TL;DR: The EU AI Act creates a risk-based compliance regime for AI systems, including embedded functions in third-party software and cloud platforms, and KOBIL says companies now need systematic inventory, documentation, transparency, human oversight, and AI literacy controls. For practitioners, the key issue is that AI governance is becoming an identity, access, and accountability problem, not just a legal one.
NHIMG editorial — based on content published by KOBIL: EU AI Act compliance and digital sovereignty for AI systems
By the numbers:
- Violations can result in fines of up to €35 million or 7% of global annual turnover, whichever is higher.
- The regulation has been in force since August 2024 and full applicability is expected by 2027.
Questions worth separating out
Q: What breaks when AI system inventory is incomplete under the EU AI Act?
A: Incomplete inventory breaks classification, and classification breaks everything downstream.
Q: Why do access controls matter in AI regulatory compliance?
A: Access controls matter because AI compliance depends on proving who could reach training data, prompts, model outputs, and supporting records.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.
Practitioner guidance
- Inventory every AI system and embedded AI function Create a full register that includes third-party software, cloud services, and platform features that use AI.
- Bind AI actions to verified identities Require identity-bound logging for model changes, administrative actions, approvals, and access to sensitive training or operational data.
- Separate development, testing, and production access Enforce role separation for developers, operators, and reviewers so no single account can move models or data across environments unchecked.
What's in the full article
KOBIL's full article covers the operational detail this post intentionally leaves for the source:
- A fuller breakdown of how the EU AI Act maps to governance, documentation, and revision-proof logging requirements.
- Examples of how identity-bound logging supports accountable AI decision-making in regulated environments.
- KOBIL's interpretation of how digital sovereignty, access control, and infrastructure choices intersect with AI compliance.
- The article's specific framing of how organisations should organise lifecycle controls from development through operation.
👉 Read KOBIL's analysis of EU AI Act compliance, governance, and identity controls →
EU AI Act compliance: what identity and access teams need now?
Explore further
Compliance-first AI governance will fail if organisations treat the EU AI Act as a legal checklist. The article shows that classification, documentation, logging, and human oversight only work when they are connected to operational identity controls. In practice, that means the compliance model must include access governance, ownership, and evidence generation across the AI lifecycle.
A question worth separating out:
Q: Who is accountable when an AI system misses EU AI Act requirements?
A: Accountability follows the role the organisation actually plays, not just the contract wording. A provider, deployer, importer, or distributor can each carry different duties, and some organisations occupy more than one role across different systems. Legal responsibility should be mapped to system ownership, operational control, and the evidence trail, not assumptions about who bought the tool.
👉 Read our full editorial: EU AI Act compliance exposes the identity gap in AI governance