AI governance when you have no bandwidth for it: Flick Fisher on the EU AI Act now in force
Everybody talks about AI governance. Flick Fisher's honest read is that most companies are scrambling for how to actually do it, and that for the ones still building basic privacy compliance, a sophisticated governance program is more than they can stomach.
Which makes the useful part of this episode the hygiene she would do instead.
Fisher is a partner in Fieldfisher's Privacy, Security and Information group and a returning guest. Her first appearance on the AI Act came the week the final text leaked. This one comes after it became law, with the first provisions in force.
What the Act does, briefly
It is the first comprehensive AI legislation implemented anywhere, aimed at ensuring AI systems are deployed transparently, safely and ethically, with a human-centric approach.
The mechanism is risk-based. Some AI systems are deemed intolerable and prohibited. Others are classified high risk and carry substantial requirements. Everything else gets transparency obligations, so people know when they are interacting with a chatbot. General purpose models, meaning the generative AI tools, are regulated separately.
Fisher's assessment of the wider effect: it prompted many other countries to look at their own AI regulation and take some inspiration, with Europe leading.
What is already prohibited
The first provisions in force cover AI literacy requirements and the outright prohibitions. Fisher's list is the practical one to audit against.
Systems deploying subliminal, manipulative or deceptive techniques to distort behavior with intent to cause significant harm.
Systems exploiting vulnerable people, including children and people with protected characteristics such as disabilities, where there is intent to cause harm.
Social scoring, where it is intended to cause significant harm or unjustified differential treatment. Her framing: extensive profiling of people to generate automated scores then used to treat them detrimentally will not be tolerated in Europe.
Predicting someone's risk of committing a criminal offense based solely on profiling or automated assessment of personality traits.
Scraping images at scale to build a facial recognition database.
And the one she flags as most relevant to ordinary companies: inferring the emotions of people in your workforce or in educational institutions. If you have video footage in a workplace and you are inferring whether people are angry or sad and using that to treat them differently, that is not allowed.
Plus biometric categorization to infer sensitive characteristics, and remote biometric identification in publicly accessible spaces for law enforcement.
Her instruction: check what you are doing against that list. The fines do not begin until later, but this is live law.
How it will actually be enforced
Michael's question is the right one, and Fisher's answer is realistic rather than dramatic.
The EU AI Office has been established and staffed to produce guidance and enforce the regulation. But she cannot imagine a regulator arriving unannounced to check whether you are running prohibited practices.
What she expects instead is complaints. A disgruntled employee who believes a tool has been used to treat them unfavorably, perhaps through emotion recognition or some scoring process. Or a consumer who believes a score built from unrelated data sets is denying them access to basic services.
Those complaints go to regulators, and investigations follow.
On whether the law has teeth: the fines mirror GDPR in scale, up to 35 million euros or 7% of global group turnover.
Can it keep pace
Michael raises the obvious tension. This is a prescriptive list of prohibitions written about a field that changes weekly.
Fisher's answer identifies the flexibility that was designed in. The high-risk list is explicitly non-exhaustive, and regulators reserve the ability to add systems to it. And much of what the law says has to be accompanied by codes of conduct and guidance from the AI Office, which is where the practical interpretation will live.
Her honest caveat: European legislation has a history of falling behind technology, because changing law takes a long time. What was attempted here is a framework approach that does not box itself into a particular sector.
Whether to launch in Europe at all
Michael notes that OpenAI and others routinely release features in the US and hold off in the EU, and asks whether US companies should copy that.
Fisher's answer depends on risk appetite and sector, with a clear warning attached.
Generative AI companies are a large target for regulators, partly because privacy activists, consumer groups and policy organizations are genuinely worried about real-world impacts and the use of personal data to train models, and partly because nobody fully understands the eventual effects.
So if you are bringing a model to market, expect regulatory questions about your privacy program and your privacy narrative. And be aware that regulators have already demonstrated the power to block a product from operating in Europe if they judge it was launched without regard for European privacy requirements.
Her live example is DeepSeek, where regulators across the bloc opened investigations and Italy went further, prohibiting the processing of Italian user information until privacy concerns were addressed.
What makes it interesting to her is the response. DeepSeek's position has been a jurisdictional argument that they are not established in Europe and are therefore not subject to GDPR. She expects that to be a genuine battleground.
The arms race problem
Asked whether companies are now designing with AI compliance in mind the way they eventually did with privacy, Fisher's answer is candid about the pressure everyone is under.
The world is watching an AI arms race. Investors demand product in market quickly and a return on very large investment. Against that, companies are moving fast and breaking things, and there is not necessarily the ability to have a complete compliance program in place or to consult regulators beforehand, which is what regulators would love.
Her practical assessment: you cannot get a product to market in Europe and keep it there without paying lawyers to fight regulators daily, unless you have had some regard for your privacy program.
The topics regulators care about most: whether you are transparent with users, whether you have thought about children and have age verification, and what data you are scraping to train models.
On that last one, she articulates both sides fairly. Companies feel that publicly available data should be usable for training. Regulators respond that people put information out without understanding it would train a model, and that they need transparency and choice.
Her example of what that costs: the Italian regulator's 15 million euro fine against OpenAI in December, substantially about training data transparency, which came with a requirement to run an expensive public campaign across media outlets and websites informing people what was being done with their data and what choices they had.
Michael's observation on the irony: OpenAI takes that fine, then points at DeepSeek for training on its output.
Regulating up while the US deregulates
Fisher notes the new US administration signaling deregulation, particularly around the executive order frameworks the previous administration established, including the NIST work that had become a de facto standard for developing AI tools and a procurement requirement for public sector buyers.
Her read on the consequence: as the US deregulates and Europe regulates, Europe may be pushed toward a stronger line, as a bulwark against what deregulated AI presents.
With the acknowledged cost. That could come at the expense of innovation, and both Europe and the UK are trying to find their footing between protecting human rights and wanting to be a center for AI. In the UK specifically, the government's stated ambition is to be an AI maker rather than an AI taker, with a focus on infrastructure, investment and talent.
The governance advice for a company with no bandwidth
This is the section to act on.
Fisher's starting point is that most sophisticated US companies already have some data governance program for privacy. The work is expanding it rather than reinventing it: adapting policies, risk assessments and notices to capture the new risks that come with integrating AI.
And the most basic step, which she stresses first: do you actually know what AI systems are in use across your organization?
That means a model inventory. What has been integrated, what is being developed, what is deployed. Understanding the supply chain behind it, the contracts signed, and what data you may be handing over when you integrate those systems.
Her warning about why this cannot wait is the recognizable one. It spins out of control quickly, because everybody is signing up to new AI features without thinking about what that means, both internally in HR tools and systems and in customer-facing features.
The three hygiene checks
For companies that cannot stand up a formal framework, Fisher names three things that matter regardless.
Know what the vendor will do with your data. When you sign with a vendor offering AI features to integrate into your own product, understand what data they want from you to train and improve their models. Because that reuse could put you in breach of commitments you have made to your own customers. If you are a processor with a new AI feature running on someone else's model underneath, make sure you are not handing over customer data for training without having established you have permission to do so.
Understand what testing was done and what the limitations are. You can take on liability in the middle for a feature without understanding where the flaws are and what disclaimers should accompany it when you put it into your own product.
Check the security. Not just to avoid a breach that would be embarrassing, but because you do not want your customers' or your own confidential information regurgitated by a model due to memorization.
Her summary: go in with a critical eye about how these tools process information, whether it will be secure, and whether the vendor will respect the usage rights they have contractually agreed to.
What actually worries her
Michael asks what freaks her out, and she gives two answers.
The first, from the privilege of seeing inside many companies, is the growing use of AI in HR and recruitment. Her framing is uncomfortable and correct: your next interview may not be with a human. Your next appraisal may be conducted by a bot. Next time you are fired, it may not be your manager who does it.
Michael's response is the right one: if you remove the human element from the actually human parts of a company, that becomes dangerous.
The second is personal rather than legal. The threat to information integrity, the risk of misinformation, and losing a shared source of truth, with consequences for society and democracy.
And underneath that, the erosion of critical thinking, because people are beginning to treat these tools as truthful and are not interrogating their output. Her position: what we have are tools, and they are not currently a replacement for the layer of critical thinking that matters.
Her analogy, offered with appropriate hedging: aircraft have long flown autonomously, and you still hope the pilot knows how to fly the plane.
The geopolitical layer
Michael's observation is that privacy debates used to be about how companies use information, and are now also about how countries do.
Fisher agrees that AI has become highly politicized, with a background fear threaded into every narrative: that using one model means one government gets your data, using another means a different one does.
From a European perspective, the structural issue is that the innovation is happening outside Europe, principally in Silicon Valley and now China. So European users' data leaves Europe and is processed in countries with different privacy regimes, and those concerns are heightening.
Michael's note on the opportunity: that creates room for European companies to build AI compliant with European standards, in a market large enough to make that worthwhile.
Where this goes
Asked for a five-year view, Fisher is appropriately careful.
Within five years all the provisions of the AI Act will have come into force on its staggered timetable, with high-risk requirements arriving next. So we will start to see how companies practically comply and whether changes are needed.
She does not expect another landmark European AI law, because the AI Office has an enormous amount of work simply implementing, enforcing and producing guidance for this one. The area she would watch is product liability, where existing regimes are being extended to cover defective AI systems.
What she thinks is more interesting is whether the Brussels effect materializes: whether other countries take inspiration from the Act. Some already are. The UK is taking a principles-based approach rather than equivalent legislation.
Her prediction: other countries may take a more pragmatic approach than the EU, out of concern for not stifling innovation in the way people fear the AI Act could in Europe.
The 5 things I took away from this conversation
1. Do the model inventory first. Before any framework, know what AI systems are actually in use across the company, what is being built, what has been integrated, and what data each arrangement hands over. Flick is right that this gets out of control fast, because everyone is accepting new AI features without registering what they signed up to.
2. Emotion inference in the workplace is now prohibited. This is the item on the banned list most likely to catch an ordinary company. If anything you run infers employees' emotional states and feeds that into how they are treated, that is not a compliance project, it is a stop.
3. Check what your vendor trains on before you resell their model. If you have added an AI feature running on somebody else's model, you may be passing your customers' data into training without the permission you promised them you would require. That is a contractual exposure to your own customers, not just a regulatory one.
4. Expect enforcement to arrive as a complaint. Not an audit. A disgruntled employee or a consumer who believes a score is being used against them. Which means the systems most likely to generate a complaint are the ones to review first.
5. Governance is an extension, not a rebuild. Most companies already have some data governance for privacy. Flick's advice is to widen the existing policies, risk assessments and notices to cover the new risks rather than starting a separate program nobody has the bandwidth to run.
FAQ
What is AI governance? The set of policies, inventories, risk assessments and controls an organization uses to manage how AI is developed and deployed. Fisher's practical version starts from extending existing data governance rather than building something separate, beginning with knowing which AI systems are actually in use.
Where do you start with AI governance if you have no dedicated resource? With a model inventory: what AI is integrated, being developed, or deployed, plus the supply chain and contracts behind each. Then three hygiene checks on any vendor: what data they use for training, what testing and limitations the model has, and whether their security is adequate.
What AI practices are prohibited under the EU AI Act? Manipulative or deceptive systems intended to cause significant harm, exploitation of vulnerable groups, social scoring used detrimentally, predicting criminality from profiling alone, untargeted scraping of facial images, emotion inference in workplaces and schools, and certain biometric categorization and identification.
Can regulators block an AI product from the European market? Yes, and they have. Fisher cites Italian regulators prohibiting the processing of Italian user data by DeepSeek pending resolution of privacy concerns, alongside investigations opened across the bloc.
How large are the penalties under the EU AI Act? Up to 35 million euros or 7% of global group turnover for the most serious breaches, with lower tiers below that, which mirrors the structure that made GDPR consequential.
Also mentioned
- Fieldfisher, and Flick Fisher's earlier appearances on GDPR and the AI Act
- The EU AI Act and the new EU AI Office
- The NIST AI Risk Management Framework, the de facto governance standard now in question
- The Italian regulator's actions against OpenAI and DeepSeek
- ISO frameworks, the other route more sophisticated companies are taking
- The UK's stated ambition to be an AI maker rather than an AI taker
Listen to the full episode
Flick Fisher on Between Two COO's
Between Two COO's is hosted by Michael Koenig. Subscribe on Apple Podcasts, Spotify, or wherever you listen.
The COO's Execution Playbook
Frameworks, templates, and hard-won lessons from operators who've been in the chair. Every Tuesday.
No spam. Unsubscribe anytime.