A common assumption in UK boardrooms is that the EU AI Act is someone else's regulation. It is worth retiring that assumption early: like GDPR before it, the Act has extraterritorial reach. If your AI system's outputs are used in the EU — by customers, users, or partners — obligations can attach to your organisation regardless of where it is headquartered.
The shape of the Act
The Act classifies AI systems by risk. A small set of practices is prohibited outright. High-risk systems — those used in areas like employment decisions, credit, critical infrastructure, and medical contexts — carry the heaviest obligations: risk management, data governance, technical documentation, logging, human oversight, and conformity assessment. General-purpose AI models have their own transparency obligations, and even limited-risk systems face disclosure duties, such as telling users they are interacting with AI.
Obligations phase in over several years, but the direction is fixed, and enterprise customers are already writing the Act's requirements into procurement questionnaires — which means the commercial deadline is arriving before the legal one.
A pragmatic starting sequence for UK organisations
- Inventory. You cannot classify what you have not catalogued. Include embedded AI features, copilots arriving through office suites, and shadow tools teams adopted independently.
- Screen for EU exposure. For each system, ask whether its outputs reach EU users or markets. This shortlist is where obligations may attach.
- Risk-classify the shortlist. Map each system against the Act's categories. Most will land in minimal or limited risk — the point is to identify the exceptions deliberately rather than discover them in a customer audit.
- Close the evidence gap. For anything approaching high-risk, start the documentation, logging, and oversight work now. These take quarters, not weeks.
- Align with what you already do. GDPR data mapping, DPIAs, and — for regulated sectors — GxP validation discipline cover real ground. The Act rewards organisations that already treat evidence as a first-class deliverable.
The strategic view
Treating the Act as a compliance chore misses the commercial point: the organisations that can evidence their AI governance will win the enterprise deals that demand it. Our TRUST-AI Compliance & Governance Assessment maps an AI estate against the EU AI Act, GDPR, and NIST AI RMF for exactly this reason — the gap register it produces is as much a sales asset as a risk document.