The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It entered into force in August 2024, and its provisions are being phased in over a two-year implementation period. The most consequential deadline for most boards is August 2026, when the Act's general-purpose AI (GPAI) and transparency obligations take full effect.

Many UK and US boards have assumed that the EU AI Act does not apply to them. This assumption is incorrect, and acting on it could prove extremely costly.

The Extraterritorial Reach of the EU AI Act

Like the GDPR before it, the EU AI Act applies on the basis of where AI systems have effect, not where their developers or deployers are based. Article 2 of the Act makes this explicit: it applies to providers and deployers of AI systems whose outputs are used in the European Union, regardless of where those providers or deployers are established.

This means that a UK-headquartered company that deploys an AI system used by EU employees, customers, or partners is subject to the Act's requirements. A US company whose AI-powered product is available in the EU market is subject to the Act's requirements. The geographic location of the company's servers or headquarters is irrelevant.

"The EU AI Act is not a European regulation. It is a global regulation with a European enforcement mechanism. Any board that has not assessed its exposure is operating without adequate information."

The Risk-Tier Framework

The Act classifies AI systems into four risk tiers, each with different compliance obligations:

Risk TierExamplesKey Obligations
Unacceptable RiskSocial scoring, real-time biometric surveillanceProhibited outright
High RiskHiring AI, credit scoring, critical infrastructureConformity assessment, registration, human oversight
Limited RiskChatbots, AI-generated contentTransparency obligations — must disclose AI interaction
Minimal RiskAI-powered spam filters, recommendation enginesNo mandatory requirements (voluntary codes of practice)

The August 2026 deadline primarily affects Limited Risk and General-Purpose AI (GPAI) systems — the category that includes most large language models and AI-powered business tools. From this date, organisations must be able to demonstrate that users are informed when they are interacting with AI, and that AI-generated content is clearly labelled as such.

What Boards Must Do Before August 2026

Step 1: Conduct an AI System Inventory

Boards must commission a complete audit of every AI system deployed across the organisation, including third-party AI tools procured by individual departments. Each system must be classified against the Act's risk-tier framework. This inventory is the foundation of all subsequent compliance work.

Step 2: Establish an AI Governance Committee

The Act requires that high-risk AI systems be subject to human oversight. This requires a governance structure. Boards should establish a formal AI governance committee — or designate an existing committee — with explicit responsibility for AI compliance, including EU AI Act obligations.

Step 3: Implement Transparency Disclosures

For all Limited Risk AI systems, organisations must implement clear disclosure mechanisms. This means informing users when they are interacting with an AI system, labelling AI-generated content, and maintaining records of AI interactions that can be produced for regulatory review.

Step 4: Audit AI Vendor Contracts

The Act places obligations on both providers (those who develop AI systems) and deployers (those who use them). Boards must review their AI vendor contracts to ensure that providers are meeting their obligations under the Act, and that the organisation's own deployment practices comply with the requirements for deployers.

Step 5: Document AI-Assisted Decisions

For high-risk AI applications, the Act requires documentation of how AI systems are used in decision-making processes. Boards should implement structured documentation protocols for all material AI-assisted decisions — particularly those affecting employees, customers, or financial outcomes.

The Penalty Regime

Non-compliance with the EU AI Act carries significant financial penalties. The maximum fines are:

These are not theoretical maximums. EU regulators have demonstrated with GDPR enforcement that they are willing to impose substantial fines on non-EU companies. The AI Act's enforcement mechanism is modelled on GDPR, and boards should expect similar enforcement vigour.

The UK Position

Post-Brexit, the UK is not directly subject to the EU AI Act. However, UK companies with EU operations, EU customers, or EU market exposure are subject to it in those contexts. The UK government has indicated it will develop its own AI regulation framework, but has not yet enacted equivalent legislation. UK boards therefore face a dual compliance challenge: EU AI Act obligations for their EU-facing operations, and evolving UK regulatory expectations for their domestic operations.

The prudent approach is to implement EU AI Act-compliant governance across the entire organisation, rather than attempting to maintain separate compliance postures for different jurisdictions. The EU standard is the more demanding one, and meeting it satisfies the UK's current expectations.

Veriqo AI Shadow Board

AI-Assisted Decisions. Fully Auditable. Zero Retention.

Every Veriqo AI analysis is zero-retention and produces a structured, attributable decision record — the documentation standard the EU AI Act requires.