The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It entered into force in August 2024, and its provisions are being phased in over a two-year implementation period. The most consequential deadline for most boards is August 2026, when the Act's general-purpose AI (GPAI) and transparency obligations take full effect.
Many UK and US boards have assumed that the EU AI Act does not apply to them. This assumption is incorrect, and acting on it could prove extremely costly.
The Extraterritorial Reach of the EU AI Act
Like the GDPR before it, the EU AI Act applies on the basis of where AI systems have effect, not where their developers or deployers are based. Article 2 of the Act makes this explicit: it applies to providers and deployers of AI systems whose outputs are used in the European Union, regardless of where those providers or deployers are established.
This means that a UK-headquartered company that deploys an AI system used by EU employees, customers, or partners is subject to the Act's requirements. A US company whose AI-powered product is available in the EU market is subject to the Act's requirements. The geographic location of the company's servers or headquarters is irrelevant.
"The EU AI Act is not a European regulation. It is a global regulation with a European enforcement mechanism. Any board that has not assessed its exposure is operating without adequate information."
The Risk-Tier Framework
The Act classifies AI systems into four risk tiers, each with different compliance obligations:
| Risk Tier | Examples | Key Obligations |
|---|---|---|
| Unacceptable Risk | Social scoring, real-time biometric surveillance | Prohibited outright |
| High Risk | Hiring AI, credit scoring, critical infrastructure | Conformity assessment, registration, human oversight |
| Limited Risk | Chatbots, AI-generated content | Transparency obligations — must disclose AI interaction |
| Minimal Risk | AI-powered spam filters, recommendation engines | No mandatory requirements (voluntary codes of practice) |
The August 2026 deadline primarily affects Limited Risk and General-Purpose AI (GPAI) systems — the category that includes most large language models and AI-powered business tools. From this date, organisations must be able to demonstrate that users are informed when they are interacting with AI, and that AI-generated content is clearly labelled as such.
What Boards Must Do Before August 2026
Step 1: Conduct an AI System Inventory
Boards must commission a complete audit of every AI system deployed across the organisation, including third-party AI tools procured by individual departments. Each system must be classified against the Act's risk-tier framework. This inventory is the foundation of all subsequent compliance work.
Step 2: Establish an AI Governance Committee
The Act requires that high-risk AI systems be subject to human oversight. This requires a governance structure. Boards should establish a formal AI governance committee — or designate an existing committee — with explicit responsibility for AI compliance, including EU AI Act obligations.
Step 3: Implement Transparency Disclosures
For all Limited Risk AI systems, organisations must implement clear disclosure mechanisms. This means informing users when they are interacting with an AI system, labelling AI-generated content, and maintaining records of AI interactions that can be produced for regulatory review.
Step 4: Audit AI Vendor Contracts
The Act places obligations on both providers (those who develop AI systems) and deployers (those who use them). Boards must review their AI vendor contracts to ensure that providers are meeting their obligations under the Act, and that the organisation's own deployment practices comply with the requirements for deployers.
Step 5: Document AI-Assisted Decisions
For high-risk AI applications, the Act requires documentation of how AI systems are used in decision-making processes. Boards should implement structured documentation protocols for all material AI-assisted decisions — particularly those affecting employees, customers, or financial outcomes.
The Penalty Regime
Non-compliance with the EU AI Act carries significant financial penalties. The maximum fines are:
- Prohibited AI practices: Up to €35 million or 7% of global annual turnover, whichever is higher
- High-risk AI non-compliance: Up to €15 million or 3% of global annual turnover
- Providing incorrect information: Up to €7.5 million or 1.5% of global annual turnover
These are not theoretical maximums. EU regulators have demonstrated with GDPR enforcement that they are willing to impose substantial fines on non-EU companies. The AI Act's enforcement mechanism is modelled on GDPR, and boards should expect similar enforcement vigour.
The UK Position
Post-Brexit, the UK is not directly subject to the EU AI Act. However, UK companies with EU operations, EU customers, or EU market exposure are subject to it in those contexts. The UK government has indicated it will develop its own AI regulation framework, but has not yet enacted equivalent legislation. UK boards therefore face a dual compliance challenge: EU AI Act obligations for their EU-facing operations, and evolving UK regulatory expectations for their domestic operations.
The prudent approach is to implement EU AI Act-compliant governance across the entire organisation, rather than attempting to maintain separate compliance postures for different jurisdictions. The EU standard is the more demanding one, and meeting it satisfies the UK's current expectations.
Veriqo AI Shadow Board
AI-Assisted Decisions. Fully Auditable. Zero Retention.
Every Veriqo AI analysis is zero-retention and produces a structured, attributable decision record — the documentation standard the EU AI Act requires.