Artificial intelligence is no longer a technology of the future. Today, it holds the promice to be embedded in core operations, driving efficiencies, enabling new product lines, and transforming enterprise strategies across nearly every sector. From predictive maintenance and fraud detection to generative design and autonomous workflows, AI is quickly becoming foundational to modern business.
Yet alongside this opportunity comes a growing concern: how can businesses scale AI responsibly, mitigate legal and reputational risks, and remain competitive in an increasingly regulated environment? Europe’s AI Act has introduced the world’s most comprehensive AI law, offering clarity in principle but also introducing significant operational uncertainty. For corporate leaders navigating this shifting landscape, one question is becoming central: how can we comply without compromising innovation? How do we protect our organizations while still enabling teams to experiment, build, and deploy AI at scale?
This question was at the heart of a thought-provoking conversation in Episode 161 of the AI After Work (AIAW) Podcast, where Luis Guillermo Martínez Ballesteros, an AI Compliance Expert at ASSA ABLOY Group, joined co-hosts Henrik Göthberg and Anders Arpteg. With a background that spans engineering, telecommunications, and regulatory affairs, Luis brought a rare hybrid perspective, someone who understands both the technical and legal complexities of bringing AI systems into the real world. What emerged from the episode is an honest and nuanced discussion about the tensions between regulation and creativity, between compliance and iteration, and between caution and momentum.
Regulation Without Roadmaps
The conversation begins with a macro-level view. AI is no longer something on the horizon; it is already here. Large language models, computer vision systems, and decision-making agents are part of enterprise strategies across sectors. This momentum has sparked a wave of global policy initiatives. In the European Union, the AI Act has been passed and is entering its enforcement phase, with key provisions set to apply from 2024 and full implementation by mid-2026. Meanwhile, the United States has issued an Executive Order on AI and continues to build on the NIST AI Risk Management Framework. Other countries, including China, Canada, Brazil, and the UK, are crafting distinct approaches.
However, having regulation is not the same as having clarity. One of the first key insights shared by Luis is the extent to which confusion reigns. Many companies are unsure whether the tools they are building fall under the scope of the AI Act. The distinctions between providers and deployers, or between high-risk and low-risk applications, are not always intuitive. For example, internal AI systems used only by employees may not be subject to the same conformity assessments as publicly marketed products. But when those systems interact with external stakeholders like patients in a hospital or customers on a digital platform the legal obligations may shift significantly.
Over-Compliance and the Risk of Paralysis
Luis highlights that organizations often overcorrect by assuming everything needs to go through a full compliance process. This reaction is understandable but counterproductive. It creates unnecessary bottlenecks and fosters a culture of risk aversion, where innovation slows not because the law demands it, but because the fear of non-compliance creates paralysis. In his view, what companies need is not less regulation, but better tools and clearer paths to understanding what is expected of them.

The AI Act is structured around a tiered system of risk classification. At the top are unacceptable-risk systems, which are banned altogether. Below that are high-risk systems, which face the most stringent requirements in terms of transparency, data governance, human oversight, and documentation. Then come limited- and minimal-risk systems, which face relatively fewer obligations. But here lies a structural problem. Although the Act’s framework is risk-based, the tools that companies need to determine where they fall on the risk spectrum specifically, the harmonized standards are not yet fully available.
Compliance as Engineering Culture
This leads to the second major theme of the conversation: compliance needs to become an embedded part of the product development process. This idea, often referred to as “compliance by design,” means that legal and ethical considerations are not bolted on at the end of a project but are woven into each phase of the AI lifecycle. Luis shares how Assa Abloy is adapting its development framework to reflect this reality. Originally a hardware-focused company known for locks and keys, Assa Abloy has evolved into a provider of digital access systems. These include biometric scanners, facial recognition, and connected IoT devices, all of which now fall under new compliance obligations.
To respond to this, companies are building internal capacity. This includes developing tools for self-assessment, creating role-specific training programs, and ensuring that compliance requirements are translated into the language of engineers, not just lawyers.
Agile Compliance and the Tesla Mindset
One of the most intriguing parts of the discussion revolves around the idea of “agile compliance.” This is best illustrated by the example of Tesla, which reportedly updates its hardware and software incrementally, submitting continuous updates to regulators rather than waiting for large, infrequent audits. Tesla’s model treats compliance not as a hurdle but as a conversation. Regulators are engaged regularly, even daily, in small review cycles that align with how modern engineering teams work. This model, Luis suggests, could be applied in the AI context as well.
Agile compliance is not about skipping rules; it’s about matching the rhythm of oversight to the pace of innovation. When regulators are part of the process rather than adversaries at the end, trust can be built, and risks can be managed more proactively.
Standards, Sandboxes, and Structural Readiness
The podcast also discusses regulatory sandboxes, controlled environments where companies can test AI systems in collaboration with regulators before full deployment. These sandboxes are mandated under the AI Act but are still largely conceptual in most EU member states.
The future role of harmonized standards is also a key topic. These are not just technical guidelines; they are the operational bridges between law and engineering. For example, a standard on data governance might translate a legal requirement about bias mitigation into concrete steps for data validation, labeling, and monitoring. Without such standards, regulation remains abstract, and compliance becomes guesswork.

Risk-Aware Innovation
Henrik introduces the concept of “risk vectors” as a way to manage AI development at scale. These include not just the model itself, but the data it was trained on, the system it interacts with, and the user interface it relies on. Each vector can be assessed for both risk and value, allowing teams to decompose complex systems into manageable units.
Luis reflects on his experience at Volvo Cars, where the emergence of generative AI prompted the formation of a cross-functional governance committee. Initially, all decisions went through this centralized group. But over time, the process evolved. Teams were given tools to do preliminary assessments themselves, escalating only the most complex cases. This hybrid model combining distributed ownership with centralized oversight is now being adapted at Assa Abloy.
Beyond Regulation – A Cultural Transformation
The episode also tackles the philosophical dimensions of regulation. What is the goal of governing AI? Is it to prevent harm, ensure fairness, or create trust? Luis argues that regulation should be about enabling thoughtful, responsible use of powerful tools. The aim is not to eliminate all risk, which is impossible, but to make those risks visible, understandable, and manageable.
Toward the end of the conversation, the focus shifts to broader societal concerns. One is the erosion of critical thinking. Luis observes that as AI systems become more capable, there is a risk that people will outsource too much cognitive effort. This insight brings the discussion full circle. Compliance and innovation are not just technical or legal matters; they are cultural.
A Nordic Opportunity for Collective Leadership
The conversation concluded with a powerful call for collaboration. Luis proposes that Nordic companies join forces to co-develop shared compliance frameworks, rather than duplicating effort. This vision of open innovation, supported by public infrastructure and standardization bodies, could make the region a global leader in trustworthy AI.
Platforms like RISE, AI Sweden, and the TEFs already exist. But to succeed, they need clearer mandates, more sustained funding, and a culture of co-creation that spans the public and private sectors.
Toward a Trustworthy AI Future
In sum, the balancing act between control and innovation is not a binary. It is a dynamic process that requires nuance, humility, and experimentation. Regulation, when designed well, does not suppress creativity; it channels it toward outcomes that are not only profitable but just, safe, and aligned with democratic values.
The AI Act, for all its imperfections, offers a scaffolding for such an approach. But it will be up to companies, regulators, and civil society to build the rest.
What this episode reveals is that responsible AI is not a destination, but a discipline. It requires organizations to rethink how they build, how they govern, and how they collaborate. It requires governments to evolve from rule-makers to ecosystem stewards. And it requires all of us to remain vigilant about the kind of world we want technology to create.
The challenge is real. But with leadership, clarity, and cooperation, it is one we can meet.
Watch or listen the entire episode here: https://aiawpodcast.com/
*Text enchanced with AI