This Platforum9 EU AI Act Forum session explored the practical implications of the EU AI Act and broader European digital regulation for organisations. The discussion was led by Professor Andrej Savin, Professor of Information Technology and Internet Law at Copenhagen Business School, Alexander Deicke, Interim Head of Legal and Chief Compliance Officer at Concept Mobility, and Sid Ali Boutellis, Co-Founder of Expanse Trade and Legal AI Applications & AI Governance Specialist. Together, they examined how organisations can move beyond viewing AI compliance as a legal obligation and instead use it as a strategic capability to support responsible innovation and stronger governance.
Overview
The session explored the practical realities of implementing the EU AI Act within an increasingly complex digital regulatory landscape. The speakers explained that organisations are no longer dealing with AI regulation in isolation. Instead, businesses must align AI governance with existing obligations such as GDPR, cybersecurity and data governance. While some organisations have already developed AI strategies and governance frameworks, many others remain at the early stages of preparation despite the Act’s phased implementation.
A key theme was the move towards risk-based regulation. Savin explained that compliance cannot be achieved through software alone or treated as a one-off legal project. Effective governance requires board ownership, clear accountability and collaboration between legal, compliance, IT, cybersecurity and data teams. Deicke added that framing AI governance as a strategic business issue, rather than simply a compliance obligation, helps leadership understand both the risks and opportunities associated with AI adoption.
The discussion also highlighted the uncertainty many organisations face when selecting AI technologies and implementing governance frameworks. Rather than adopting multiple AI tools, the speakers recommended focusing on trusted, well-governed solutions supported by strong internal processes, staff training and continuous oversight. They also stressed the growing need for AI governance specialists and called for legal education to place greater emphasis on data governance, risk management and digital regulation.
Key Takeaways
- Treat AI compliance as an organisation-wide governance responsibility rather than a standalone legal project.
- Ensure boards take ownership of AI governance and promote collaboration across legal, compliance, IT, cybersecurity and data functions.
- Risk-based regulation requires continuous assessment, documentation and management of AI-related risks.
- Build on existing compliance programmes, including GDPR and cybersecurity, to create integrated governance across digital regulation.
- Prioritise a smaller number of trusted AI tools supported by clear governance, staff training and ongoing oversight.
- Future legal professionals will need stronger expertise in AI governance, data regulation and risk management.