AI, Data & Technology

    The EU AI Act: What It Actually Means for Your Business

    Ou-Jue Cheng CA7 min read

    The EU AI Act Isn't Just Another Regulation. It Changes the Rules.

    Having spent years advising FTSE 250 organisations on governance and compliance, I've seen plenty of regulation come through. Most of it lands with a thud, gets absorbed into existing frameworks, and life moves on.

    The EU AI Act is different. It's the world's first comprehensive law governing artificial intelligence — and it doesn't just affect EU-based companies. If your AI systems touch EU users in any way, you're in scope. Regardless of where your headquarters are.

    I wanted to write this because the Act is complex, and most of the summaries I've seen are either overly legal or sensationalised. What follows is a plain-English breakdown of what the EU AI Act actually says, who it affects, and what you should be doing about it right now.

    What Is the EU AI Act?

    At its core, the EU AI Act is a risk-based regulatory framework for artificial intelligence. It was formally adopted in 2024 and is being phased in over several years.

    The thinking behind it is straightforward: AI systems carry different levels of risk depending on how they're used. A chatbot answering product questions is very different from an AI system making decisions about someone's credit application or criminal sentencing. The Act says these should be governed differently — and it sets out exactly how.

    Three principles run through everything:

    • Transparency — People have the right to know when they're interacting with AI, and organisations must be clear about how their AI systems work.
    • Human oversight — AI shouldn't make high-stakes decisions without meaningful human involvement. The Act requires clear governance structures and accountability.
    • Data governance — The data feeding AI systems must be relevant, representative, and properly managed. This includes training data, operational data, and ongoing monitoring data.

    The Risk Classification System

    This is the backbone of the Act. Every AI system falls into one of four categories:

    Unacceptable Risk (Banned)

    These AI practices are prohibited outright. They include:

    • Social scoring by governments
    • Real-time biometric surveillance in public spaces (with limited exceptions)
    • AI that manipulates human behaviour to cause harm
    • Systems that exploit vulnerabilities of specific groups (age, disability)

    These prohibitions have been enforceable since February 2025, with penalties of up to €35 million or 7% of global annual revenue.

    High Risk (Strict Requirements)

    This is where the most significant compliance obligations sit. High-risk AI systems include those used in:

    • Employment and recruitment decisions
    • Credit scoring and financial assessments
    • Critical infrastructure management
    • Education and vocational training assessments
    • Law enforcement and border control
    • Healthcare diagnostics and treatment recommendations

    For these systems, the Act requires:

    • Comprehensive risk management throughout the system lifecycle
    • Data governance controls covering quality, relevance, and bias
    • Full technical documentation and traceability
    • Human oversight mechanisms
    • Accuracy, robustness, and cybersecurity standards
    • Ongoing monitoring for drift, bias, and performance degradation

    These obligations go live on 2 August 2026, with the same penalty ceiling — up to €35 million or 7% of global annual revenue.

    Limited Risk (Transparency Obligations)

    Systems like chatbots, deepfake generators, and emotion recognition tools must clearly disclose to users that they're interacting with AI. The requirements here are lighter but still real.

    Minimal Risk (Largely Unregulated)

    Most everyday AI applications — spam filters, AI-powered recommendations, basic automation — fall here. The Act doesn't impose specific requirements on these, though general transparency principles still apply.

    The Timeline That Matters

    This is where I see the most confusion. The EU AI Act isn't a single deadline. It's a phased rollout:

    • February 2025 — Prohibited AI practices became enforceable. This is already live.
    • August 2025 — Rules for general-purpose AI models (like large language models) apply.
    • August 2026 — Full high-risk system obligations go live. This is the big one.
    • August 2027 — Extended deadline for high-risk AI systems that are components of regulated products.

    The penalty framework is already in force across all phases. We're not waiting for enforcement to begin — it's already here.

    What This Means for UK-Based Businesses

    Post-Brexit, the UK isn't directly bound by EU regulation. But the EU AI Act has extraterritorial reach. You're in scope if:

    • Your AI systems are used by people in the EU
    • You deploy AI systems within the EU market
    • The output of your AI systems is used in the EU

    For many UK businesses operating internationally, this means compliance isn't optional — it's a market access requirement.

    It's also worth noting that the UK is developing its own AI governance framework. While the approach differs — more principles-based, less prescriptive — the direction of travel is the same. Getting your governance foundations right now serves you regardless of which regulatory framework ends up applying to you.

    Who Actually Needs to Worry?

    I want to be honest about this, because there's a lot of noise in the market designed to make every business feel like they're at risk.

    The EU AI Act primarily targets larger organisations with significant AI deployments — particularly those deploying high-risk systems at scale. If you're a FTSE 250 company using AI in recruitment, credit scoring, or critical infrastructure, you need to be well into your compliance programme by now.

    If you're a smaller business using off-the-shelf AI tools — a chatbot on your website, AI-powered accounting software, automated email responses — you're almost certainly in the minimal or limited risk categories. The tools' providers bear the primary compliance burden, not you. That doesn't mean you should ignore the Act entirely, but the scale of what's required is proportionate.

    The organisations I'm most concerned about are the mid-to-large businesses that are deploying AI across multiple functions without a clear governance framework. They often don't have a complete inventory of their AI systems, let alone risk classifications or data governance controls. That's where the real exposure sits.

    There's a fourth group worth naming separately, because they don't fit the "large vs small" framing above: founders of fintech or AI-touching tech businesses heading toward an exit. Your AI footprint today might be minimal — a few embedded tools, an early product feature. But a buyer's due diligence team will ask exactly the questions this Act asks: what AI systems does the business run, what data feeds them, and can you evidence how they're governed. Weak or improvised answers here don't just create legal exposure — they slow a deal down, or hand the buyer a lever to discount valuation. If you're preparing a business for sale, treat this as a data-room readiness question as much as a compliance one.

    What You Should Be Doing Right Now

    Whether the Act applies to you directly or not, good AI governance is good business practice. Here's where to start:

    It's worth noting that ISO/IEC 42001 — the international standard for AI management systems — maps closely to the EU AI Act's requirements. The standard covers risk management, data governance, documentation, and accountability — the same foundations the Act demands. Organisations that build toward ISO 42001 readiness are simultaneously building their EU AI Act compliance framework. It's not a coincidence. They're solving the same problem from different angles.

    1. Build Your AI Inventory

    You can't govern what you can't see. Map every AI system in your organisation — including vendor-provided tools, internal builds, and the ones your teams are using without formal approval.

    2. Classify Your Risk

    Against the Act's framework, categorise each system. Most will fall into minimal or limited risk. The ones that don't need immediate attention.

    3. Assess Your Data Governance

    For any high-risk systems: where does the training data come from? How is operational data managed? What controls exist around quality, bias, and representativeness? This is where most organisations have the biggest gaps.

    4. Document Everything

    From my audit background, I can tell you: if it isn't documented, it doesn't exist. The Act requires full traceability for high-risk systems — design decisions, data sources, testing results, monitoring processes. Start building these records now.

    5. Assign Accountability

    Someone in your organisation needs to own AI governance. Not as a side project — as a defined responsibility with clear authority and reporting lines.

    This Isn't Going Away

    The EU AI Act isn't a one-off compliance exercise. It's a permanent shift in how organisations are expected to develop, deploy, and govern AI systems. The businesses that treat it as a governance opportunity rather than a regulatory burden will be better positioned — not just for compliance, but for building AI systems their customers, employees, and stakeholders actually trust.

    If you're looking for a structured approach, ISO 42001 readiness gives you a recognised framework to build from — one that aligns directly with what the Act requires.

    If your organisation needs clarity on where you stand with the EU AI Act, this is exactly the kind of work we help with — whether that's a larger business preparing for the August 2026 obligations, or a founder preparing a fintech or tech business for sale who needs their AI and data governance to hold up under a buyer's scrutiny. We bring audit discipline and practical governance experience to help you understand your obligations, build the right frameworks, and get compliant without overcomplicating things.

    Written by
    Ou-Jue Cheng CA

    Finance & Data Partner supporting businesses with their finances & data to grow and build better businesses together.

    About Straxa →
    Ready to talk it through?

    Book a free discovery call.

    A 30-minute conversation about where you are and what would actually help. No pressure, no jargon, no obligation.