Responsible AI Is Not a Project. It’s an Operating Model.

Most organisations treat responsible AI as an undertaking with a start, an end and a sign-off. At the end there is an audit, a certificate, a folder. None of that is wrong — it is simply incomplete. A certificate documents a date. An AI system operates in continuous time.

The project reflex, and where it comes from

The reflex is understandable. Organisations know how to run projects. There is a budget, a milestone plan, a sign-off, and afterwards a line in the status report that reads green. Regulation produces deadlines, and deadlines produce projects: gap analysis, remediation plan, implementation, closing documentation. The governance function ticks the box, the undertaking closes, the resources move on.

The project form is not the problem. A governance framework has to be built once, and project discipline is exactly the right instrument for that. The problem is the assumption buried in the sign-off: that something is now finished.

Because a project delivers a state. An AI system produces a trajectory. The entire governance question sits in the gap between those two things, and it cannot be closed by more diligence inside the project — only by something that continues after it.

The difference becomes visible at an unremarkable point. A model that shows stable outcomes across every tested group at acceptance testing is not thereby fair. It was fair — on that data, in that population, under those assumptions, at the moment of measurement. Shift the population, change an upstream data supplier, deploy the model into a new segment, or let the business team move a decision threshold, and the finding no longer holds. It has not been refuted. It has expired.

The deadline moved. The operation did not.

How little the project logic carries has been demonstrated this year in an unexpected way. The Digital Omnibus moved the central application dates of the EU AI Act: obligations for high-risk systems under Annex III now apply from 2 December 2027, those under Annex I from 2 August 2028.

For institutions that had hung their programme on a date, the justification disappeared with it. Undertakings were postponed, budgets pushed into the next planning year, working groups placed on hold. Institutions that had instead built an operating rhythm carry on unchanged — their rhythm was never attached to the deadline, but to systems that run regardless.

That is the actual news in the delay. It takes the pressure out of the topic and, in doing so, exposes the better question. Not will you be finished in time? but what will you be holding when the date arrives? An institution that can present two years of operating history — measurement series, documented deviations, traceable decisions — is having a different conversation from one presenting a freshly drafted declaration of conformity.

The regulation is written as an operation, not as a project

What makes this reading notable is that it is not an interpretation. The regulatory text anticipates it.

Article 9 of the AI Act describes risk management explicitly as a continuous, iterative process across the full lifecycle of a high-risk system, to be reviewed and updated regularly. Article 17 requires the provider to maintain a quality management system — a system, not a document. Article 26 obliges the deployer to monitor the operation of the system. Article 27 makes the fundamental rights impact assessment subject to updating as soon as any of its underlying elements ceases to be current. And Article 72 requires post-market monitoring that runs systematically and to a plan across the lifetime of the system.

ISO/IEC 42001:2023 makes the same assumption in the language of management systems: performance evaluation and improvement are not project phases there, but standing obligations.

None of these instruments recognises a state called finished. All of them recognise a state called current — and current is a state that can only be held by repetition.


What an operating model actually consists of

An operating model for responsible AI is less demanding than the term suggests. At its core it consists of five elements, none of which requires a parallel organisation.

A named responsibility inside the existing structure. Not another committee, but a person with a name who owns a specific system and whose ownership survives the closure of the implementation project. Committees advise; accountability always sits with a role.

A cadence — both scheduled and event-driven. The scheduled part is the easier one: quarterly, semi-annually, annually, depending on criticality. The event-driven part is the more effective one. It defines in advance which events trigger a review: a model change, a new or altered data supplier, extension into a new segment, a moved decision threshold, a cluster of complaints.

Reproducible evidence. A finding that cannot be reproduced is an opinion with a chart attached. Reproducibility means versioned data, versioned analysis code, documented thresholds, and a result that a third party can recompute six months later from the same state. This is the point at which internal audit and supervisors distinguish between a test and a presentation.

Thresholds and an escalation path, set in advance. Anyone who decides what counts as a deviation only once the event occurs is deciding under pressure — and as a rule, in favour of carrying on. The question at what point does a metric shift become reportable, to whom, and within what deadline belongs in quiet operations, not in the incident.

A closed loop. The finding has to be able to change something: retraining, a data correction, a tighter approval rule, in the limiting case a shutdown. Without that feedback, monitoring is an observation rather than a control — and any competent examiner notices the difference.

What an operating model is not

Three misunderstandings are worth stating explicitly, because they make the concept look more expensive than it is.

It does not mean doing everything continuously. Cadence is a decision with costs and should be made deliberately. A system making daily credit decisions warrants a different frequency from one supporting an annual segmentation exercise. The task is not to run everything at maximum frequency, but to give each application a defensible one.

Nor does it devalue audits and certificates. They keep their function — as measurement points within a running operation, not as a substitute for it. A B Corp recertification, an ISO 42001 certificate, an assurance report are informative precisely to the extent that a rhythm sits behind them for them to sample.

And it is not a tooling question. Tooling lowers the cost of repetition considerably, and without it an operating model usually becomes too expensive to sustain in practice. But tooling produces no accountability, no threshold and no escalation. Those three are organisational decisions.

Three audiences, one rhythm

The idea travels; its concrete shape does not. Over the coming weeks this theme will be worked out in three parallel strands, because the starting position differs sharply across three groups of readers.

Regulated financial institutions already have the rhythm. Model validation, annual review, drift monitoring, the use test, the requirements arising from MaRisk and DORA, and for significant institutions the ECB’s guide to internal models: the cadence exists, is documented and is examined. The AI Act’s obligations are largely extensions of that cadence rather than a second structure beside it. The notable exception is the fundamental rights impact assessment under Article 27 — the one artefact that cannot be derived from prudential validation. That is the subject of the next article.

Values-driven mid-sized companies: values that live only in a mission statement do not survive the first genuine trade-off. Since the CSRD thresholds were raised by Directive (EU) 2026/470, most companies of this size fall out of the reporting obligation — and with it, out of external compulsion. What remains are voluntary cycles: B Corp recertification, the Common Good Balance Sheet, DNK, and in future VSME. Voluntary cycles are still cycles. They have a cadence, and that cadence is the natural anchor for AI governance.

Non-EU vendors with European market access: conformity is not a stamp you acquire but a state you hold. Market access resting on a single point-in-time demonstration is borrowed — it ends with the first product change nobody carried through regulatorily. Durable market access is therefore itself an operating model.

The entry point is smaller than the ambition

Anyone who derives a programme from this diagnosis has missed the point — that simply produces another project, only a larger one. The defensible entry point is considerably narrower: one system that already matters, and four questions about it.

Who notices when this system’s behaviour changes? What exactly does that person notice it by? At what point does a change become a deviation? And who is told, within what deadline, with what consequence?

Anyone who can answer those four questions for one system has an operating model — small, but real. Anyone who cannot answer them for any system has a project. The difference does not show on the day of sign-off. It shows two years later, when somebody asks how the system has behaved in the meantime.

So the honest question back to you: if the behaviour of your most consequential AI-supported decision system shifted tomorrow, who would find out, and after how many weeks?

Similar Posts