12. What the CEO Does, and What the CEO Delegates
Two chapters of rules can leave a CEO with the wrong conclusion: that AI compliance is a legal matter, to be handed to a lawyer and forgotten. It is not. In every framework in the world the person who answers for how AI is used in a company is the person who runs it; the lawyer advises, the consultant builds, IT operates, and none of them signs. The good news is that what the law asks — the six things in chapter 10 — is almost exactly what a well-run AI program does anyway. Compliance is not a layer on top of the method; it is the method with a paper trail.
This chapter is the operating guide. It separates the three decisions only you can take from everything you can and should delegate; says who does what inside the company and what goes outside; places the compliance gates inside the life of an agent so that nothing is checked twice or too late; and ends with a checklist and the clauses to require from suppliers. By the end you will be able to run the first AI governance meeting of your company in an hour, with the right people in the room.
The three decisions you cannot delegate
Where the lines are. Which uses of AI your company will not make, whatever the return — and which uses require your personal sign-off before they go live. Every legal framework draws lines (prohibited practices, high-risk tiers); your company should draw its own one notch tighter, because your reputation is not protected by a compliance certificate. Hiring, evaluating people, granting credit, anything touching health or safety, anything a customer would be angry to discover: those are yours to decide, in writing, once.
Who answers. One person accountable for AI in the company, by name, in the org chart. Not a committee, not "the AI team," not the consultant. In an SME that person is often you for the first year, then a function head with a written mandate. Every framework — the UK's, Korea's, the Gulf's central-bank guidance, ISO 42001 — asks for this, and it is the first question an inspector or a large customer will ask.
How much risk, at what evidence. The level of oversight you require for each class of agent: which agents act alone inside thresholds, which propose and wait, which never act without a person; and what proof you want to see, and how often. This is the same decision you took in chapter 7 for the decision playbook, read from the side of responsibility instead of the side of speed. It cannot be delegated because it is the definition of how much you trust the machine on your behalf.
Everything else — the register, the assessments, the notices, the training records, the contracts, the technical controls — is execution, and execution is delegated.
The inventory: what AI is already inside your company
Before governing anything you need to know what you have, and every CEO I have worked with has underestimated it. AI is already in your company in three forms: features inside the software you already use — the ERP that forecasts, the CRM that scores leads, the email that drafts; tools people have adopted on their own — the assistants, translators and generators of shadow AI; and agents you have deliberately put in place. The UK's approach makes the point explicit: an AI register must include AI features inside existing software, not only what you bought as "AI."
The inventory is a table, one row per system, and it is the foundation of every other document in this chapter.
| Column | What to write |
|---|---|
| System | Name and supplier; feature, tool or agent |
| What it does | In one line, in business terms |
| Data it touches | Personal, customer, employee, financial; where it is stored |
| Decisions it influences | None · proposes · decides inside thresholds · decides on people |
| Countries | Where the people affected are |
| Risk tier | Prohibited · high · transparency-only · minimal (chapter 10 core) |
| Owner | The function head who answers for it |
| Evidence | Where the documentation, training records and reviews are kept |
Watch out. The shadow-AI rows are the ones that matter most and the ones nobody volunteers. Across the surveys, roughly three in four employees use AI regularly and only a third feel adequately trained; the tools they use on their own send your data somewhere you have not approved and produce outputs nobody reviews. Do not run the inventory as a hunt. Run it as an amnesty: two weeks, no consequences, and the promise that the tools people like will be evaluated for adoption. You will learn more about your company in those two weeks than in a year of meetings.
Who does what inside
An SME does not need a compliance department. It needs four people who already exist to add a defined slice of AI to what they do, with the accountable person above them.
| Role | What they own | What they deliver | What they do not do |
|---|---|---|---|
| Legal / data protection (in-house or external) | Data lawfulness, notices, contracts, impact assessments | The legal basis for each data flow; the transparency notice; the contract clauses; the register of assessments | Decide which agents to build |
| Human resources | Literacy and the people side | Training plan and records per role; the rule on personal AI tools; the reskilling paths (chapter 5) | Own the inventory |
| IT and security | Access, logging, data location | Who can reach what; the logs that prove what an agent did; where data sits; the kill-switch | Choose use cases |
| Finance | Cost governance and evidence of return | Cost per agent, per work unit; the audit trail on spending caps; the numbers for the reviews | Approve risk tiers |
| Function heads | Each agent in their area | The CoS, the thresholds, the human on the loop, the monthly review | Sign for the company |
| Accountable person | The whole | The inventory, the risk decisions, the evidence file, the answer when someone asks | Delegate the three decisions |
The pattern to notice: every role delivers documents that already exist in a well-run project. The training plan from chapter 5, the CoS and thresholds from chapters 3 and 7, the cost per work unit from chapter 4. Compliance adds columns, not work.
What goes outside
Four external roles, each with a defined boundary.
The lawyer confirms the legal basis, the notices, the contracts and — where a law requires it — the impact assessment. Used at three moments: the inventory, every new high-risk agent, every new country. Not used to design agents or to decide risk tiers: that is your call on their advice.
The AI consultant designs the agents with the gates built in (next section), writes the technical and semantic CoS, prepares the documentation an inspector would read, and trains your supervisors. Chapter 8 told you how to choose one; the test here is question 9 of the first meeting — a consultant who treats compliance as "not a problem" is not qualified.
The auditor — internal or external — verifies, once or twice a year, that the evidence file matches reality: that the logs exist, the reviews happened, the training records are current. Not needed in year one for most SMEs; needed the moment a large customer, a bank or a regulator asks.
The certification body applies when you decide to certify against ISO/IEC 42001, the AI management-system standard. More than 350 organizations were certified worldwide by early 2026, including the major model providers; for an SME the standard is worth borrowing as a structure long before it is worth certifying. Certify when a market or a customer requires it, not before — but ask every supplier and consultant whether they are certified, because it is becoming a line item in procurement questionnaires.
Compliance inside the method: the gates in an agent's life
The costly way to do compliance is to check at the end. The cheap way is to place five gates inside the loop you already run — request, negotiation, execution, acceptance — so that each check happens once, at the moment the information exists, by the person who has it.
| Gate | When | Question answered | Who signs |
|---|---|---|---|
| 1. Classification | At the request, before design | Which risk tier? Which countries? Which data? Is it on the "never" list? | Accountable person, on legal advice |
| 2. Design | During negotiation of the CoS | Are transparency, human oversight, thresholds, logging and data location in the design? | Function head + consultant |
| 3. Pre-launch | Before the first live run | Notices in place, training recorded, contracts signed, assessment done where required, kill-switch tested | Legal + IT + HR |
| 4. Live review | Monthly, with the CoS review | Did the agent stay inside thresholds? Any breakdowns, complaints, near-misses? Logs intact? | Function head |
| 5. Change or retirement | When the model, data or scope changes; when the agent stops | Does the classification still hold? What is archived, for how long? | Accountable person |
Gate 1 is the one that saves money: an agent classified as high-risk before design costs a fraction of one reclassified after launch. Gate 4 is the one that keeps you honest: it is the same monthly review where you read the CoS, with three more questions. If your consultant's method does not show you these five gates on a page, ask why.
Example. A staffing agency with sixty employees wanted an agent to pre-screen applications. Gate 1 classified it as high-risk in the EU (employment decisions) and under the Korean and Brazilian regimes it also operated in. The design changed before a line was built: the agent would rank and summarize but never reject; every rejection stayed with a recruiter; candidates were told an AI had helped; the ranking logic was documented and tested for bias on a year of past data. Launch took six weeks longer than the "quick pilot" first proposed. When the first candidate asked how the decision had been made, the answer took ten minutes and one file. (Case anonymized.)
The evidence file: what you show when someone asks
Someone will ask — a customer's procurement team, a bank, a regulator, a candidate's lawyer, a journalist. The answer is a file, kept current by the accountable person, that anyone in the company can find in ten minutes. It contains, for the company: the inventory; the written lines (what we never do, what needs the CEO's sign-off); the training plan and records; the rule on personal tools; the contracts with AI suppliers and consultants. And, for each agent: its classification and the reasoning; the CoS and thresholds; the transparency notice used; the name of the human on the loop; the logs, or where they are; the monthly reviews; the assessments where a law required them; and the change history.
Every item in that list is produced by a gate or by a role in the tables above. The file is the by-product of the method, not an extra project. Where a country requires a specific document — a Korean self-assessment, a Brazilian impact assessment, a Californian notice — it is one more item in the same folder, produced at the same gate.
The CEO's checklist
Ten questions; if you can answer yes to all ten, you are ahead of most companies twice your size.
| # | Question | Yes / No |
|---|---|---|
| 1 | Do we have an inventory of every AI system, feature and tool in use, including the ones people adopted on their own? | |
| 2 | Have I written the lines: what we never do, and what needs my sign-off? | |
| 3 | Is one person accountable for AI, by name, with a mandate? | |
| 4 | Does every agent have a named human on the loop and written thresholds? | |
| 5 | Are people told when they are dealing with AI, and is AI-generated content labeled where the law requires it? | |
| 6 | Do we have training records per role, and a rule on personal tools? | |
| 7 | Do we know where each agent's data sits and who can see it, country by country? | |
| 8 | Do our contracts with AI suppliers and consultants contain the clauses below? | |
| 9 | Do the monthly reviews include the three compliance questions of gate 4? | |
| 10 | Could anyone in the company find the evidence file in ten minutes? |
Clauses to require from suppliers and consultants
Your contracts are where compliance becomes enforceable. Eight clauses cover most cases; your lawyer will adapt the wording.
| # | Clause | Why |
|---|---|---|
| 1 | Data processing agreement naming purposes, locations and sub-processors, and barring transfers to non-compliant systems | Every data-protection law; the basis of "follow the data" |
| 2 | No training on your data without written consent, and deletion on termination | Protects customers, employees and trade secrets |
| 3 | Provider attestation on training data, security, testing, labeling of outputs and the standards followed (ISO 42001, NIST) | Your evidence file depends on their evidence |
| 4 | Transparency and labeling support: the system exposes what you need to notify users and mark content | EU since August 2026, China, Korea, US states |
| 5 | Human-oversight and kill-switch: the ability to pause, override and stop any agent, and to reach a person at the supplier | Every framework; the Gulf central-bank guidance spells it out |
| 6 | Logs and audit access: complete records of what the agent did, retained for a defined period, available on request | Gate 4 and any inspection |
| 7 | Allocation of conformity responsibility: who does what when a law requires an assessment or a filing, and who pays | High-risk uses in the EU, Brazil, Korea |
| 8 | Change notification: advance notice of model, data or scope changes, with the right to re-test before they apply | Gate 5; models change under your feet |
For consultants, add the three from chapter 8's relationship pact: cost transparency per agent, ownership of the CoS register and the documentation, and the exit clause with full handover.
What to take away
Three decisions are yours: where the lines are, who answers, how much risk at what evidence. Everything else is delegated to four internal roles and four external ones, each with a boundary, and produced at five gates inside the loop you already run — so the evidence file writes itself. Start with the inventory, because you cannot govern what you have not counted; and put the eight clauses in every contract, because the law you answer for is only as strong as the paper your suppliers signed.
Your to-do list.
- Book one hour with your accountable person, legal, HR, IT and finance. Answer the ten questions in the room and write the "no" answers on the whiteboard: that is your compliance plan for the quarter.
- Run the inventory as a two-week amnesty, shadow AI included.
- Send the eight clauses to your lawyer and ask which are missing from current contracts.
Frequently asked questions
Who is actually responsible for AI governance in my company — me, IT, or legal?
You are. In every legal framework worldwide, the person who answers for how AI is used is the person who runs the company; the lawyer advises, the consultant builds, IT operates, and none of them signs. Three decisions cannot be delegated: where the lines are, who is accountable by name, and how much risk to accept at what evidence — everything else is execution and can be delegated.
What's a simple way to check if my company's AI governance is solid?
Run the ten-question checklist: do you have a full inventory including tools people adopted on their own, have you written the lines you will never cross, is one named person accountable, does every agent have a human on the loop, are customers told when they are dealing with AI, and could anyone in the company find the evidence file in ten minutes if someone asked. Answering yes to all ten puts you ahead of most companies twice your size.
What is 'shadow AI' and should I be worried about it?
It is the AI tools your employees adopted on their own — assistants, translators, generators nobody approved — and yes, it deserves attention: roughly three in four employees use AI tools regularly, and only about a third feel adequately trained. Run the discovery as a two-week amnesty with no consequences, not a hunt; you will learn more about your company in those two weeks than in a year of meetings.
What contract clauses should I require from AI suppliers or consultants?
Eight matter most: a data-processing agreement barring transfers to non-compliant systems, a no-training-on-your-data clause, a provider attestation on security and training data, transparency and labeling support, a human-oversight and kill-switch guarantee, complete audit logs, clear allocation of who handles required conformity assessments, and advance notice before any model or scope change.
Sources
- European Union, Regulation (EU) 2024/1689 — Artificial Intelligence Act, 2024.
- Cooley, EU AI Act: Transparency Obligations Take Effect 2 August 2026, August 2026.
- Scaffold Digital, UK AI Regulation in 2026: What's in Force, What's Coming, 2026.
- ISO, ISO/IEC 42001:2023 — AI management systems, 2023.
- AI Compliance Vendors, ISO 42001 Certified Companies: Verified Public List, 2026.
- NIST, AI Risk Management Framework, 2023-2024.
- Regulations.ai, Singapore: Model AI Governance Framework for Agentic AI, January 2026.
- The Middle East Insider, UAE AI Regulation 2026: Federal Framework Explained, April 2026.
- Legalithm, AI Regulation Compared: EU, US, UK, China, 2026.
- BCG, AI at Work 2025: Momentum Builds, but Gaps Remain, June 2025.
- Microsoft, 2026 Work Trend Index, May 2026.
Comments & reviews
No comments yet.
Log in to leave a comment or review.