INSIGHTS · AI GOVERNANCE

A simple way to gate AI use by risk

Leighton Wilson, Indura Labs
Reviewed 4 September 2026. Reflects the AI Act timeline as amended by Regulation (EU) 2026/1744, in force since 27 July 2026.

Not every AI use in your organisation needs the same level of scrutiny. Someone using a chatbot to draft an email is a very different risk to a tool helping decide who gets a loan. Most SMEs don't have a governance programme and don't need one to get this right. What you need is a quick way to sort what people are already doing into the right bucket, so you know where to spend attention, and a clear view of which of those buckets the law actually has something to say about.

First: what's actually in force

The EU AI Act applies to you as an organisation using AI, not just to the companies building models. Its timeline was amended in July 2026 and most published summaries are now wrong in one direction or the other, so it's worth being precise about what has already landed and what hasn't.

DateWhat appliesStatus
2 Feb 2025Prohibited practices, and the Article 4 duty to ensure staff have adequate AI literacyIn force
2 Aug 2025Obligations on general-purpose AI model providersIn force
2 Aug 2026Article 50 transparency: people must be told when they are interacting with an AI system, and synthetic content must be markedIn force
2 Dec 2026Article 50(2) marking extends to systems already deployed; further prohibited practices addedUpcoming
2 Dec 2027High-risk obligations for standalone Annex III systems, moved back from 2 Aug 2026Deferred
2 Aug 2028High-risk obligations for AI embedded in regulated products under Annex I, moved back from 2 Aug 2027Deferred

The deferral came through the Digital Omnibus on AI, Regulation (EU) 2026/1744, published on 24 July 2026 and in force from 27 July, six days before the original high-risk deadline would have bitten. It is enacted law rather than a proposal, so the December 2027 date is real.

The relief is narrower than the headlines suggest. What moved is the heavy conformity regime for high-risk systems. What did not move is the AI literacy duty, which has applied since February 2025, or the Article 50 transparency rules, which have applied since 2 August 2026. If you filed AI compliance under "2027 problem" in the summer, the two obligations most likely to touch an ordinary Swedish SME are both already live.

The four gates

This isn't a formal framework, it's a sorting exercise. Each AI use in your organisation sits at one of four gates, and the gate tells you how much scrutiny it needs, from "make sure people know the basics" to "this needs sign-off before it goes anywhere near production." Each gate below also names what the AI Act asks of it, so you can see where a legal obligation attaches and where the answer is just good practice.

GATE 1
Productivity
Individual use to save time: drafting, summarising, brainstorming. No sensitive data going in, and nothing downstream depends on the output being correct. Lightest touch: a short acceptable-use note (don't paste customer data in, check anything before it goes out the door) usually covers it.

Legal hook: Article 4. You are required to take measures to ensure the people operating AI on your behalf have a sufficient level of AI literacy, taking into account their role and context. This has applied since February 2025 and there is no size exemption. A recorded briefing and a one-page use note is a proportionate answer for most SMEs. Doing nothing is not.
GATE 2
Capability
AI built into a tool or workflow people rely on to do their job: a chatbot answering questions from your own documents, an assistant drafting first-pass reports. Needs a named owner, a basic sense of what data it touches, and some testing before it's trusted.

Legal hook: usually none directly under the AI Act, which is exactly why this gate is dangerous. Your obligations here come from elsewhere: GDPR if it touches personal data, and NIS2 supply-chain expectations if you are in scope or serve someone who is. Gate 2 is where governance is voluntary and the consequences are not.
GATE 3
Business-standard or regulated
Touches regulated data, or feeds a decision that affects a person or a compliance obligation: customer data, HR decisions, credit assessment, anything overlapping with NIS2, DORA or GDPR duties you already carry. Needs a real risk assessment and formal sign-off before it goes live, not just a heads-up to IT.

Legal hook: this is where Annex III high-risk classification starts to bite. Recruitment and employment tools, creditworthiness assessment, access to essential services and critical infrastructure management are named categories. Those obligations now apply from 2 December 2027, which is a working window rather than an exemption. If you have a Gate 3 use today, you are inside the runway.
GATE 4
External-facing
Anything a customer or the public interacts with directly: a support chatbot, a public-facing decisioning tool. Highest scrutiny, because reputational and regulatory exposure both apply, and it needs ongoing monitoring and an incident plan rather than one-time approval.

Legal hook: Article 50, in force since 2 August 2026. If a person is interacting with an AI system, they have to be told, unless it is obvious from context. Generated or manipulated content generally has to be marked as such, and from 2 December 2026 that marking requirement reaches systems that were already deployed. This is the one obligation on this page with a live deadline behind it and a public-facing surface where non-compliance is visible to anyone who looks.

Frameworks versus obligations

The gate structure is loosely anchored to NIST's AI Risk Management Framework, which is a useful way of organising the thinking. It is worth being clear about what that is and isn't: the NIST framework is voluntary, American in origin, and carries no legal force in Sweden. The EU AI Act is binding law. ISO/IEC 42001 sits between them as a certifiable management system standard that buyers increasingly ask about in procurement.

Use the framework for structure and the Act for obligations. Problems start when an organisation adopts a framework, produces a policy document, and believes it has addressed a legal requirement it has never actually read.

Where this usually breaks down

Most organisations don't fail because Gate 4 uses go unnoticed. Those tend to be visible, someone signed off on them, and there's a launch date attached. It's Gate 2 that quietly grows: an internal tool someone built to be helpful, which ends up handling more sensitive data than anyone intended, without ever being reclassified. Nobody made a decision to move it up a gate, because nobody was looking.

Two things prevent it, and neither is expensive. Give every Gate 2 use a named owner, so there is someone whose job it is to notice. And re-run the sort every few months rather than treating it as a one-off, because the sort has a shelf life measured in whatever your fastest-moving team can ship.

What the next sixteen months are actually for

The obvious reading of the deferral is that AI governance can wait until 2027. That is the reading most organisations have taken and it is a mistake, for a practical reason rather than a moral one.

The high-risk regime asks for risk management systems, technical documentation, logging, human oversight and conformity assessment. None of that can be assembled retrospectively in the month before a deadline, because most of it is evidence of how a system was built and operated over time. Logs you did not keep cannot be produced later. An organisation that starts in mid-2027 will be documenting a system it can no longer describe accurately.

The more useful framing is that the window exists to build and test, not to file. A governance model you have not stress-tested against a real system is a document, not a control. If you have a Gate 3 use, the highest-value thing to do before 2027 is to run it against adversarial cases, record what happened and fix what broke, because that record is most of what the conformity work will eventually ask you to produce.

This is a starting point, not a governance programme. If you want it built out for your actual AI use, mapped to what's live rather than a hypothetical, that's the kind of work I do.