AI, Data & Technology

    AI Data Governance Is Already a 2026 Problem

    Ou-Jue Cheng CA7 min read

    Most Leadership Teams Think the EU AI Act Is a 2027 Problem. It Isn't.

    Something that keeps coming up in conversations with leadership teams: they're treating the EU AI Act as a future concern. Something for next year's planning cycle, or the one after that.

    Having worked on governance frameworks for clients previously, I can tell you — that thinking is already out of date.

    Since February 2025, prohibited AI practices have been enforceable. The penalties are real: up to €35 million or 7% of global annual revenue. And on 2 August 2026, the full high-risk obligations go live — strict, auditable requirements for data governance, documentation, oversight, and traceability. For SMBs, the same data-trust principles apply at a smaller scale — see why AI fails when data can't be trusted.

    We're not approaching the enforcement window. We're already within it.

    For a full breakdown of the Act, including the risk classification system and who it applies to, read our EU AI Act summary.

    The Gap Between What's Required and What's Been Built

    From my financial services experience in recent years, there's a pattern I recognise here. It's the same pattern I've seen with every major regulatory shift: organisations understand the headline but underestimate the operational detail.

    The EU AI Act doesn't just ask organisations to be aware of their AI systems. It requires evidence. Specifically:

    • A complete inventory of every AI system impacting EU users
    • A risk classification for each system against the Act's framework
    • Provenance, lineage, and quality controls for all training and operational data
    • Bias, drift, and performance monitoring as ongoing obligations
    • Full documentation and traceability for every high-risk system

    That's not a statement of intent. It's a documentation and governance requirement — the kind that gets tested in an audit.

    And when I look at where most organisations actually are today, the gap is significant. Many don't have a complete AI inventory. Fewer have formal risk classifications. And data governance — the provenance, lineage, and quality controls the Act demands — is often the weakest link.

    The Biggest Risk Isn't Malicious AI. It's Accidental Non-Compliance.

    This is the point I want to make clearly, because it's the one that gets lost in the headlines.

    AI systems sprawl. They spread across vendors, teams, functions, and shadow deployments faster than most governance structures can keep up with. A marketing team adopts a new AI marketing tool. A developer integrates an API. A department starts using a large language model for internal analysis. None of it malicious. An existing vendor has added a new AI LLM capability on top of existing features. All of it potentially in scope.

    I wrote recently about the hidden risks of shadow AI — AI tools being used across a business without formal oversight. That risk is directly relevant here. Every untracked AI deployment is a potential compliance gap under the EU AI Act.

    The organisations most at risk aren't the ones doing something wrong. They're the ones that simply don't have visibility over what they're doing at all.

    An Honest Self-Assessment

    My background is in audit, and one of the things that discipline teaches you is the value of a clear-eyed diagnostic and to establish facts.

    If your organisation can't confidently answer these questions, you have work to do:

    • Which AI systems do we have? Not just the ones IT procured — all of them, including vendor-embedded AI and tools teams adopted independently.
    • What data do they rely on? Where does the training data come from? What operational data feeds them? Is it documented? Are our users inputting sensitive data inadvertently?
    • Who owns that data? Is there clear accountability for data quality, provenance, and governance?
    • How is it governed? Are there policies, controls, and monitoring in place — or are we relying on good intentions? Is access limited?
    • Does it meet EU risk obligations? Have systems been classified against the Act's framework? Can we evidence compliance if asked?

    If you're answering "I'm not sure" to more than one of these, you're not in a compliance-ready position. That's not a criticism — it's where most organisations are right now. But the window to close that gap is narrowing.

    What To Do Right Now

    The good news is that this is solvable. The Act is detailed, but it's structured — and if you approach it methodically, the path forward is clear.

    If you're looking for a recognised framework to guide your approach, ISO/IEC 42001 — the international standard for AI management systems — covers exactly the governance foundations the EU AI Act demands: risk management, data governance, documentation, accountability, and ongoing monitoring. Building toward ISO 42001 readiness and building toward EU AI Act compliance are largely the same work.

    1. Start With the Inventory

    You can't classify, govern, or document what you can't see. A complete AI inventory is the foundation. Include everything: enterprise platforms, vendor tools with embedded AI, internal prototypes, and unofficial team-level deployments.

    2. Classify Against the Framework

    Map each system against the Act's risk categories. Most will fall into minimal or limited risk, which significantly reduces your obligations. Focus your governance effort on the systems that genuinely fall into high-risk.

    3. Close the Data Governance Gaps

    For high-risk systems, the Act requires demonstrable data governance — provenance, quality, representativeness, and bias controls. This is where I see the biggest gaps in practice. If your data governance exists only as a policy document rather than operational controls, that needs to change.

    4. Build the Documentation Trail

    From an audit perspective, documentation isn't bureaucracy. It's your evidence base. Design decisions, data sources, testing outcomes, monitoring processes, human oversight mechanisms — all of it needs to be recorded and traceable.

    5. Assign Clear Ownership

    AI governance can't be an orphan responsibility. Someone senior needs to own it, with authority to make decisions and a clear reporting line. Without accountability, governance frameworks become shelf-ware.

    This Is the Regulatory Landscape You're Operating In

    I want to be straight about this: 2026 isn't the warm-up phase. For organisations deploying AI at any meaningful scale, the compliance obligations are real and they're already here.

    The businesses that act now — building inventories, classifying risk, getting their data governance in order — will be in a much stronger position. Not just for compliance, but for actually understanding what their AI systems do and whether they're working as intended.

    That clarity has value far beyond regulation. It's the foundation for AI systems your board, your customers, and your regulators can trust. And if you're building toward ISO 42001 readiness, you're already on the right path — the compliance overlap is significant.

    The same logic applies if you're not scaling toward more regulation, but toward an exit. A founder taking a fintech or AI-enabled tech business to market faces the same underlying question from a different direction: not "will a regulator ask for this," but "will a buyer's due diligence team find it." AI inventory, data lineage, and governance evidence are exactly the kind of thing that gets tested in a data room — and a gap here reads to a buyer as unmanaged risk, which shows up in price or pace, not just in a compliance letter.

    If your organisation needs to get its arms around AI governance before August 2026 — or you're a founder getting a fintech or tech business ready for sale — this is exactly the kind of work we do. We bring audit discipline and practical governance experience to help you understand where you stand, close the gaps, and build frameworks that actually work — not just tick boxes.

    Written by
    Ou-Jue Cheng CA

    Finance & Data Partner supporting businesses with their finances & data to grow and build better businesses together.

    About Straxa →
    Ready to talk it through?

    Book a free discovery call.

    A 30-minute conversation about where you are and what would actually help. No pressure, no jargon, no obligation.