to the institution. That is where leadership begins.
As of April 2026, 78% of organizations had not taken meaningful steps toward compliance. The December 2027 deferral does not change the governance work required — it extends the window to complete it. An institution that uses that window to build governance is better positioned than one that treats the deferral as permission to wait.
Consider what the Act requires of deployers of high-risk AI systems and what institutional leadership must provide. Who in your organization has determined whether your AI systems are high-risk under Annex III? Who owns the conformity assessment documentation? Who is named as the responsible human in your operational oversight workflows, and what authority do they hold to intervene? Who maintains technical documentation and updates it when the vendor changes the model? Who is responsible for reporting serious incidents to national competent authorities? Who reviews ongoing system performance against the standards established at deployment?
The EU AI Act defines the compliance floor. Leadership governance builds the institutional capability to meet it — and demonstrates that it is doing so on the record.
Question Three — What does governance as leadership look like before deployment?
This is where AI Minimum Viable Governance (AI-MVG) begins. Not after an enforcement action identifies gaps — before deployment, when the institution still has the leverage to govern with intention. This is not a compliance checklist. It is a leadership architecture.
Risk classification mapping — classify every AI system your institution deploys against the Act’s four-tier risk framework, including an EU exposure assessment if your institution serves EU users in any capacity Conformity assessment ownership — name who is responsible for completing and maintaining conformity documentation for each high-risk system before the December 2, 2027 deadline Human oversight assignment — define who is responsible for human oversight in each AI-assisted workflow and what intervention authority they hold Technical documentation maintenance — establish a process for updating documentation when vendors change models or terms Incident reporting process — document who reports serious incidents, to which national authority, and within what timeframe EU representative designation — if your institution is a non-EU provider of high-risk AI systems, designate an authorized EU representative under Article 22 Executive accountability — assign a named leader responsible for EU AI Act compliance outcomes across the institution.
This week’s 12 Ps lens: Processes
The EU AI Act is, at its core, a process regulation. Every high-risk obligation is a process requirement — and every process requirement lands at the institution. Processes — the third P — means your institution has governance procedures in place before the regulation requires you to demonstrate them. Leadership governance means those processes are built, tested, and owned before the enforcement date — not assembled in response to an investigation.
Purpose: The Act governs risk to safety and fundamental rights. Your institution must align its AI purpose statements against the Act’s risk classifications before deployment. People — The Act assigns roles to providers, deployers, importers, and distributors. Your institution must name the responsible individual for each role — not just the category. Processes — Risk management systems, conformity assessments, documentation, logging, human oversight, and post-market monitoring are all required. All yours to build and demonstrate. Policy — The Act is binding regulation with enforcement mechanisms now active. Your institution must translate it into internal policy with named owners and review cadences. Privacy — The AI Act and the GDPR apply concurrently to AI systems that process personal data. Your institution must map the overlap and govern both simultaneously. Performance — Accuracy, robustness, and cybersecurity requirements apply to high-risk systems. Your institution must define and monitor performance thresholds against Act standards.
Procurement: Obligations extend across the AI value chain. Vendor contracts must reflect Act obligations, documentation requirements, and exit provisions. Partnerships — Third-country providers are subject to the Act if their outputs are used in the EU. Institutional third-party AI risk must be mapped against the Act’s extraterritorial reach. Predictability — The Digital Omnibus deferred some deadlines, and further changes are possible. Your institution must monitor regulatory updates and adjust governance plans accordingly. Protection — Fundamental rights impact assessments are required for high-risk systems used by public authorities. Complete these before deployment in applicable contexts. Proof — Technical documentation, logs, and conformity assessments are required. Your institution must build and maintain the audit trail that demonstrates compliance. Precedent — The Act requires human oversight but does not assign institutional accountability for unexpected outcomes when compliant AI produces them. That assignment belongs to the institution. Answering that question before deployment is what governance-as-leadership looks like.
The EU AI Act governs what AI systems must demonstrate to be legally compliant. Institutional leadership governance governs the processes, people, and proof that demonstrate compliance in practice. One defines the standard. The other builds the capability to meet it. That is the foundation of AI Minimum Viable Governance.
For executive briefings, board workshops, and keynote presentations → freddieseba.com
About the Author
Dr. Freddie Seba helps boards, trustees, and executive leadership teams build practical AI governance before AI failures make governance unavoidable. Scholar-operator, Silicon Valley founder, and global executive — EdD, USF · MBA, Yale · MA, Stanford.
This analysis is part of Ungoverned: Applied Frameworks Under the Lens, a recurring miniseries applying the AI Minimum Viable Governance (AI-MVG) framework and the Seba 12 Ps of Responsible AI to organizations shaping AI governance globally — including AI labs, governments, standards bodies, and international actors across the United States, Europe, Asia-Pacific, the Gulf, Latin America, and beyond. Drafted with AI-assisted tools. Final editorial judgment and responsibility remain with the author.
© 2026 Freddie Seba. All rights reserved.
References
European Parliament & Council of the EU. (2024). Regulation (EU) 2024/1689 (EU AI Act). https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689
European Commission. (2026). AI Act implementation. https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
AI Act Service Desk. (2026). Timeline for implementation of the EU AI Act. https://ai-act-service-desk.ec.europa.eu/en/ai-act/timeline
Axis Intelligence. (2026, July). EU AI Act news 2026: The revised timeline, August enforcement and Omnibus deal explained. https://axis-intelligence.com/eu-ai-act-news/
IAPP. (May 28, 2026). AI Act Omnibus: What just happened and what comes next. https://iapp.org/news/a/ai-act-omnibus-what-just-happened-and-what-comes-next
Latham & Watkins. (May 13, 2026). AI Act update: EU resolves to change rules and extend deadlines. https://www.lw.com/en/insights/ai-act-update-eu-resolves-to-change-rules-and-extend-deadlines
SureCloud. (2026, June). EU AI Act compliance guide: Updated June 2026. https://www.surecloud.com/resource-hub/eu-ai-act-complete-compliance-guide
ComplianceStack. (July 1, 2026). EU AI Act enforcement timeline: 2025 to 2027. https://compliancestack.ai/penalties/eu-ai-act/enforcement-timeline
Future of Life Institute. (2026). EU AI Act implementation timeline. https://artificialintelligenceact.eu/implementation-timeline
#AIGovernance #EUAIAct #AIMVG #AILeadership #Ungoverned #BoardGovernance #AIPolicy #CIO #AICompliance #AIRisk #Europe #GeneralCounsel

Leave a Reply