The EU AI Act is often discussed as a legal project. Inside companies it is becoming an organisational-design project. Someone has to know which systems are being used, which obligations apply, how staff are prepared and how evidence moves between technical teams, legal functions and management.
The implementation timeline changed again in 2026, but the direction is clear: AI governance is becoming a continuing corporate capability rather than a one-time compliance exercise.
AI literacy makes governance distributed
The Commission says providers and deployers must take measures supporting AI literacy while taking account of staff knowledge, experience and the context in which systems are used. Enforcement of Article 4 began in August 2026.
That makes generic annual training an incomplete response. A developer, procurement manager and executive face different decisions and need different levels of understanding.
Central ownership still matters
Distributed literacy does not remove the need for central coordination. Companies need inventories, escalation paths and common evidence so that business units do not create incompatible approaches.
The governance function may sit in risk, legal, technology or a dedicated AI office. The title matters less than whether authority and information actually connect.
German companies should treat this as operating infrastructure
The opportunity is to build governance that improves decisions rather than merely producing documents. Good controls can make experimentation safer because teams know the boundaries within which they can move quickly.
Companies that wait for every implementation detail to settle risk discovering that the harder work was organisational all along.