From the European AI Act to a policy framework with roles, processes and instruments people can work with
At a large public organisation, AI was already fully present. The leadership at the time believed strongly in the technology and wanted to be at the front: Google Gemini was made available organisation-wide, a specialised team built its own applications, and purchased software increasingly contained AI components. The technical framework was in place, but a policy framework was not there beforehand. The arrival of the European AI Act made clear that responsible AI use cannot be organised within one expert team alone. The question: how do you turn complex legislation into a workable practice that keeps innovation possible?
The building blocks were there, but loose from each other. There was no complete view of all AI applications in use, no unambiguous ownership of AI governance, and unclarity about the roles of business owners, legal, privacy, security and system owners. Outside the central AI team, a shared approach was missing, the procurement process still took AI components too little into account, and legal requirements were hardly translated into executable work.
Employees used the tool with the best intentions, but without agreements and guidelines, risks emerged. That is the most expensive order: behaviour that is already established has to be reined back afterwards, and that weighs more than framing it up front. The guidelines themselves did get worked out, but the policy framework stalled: without ownership, the choices such a framework needs were not made. Every new application thus arrived again as an exception, and every question became a round trip along departments that didn't automatically find each other. Precisely the pattern in which AI becomes the heaviest change load: much movement, little decision.
Three tracks: research and legal interpretation, design of the operating model, and implementation with structural follow-up. The possible approaches were worked out in ambition levels, from minimum compliance to full implementation, and tested against legal risk, capacity, feasibility, business value, impact on existing processes, reputation and the organisation's change capacity. That led to a phased choice: the heaviest risks and legal obligations first, with a growth path afterwards.
Together with the experts involved, an operating model emerged that clarified roles and responsibilities, from AI leadership and system ownership through business owners, ambassadors, data ownership, legal support, privacy and security to procurement and contract management, with the advisory and decision-making forums included. Alongside that, processes for the full life cycle: identifying and registering, classifying and following up on risks, assessing purchased solutions with an AI component, conditions for putting into use and periodic reassessment.
The emphasis lay on usability. Not everyone who starts an AI application or builds an assistant is a lawyer or AI specialist. Legal checklists and classification models were therefore translated into instruments for project managers, product owners and employees: a central inventory, a simple intake and triage, clear roles and escalation lines, concrete decision questions, practical guidelines for generative AI, and communication aimed at AI literacy.
The moment when the framework and a real application began to feed each other. An organisation-wide generative AI solution served as prototype: it moved from experiment to a controlled, approved way of working with usage conditions, human end-responsibility, review, training and central follow-up, and at the same time showed where the model was still vague. A real dossier forced the choices that stayed open on paper, and thereby accelerated the framework itself. What was learned there about quality and manageability went straight into the organisation-wide elaboration.
An integrated governance practice in which legislation, innovation and daily practice hang together. There is a supported implementation strategy and an organisation-wide operating model, with clear roles and decision forums. Registration, classification and risk management run according to fixed processes, for self-built and purchased AI. And lawyers, AI experts, business and supporting departments now find each other along a fixed path.
New AI applications go through that trajectory faster since then, because the path the first had to blaze now lies fixed. Responsible AI governance is, after all, about more than avoiding legal risks: it determines the conditions under which an organisation can deploy AI sustainably, with human responsibility preserved and with room for innovation. The AI Act thus became not a brake but an occasion to anchor AI more consciously.
Transformation programme led
Public sector
Google Gemini