Organisations deploying artificial intelligence face a growing operational hurdle as the European Union Artificial Intelligence Act takes effect: managing regulatory compliance while maintaining human oversight. According to Carina Zehetmaier, co-founder of the Vienna-based governance platform HUMABLY, many businesses purchase top-tier AI licenses without establishing internal controls, proper training, or clear lines of responsibility.
Bridging Governance, Compliance, and Enablement
HUMABLY was developed by Zehetmaier and co-founder Gabriele Bolek-Fügl to address the intersection of legal requirements and organizational workflow. The platform integrates three core pillars: governance, compliance, and enablement. The governance component establishes transparency regarding active AI applications, institutional responsibilities, and approval protocols. Meanwhile, the compliance framework evaluates and documents regulatory risks, and the enablement approach focuses on workforce training.
According to Zehetmaier, who previously helped initiate the Women in AI movement in Austria and contributed to European Union trust guidelines, organizations often treat AI adoption as a simple software rollout rather than a structural change. Standard corporate responses frequently involve basic text-based staff training detailing prohibited uses, while failing to address fundamental operational questions regarding organizational values, internal processes, and data oversight.
Managing High-Risk AI Cases and Standardisation
The platform addresses different tiers of tool usage through structured inquiry matrices. For standard operational software, such as generating marketing images via tools like Midjourney, approved usage rights can be logged centrally for cross-departmental visibility. For high-risk applications, the system requires more granular evaluation, incorporating dual-control approval processes and context-gathering AI assistants.
As the chair of the Austrian Standards working group for AI, Zehetmaier emphasizes that comprehensive compliance certification remains difficult while formal standards are still being developed. Citing the framework of ISO/IEC 42001—certification standards that HUMABLY itself has adopted—she notes that structured guidelines provide small and medium-sized enterprises (SMEs) with a clear roadmap similar to standard building regulations.
Stakeholder Integration and Corporate Oversight
Responsibility for artificial intelligence within corporate hierarchies remains fragmented. According to Zehetmaier, oversight duties are distributed across data protection officers, IT departments, legal teams, and newly formed AI offices. Effective deployment often requires cross-departmental coordination, including security teams and works councils, particularly when systems impact human workers.
Addressing concerns that European regulations risk stifling technological competitiveness, Zehetmaier argues that consistent regulatory frameworks offer legal certainty and long-term stability. Rather than viewing compliance as a barrier, structured guidelines help organizations align technology deployment with internal values and establish reliable operational standards across international markets.
Worth a look