En este modulo

  1. Why the AI Act affects you personally
  2. The AI Act structure in 5 minutes
  3. Obligations of the board and executive management
  4. Personal liability of the executive
  5. 10 questions you must ask your legal team
  6. 5-step compliance plan
  7. SME exemptions
  8. Sanctions that matter to leadership
  9. Critical deadlines: August 2026 is here
  10. Insurance and liability coverage
  11. Practical exercise
  12. Puntos clave

Why the AI Act affects you personally

Regulation (EU) 2024/1689, known as the AI Act, entered into force on 1 August 2024. It is not a directive that each country transposes in its own way. It is a regulation: it applies directly in all member states. No interpretations, no excuses, no "let's see how Spain transposes it".

For the executive, three realities change everything:

  1. Liability is personal. Not just the company's. The AI Act establishes obligations that fall on the individuals who make decisions about AI systems. If your company deploys a high-risk system without meeting the requirements, the executive who approved that deployment can be held liable.
  2. The fines are existential. Up to EUR 35 million or 7% of global turnover. For an SME with EUR 5 million in revenue, 7% is EUR 350,000. Enough to close the business.
  3. The deadlines are imminent. August 2026 is when most obligations for high-risk systems come into force. It is not a distant horizon. It is weeks away.

For the executive

This module is not a law course. That is the job of your legal team (and module LG04 for legal professionals). Here we give you what you need to make informed decisions: what to ask, what to approve, what to delegate and what not to ignore.

The AI Act structure in 5 minutes

The AI Act classifies AI systems into four risk levels. Your first job as an executive is to know which level your company's systems fall into:

Unacceptable risk (prohibited)

Systems the EU considers incompatible with fundamental rights. Prohibited since February 2025.

If your company uses any of these, stop immediately. There is no exception or transition period.

High risk

Systems that significantly affect people. They must meet strict requirements before deployment.

Requirements: risk management system, documented training data, transparency, human oversight, demonstrated accuracy and robustness, registration in the EU database.

Limited risk

Systems that interact with people. Main requirement: transparency.

Minimal risk

Everything else. Spam filters, product recommendations, writing assistants. No specific obligations. Most AI productivity tools fall here.

Obligations of the board and executive management

The AI Act does not say "the company must". It says "the provider must" and "the deployer must". If your company uses high-risk AI systems, you are a "deployer". That creates concrete obligations for leadership:

What the board must approve

  1. AI systems inventory. A complete list of all AI systems the company uses, classified by risk level. If you do not know what AI your company uses, you cannot comply with anything.
  2. Risk assessment. For each high-risk system, a documented impact assessment including risks to fundamental rights.
  3. AI policy. A governance framework that defines who can deploy AI, with what approvals, under what conditions and with what oversight.
  4. Compliance budget. Complying with the AI Act has a cost: auditing, documentation, training, monitoring tools. The board must approve that budget.

What executive management must execute

Personal liability of the executive

The AI Act combines with each member state's corporate law and director liability legislation. In Spain, the Companies Act (art. 225-236) establishes that directors are liable for damage caused by acts contrary to law.

Personal liability scenarios:

Scenario 1: Deployment without assessment

The company deploys an AI system for candidate screening without conducting the required impact assessment. A rejected candidate files a discrimination claim. The inspection discovers there is no documentation. The executive who approved the deployment is liable.

Scenario 2: Ignoring alerts

The technical team reports that a credit scoring system shows statistical bias against a demographic group. Leadership decides not to act because "it generates good commercial results". If there is a complaint, the documented inaction is evidence against the executive.

Scenario 3: Lack of training

An untrained employee makes automated decisions about social benefits. The system commits systematic errors. The company cannot demonstrate it trained the employee. The HR director is exposed.

The golden rule

The executive's best personal protection is documented diligence. Did you conduct the assessment? Document it. Did you consult legal? Document it. Did you train the team? Document it. Documentation does not prevent errors, but it demonstrates you acted with reasonable diligence.

10 questions you must ask your legal team

You do not need to be an AI Act expert. You need to ask the right questions. These 10 are the minimum:

  1. How many AI systems do we currently use? Include SaaS tools, APIs, proprietary models, automations with integrated AI. The answer usually surprises.
  2. Which ones classify as high-risk under the AI Act? Especially HR, credit, insurance, education. If you use AI to screen CVs, it is high-risk.
  3. Do we have a documented impact assessment for each one? "We thought about it" does not count. It must be written, dated and signed.
  4. Who is our AI compliance officer? If the answer is "nobody" or "IT handles it", you have a problem.
  5. Do we meet the transparency requirements? Do users know they are interacting with AI? Are AI outputs identified as such?
  6. Do we have human oversight for high-risk systems? Who can intervene? Are they trained? Do they have real authority to disable the system?
  7. Do our AI providers comply with the AI Act? The AI Act holds the deployer responsible if the provider does not comply. Review contracts.
  8. Do we have an AI literacy training plan? The AI Act requires it. How many people need training? By when?
  9. What insurance do we have that covers AI liability? General liability policies may not cover damages caused by AI systems.
  10. Are we prepared for an inspection? If an inspector from the national supervisory authority arrives tomorrow, can we demonstrate compliance within 48 hours?

5-step compliance plan

This plan is designed so an executive can activate it at the next committee meeting. It does not require deep legal knowledge. It requires willingness to act.

Step 1: Inventory (weeks 1-2)

Catalog all AI systems in use. For each one: name, provider, function, data processed, responsible department, risk classification (unacceptable, high, limited, minimal). A spreadsheet is enough.

Owner: CTO or CISO, with input from each department.

Deliverable: complete inventory with risk classification.

Step 2: Risk assessment (weeks 3-6)

For each high-risk system: impact assessment including risks to fundamental rights, mitigation measures, human oversight plan. Use the European AI Office template as a baseline.

Owner: legal team + AI compliance officer.

Deliverable: documented impact assessment per system.

Step 3: Governance (weeks 4-8)

Create or update the company's AI policy. Define roles: who approves new AI systems, who oversees existing ones, who reports incidents. Approve at board level.

Owner: general management + legal.

Deliverable: AI policy approved by the board.

Step 4: Training (weeks 6-12)

AI literacy plan for all employees who interact with AI systems. Specific training for high-risk system operators. Training record (who, when, what).

Owner: HR + AI compliance officer.

Deliverable: completed training record.

Step 5: Ongoing monitoring (permanent)

Quarterly review of the inventory (new systems, changes to existing ones). Annual compliance audit. Update risk assessments when the system or the regulation changes.

Owner: AI compliance officer.

Deliverable: quarterly report to the board.

SME exemptions

The AI Act includes measures to avoid overburdening SMEs. If your company is small, this matters:

What benefits you

What does NOT exempt you

Reality for SMEs

Most SMEs use minimal or limited-risk AI (chatbots, writing assistants, content generators). If that is your case, your obligations are essentially transparency: disclose that you use AI. The AI Act does not require you to stop using ChatGPT for emails. It requires you to be transparent about it.

Sanctions that matter to leadership

The AI Act establishes three levels of sanctions. The figures are maximums, but they convey the seriousness of regulatory intent:

InfringementMaximum sanctionExample
Prohibited practicesEUR 35M or 7% global turnoverSocial scoring, subliminal manipulation
Non-compliance with requirementsEUR 15M or 3% global turnoverDeploying high-risk without impact assessment
Incorrect informationEUR 7.5M or 1% global turnoverDeclaring a high-risk system as minimal risk

For SMEs and startups, the lesser of the two amounts applies (percentage or fixed amount). But even the minimum can be devastating for a small company.

Beyond direct fines, the reputational damage is real. An AI Act sanction generates headlines, erodes client trust and makes it harder to attract talent. In regulated industries (banking, insurance, healthcare), it can mean the loss of operating licenses.

Critical deadlines: August 2026 is here

The AI Act has a phased rollout. These are the deadlines that matter to leadership:

If your company uses high-risk systems and you have not started the compliance plan, the time to act is now. Not August. Now.

Insurance and liability coverage

Traditional liability insurance policies (general liability, D&O) may not cover specific damages caused by AI systems. Three concrete actions:

1. Review current policies

Ask your broker to confirm in writing whether your liability policy covers: damages caused by automated decisions, algorithmic discrimination, AI system failures in production. If the answer is "it depends", it does not cover them.

2. Evaluate AI-specific insurance

The insurance market is creating AI-specific products. They are expensive and have many exclusions, but they exist. Assess whether your risk level justifies it. For most SMEs with limited-risk AI, it is not necessary yet.

3. Provider contract clauses

Review your AI provider contracts. Who assumes liability if the system fails? Many SaaS contracts exclude liability for incorrect outputs. If you use a high-risk system, that clause is unacceptable. Negotiate or switch providers.

Practical exercise

Ejercicio CX05: AI Act compliance checklist for your company
  1. Create the inventory: list all AI systems your company uses (include SaaS tools with integrated AI that you might not consider "AI systems")
  2. Classify each system: unacceptable, high, limited or minimal risk. Use the AI Act categories, not your intuition
  3. For each high-risk system: is there a documented impact assessment? Is there a designated human overseer? Is the operator trained?
  4. Identify the AI compliance officer in your company. If none exists, propose who it should be and with what resources
  5. Submit the 10 questions to the legal team. Set a 2-week response deadline
  6. Prepare a 1-page briefing for the board with: risks identified, required actions, estimated budget, deadlines

Bonus: ask the AI: "I am an executive at a [industry] company with [N] employees in [country]. We use these AI systems: [list]. What are my obligations under the AI Act and what deadlines apply?" Validate the answer with your legal team.

Puntos clave

Puntos clave from CX05

  1. The AI Act is a European regulation with direct application. It does not wait for national transposition.
  2. Liability is personal for the executive who approves high-risk system deployment without meeting requirements.
  3. Fines: up to EUR 35M or 7% of global turnover. Existential for SMEs.
  4. August 2026: high-risk requirements enter into force. The time to act is now.
  5. 5 steps: inventory, risk assessment, governance, training, ongoing monitoring.
  6. SMEs are not exempt from high-risk requirements, but do have access to sandboxes, reduced fees and simplified guidelines.
  7. Documented diligence: your best personal protection as an executive.
Guia de estudio — Conceptos clave de CX05

Por que el AI Act te afecta personalmente

  • La responsabilidad es personal.No solo de la empresa. El AI Act establece obligaciones que recaen sobre las personas que toman decisiones sobre sistemas de IA. Si tu empresa despliega un sistema de alto riesgo sin cumplir los requisitos, el directivo que aprobo ese despliegue puede ser responsable.
  • Las multas son existenciales.Hasta 35 millones de euros o el 7% de la facturacion global. Para una PYME de 5 millones de facturacion, el 7% son 350.000 EUR. Suficiente para cerrar.
  • Los plazos son inminentes.Agosto 2026 es la fecha en la que la mayoria de obligaciones para sistemas de alto riesgo entran en vigor. No es un horizonte lejano. Son semanas.
  • Para el directivo: Este modulo no es un curso de derecho. Eso es trabajo de tu equipo legal (y del modulo LG04 para juristas). Aqui te damos lo que necesitas para tomar decisiones informadas : que preguntar, que aprobar, que delegar y que no ignorar.

Estructura del AI Act en 5 minutos

  • Social scoring (calificacion social de ciudadanos)
  • Manipulacion subliminal que cause dano
  • Explotacion de vulnerabilidades de grupos especificos
  • Identificacion biometrica en tiempo real en espacios publicos (con excepciones para seguridad)
  • RRHH: seleccion de candidatos, evaluacion de desempeno, decisiones de promocion o despido basadas en IA
  • Credito: scoring crediticio, evaluacion de solvencia

Obligaciones del consejo y la direccion

  • Inventario de sistemas IA.Lista completa de todos los sistemas de IA que usa la empresa, clasificados por nivel de riesgo. Si no sabes que IA usa tu empresa, no puedes cumplir nada.
  • Evaluacion de riesgo.Para cada sistema de alto riesgo, una evaluacion documentada de impacto que incluya riesgos para derechos fundamentales.
  • Politica de IA.Marco de governance que defina quien puede desplegar IA, con que aprobaciones, bajo que condiciones y con que supervision.
  • Presupuesto de compliance.Cumplir el AI Act tiene coste: auditoria, documentacion, formacion, herramientas de monitoring. El consejo debe aprobar ese presupuesto.
  • Designar un responsable de AI compliance.Puede ser el DPO, el CISO, un nuevo rol, o una funcion compartida. Pero alguien debe tener la responsabilidad explicita.
  • Implementar supervision humana.Para sistemas de alto riesgo, debe haber una persona (con formacion adecuada) que pueda intervenir, anular o desactivar el sistema.

Responsabilidad personal del directivo

  • La regla de oro: La mejor proteccion personal del directivo es la diligencia documentada . Hiciste la evaluacion? Documentala. Consultaste a legal? Documentalo. Formaste al equipo? Documentalo. La documentacion no evita errores, pero demuestra que actuaste con diligencia razonable.

10 preguntas que debes hacer a tu equipo legal

  • Cuantos sistemas de IA usamos actualmente?Incluye herramientas SaaS, APIs, modelos propios, automatizaciones con IA integrada. La respuesta suele sorprender.
  • Cuales clasifican como alto riesgo bajo el AI Act?Especialmente RRHH, credito, seguros, educacion. Si usas IA para filtrar CVs, es alto riesgo.
  • Tenemos evaluacion de impacto documentada para cada uno?No vale "lo hicimos mentalmente". Debe estar escrito, fechado y firmado.
  • Quien es nuestro responsable de AI compliance?Si la respuesta es "nadie" o "IT se encarga", tienes un problema.
  • Cumplimos con los requisitos de transparencia?Los usuarios saben que interactuan con IA? Los outputs IA estan identificados?
  • Tenemos supervision humana para sistemas de alto riesgo?Quien puede intervenir? Tiene formacion? Tiene autoridad real para desactivar el sistema?

Plan de cumplimiento en 5 pasos

  • Responsable: CTO o CISO, con input de cada departamento.
  • Entregable: inventario completo con clasificacion de riesgo.
  • Responsable: equipo legal + responsable de compliance IA.
  • Entregable: evaluacion de impacto documentada por sistema.
  • Responsable: direccion general + legal.
  • Entregable: politica de IA aprobada por consejo.

Siguiente: CX06 - Sovereign and Open-Source AI

You know the regulation. Now understand what options you have to maintain control over your data and your AI infrastructure.

Ir al modulo CX06