En este modulo
- Why the AI Act affects you personally
- The AI Act structure in 5 minutes
- Obligations of the board and executive management
- Personal liability of the executive
- 10 questions you must ask your legal team
- 5-step compliance plan
- SME exemptions
- Sanctions that matter to leadership
- Critical deadlines: August 2026 is here
- Insurance and liability coverage
- Practical exercise
- Puntos clave
Why the AI Act affects you personally
Regulation (EU) 2024/1689, known as the AI Act, entered into force on 1 August 2024. It is not a directive that each country transposes in its own way. It is a regulation: it applies directly in all member states. No interpretations, no excuses, no "let's see how Spain transposes it".
For the executive, three realities change everything:
- Liability is personal. Not just the company's. The AI Act establishes obligations that fall on the individuals who make decisions about AI systems. If your company deploys a high-risk system without meeting the requirements, the executive who approved that deployment can be held liable.
- The fines are existential. Up to EUR 35 million or 7% of global turnover. For an SME with EUR 5 million in revenue, 7% is EUR 350,000. Enough to close the business.
- The deadlines are imminent. August 2026 is when most obligations for high-risk systems come into force. It is not a distant horizon. It is weeks away.
For the executive
This module is not a law course. That is the job of your legal team (and module LG04 for legal professionals). Here we give you what you need to make informed decisions: what to ask, what to approve, what to delegate and what not to ignore.
The AI Act structure in 5 minutes
The AI Act classifies AI systems into four risk levels. Your first job as an executive is to know which level your company's systems fall into:
Unacceptable risk (prohibited)
Systems the EU considers incompatible with fundamental rights. Prohibited since February 2025.
- Social scoring (social credit scoring of citizens)
- Subliminal manipulation causing harm
- Exploitation of vulnerabilities of specific groups
- Real-time biometric identification in public spaces (with exceptions for security)
If your company uses any of these, stop immediately. There is no exception or transition period.
High risk
Systems that significantly affect people. They must meet strict requirements before deployment.
- HR: candidate selection, performance evaluation, AI-based promotion or dismissal decisions
- Credit: credit scoring, creditworthiness assessment
- Insurance: premium calculation based on individual profiles
- Education: student assessment, access to education
- Essential public services: access to benefits, emergency services
- Justice and migration: evidence assessment, border control
Requirements: risk management system, documented training data, transparency, human oversight, demonstrated accuracy and robustness, registration in the EU database.
Limited risk
Systems that interact with people. Main requirement: transparency.
- Chatbots: must inform the user they are talking to AI
- Deepfakes: must be labeled
- AI-generated content: must be identified as such
Minimal risk
Everything else. Spam filters, product recommendations, writing assistants. No specific obligations. Most AI productivity tools fall here.
Obligations of the board and executive management
The AI Act does not say "the company must". It says "the provider must" and "the deployer must". If your company uses high-risk AI systems, you are a "deployer". That creates concrete obligations for leadership:
What the board must approve
- AI systems inventory. A complete list of all AI systems the company uses, classified by risk level. If you do not know what AI your company uses, you cannot comply with anything.
- Risk assessment. For each high-risk system, a documented impact assessment including risks to fundamental rights.
- AI policy. A governance framework that defines who can deploy AI, with what approvals, under what conditions and with what oversight.
- Compliance budget. Complying with the AI Act has a cost: auditing, documentation, training, monitoring tools. The board must approve that budget.
What executive management must execute
- Designate an AI compliance officer. This can be the DPO, the CISO, a new role, or a shared function. But someone must have explicit responsibility.
- Implement human oversight. For high-risk systems, there must be a person (with adequate training) who can intervene, override or disable the system.
- Document everything. Decisions, assessments, incidents, corrective actions. Documentation is the primary defense in an inspection.
- Train the team. The AI Act requires that people who use high-risk systems have "sufficient AI competence" (AI literacy). This is not optional.
Personal liability of the executive
The AI Act combines with each member state's corporate law and director liability legislation. In Spain, the Companies Act (art. 225-236) establishes that directors are liable for damage caused by acts contrary to law.
Personal liability scenarios:
Scenario 1: Deployment without assessment
The company deploys an AI system for candidate screening without conducting the required impact assessment. A rejected candidate files a discrimination claim. The inspection discovers there is no documentation. The executive who approved the deployment is liable.
Scenario 2: Ignoring alerts
The technical team reports that a credit scoring system shows statistical bias against a demographic group. Leadership decides not to act because "it generates good commercial results". If there is a complaint, the documented inaction is evidence against the executive.
Scenario 3: Lack of training
An untrained employee makes automated decisions about social benefits. The system commits systematic errors. The company cannot demonstrate it trained the employee. The HR director is exposed.
The golden rule
The executive's best personal protection is documented diligence. Did you conduct the assessment? Document it. Did you consult legal? Document it. Did you train the team? Document it. Documentation does not prevent errors, but it demonstrates you acted with reasonable diligence.
10 questions you must ask your legal team
You do not need to be an AI Act expert. You need to ask the right questions. These 10 are the minimum:
- How many AI systems do we currently use? Include SaaS tools, APIs, proprietary models, automations with integrated AI. The answer usually surprises.
- Which ones classify as high-risk under the AI Act? Especially HR, credit, insurance, education. If you use AI to screen CVs, it is high-risk.
- Do we have a documented impact assessment for each one? "We thought about it" does not count. It must be written, dated and signed.
- Who is our AI compliance officer? If the answer is "nobody" or "IT handles it", you have a problem.
- Do we meet the transparency requirements? Do users know they are interacting with AI? Are AI outputs identified as such?
- Do we have human oversight for high-risk systems? Who can intervene? Are they trained? Do they have real authority to disable the system?
- Do our AI providers comply with the AI Act? The AI Act holds the deployer responsible if the provider does not comply. Review contracts.
- Do we have an AI literacy training plan? The AI Act requires it. How many people need training? By when?
- What insurance do we have that covers AI liability? General liability policies may not cover damages caused by AI systems.
- Are we prepared for an inspection? If an inspector from the national supervisory authority arrives tomorrow, can we demonstrate compliance within 48 hours?
5-step compliance plan
This plan is designed so an executive can activate it at the next committee meeting. It does not require deep legal knowledge. It requires willingness to act.
Step 1: Inventory (weeks 1-2)
Catalog all AI systems in use. For each one: name, provider, function, data processed, responsible department, risk classification (unacceptable, high, limited, minimal). A spreadsheet is enough.
Owner: CTO or CISO, with input from each department.
Deliverable: complete inventory with risk classification.
Step 2: Risk assessment (weeks 3-6)
For each high-risk system: impact assessment including risks to fundamental rights, mitigation measures, human oversight plan. Use the European AI Office template as a baseline.
Owner: legal team + AI compliance officer.
Deliverable: documented impact assessment per system.
Step 3: Governance (weeks 4-8)
Create or update the company's AI policy. Define roles: who approves new AI systems, who oversees existing ones, who reports incidents. Approve at board level.
Owner: general management + legal.
Deliverable: AI policy approved by the board.
Step 4: Training (weeks 6-12)
AI literacy plan for all employees who interact with AI systems. Specific training for high-risk system operators. Training record (who, when, what).
Owner: HR + AI compliance officer.
Deliverable: completed training record.
Step 5: Ongoing monitoring (permanent)
Quarterly review of the inventory (new systems, changes to existing ones). Annual compliance audit. Update risk assessments when the system or the regulation changes.
Owner: AI compliance officer.
Deliverable: quarterly report to the board.
SME exemptions
The AI Act includes measures to avoid overburdening SMEs. If your company is small, this matters:
What benefits you
- Regulatory sandboxes: national authorities must create testing environments where SMEs can test AI systems with free regulatory guidance. Spain is required to create at least one.
- Reduced fees: conformity and registration fees are reduced proportionally to company size.
- Simplified guidelines: the European AI Office must publish SME-specific guidelines. If you cannot find them, your industry association should demand them.
- Extended deadlines: for some documentation requirements, SMEs have more generous timelines.
What does NOT exempt you
- High-risk systems: if you use high-risk AI, you must meet the same requirements as a multinational. No exceptions by size.
- Prohibited practices: apply to all companies, regardless of size.
- Transparency: the requirement to inform users applies to everyone.
Reality for SMEs
Most SMEs use minimal or limited-risk AI (chatbots, writing assistants, content generators). If that is your case, your obligations are essentially transparency: disclose that you use AI. The AI Act does not require you to stop using ChatGPT for emails. It requires you to be transparent about it.
Sanctions that matter to leadership
The AI Act establishes three levels of sanctions. The figures are maximums, but they convey the seriousness of regulatory intent:
| Infringement | Maximum sanction | Example |
|---|---|---|
| Prohibited practices | EUR 35M or 7% global turnover | Social scoring, subliminal manipulation |
| Non-compliance with requirements | EUR 15M or 3% global turnover | Deploying high-risk without impact assessment |
| Incorrect information | EUR 7.5M or 1% global turnover | Declaring a high-risk system as minimal risk |
For SMEs and startups, the lesser of the two amounts applies (percentage or fixed amount). But even the minimum can be devastating for a small company.
Beyond direct fines, the reputational damage is real. An AI Act sanction generates headlines, erodes client trust and makes it harder to attract talent. In regulated industries (banking, insurance, healthcare), it can mean the loss of operating licenses.
Critical deadlines: August 2026 is here
The AI Act has a phased rollout. These are the deadlines that matter to leadership:
- February 2025 (already past): prohibition of unacceptable-risk practices. If you have not reviewed this, do it today.
- August 2025 (already past): AI literacy obligations for all providers and deployers. Your team should already be trained.
- August 2026 (imminent): entry into force of requirements for high-risk systems. Impact assessments, human oversight, technical documentation, EU database registration. This is the critical deadline.
- August 2027: requirements for general-purpose AI models (mainly affects model providers, not users).
If your company uses high-risk systems and you have not started the compliance plan, the time to act is now. Not August. Now.
Insurance and liability coverage
Traditional liability insurance policies (general liability, D&O) may not cover specific damages caused by AI systems. Three concrete actions:
1. Review current policies
Ask your broker to confirm in writing whether your liability policy covers: damages caused by automated decisions, algorithmic discrimination, AI system failures in production. If the answer is "it depends", it does not cover them.
2. Evaluate AI-specific insurance
The insurance market is creating AI-specific products. They are expensive and have many exclusions, but they exist. Assess whether your risk level justifies it. For most SMEs with limited-risk AI, it is not necessary yet.
3. Provider contract clauses
Review your AI provider contracts. Who assumes liability if the system fails? Many SaaS contracts exclude liability for incorrect outputs. If you use a high-risk system, that clause is unacceptable. Negotiate or switch providers.
Practical exercise
- Create the inventory: list all AI systems your company uses (include SaaS tools with integrated AI that you might not consider "AI systems")
- Classify each system: unacceptable, high, limited or minimal risk. Use the AI Act categories, not your intuition
- For each high-risk system: is there a documented impact assessment? Is there a designated human overseer? Is the operator trained?
- Identify the AI compliance officer in your company. If none exists, propose who it should be and with what resources
- Submit the 10 questions to the legal team. Set a 2-week response deadline
- Prepare a 1-page briefing for the board with: risks identified, required actions, estimated budget, deadlines
Bonus: ask the AI: "I am an executive at a [industry] company with [N] employees in [country]. We use these AI systems: [list]. What are my obligations under the AI Act and what deadlines apply?" Validate the answer with your legal team.
Puntos clave
Puntos clave from CX05
- The AI Act is a European regulation with direct application. It does not wait for national transposition.
- Liability is personal for the executive who approves high-risk system deployment without meeting requirements.
- Fines: up to EUR 35M or 7% of global turnover. Existential for SMEs.
- August 2026: high-risk requirements enter into force. The time to act is now.
- 5 steps: inventory, risk assessment, governance, training, ongoing monitoring.
- SMEs are not exempt from high-risk requirements, but do have access to sandboxes, reduced fees and simplified guidelines.
- Documented diligence: your best personal protection as an executive.
Guia de estudio — Conceptos clave de CX05
Por que el AI Act te afecta personalmente
- La responsabilidad es personal.No solo de la empresa. El AI Act establece obligaciones que recaen sobre las personas que toman decisiones sobre sistemas de IA. Si tu empresa despliega un sistema de alto riesgo sin cumplir los requisitos, el directivo que aprobo ese despliegue puede ser responsable.
- Las multas son existenciales.Hasta 35 millones de euros o el 7% de la facturacion global. Para una PYME de 5 millones de facturacion, el 7% son 350.000 EUR. Suficiente para cerrar.
- Los plazos son inminentes.Agosto 2026 es la fecha en la que la mayoria de obligaciones para sistemas de alto riesgo entran en vigor. No es un horizonte lejano. Son semanas.
- Para el directivo: Este modulo no es un curso de derecho. Eso es trabajo de tu equipo legal (y del modulo LG04 para juristas). Aqui te damos lo que necesitas para tomar decisiones informadas : que preguntar, que aprobar, que delegar y que no ignorar.
Estructura del AI Act en 5 minutos
- Social scoring (calificacion social de ciudadanos)
- Manipulacion subliminal que cause dano
- Explotacion de vulnerabilidades de grupos especificos
- Identificacion biometrica en tiempo real en espacios publicos (con excepciones para seguridad)
- RRHH: seleccion de candidatos, evaluacion de desempeno, decisiones de promocion o despido basadas en IA
- Credito: scoring crediticio, evaluacion de solvencia
Obligaciones del consejo y la direccion
- Inventario de sistemas IA.Lista completa de todos los sistemas de IA que usa la empresa, clasificados por nivel de riesgo. Si no sabes que IA usa tu empresa, no puedes cumplir nada.
- Evaluacion de riesgo.Para cada sistema de alto riesgo, una evaluacion documentada de impacto que incluya riesgos para derechos fundamentales.
- Politica de IA.Marco de governance que defina quien puede desplegar IA, con que aprobaciones, bajo que condiciones y con que supervision.
- Presupuesto de compliance.Cumplir el AI Act tiene coste: auditoria, documentacion, formacion, herramientas de monitoring. El consejo debe aprobar ese presupuesto.
- Designar un responsable de AI compliance.Puede ser el DPO, el CISO, un nuevo rol, o una funcion compartida. Pero alguien debe tener la responsabilidad explicita.
- Implementar supervision humana.Para sistemas de alto riesgo, debe haber una persona (con formacion adecuada) que pueda intervenir, anular o desactivar el sistema.
Responsabilidad personal del directivo
- La regla de oro: La mejor proteccion personal del directivo es la diligencia documentada . Hiciste la evaluacion? Documentala. Consultaste a legal? Documentalo. Formaste al equipo? Documentalo. La documentacion no evita errores, pero demuestra que actuaste con diligencia razonable.
10 preguntas que debes hacer a tu equipo legal
- Cuantos sistemas de IA usamos actualmente?Incluye herramientas SaaS, APIs, modelos propios, automatizaciones con IA integrada. La respuesta suele sorprender.
- Cuales clasifican como alto riesgo bajo el AI Act?Especialmente RRHH, credito, seguros, educacion. Si usas IA para filtrar CVs, es alto riesgo.
- Tenemos evaluacion de impacto documentada para cada uno?No vale "lo hicimos mentalmente". Debe estar escrito, fechado y firmado.
- Quien es nuestro responsable de AI compliance?Si la respuesta es "nadie" o "IT se encarga", tienes un problema.
- Cumplimos con los requisitos de transparencia?Los usuarios saben que interactuan con IA? Los outputs IA estan identificados?
- Tenemos supervision humana para sistemas de alto riesgo?Quien puede intervenir? Tiene formacion? Tiene autoridad real para desactivar el sistema?
Plan de cumplimiento en 5 pasos
- Responsable: CTO o CISO, con input de cada departamento.
- Entregable: inventario completo con clasificacion de riesgo.
- Responsable: equipo legal + responsable de compliance IA.
- Entregable: evaluacion de impacto documentada por sistema.
- Responsable: direccion general + legal.
- Entregable: politica de IA aprobada por consejo.
Siguiente: CX06 - Sovereign and Open-Source AI
You know the regulation. Now understand what options you have to maintain control over your data and your AI infrastructure.
Ir al modulo CX06