An organisation-wide approach to the EU AI Act, where regulation, innovation and daily practice come together
Client
Flemish Government entity
Role
Organisational developer - AI governance, organisational development and implementation strategy
Artificial intelligence was already fully present within the organisation. A specialised AI team developed its own applications, employees experimented with generative AI and purchased software increasingly contained AI components as well. There was already a strong technical framework for AI governance, but the arrival of the European AI Act made clear that responsible AI use could not be organised only within a technical expertise team. The central question became: how do we turn complex regulation into a workable organisational practice that keeps innovation possible?
At the start, various building blocks were present but not yet integrated into one organisation-wide operation. There was insufficient full view of all AI applications in use, no unambiguous ownership of AI governance, ambiguity about the roles of business owners, legal, privacy, security and system leads, no uniform approach for AI outside the central AI team, a procurement process that didn't yet take AI components sufficiently into account, and limited practical translation of legal requirements into executable processes.
The regulation had to be translated into clear responsibilities, workable processes, legal and ethical review, registration and risk classification, agreements for development, procurement and use, awareness and AI literacy, and organisation-wide decision-making. The AI Act must not become a standalone legal compliance project: the introduction had to connect with existing processes, governance forums and responsibilities, so responsible AI use also remains sustainably safeguarded after the project.
We built the assignment around three tracks: research and legal interpretation, design of the Target Operating Model, and implementation and structural follow-up. Possible approaches were translated into different ambition levels - from minimal compliance to full implementation - and tested on legal risks, available capacity, organisational feasibility, business value, impact on existing processes, reputation and trust, and the organisation's change capacity. That led to a pragmatic, phased approach: the biggest risks and legal obligations first, combined with a growth path towards further maturity.
Together with the involved experts, a Target Operating Model was developed in which roles and responsibilities were clarified for AI leadership and AI governance, AI project and system ownership, business owners, AI ambassadors, data ownership, legal support, privacy and security, procurement and contract management, system and application management, and the advisory and decision-making governance forums. In addition, we designed processes for the full life cycle of AI: identifying and registering, risk classification, risk follow-up, assessment of purchased solutions with an AI component, conditions for going live and periodic reassessment.
An important point of attention was practical usability. Legal checklists and classification models were translated into instruments that project leaders, product owners and employees can also work with. After all, not everyone who initiates an AI application or builds a generative-AI assistant is a lawyer or AI specialist. We therefore invested in a central AI inventory, a simple intake and triage, clear roles and escalation lines, concrete decision questions, quality and risk control measures, practical guidelines for generative AI, communication and AI literacy, and reusable governance processes.
The turning point came as soon as the governance principles were applied for the first time to a real AI application. An organisation-wide generative AI solution supporting employees in preparing transmission reports was transformed from an experiment into a controlled, approved way of working with clear usage conditions, human end responsibility, legal, privacy and ethical review, transparent communication, training and guidance, central follow-up and agreements on further rollout and management.
With that, the programme shifted from a paper operating model to a working practice. The application became not only an operational aid, but also the first tangible demonstration of how responsible AI use can be organised in practice.
The assignment laid the basis for an integrated AI governance operation in which regulation, innovation and daily practice are connected: a supported, phased implementation strategy, an organisation-wide Target Operating Model, clearer roles and decision-making forums, processes for registration, classification and risk management, attention to both internally developed and purchased AI, a bridge between lawyers, AI experts, business and supporting services, practical instruments for employees and project owners, and a basis for structural AI literacy and responsible use.
Responsible AI governance is about more than avoiding legal risks. It is about the conditions under which an organisation can deploy AI sustainably: with preservation of human responsibility, protection of citizens and employees, sufficient transparency, room for innovation and trust as foundation. In this way the AI Act became not a brake on innovation, but a trigger to anchor AI more professionally, more consciously and organisation-wide.
