EU AI Act Masterclass, Part Three

The most expensive sentence in AI governance is somebody must have checked this.

Executive brief

The department matters less than the name. What matters is that one named person is accountable, because when nobody owns it everybody assumes somebody else checked

Information is not the constraint. What people need is a sequence: am I exposed, can I prove it, what do I do first

Clients pay for application, not recitation. Classify my system. Fix my contract. Train my team

Getting certified makes you certified. Credibility comes from demonstrating you can operationalise the requirements

You already have more transferable competence than you think. An inventory, a data map, a gap analysis or an incident response is the same shape of work

Episode conversation

Watch the episode

What GDPR taught us about who becomes indispensable

Ahmed starts with a pattern, because patterns repeat.

 Between 2016 and the May 2018 deadline, companies had two years to comply with GDPR. Most treated it as a compliance project to survive. A small group treated it as an opening, and that group became the data protection officers, the consultants and the trusted advisers who have owned the field ever since.

 His read on why is worth sitting with. They were not necessarily the smartest people in the room. They were the ones who prepared before everyone else realized they should.

 What is different this time is scope and speed. GDPR was about personal data, so it touched a few departments and the data governance function carried most of it. AI touches every function, not just data flows. The timeline is faster, the fines are larger, and, as he puts it, this time everybody can see the wave coming and is still not moving.

Why more information has not made anyone more confident

People read every article and sit through every webinar on AI compliance and still feel lost. Jeff asked why.

 Ahmed’s answer is that information stopped being scarce a long time ago. This is not the nineteen eighties, when knowledge sat behind money and access and people hoarded it. Everything is available. What is genuinely hard is finding good information, and what is harder still is doing anything with it.

 The people saving articles are collecting, not learning. Information without a framework is noise, and the regulation itself is organised for lawyers rather than for decisions. Reading it in article order tells you what the law says in the order the drafters wrote it, which is not the order in which anything gets decided.

 What people need instead is a sequence. Am I exposed? Can I prove it? What do I do first?

The three lies professionals tell themselves about the EU AI Act

Having trained more than seventy thousand people, Ahmed has seen enough of them to sort the patterns into three buckets. His more direct description is three lies people tell themselves.

The lie

Why it does not hold

I will figure it out if I read enough

It is 113 articles plus the annexes, plus an omnibus amending it. Reading the Act is not the same as being able to answer a question in a meeting, and no amount of reading teaches you how to operationalise it into something that works with the business rather than blocking it.

I will deal with it when it becomes urgent

When it is urgent you are competing with everybody else who waited. You are paying panic prices and you have no runway. The people getting into it now will be rewarded for it in a few months, precisely because it never became a panic for them.

Once I understand the law, I will be ready

Clients do not pay for recitation. They pay for application. Classify my system. Fix my contract. Train my team. The law itself is available to them free of charge, so reciting it back adds nothing they could not have got without you.

That third one carries the sharpest edge, and it applies to consultants and internal hires alike. The value is in explaining the requirement so anyone in the business can understand it, then handing over something practical they can act on quickly without the whole operation seizing up. Unless it is a banned practice, in which case the pragmatic answer is that it stops.

Who should own AI governance inside a company

Jeff put the question directly. Legal, privacy, risk, or IT? And what happens if nobody takes it?

 Ahmed answers the first half with an admitted bias. He thinks privacy professionals are closest, because they already run the muscle this work requires: rights, risk, and accountability, exercised daily. They have spent years classifying risk, understanding what people are entitled to, and living with the idea that somebody has to answer for it.

 But he is clear that ownership beats department. Legal can own it. Risk can own it. Engineering can own it. What actually matters is that one named person does, and that the person knows they do.

The accidental provider problem is an ownership gap

When nobody owns AI governance, everybody assumes somebody else checked.

 Ahmed has watched this play out enough times to recite the internal monologue. We have got the tool. It is fine. Somebody must have looked at this, otherwise they would have come and asked us about it. It is safe. Let us carry on.

 Nobody was lying. Nobody was reckless. There was simply no name attached to the question, so the question never got asked, and a company that believed it was a user turned out to be a provider with a full set of obligations it had never read.

 The part that makes this unrecoverable is what happens afterwards. When something goes wrong, everyone looks at everybody else. The regulator does not care about that. The people who were harmed care about it even less.

How to become the go-to person on AI governance

Ahmed’s first instruction is not what most people expect. Understand AI before you touch the Act, and not in a technical way. What is artificial intelligence, what are the different types, what is machine learning, and the single distinction that unlocks the rest: AI either predicts things or generates things.

 Once that lands, the Act reads differently. And it needs to, because it was written for lawyers by lawyers and may not make much sense to anyone else.

 The profile he describes is someone who can understand the obligations, help a business classify its risks and the roles it is playing, and then help it mitigate and manage those risks in a way that is safe, ethical, compliant, and evidenced.

Why AI governance certification and credibility are not the same thing

The market for credentials here is wide open and very new. There is no standard benchmark yet. The IAPP offers certifications, ISACA offers certifications, PECB offers certifications, and effectively everybody is offering their own.

 Ahmed’s advice is to look at your background, decide which area of AI governance you actually want to work in, and then make an informed choice. What he would not do is rush.

 The reason is a pattern he sees constantly among smart professionals. They do not get the job, they conclude the problem is credibility, and they go and buy a certification to fix it. But getting certified makes you certified. It does not make you credible.

 Credibility comes from demonstrating to stakeholders that you understand the thing and can put it into practice. Talking the talk and walking the walk, as he puts it, which in this field means turning requirements into work streams somebody can actually run. Credibility comes from showing you can do the work.

The transferable skills you already have

This is the most useful thing in the conversation for anyone trying to move into the field, and it is the opposite of what most career advice says.

 Before you go and acquire anything new, look at what you have already done and find the shape of AI governance work inside it.

 Ever built an inventory of anything? That is evidence you can build an AI inventory. Done data mapping, or built a record of processing activities? That is evidence you can inventory and classify. Handled an incident response, a gap analysis, or any kind of structured assessment? That is evidence you can run a fundamental rights impact assessment.

 As Ahmed says, you bring more to the table than you realise. The work is not unfamiliar. What is unfamiliar is the vocabulary, and vocabulary is a much smaller gap to close than competence.

Why visibility is the currency

The second half of his advice is to build a personal brand, and his reasoning is mechanical rather than aspirational.

 Think about how hiring actually happens. Nobody wakes up and decides to hire ten people and post to a job board. A manager decides they need headcount, tells the team, and asks whether anyone knows good people, because good people know good people. Only when that network comes up empty does it reach HR. And HR is not the AI governance expert, so the job description that finally gets published may well have been drafted with a general-purpose AI tool and may sit a long way from what the hiring manager actually wanted. It then puts off qualified candidates who read the list and decide they do not tick every box.

 Which is why applying through the front door is harder than it needs to be. The better route is to be findable. Write posts and articles. Explain how you are handling things and what your take is. Find the problems people in the industry keep hitting and offer solutions to them.

 Ahmed’s own evidence is that he woke up recently to an inbound approach for a lead AI governance role he never applied for. And it is not only happening to him. Everybody on his book launch team who spent eight weeks posting, sharing takeaways, and talking through how to implement parts of the Act started getting recruiters on their profiles, podcast invitations, and product focus-group requests.

 Opportunities find people who are visible. As he put it, visibility is the currency in 2026 and beyond.

EU AI Act terms people constantly mix up

The conversation closed with a lightning round. Jeff named the pairs people confuse, Ahmed defined the difference in a sentence. This is the cleanest set of plain-language definitions of the Act’s core distinctions that we have on tape.

The pair

The difference

Provider or deployer

The provider builds it or puts its name on it. The deployer uses it under its own authority. Build it and it is yours. Use it and you still have homework.

Placing on the market or putting into service

Placing on the market is making it available to others in the EU. Putting into service is using it yourself for its intended purpose. Selling it versus switching it on.

Importer or distributor

The importer brings a non-EU system into the EU market first. The distributor passes along a system that is already available. First through the door versus passing it along.

Substantial modification or normal operation

A substantial modification changes the system in a way that affects compliance or its purpose, and it can make you the provider. Normal operation, including expected updates, keeps you where you are.

AI system or general-purpose AI model

The model is the engine. The system is the car built around it. Rules for models hit the labs. Rules for systems hit everyone who builds with them.

Serious incident or malfunction

A malfunction is the system misbehaving. A serious incident is misbehaviour that harms health, safety, fundamental rights or critical infrastructure. One is a fault. The other is a fault with a victim, and only one starts a reporting clock.

High risk or systemic risk

High risk is about the use, meaning what the system is used for, such as hiring, credit or education. Systemic risk is about the model, meaning frontier-scale general-purpose models powerful enough to matter economy-wide.

Conformity assessment or fundamental rights impact assessment

A conformity assessment is the provider proving its product meets the rules before it goes to market. A fundamental rights impact assessment is the deployer proving the way it intends to use the system on particular people is acceptable. Product check versus use check.

Why any of this exists

Ahmed closed on the question of why the obligations are there at all, and he answered it with a case rather than a principle.

 A Finnish psychotherapy provider, Vastaamo, failed to protect its patient records. Attackers took them, demanded payment, and when the company would not pay, went to the patients directly and threatened to publish their therapy notes unless they paid individually. The records contained the things people tell a therapist and nobody else. The harm to those patients has been severe and lasting.

 His point in raising it is that people say Europe has too much red tape, too many regulations, too many rules. And then something like Vastaamo happens, and Europe is the place you would rather be, because the framework was built to put people first. As he frames it, the obligations trace back to protecting fundamental rights. They are not there to generate fines.

 He extended it to what technology should be doing in the first place. It should be giving us more freedom, not less. If it is being used to surveil, restrict, or manipulate people, the question is not just what world we are living in but what world we are leaving behind. His own version of that is personal. He would rather be on the side that did everything it could for his daughter and the people who come after her.

Risk avoided is not value created

Jeff’s close is the line the whole series has been building toward.

 The EU did not just write a rule book. It took one of the first serious swings at defining what AI risk even is. And the companies that learn to measure it do more than protect themselves, because measurement is what turns you into the organisation people call.

 Risk avoided is not value created. The goal was never just to be safe. It is to capture the upside and do it safely.

 Which is the same three questions a board is going to ask, in whatever order they arrive. Is it paying off. Is it under control. And what could it cost us.

Is your AI investment making money or losing money?

TheAIAudit measures your organization’s collective AI investment and returns a single AI Health Score from 0 to 100, with three statements behind it that say what to fix: Governance, Impact, and Risk Flow.

Apply for the founding cohort

Questions answered in this episode

Who inside a company should own AI governance?

One named person, and the department matters less than the name. Ahmed argues privacy professionals are closest because they already run rights, risk and accountability daily, but legal, risk or engineering can own it equally well. What cannot happen is nobody owning it, because then everybody assumes somebody else checked.

What is the accidental provider problem under the EU AI Act?

A company that believes it is simply a user of an AI tool turns out to be a provider, with the full set of provider obligations it has never read. It happens when no one is accountable for asking the question, so the question never gets asked. It is an ownership gap before it is a compliance failure.

Do I need a certification to work in AI governance?

Not urgently. The market is new and there is no standard benchmark yet, with the IAPP, ISACA, PECB and others all offering their own. Ahmed’s advice is to match a certification to your background and your chosen area rather than rushing. Getting certified makes you certified; credibility comes from showing you can operationalise the requirements.

What skills transfer into AI governance work?

More than most people think. Anyone who has built an inventory can build an AI inventory. Anyone who has done data mapping or a record of processing activities can inventory and classify. Anyone who has run an incident response, a gap analysis or a structured assessment has done the shape of a fundamental rights impact assessment. The unfamiliar part is the vocabulary, not the competence.

What is the difference between a provider and a deployer?

The provider builds the system or puts its name on it. The deployer uses it under its own authority. Build it and it is yours. Use it and you still have homework.

What is the difference between a conformity assessment and a fundamental rights impact assessment?

A conformity assessment is the provider proving its product meets the rules before it goes to market. A fundamental rights impact assessment is the deployer proving that the way it intends to use the system on particular people is acceptable. Product check versus use check.

Chapters

00:00   Certified is not the same as credible

00:22   Why the loudest voices in AI are often the least qualified

01:19   Meet Jamal Ahmed

02:39   The GDPR pattern, and who it made

03:33   They were not the smartest people in the room

04:56   Why more information does not fix it

05:51   What people actually need is a sequence

06:21   Lie one: I will figure it out if I read enough

07:11   Lie two: I will deal with it when it becomes urgent

07:41   Lie three: once I understand the law, I will be ready

09:11   Who should own AI governance inside a company

10:15   When nobody owns it, everybody assumes somebody checked

10:45   How to become the go-to person

12:45   Certifications, and why not to rush one

14:14   The transferable skills you already have

15:12   Why visibility is the currency

19:07   Why any of this exists

22:24   What technology should be giving us back

23:09   Lightning round: the terms people mix up

26:07   Risk avoided is not value created

Sources

The EU AI Act

Regulation (EU) 2024/1689. eur-lex.europa.eu/eli/reg/2024/1689/oj/eng

 The Digital Omnibus on AI

Regulation (EU) 2026/1744, in force 27 July 2026.

 The Vastaamo breach

Finnish psychotherapy provider, patient records compromised in 2020. Referenced in the conversation as the reason the obligations exist.

 Certification bodies referenced

IAPP, ISACA, PECB.

 Jamal Ahmed’s guide

The Easy Peasy Guide to the EU AI Act. amazon.co.uk/dp/1917534175