What the AI Act is about
The AI Act is the EU's first comprehensive AI regulation. At its core is a risk-based approach: AI applications are classified according to their risk. Some practices are banned, many applications are considered limited or minimal risk—and a significant share falls into the "high-risk" category. This is where the biggest obligations arise.
For high-risk systems, the AI Act requires, among other things, risk management, data governance, technical documentation, transparency, human oversight, and traceability. That sounds abstract—but in practice it means ongoing work that someone has to carry out.
Worth knowing: with the so-called Digital Omnibus, the deadlines for high-risk systems were adjusted in spring 2026. The core obligations now apply not from August 2026 but in stages—from December 2027 for standalone high-risk systems (Annex III) and from August 2028 for AI embedded as a safety component in regulated products (Annex I). What will take effect on 2 August 2026, however, are the transparency obligations and the first real fines. The later deadline sounds relaxed—but it isn't: anyone who waits to fill these roles until just before the deadline will be fishing in the same small talent pool as everyone else.
Why is this a people issue
A regulation can be read. But a classification can't be automated like a software update. Someone has to decide whether a given AI system is high-risk. Someone has to maintain the documentation, check data quality, ensure human oversight, and answer for it in an audit.
These tasks require a rare combination: a technical understanding of machine learning, plus regulatory knowledge, plus the ability to connect the two. Pure lawyers don't understand the models deeply enough. Pure ML engineers don't know the regulations. What's needed are bridge-builders.
The roles being sought right now
- AI and data governance leads, who define responsibilities, policies, and documentation standards for AI.
- ML Engineers who understand regulation and can translate compliance requirements into technical implementation.
- Compliance experts with real technical depth, who translate between law, risk, and development.
- Data quality and documentation specialists, who ensure traceability across the entire lifecycle.
These profiles are scarce today because they're new. The market hasn't trained them in sufficient numbers yet. Anyone who waits until the deadline bites will be searching in the same small talent pool as everyone else.
Maturity check: three questions
Before you post job openings, clarify three things. First: which AI systems do you actually use, and what risk class do they fall into? Second: who is responsible today — and is that responsibility documented? Third: Which competency are you missing internally to meet high-risk requirements?
The answers quickly show whether you need a permanent role, external support for a project, or a combination. Often, the first sensible step isn't a permanent hire but an experienced external person who assesses your AI landscape and cleanly defines the roles you need.
The AI Act forces no one to buy or use AI. But anyone who does use AI must have the right people to take responsibility for it. The tools are the easy part. The people who connect governance and tech are the real competitive advantage.

