Skip to main content
onext technology
Transformation 2 August 2026 - 8 min read

AI governance: the minimum required in 2026

Two opposite mistakes coexist in the same sector: paralysis and theatre. The middle ground is surprisingly small, and almost nobody writes it down because it does not sell a programme.

Jordi García
Tech Lead at onext
Two colleagues reviewing and signing a printed policy document at a meeting table

For your board (60 seconds)

The test for this layer is usefully blunt: when an AI output is about to reach a client, a regulator or a court, who answers for it? If the answer takes more than three seconds or contains the word "depends", there is no governance: there is trust, and it lasts until the first incident. The required minimum fits on two pages and a spreadsheet.

What this layer actually measures

It measures whether somebody signs.

When an AI output is about to reach a client, a regulator or a court, who answers for it? If the answer takes more than three seconds or includes "depends", there is no governance. There is trust, which is a different thing and lasts until the first incident.

What it does not measure: how much documentation you have. We have seen excellent AI policies in companies where nobody knew they existed.

The two opposite mistakes

Paralysis. The EU AI Act reads as something vast and foreign, the conclusion is that it requires a compliance effort the company cannot fund, and everything gets postponed. Meanwhile people use AI tools on their own, unlogged and unguided — precisely the scenario the paralysis was meant to avoid.

Theatre. A corporate policy is approved, emailed and filed. Nothing changes in the real work because the policy touches no concrete process. It is more dangerous than having nothing, because it produces the feeling of being covered.

The timeline that matters

Precision matters here, because the market has spread a lot of noise. The EU AI Act went through a legislative delay — the Digital Omnibus — that did not delay everything:

  • Transparency obligations apply from 2 August 2026. They were not postponed. They are the ones affecting most mid-sized companies: disclosing that a user is interacting with an AI system, and marking artificially generated or manipulated content.
  • Annex III high-risk obligations moved to December 2027, and Annex I to August 2028.

For a mid-sized company using AI in internal and client-facing processes, this means what is required is already here, and what was postponed is the part that probably does not apply to it. That is the opposite of the reading in circulation.

Diagnosis: where you are

Stage 1 · Ungoverned use. There is AI in the company and nobody knows where or on what data. Observable signal: if you ask how many AI tools are in use, the number you get will be lower than the real one.

Stage 2 · Declared perimeter. There is a short list of what is forbidden, a name per decision type, and a register of what is used for what. It fits on two pages. Observable signal: a new employee knows in week one what they can and cannot put into an AI system.

Stage 3 · Traceability. Outputs reaching clients are logged with their source and reviewer, and a decision can be reconstructed months later. Observable signal: faced with a complaint, someone can show what the system based itself on.

The first 90 days

Weeks 1-2 · The forbidden list. Ten lines, not forty pages. What information does not leave the building, what decisions are never made by a system without a person, what uses are vetoed. Written in the language of the people doing the work, not the adviser's.

Weeks 3-4 · The names. Who authorises a new tool. Who signs that an output can go to a client. Who answers if something goes wrong. Three names. That they are real matters more than the org chart.

Weeks 5-8 · The register. What AI systems exist, for what, on what data, since when. A spreadsheet will do. It is 80% of what any audit asks for first.

Weeks 9-12 · Applicable transparency. Review where there is client interaction or generated content, and apply the required marking.

Deliverable: two pages and a spreadsheet. If your first-quarter governance deliverable runs longer, it was built for the auditor, not the company.

What NOT to do yet

  • Do not set up an AI committee for one pilot. A committee for a single case is bureaucracy with minutes.
  • Do not copy a multinational's AI policy. It is calibrated for risks and structures you do not have.
  • Do not certify anything yet. Certifications rest on existing practice. Practice first.
  • Do not ban by default. A blanket ban with no alternative produces clandestine use: same risk, zero visibility.

What skipping it costs

It costs little for quite a while, and then it costs all at once. This is a layer with deferred damage, which is why it is so easy to postpone.

The scenario we see repeat is not a regulatory fine: it is an internal incident. A proposal that goes out carrying another client's data. A report with an invented figure nobody checked. The immediate damage is reputational and the lasting damage is political: after an incident like that, AI is marked inside the house and the next project starts uphill.

Third layer of the series on the seven layers of AI maturity.

Frequently asked questions

What AI governance does a mid-sized company need?

Three things: a short list of what is forbidden, a name for each type of decision, and a register of which systems are used and on what data. It fits on two pages and a spreadsheet. Committees and long policies are appropriate when there is a portfolio of cases, not when there is one pilot.

Which EU AI Act obligations already apply?

Transparency obligations apply from 2 August 2026 and were not postponed: disclosing interaction with an AI system and marking artificially generated content. Annex III high-risk obligations moved to December 2027. For most mid-sized companies, what is required is already in force.

Do you need an AI committee?

Not to start. A committee for a single case adds process without adding judgement. It makes sense when several live cases compete for budget and someone has to choose between them on a common yardstick.

Can AI make decisions without human review?

It depends on the impact of the decision, and making that classification is the work of this layer. The practical rule we apply: if the output reaches a client, a regulator or a contractual obligation, there is human review and who performed it is logged.

See how we work
Jordi García
Written by
Jordi García
Tech Lead at onext

Jordi García is Tech Lead at onext. He works on bringing AI into governed production across development and product teams —with Spec-Driven Development, context engineering and human verification at every step— and authors onext's technical insights on the method, quality and cost of applied AI.

LinkedIn →