BICG 2026: AI risk through the board's eyes

BICG 2026: AI risk through the board's eyes

Slides, sources and tools from the talk on 09/09/2026. Not a study.

On the morning of 09/09/2026 I spoke at the BICG members' breakfast in Vilnius. The room was board members and executives, and the talk covered three things: what already applies under the AI Act, which AI risks are already inside the company, and what a board can do this month. This page is for the people who were in the room and want the slides, the sources and the printed handout in one place.

The law gave you fifteen months. The risks did not. The board's work starts now.

Date
09/09/2026
Venue
BICG members' breakfast, Vilnius
Length
30 min plus 15 min of questions
Slides
27, in Lithuanian
What was checked
Every number on a slide has a row in the sources table below. Last checked 08/09/2026.

Slides

  1. Slide 1: AI risk through the board's eyes
    1 / 27 AI risk through the board's eyes
  2. Slide 2: What applies now, what is delayed, what arrives in 2027
    2 / 27 What applies now, what is delayed, what arrives in 2027
  3. Slide 3: 15 million EUR or 3% of global annual turnover
    3 / 27 15 million EUR or 3% of global annual turnover
  4. Slide 4: The first consequences will not come from the regulator
    4 / 27 The first consequences will not come from the regulator
  5. Slide 5: AI in recruitment: allowed, on two conditions
    5 / 27 AI in recruitment: allowed, on two conditions
  6. Slide 6: The accidental provider
    6 / 27 The accidental provider
  7. Slide 7: When to label: four everyday cases
    7 / 27 When to label: four everyday cases
  8. Slide 8: 80% of boards have no process to check their own AI use
    8 / 27 80% of boards have no process to check their own AI use
  9. Slide 9: The line that appeared without your decision
    9 / 27 The line that appeared without your decision
  10. Slide 10: On the website, on the phone, in the inbox
    10 / 27 On the website, on the phone, in the inbox
  11. Slide 11: Permissions, documents, training data
    11 / 27 Permissions, documents, training data
  12. Slide 12: Two in three used AI tools believing the policy forbade it
    12 / 27 Two in three used AI tools believing the policy forbade it
  13. Slide 13: An agent deleted a live database
    13 / 27 An agent deleted a live database
  14. Slide 14: An agent is already switched on in your hosting account
    14 / 27 An agent is already switched on in your hosting account
  15. Slide 15: The same permission decision is already on your computer
    15 / 27 The same permission decision is already on your computer
  16. Slide 16: 26,000 families, more than 2,000 children, one government
    16 / 27 26,000 families, more than 2,000 children, one government
  17. Slide 17: 25.6 million USD, 15 transfers, one video call
    17 / 27 25.6 million USD, 15 transfers, one video call
  18. Slide 18: Manager's tools built with AI in one evening
    18 / 27 Manager's tools built with AI in one evening
  19. Slide 19: Team and sales systems with nothing purchased
    19 / 27 Team and sales systems with nothing purchased
  20. Slide 20: Readers picked the AI-written text as the most human
    20 / 27 Readers picked the AI-written text as the most human
  21. Slide 21: Watermarks in text: a promise, not a standard
    21 / 27 Watermarks in text: a promise, not a standard
  22. Slide 22: 66% of boards have little or no AI experience
    22 / 27 66% of boards have little or no AI experience
  23. Slide 23: Who is responsible for what
    23 / 27 Who is responsible for what
  24. Slide 24: Does a company need a chief AI officer? A mid-size one does not.
    24 / 27 Does a company need a chief AI officer? A mid-size one does not.
  25. Slide 25: ISO/IEC 42001 certifies the process, not the safety
    25 / 27 ISO/IEC 42001 certifies the process, not the safety
  26. Slide 26: Three things a board can do this month
    26 / 27 Three things a board can do this month
  27. Slide 27: Where to find me
    27 / 27 Where to find me

Download the slides (PDF, 2.3 MB), slides in Lithuanian

Three things a board can do this month

  1. A one-page list of which AI tools the company already uses, including the ones employees picked up themselves. The policy comes after that.
  2. Two sentences on confirming money transfers through a second channel. No exceptions for urgency.
  3. One name against AI, in writing, and one line in the terms of reference of the audit or risk committee.

The deadline moved. The risks did not.

Ten questions for management

The same text that was on the printed handout. One line under each question on what a good answer sounds like.

  1. Do we have a list of every AI tool the company uses, including the ones employees picked up themselves?
    A good answer shows a table rather than telling a story. A bad answer starts with the words “broadly speaking”.
  2. Who exactly, by name, answers for AI risk, the way someone answers for financial risk?
    A good answer names one person and one committee, and it is written into the committee's terms of reference.
  3. What is our AI risk appetite, and did the board actually set it, or did it simply happen?
    A good answer points at the minutes of a meeting. If the appetite is written down nowhere, it does not exist.
  4. Where does AI take part in a decision that touches a customer or an employee, and who is the responsible human there?
    A good answer names a person who can stop the system and who will face nothing for doing it.
  5. Could we trace one specific AI decision back to a human decision?
    A good answer: yes, and here is the log. If we cannot trace it, the system should not be running.
  6. What have we said publicly about our use of AI to customers, investors or the market, and can we back up every one of those words?
    A good answer: the marketing text and the real product match. The gap between them is already punished in the US.
  7. Which data is forbidden in AI tools, and how do we know that rule is kept?
    A good answer rests on measurement rather than on policy: logs, blocking, checks.
  8. What rights do our AI agents have in production systems, and who approves a destructive action?
    A good answer: the default right is read only, writing needs a human approval.
  9. How do we verify that a request to move money really comes from the person we can see and hear?
    A good answer: there is a second, independent channel, and it is mandatory above a set amount.
  10. Does the board itself understand AI well enough to ask the second question after the first one, and when are we fixing that?
    A good answer has a date. A bad answer is “we trust management”.

A minimal AI policy, one page

  1. Scope. Who it applies to (every employee and contractor) and what counts as an AI tool in this policy.
  2. Allowed tools. A short list by name. Anything not on the list is agreed before it is used.
  3. Forbidden data. Personal data of customers and employees, financial records, credentials, unreleased commercial information. A simple test: if you would not email it to a stranger, do not paste it into a chatbot.
  4. Human review. Any AI output going to a customer, into finance, into legal or into a people decision is reviewed by a named person. AI does not sign off its own work.
  5. Disclosure. Where AI substantially shapes a product, a decision or a conversation, that is said in plain words.
  6. Logs. Write down which tool was used for what, and keep it somewhere findable.
  7. Incidents. One channel and one name for the report “AI got it wrong, leaked something or made a bad decision”.
  8. Owner. One person or role accountable for the content of this policy and for it being followed.
  9. Review. At least once a year. That is the floor, not the goal.

Who is accountable for AI

  1. A mid-size Lithuanian company does not need a separate chief AI officer role. It needs a written decision on which of the existing executives owns AI: usually the IT lead, the risk lead or the lawyer.
  2. Oversight is attached to the audit or risk committee and written into its terms of reference. If the board has a technology committee, that one takes architecture, vendor dependency and opportunity, and the audit committee takes control and assurance.
  3. The work is cross-functional (legal, IT, people, compliance), but the accountability is single and has a name. “Everyone is accountable” means nobody is.

Tools for the board

This list is for a board that wants to review and monitor the risks from the talk, and it leans towards what a 50 to 500 person Lithuanian or Baltic company can actually put in place.

Where to start

  1. AI Act implementation timeline. One page that settles the argument about dates: transparency and enforcement since 02/08/2026, Annex III high-risk AI systems from 02/12/2027. Free. Fits any company.
  2. VDAI FAQ “where to start”. The Lithuanian-language questionnaire behind the one-page inventory: who provides the system, what data it touches, whether personal data is involved. Free. Fits any Lithuanian company.
  3. The NCSC second-channel rule and the FBI IC3 code-word advice. The two sentences of the payment rule are already written; the company only has to adopt them. Free. Fits the finance team.
  4. The admin report you already pay for: the Google Workspace third-party app report or Microsoft Defender for Cloud Apps shadow IT discovery. Turns “we think we have about ten tools” into a list. Free (with an existing licence). Fits a company already on one of those suites.
  5. Nudge Security free shadow AI inventory. A read-only connection to the mail system, five minutes, an inventory on day one including accounts created years ago. Freemium. Fits a 50 to 300 person company with no security team.
  6. NIST AI RMF and its Playbook. Where the named owner and the committee charter line come from, plus a free Excel to start the risk register. Free. Fits any company.
  7. The Future of Life Institute EU AI Act compliance checker or the Commission's own checker in the Service Desk. Answers “are we high-risk” in about ten minutes. Free, and explicitly not legal advice. Fits any company.
  8. The Article 50 guidelines and Content Credentials. The labelling duty and the standard that carries it. Free. Fits marketing and communications.
  9. AI Incident Database and OECD AIM. Fifteen minutes before a risk committee meeting, filtered to your own sector. Free. Fits the risk committee.
  10. The Lithuanian escalation path: RRT operator guidance and the AI regulatory sandbox. Who supervises, and the free sandbox an SME can apply to. Free. Fits Lithuanian SMEs.

Deliberately not in this shortlist: the AI governance platforms and ISO/IEC 42001 certification. They are the right answer for a company whose customers demand certification, and an expensive distraction for everyone else this year.

Frameworks and checklists

ToolForPriceNote
EU AI Act Service Deskany company looking for an official answerfreeThe answers are guidance, not a binding legal opinion.
AI Act implementation timelinea board arguing about datesfree02/12/2027 is the post-Omnibus date. Older decks and articles still print 02/08/2026.
Regulation (EU) 2024/1689 on EUR-Lexa lawyer or a compliance leadfreeRead the consolidated version: the original 2024 text no longer matches the current dates.
Commission guidelines on classifying high-risk AI systemsa company working out its own risk categoryfreeStill in draft and not binding, but it shows how the Commission intends to read the rules.
Commission guidelines on the Article 50 transparency obligations, C(2026) 5054marketing, communications and the product teamfree51 pages of heavy reading. For a board the summary plus the deployer obligations is enough.
Code of Practice on transparency of AI-generated contenta company that generates or publishes AI contentfreeThe code is voluntary. Take the “about 190” figure from this page itself.
Enforcement framework of the AI Acta board asking about finesfreeNational penalty regimes sit on top of this. In Lithuania the address is RRT.
NIST AI Risk Management Framework 1.0 and the Generative AI Profilea risk committee that lacks shared vocabularyfreeAmerican, and written for practitioners rather than directors. The board value is the Govern function.
NIST AI RMF Playbookwhoever is starting the risk registerfreeNIST itself says it is neither a checklist nor a set of steps. It needs trimming before a 50-person company can use it.
ISO/IEC 42001:2023, AI management systema company whose customers already ask about certificationpaidThe standard costs CHF 225 and certification costs a great deal more. For most Baltic companies this is a decision for later.
OECD AI Policy Observatorywhoever follows policy and incidentsfreePolicy-oriented. Useful to a board mostly through the incidents monitor.
ICO AI and data protection risk toolkita data protection officerfreeThe page says the guidance is under review after the UK Data (Use and Access) Act, and it is UK rather than EU GDPR. The structure transfers, the legal references do not.
CNIL self-assessment guide for AI systemsa team scoring one AI system against the GDPRfreeThe English version is a courtesy translation; the French one prevails.
Deloitte, “Governance of AI: A critical imperative for today's boards”a board comparing itself with othersfreeSurvey data, self-reported, global rather than European. Good for one slide, not for a claim about Lithuania.
NACD AI governance resourcesa director looking for a list of questionsfreemiumMuch of it is member-only and the legal framing is American. Borrow the questions, not the legal framing.
IoD New Zealand, “AI in the boardroom: a guide for directors”a director who wants a short guidefreeNew Zealand company law. The transferable part is that a director's duty of care is personal and non-delegable.
RRT, information for AI operatorsany Lithuanian companyfreeNo dedicated FAQ or deadline list on that page. General contact: rrt@rrt.lt, +370 800 20030.
VDAI FAQ “You want to start using an AI system: where to start?”a company starting its AI inventoryfreeIt covers the GDPR, not the AI Act.
Lithuanian AI regulatory sandboxa Lithuanian SME building or deploying AIfreePlaces are selected, not open to everyone. A board can ask management whether the company applied.
Inovacijų agentūra, AI news and callsa company looking for funding and national guidelinesfreePublication dates are not shown on the tag page, so cite individual articles rather than the index.

AI inventory and shadow AI

ToolForPriceNote
Nudge Securitya 50 to 300 person company with no security teamfreemiumPricing is not published and neither is the trial length. It finds only what a provider emailed to a company address, so an account created with a personal mailbox stays invisible.
Microsoft Purview, DSPM for AIa company on Microsoft 365 E5-class licensingpaidThis is the enterprise-stack answer: it assumes Purview licensing, onboarded endpoints and someone to run it.
Microsoft Defender for Cloud Apps, shadow IT discoverya company with Microsoft security licensingpaidBy default it cannot discover apps that are not in its catalogue.
Cloudflare, shadow IT and AI discoverya company with Cloudflare Zero Trust or SASEpaidNo free plan is mentioned for this use case, and it presumes Cloudflare already sits in front of employee traffic.
Google Workspace, security report on third-party connected appsany company on Workspacefree (with an existing licence)It counts OAuth grants, so it catches a tool that connected to Drive or Gmail and misses one an employee simply pastes text into.
NIST AI RMF Playbook ir VDAI FAQa company that will not buy anything this quarterfreeA questionnaire only finds what people admit to. Pair it with the admin report the company already pays for.

AI governance platforms

ToolForPriceNote
Credo AIlarge organisationspaidPricing is not public; it is sold through a conversation with a sales expert.
Holistic AIlarge organisationspaidNo pricing is shown.
OneTrust AI Governancea company already using the OneTrust privacy platformpaidPricing requires a sales conversation.
IBM watsonx.governancelarge organisationspaidThere is a free 14-day trial, but no per-unit prices appear on the page.
Vanta, ISO 42001an SME already doing SOC 2 or ISO 27001paidIt aims at certification rather than at governing AI risk in general. Pricing is behind a demo request.
Drata, ISO 42001a company that already runs an ISO 27001 programmepaidIt cross-maps ISO 42001 controls into an existing ISO 27001 programme. Pricing is also not public.
Trustibleregulated enterprisespaidPricing is behind a demo request.

Incident registers

ToolForPriceNote
AI Incident Databasea risk committee before a meetingfreeIncidents are press-sourced, so severity and verification vary.
OECD AI Incidents Monitor (AIM)finding examples from your own sectorfreeIt counts media reports, not confirmed incidents. Useful for direction of travel, not for a statistic on a slide.
AIAAIC repositorylooking up an individual casefreeAn honest limit: the pages do not state who maintains it, the entry count or the licence. Cite individual cases, not the repository itself.
Enforcement framework of the AI Acta board asking who can fine whom, and how muchfreeThis is a framework page, not a tracker. There is no official EU register of AI Act enforcement actions yet.

Deepfakes and payment confirmation

ToolForPriceNote
UK NCSC, “Phishing attacks: defending your organisation”the finance and admin teamfreeWritten before the deepfake wave, so it says nothing about voice. The rule survives anyway: a call is not a second channel if the attacker chose it.
FBI IC3 public service announcement on impersonation of senior officialsa CFO and a treasurerfreeWritten for individuals and officials rather than finance teams. The transferable parts are the code word and calling back on a number you found yourself.
NSA, FBI and CISA, “Contextualizing Deepfake Threats to Organizations”a security or risk leadfreeThe CISA page is marked as archived content and the PDF itself refused an automated fetch. Open it by hand before quoting from it.
NKSC recommendations librarya Lithuanian company writing its own rulesfreeThere is no dedicated NKSC deepfake document in that list. These are email security and social engineering recommendations.
Reality Defenderbanks and contact centresfreemiumThe site publishes no accuracy figures at all. Detection is a signal, never the control. The control is the callback.
Hive, AI-generated and deepfake content detectionplatforms and media companiespaidThe accuracy claim is the vendor's own summary of a study, and text detection is not offered.

Content labelling and provenance

ToolForPriceNote
C2PA and Content Credentialsmarketing and the content teamfreeCredentials survive only if every tool in the chain preserves them. A screenshot, a re-upload or a careless CMS strips them.
Commission guidelines on Article 50, C(2026) 5054whoever decides what gets labelledfreeThe retroactivity rule matters for marketing. Confirm it in the PDF before relying on it.
Code of Practice on transparency of AI-generated contenta company publishing AI contentfreeThe voluntary route to showing Article 50 compliance. It has a separate section for deployers.
Anthropic, “How Claude's text watermarking works”anyone using AI-written textfreeThis is one provider. Do not generalise it to all AI text.
OpenAI, “New AI classifier for indicating AI-written text”a board being sold an AI-text detectorfreeOpenAI itself withdrew the classifier on 20/07/2023 for low accuracy: it identified 26% of AI-written text and labelled 9% of human writing as AI.
Liang et al., “GPT detectors are biased against non-native English writers”a company where English is written by non-native speakersfree2023 models and 2023 detectors. The direction of the finding has not been overturned, and no detector vendor has published evidence that it has.
Dutch Algorithm Registeranyone who wants to see a public inventoryfreeIt is a government transparency register, not a template. Its value is as the picture of what a one-page inventory could grow into.

Agent permissions

ToolForPriceNote
Anthropic, Claude Code security and permission modela company running coding or agentic toolsfreeThis documents one product. For a board the point is the shape of the question: what may the agent write to, who approves it, and where is the log.
Microsoft 365 Copilot setup and admin controlsa company on Microsoft 365paidThe oversharing work is the real project, and it is bigger than the Copilot rollout itself.
Google Workspace, Gemini admin controlsany company on Workspacefree (with an existing licence)The training commitment is about Workspace content. It says nothing about what an employee pastes into a consumer Gemini account in a browser.
OpenAI, enterprise privacy and data controlsa company using ChatGPT Business or Enterprisepaid“By default” and “opt-in” are doing real work in that sentence. The board question is whether anyone opted in, and on consumer accounts the answer is different again.
Anthropic, API data retention and traininga company using Claude via the APIfreeFor paid API customers there is no ad hoc deletion. Check that against your own GDPR commitments.
GitHub Copilot organisation policiesa company with in-house developmentpaidThe public-code-matching filter and the retention settings are not on this page; they live on adjacent ones.

List checked on 10/09/2026; tools change and links go stale.

Sources by slide

Every number on a slide has a row here. The slide number is a link to the slide itself.

SlideClaimSourceCheckedConfidence
2 What applies nowRegulation (EU) 2026/1744 adopted 08/07/2026, in force from 27/07/2026; the high-risk package from 02/12/2027; embedded AI 02/08/2028; prohibited practices and AI literacy from 02/02/2025; transparency from 02/08/2026EUR-Lex, Reglamentas (ES) 2026/1744 (Digital Omnibus)05/09/2026High
2 What applies nowDefinitions of deployer and provider; the Annex III areasDI aktas, Reglamentas (ES) 2024/1689, 3 str., III priedas05/09/2026High
3 Fines15 million EUR or 3%; 35 million EUR or 7%; 7.5 million EUR or 1%High. The AI literacy duty (Article 4) is not on the list of finable breachesDI aktas, 99 str. 3-5 d.05/09/2026High
4 My assessmentThe headline “breaches may end in more than fines”Headline. The four lines on the slide are the author's own assessmentVerslo žinios, 03/08/2026 (tik antraštė, straipsnis mokamas)23/08/2026Headline
5 AI in recruitmentMobley v. Workday (US), case pending; on 22/06/2026 the court let part of the claims standHigh on the status; say “pending”Duane Morris apžvalga, 24/06/2026; CourtListener byla 3:23-cv-0077008/09/2026High
5 AI in recruitmentEmotion recognition in the workplace prohibited from 02/02/2025DI aktas, 5 str. 1 d. f p.05/09/2026High
6 The accidental providerA deployer becomes a provider under Article 25(1)DI aktas, 25 str. 1 d.05/09/2026High
6 The accidental providerIn an Irish survey 25% of companies did not know whether they were providers or deployersMedium. A single country business survey, quoted only with that namedArthur Cox apklausa, Airija, per mondaq.com29/08/2026Medium
7 When to labelThe Article 50 labelling duties; the rule for agentsDI aktas, 50 str.; Europos Komisijos gairės C(2026) 5054, 20/07/202605/09/2026High
7 When to labelRRT guidance 19/08/2026: deepfakes and public AI text that no human reviewed are labelled; prevention and advice firstRyšių reguliavimo tarnyba29/08/2026High
8 The blind spot80% of boards have no process to check their own AI useMedium. A UK members' survey, 2022Institute of Directors, „AI in the Boardroom: the essential questions for your next board meeting“, 2023, aut. Pauline Norstrom; IoD narių apklausa 202205/09/2026Medium
9 How AI enters a companyIn 2025, 21.3% of Lithuanian companies (10+ employees) used AI, in 2024 it was 8.8%; the EU average is 20%High, checked through the APIEurostat, duomenų rinkinys isoc_eb_ai29/08/2026High
9 How AI enters a companyFrom 02/08/2026 a chatbot has to say what it isDI aktas, 50 str. 1 d.05/09/2026High
10 ExamplesScreenshots: an AI assistant in an online shop; a search for “ChatGPT” in the App Store; an AI mail assistantIllustration, not a study. The mail window is blacked out in the public versionAutoriaus ekrano nuotraukos, 09/202608/09/2026Illustration
11 ExamplesAdd-in permissions (Microsoft Entra); one real receipt and three generated by AI; the ChatGPT setting “Improve the model for everyone”Autoriaus ekrano nuotraukos, 09/202608/09/2026Illustration
12 Shadow AI66% used AI tools believing the policy forbade it; 88% of them shared work information (43% emails, 34% customer data, 31% financial documents)High on the source; not Lithuanian dataPagerDuty ir Wakefield Research, 1 250 biuro darbuotojų, JAV, JK, Australija, Japonija, apklausa 09-20/04/2026, paskelbta 11/06/202605/09/2026High
13 Operational riskOn 18/07/2025 a Replit agent deleted a live database holding 1,200+ executive records, then fabricated dataAI Incident Database, incidentas 115205/09/2026High
14 AgentsAI agents switched on for free inside a Hostinger hosting account (OpenClaw, Hermes Agent, n8n)Autoriaus ekrano nuotraukos, 09/202608/09/2026Illustration
15 On your own computerPermissions for add-ins, browser agents and appsStatement, not a numberAutoriaus tekstasStatement
16 Legal riskAbout 26,000 families; more than 2,000 children (CBS 2022: 2,090); the government resigned on 15/01/2021; a self-learning risk algorithm (AP fine of 2.75 million EUR)High. Do not use 3,532: that is the Museum of Failure figureWikipedia; CBS (Nyderlandų statistika) 2022; Autoriteit Persoonsgegevens, 202108/09/2026High
17 Cyber security riskArup: 25.6 million USD (200 million HKD), 15 transfers, one video call, 01/2024CNN, 16/05/202405/09/2026High
17 Cyber security riskFerrari 2024: the attack stopped by a question about a recently recommended bookMIT Sloan Management Review05/09/2026High
17 Cyber security riskLithuania, 06/2025: a deepfake campaign imitating Lithuanian TV newsLRT English05/09/2026High
18 You become a providerComms Center and Executive Operating Dashboard, the author's own local appsIllustration, the data is inventedAutoriaus programos, demonstraciniai duomenys08/09/2026Illustration
19 You become a providerA team system and a sales CRM with an AI assistantAutoriaus programos, demonstraciniai duomenys08/09/2026Illustration
20 Reputational riskReaders picked the AI-written text as the most human, 04/12/2024The author's own experiment; the number of participants is not on the slidetv3.lt, 04/12/2024; bernardinai.lt, 06/12/202423/08/2026
21 Reputational riskAnthropic text watermarks under the Article 50(2) code of practice of the AI Act, from 02/08/2026High on the fact; one vendor's decision onlyForbes, 13/08/2026; The New Stack08/09/2026High
22 The board's side66% (79% a year earlier); 31% (45% a year earlier); 5%Deloitte, „Governance of AI: a critical imperative for today's boards“, 2 leid., 695 direktorių, 56 šalys, 01-02/202505/09/2026High
23 Who answers for what11% → 40% of companies assigned AI oversight to a board committee within a year, most often auditMedium. US disclosure dataHarvard Law School Forum on Corporate Governance, 28/10/202505/09/2026Medium
24 A chief AI officer roleIBM survey: 76% have such a role, across 2,000+ large, mostly US organisationsMedium. Only with the sample namedCIO.com apie IBM apklausą, 202605/09/2026Medium
25 ISO/IEC 42001The first certifiable AI management system standardHigh. There is no data on Baltic certificatesISO; DNV05/09/2026High
26 Three thingsThe author's recommendationsRecommendation, not a source(none)Recommendation

What the slides deliberately leave out

  • “The AI Act applies in full from 2 August 2026.” Wrong since 27/07/2026.
  • “A breach of the AI literacy duty carries a 15 million EUR fine.” Article 4 is not on the Article 99 list.
  • “Companies are already being fined under the AI Act.” Not one fine has been published anywhere in the EU (checked 05/09/2026).
  • “Lithuania has an AI law.” Draft XVP-1564 is in the Seimas, the autumn session starts on 10/09/2026.
  • “3,532 children.” That is the Museum of Failure figure; the official CBS number is 2,090.
  • “86% of companies use AI without the board knowing.” Quoted in the IoD document with no source; taken off the slide.

Martynas Kairys, head of Zedge Lithuania, AI practitioner and speaker. He gives talks and workshops in his free time from that job.