AI Is Everywhere in Your Organization. The EU AI Act Calls You a Deployer. Do You Know What That Means?
Obligations, deadlines, and fines you may not know exist. But there's still time to get ready.
It was a late October afternoon and I was deep in code.
Alessandro Di Gioia and I were rebuilding the product discovery layer of nWave, trying to answer a question nobody in our industry was asking yet: when AI ships code faster than Product Management can design what to build, where does the organization break?
The call came from a friend, Andrea Provaglio. He wanted to introduce someone. A legal consultant, he said. Expert in innovation. Specialized in AI.
I kept my face neutral.
Ten years of legal battles to save your son from a catastrophic divorce will do that to you as well. I had seen enough courtrooms, enough lawyers, enough judges to know what the profession looked like up close. I came to that call with a heavy heart. I gave Helga Carlotta Zanotti the benefit of the doubt anyway. It turned out to be the best decision I made that afternoon.
But I am getting ahead of myself.
Last week we looked at the perception gap: the 39 points of distance between how fast your team believes AI is making them and how fast the data says they actually are. The cost of that gap, I said, compounds. And it stays invisible until it isn’t.
What I didn’t say is that the invisibility has an expiry date.
August 2, 2026. 117 days from now.
That is the date the EU AI Act becomes fully enforceable for the organizations most likely reading this. Not a future regulation. Not a proposal. A law that entered into force on August 1, 2024 and has been running a phased implementation clock ever since. The prohibitions went live in February 2025. The governance framework went live in August 2025. What lands in August 2026 is the part that touches your organization directly: the high-risk system obligations, the transparency requirements, the conformity assessments, the fines.
The fines are real. Up to €35 million or 7% of global annual turnover, whichever is higher, for the most serious violations. €15 million or 3% for broader compliance failures. These are not theoretical numbers. They are Article 99 of a published regulation.
Most organizations I speak with don’t know which side of those numbers they’re on.
The terrain most CTOs are navigating blind
The Act does not regulate technology. It regulates purpose.
The same AI model that powers a code assistant (low risk, minimal obligations) becomes a high-risk system the moment it is used to screen job applicants, assess creditworthiness, or make decisions about access to essential services. The model doesn’t change. The deployment context does. And the obligations that attach to it change with it.
The Act organizes AI systems into four tiers. At the top, eight practices are outright prohibited: social scoring, subliminal manipulation, real-time biometric surveillance in public spaces. These have been banned since February 2025. Below that sits the high-risk tier: eight domains where AI touching human decisions triggers the full compliance framework. Employment and recruitment. Education. Critical infrastructure. Essential services. Law enforcement. Migration. Justice.
Below that, limited risk, transparency obligations only. Chatbots must disclose they are AI. Synthetic content must be marked. And at the base, the vast majority of AI systems: minimal risk, no mandatory obligations.
Here is where most software organizations sit in practice: probably not high-risk by the Act’s definition. Probably in the limited or minimal risk tier. But probably is doing a lot of work in that sentence. Because the classification depends entirely on how AI is being used inside the organization, and most organizations haven’t done that audit.
The most common blind spot isn’t technical. It’s structural. Most CTOs can map their stack with precision; what they struggle to map is how that stack translates into legal exposure. The EU AI Act introduces a concept most engineering leaders haven’t encountered before: the deployer. The moment an organization embeds AI into its workflows (any AI, for any purpose), it becomes a deployer under the Act, with obligations that attach regardless of whether it built the system or simply licensed it. And it doesn’t stop there. AI deployment doesn’t sit in isolation from the rest of the legal landscape. GDPR, cybersecurity directives, data protection regulation. These compounds with the Act in ways that aren’t visible if you’re looking only at what your team builds. A software factory that uses AI coding tools has just given those tools access to nearly everything: codebases, architecture decisions, client data, infrastructure details. The CTO sees a productivity investment. The regulation sees a data governance question. Both are right. That’s the terrain most C-suite leaders (CTOs, CEOs, CFOs alike) are navigating without a map.
Why this is not a CTO problem
This is the part most compliance conversations get wrong.
The EU AI Act compliance journey requires three actors working together. The CTO who understands what the technology is actually doing. The internal legal team who understands the organization’s exposure. And an external legal counsel who understands the regulation deeply enough to map one onto the other.
Remove any one of those three and the audit produces noise instead of signal.
The CTO alone cannot assess legal exposure. The legal team alone cannot assess what the technology is actually doing. And an external legal expert, however sharp, cannot do the compliance work without the data that bridges the technical and the legal domains.
This is the gap nobody talks about. Not the regulation itself. Not the deadline. The missing translation layer between the technical reality and the legal audit.
The conversation usually starts the same way. We ask: which AI tools is your organization using? The answer comes quickly and confidently. A coding assistant, a specific development platform, one or two tools the engineering team adopted deliberately. Then we look at the actual environment. AI is embedded in the email system. AI is inside the office suite. AI is in the calendar, the document editor, the customer support platform. It is almost everywhere the organization handles data, not because anyone decided to deploy it there, but because the vendors did. Every one of those systems is processing organizational data, generating artifacts on behalf of employees, and making decisions that touch the people inside and outside the organization. The deployer definition in the EU AI Act doesn’t ask whether you chose the AI intentionally. It asks whether you use it. Most organizations are deployers ten times over before they’ve answered the first question.
The translation layer
When my friend Andrea Provaglio introduced me to Helga Zanotti that October afternoon, neither of us knew exactly what we were building.
What emerged over the following weeks was something I had not expected to find: a legal professional who thought in terms of ethics first and compliance second. Who understood that an audit without organizational understanding is just a checklist. Who had been searching, she told me, for a technical counterpart capable of speaking across domains, to leadership, to legal, to engineering, without losing precision in any of them.
We were deep in Article 4, the AI literacy obligation, when I pushed on a word she had used. Ethical, I said. Which kind of ethics? She didn’t pause. The Act’s ethics are legally grounded, she told us; not philosophical, but not empty either. Then she said something I hadn’t expected: that she liked our philosophical angle, that AI should augment human beings, not replace them. That it pointed in the same direction as where she believed the law was trying to go. I had spent years watching legal professionals use precision as a shield against meaning. She was using it as a bridge toward it. She understood that equity and equality are two different things. And she understood why that difference matters when the system making decisions is a machine.
What she found in our assessment surprised her.
The AI Readiness Assessment measures four dimensions: FOCUS, TECHNICAL, PRODUCT, FEEDBACK. Four macro clusters that compress years of behavioral observation into a diagnostic that any senior leader can understand and any legal expert can use. In our discussions, she realized that what we measure covers more than 80% of the organizational behaviors the Act is designed to regulate. Not by accident. Because the Act, at its core, is not about technology. It is about whether an organization has the human judgment, the process discipline, the cognitive capacity, and the oversight mechanisms to be trusted with AI that affects people’s lives.
Those are behavioral questions. And behavioral measurement is exactly what the assessment does.
The legal audit needs to know: does the organization supervise AI output before it reaches production? Does it maintain traceability between AI decisions and human approval? Does it have feedback mechanisms fast enough to catch errors before they compound into liability? These are not abstract compliance requirements. They are the dimensions of our readiness model, expressed in legal language.
What domain-driven design gives us, and what most technical-legal conversations lack, is a ubiquitous language. A consistent vocabulary that means the same thing to the engineer, the legal counsel, and the board. Without it, the compliance audit is a translation exercise that loses critical nuance at every handover. With it, the data flows cleanly from the technical assessment directly into the legal gap analysis.
The assessment is not a compliance tool. It is the prerequisite that makes compliance work possible.
The value isn’t that the assessment finds what a legal expert would miss. It’s that it eliminates the most expensive part of every legal engagement: the discovery phase. Every hour a legal consultant spends asking an organization to explain how it works, waiting for data that doesn’t exist in the right format, translating technical reality into legal language; that hour is on the bill. And legal bills, as every CTO who has been through a serious compliance process knows, compound faster than technical debt. What the AI Readiness Assessment does, across its three layers of organizational, code, and governance analysis, is arrive at the legal conversation already prepared. The organization understands its own blind spots. The data exists in a format the legal expert can use directly. The ubiquitous language we build across technical, product, and governance domains is the same language the regulation speaks. The legal consultant doesn’t have to excavate. She can start where most engagements take months to reach. That’s not a convenience. For an organization four months from an enforcement deadline, it’s the difference between having time to act and running out of it.
What the path forward looks like
The organizations that will navigate August 2026 well are not the ones that hire the best lawyers. They are the ones that arrive at the legal conversation with their house already described accurately.
That means knowing which AI systems are deployed and for what purpose. It means having traceability between AI output and human decision. It means having a feedback loop fast enough to catch errors before they become liability. And it means having leadership that can read a technical diagnosis in plain language and make decisions from it.
The journey starts with a free AI Readiness Assessment. Four questions. Thirty minutes. It measures the gap between where your organization thinks it is with AI and where it actually is, across FOCUS, TECHNICAL, PRODUCT, and FEEDBACK. It’s self-serve, it costs nothing, and it produces the awareness that makes every subsequent conversation more precise.
For organizations ready to go further, that assessment is the entry point to something deeper. A discovery call to map the actual technology landscape. Not the one on the architecture diagram, the one running in production. A codebase assessment that surfaces how AI is embedded in the engineering layer. An organizational and governance assessment in partnership with Andrea Provaglio that maps how deeply AI is wired into decision-making, where accountability exists and where it doesn’t. And then, with the full picture in hand, Helga Zanotti steps in; legal audit, compliance gap analysis, remediation roadmap.
The legal expert handles the regulation. We handle the organizational reality of modern AI-governance. Together, the gap between them closes.
Andrea Provaglio leads the AI organizational governance assessment: the layer that maps how an organization actually makes decisions with AI, where accountability sits, and where it doesn’t. Helga Zanotti handles the legal compliance work: the EU AI Act audit, the gap analysis, the remediation roadmap. I bring 15 years of Software Craftsmanship teaching through the Software Craftsmanship Dojo®, Behavioral OKRs and AI Governance frameworks that measure what organizations actually do rather than what they report, and nWave.ai Enterprise: the technical governance layer that produces the audit trail both Andrea and Helga need to do their work. The keystone of this partnership isn’t coordination. It’s translation: the ability to go inside an engineering organization, observe its real behaviors, and produce data that is simultaneously legible to a developer, a legal counsel, and a board.
Three professionals, each with nearly three decades of experience, each having worked with hundreds of organizations from early-stage startups to global enterprises across Europe and worldwide. Governance, technical leadership, and legal compliance, connected together for the first time as a single service. Not to add overhead. To give organizations the competitive edge that comes from being genuinely ready: technically, organizationally, and legally. Most of their competitors won’t even understand what that means until it’s too late.
That October afternoon ended differently than I expected.
She talked about ethics. Not as a philosophical sidebar. Not as a disclaimer buried in section twelve of a compliance framework. As the actual foundation of what she was trying to build. A practice that helps organizations use AI in ways that are not just legally defensible but genuinely responsible.
I had not heard a legal professional talk that way before.
For years, every legal conversation I had felt like a system designed to find the guilty party and assign a number to the damage. Not justice. Arithmetic. The best lawyer wins; the rest is paperwork. Nobody spoke in human language. She was the first one in a long time who did. AI has to augment people, not replace them. The European AI Act exists to protect that right. The right to work, to adapt, to be part of what comes next rather than discarded by it. I didn’t expect to hear that from a legal professional. I didn’t expect to feel what I felt when she said it.
I don’t know if the future of AI governance will be built by people who think this way. I hope it will. What I know is that for the first time in a long time, I sat across from someone in that profession and felt something I had not felt in years.
Hope is not a strategy. But it is a beginning.
The compliance conversation doesn’t start with a lawyer. It starts with knowing where you actually are.
Start with the free AI Readiness Assessment. Four questions, a few minutes, no strings. It will tell you more about your organization’s AI exposure than most internal audits surface in months. If what it reveals opens a deeper conversation, about governance, about codebases, about legal compliance , then Andrea, Helga, and I are beside you for that too.
When you’re ready to walk the last mile, we’re ready to walk it with you.
→ Online FREE version of the AI Readiness Assessment
Next week***: what does the AI Readiness Assessment actually reveal when you run it on a real organization? We walk through a real result, dimension by dimension, and show what the gap looks like when you finally measure it properly.*