On 21 January 2026, the European Data Protection Board (EDPB) and the European Data Protection Supervisor (EDPS) published a joint opinion on the Digital Omnibus on AI, the proposal to simplify the implementation of the AI Act. Both regulators support the aim of reducing administrative burden, but attach a clear condition to it: the simplification must not hollow out governance responsibility. According to the joint opinion, removing the obligation to include certain AI systems in a public register would substantially undermine accountability.
The objection is sharply formulated. When providers are allowed to classify their own systems as 'not high-risk' and can thereby avoid registration obligations, the EDPB and EDPS argue that an incentive arises to wrongly claim exemptions. In addition, the regulators emphasise that data protection authorities must remain structurally involved in overseeing AI applications that process personal data. The debate is therefore not about a technical detail, but about a governance question: who is accountable for what, and which registrations safeguard that?
From ethical principles to concrete governance obligations
The European debate does not stand alone. The OECD's Recommendation of the Council on Artificial Intelligence has long placed emphasis on governance mechanisms: a whole-of-government approach, clear objectives, oversight, traceability and open registers of government algorithms. The starting point is that those who build, procure or use algorithms must ultimately be accountable for the effects on citizens.
An implementation guide based on the OECD's Governing with Artificial Intelligence, published on aigovernance.com, translates this into concrete actions for governments. The most important: assign a named responsible official for every AI-supported decision chain, carry out a documented risk analysis for each public AI deployment, publish transparency mechanisms and a public register of AI applications, and monitor over-reliance on AI output in high-impact contexts such as benefit decisions and permit granting.
This makes the core clear: governance responsibility does not mean 'we have ethical principles', but 'we can identify per process who is ultimately responsible, which risk analysis was carried out and how that can be checked'.
Practice lags behind
There is a gap between this design and day-to-day practice. An overview on voxbooster.com brings together recent signals about AI use in the public sector and states that the adoption of generative AI by civil servants often moves faster than the establishment of formal governance. Notably, AI is relatively rarely deployed in functions where accountability is precisely central, while regulators warn of a growing gap between decentralised experiments and central steering and accountability.
How that gap can concretely go off the rails is illustrated by a July 2026 governance commentary on agentic AI authorization failures. A commentary on lozenadvisory.com describes how an autonomously operating AI agent gained access to a partner's production infrastructure. The author explicitly treats this not as merely a security incident, but as a board-accountability problem: who authorised the access, who could assess the risk in advance, who was empowered to limit it and who now bears the financial and legal consequences? The recommendation is to bring risky AI experiments explicitly under board and CFO oversight.
What this demands of boards and management
The common thread through all these developments is that AI governance is shifting towards the level of explicit, traceable responsibility. For boards of directors, executive teams and public administrators working with sensitive or high-trust information, that means concretely: being able to identify per AI workflow who is liable for which outcomes, which registrations and risk analyses have been set up, which transparency mechanisms exist and how deviations and incidents are handled.
That requires visibility. Governance decisions that exist only on paper do not hold up when a regulator or internal audit wants to know who authorised which decision. The incident around agentic AI in particular underlines the need for traceable decision and authorisation paths.
At this point, a verification layer such as IamVera.ai comes into view. Vera does not itself make policy and is not a chatbot or its own language model; it is a verification layer for professionals working with confidential information. Vera can route a task through selected independent AI models and make the verification steps, corrections, mutual differences and sources visible for inspection. That supports review, but does not guarantee outcomes.
For sensitive documents, the Semantic Privacy Shield is relevant: sensitive values can be replaced on EU infrastructure with synthetic, session-only equivalents before any processing takes place. The workflow is designed to send only anonymised content to the selected models, and works fail-closed: if the privacy check fails, the document is not sent onward. Within that verifiable set-up, a console can help make visible which AI systems are running, which responsible owner is attached to them and which decisions and authorisations have been taken.
The core remains: a verification console can make governance agreements visible and testable, but does not take over the governance choice. The professional final judgement and the liability remain with the organisation and the people who deploy the AI. That is precisely what the EDPB, EDPS and OECD are calling for in 2026: not less responsibility, but more identifiable responsibility.