Category: EU AI Act
The EU AI Act (Regulation (EU) 2024/1689) is the world’s first comprehensive AI law, applying risk-based obligations to providers and deployers of AI systems — including UK and other non-EU organisations whose systems or outputs reach the EU market. This section covers the Act as it applies in practice: how risk classification works across the prohibited, high-risk, limited-risk and minimal-risk tiers, what obligations attach to each role in the AI value chain, and how to build the documentation, oversight and monitoring arrangements the Act expects. The articles here are written for compliance, legal and risk professionals who need to move beyond summaries of the legislation to defensible implementation — with particular attention to the questions that arise for UK organisations and SMEs caught by the Act’s extraterritorial reach under Article 2. Key compliance dates are staged: prohibitions and AI literacy duties have applied since 2 February 2025, general-purpose AI obligations since 2 August 2025, and the main high-risk framework applies from 2 August 2026.
-

Does GDPR Cover AI Models? The Compliance Test
Does GDPR cover AI models? Learn when training, deployment and outputs trigger GDPR duties, and how to build evidence for defensible AI governance records.
-

AI Risk Treatment That Stands Up to Audit
AI risk treatment needs more than a risk register. Build accountable controls, evidence and monitoring for EU AI Act and ISO 42001 compliance at scale.
-

Which Systems Need AI Registration Under EU Rules?
Which systems need AI registration under the EU AI Act? Identify scope, assign ownership and build the evidence needed for defensible governance records.
-

AI Policy Checklist for EU AI Act Readiness
Use this AI policy checklist to set scope, ownership, risk controls and evidence for EU AI Act and ISO 42001 readiness in regulated UK organisations.
-

When Do AI Rules Apply Under the EU AI Act?
When do AI rules apply? Map EU AI Act duties by role, use case and timeline, then build the evidence your compliance team needs for audit-ready control.
-

How to Monitor AI Controls for Audit Readiness
Learn how to monitor AI controls with evidence, ownership, testing and escalation for EU AI Act and ISO 42001 assurance in production at operational scale.
-

A Spreadsheet Alternative for AI Governance
Choose a spreadsheet alternative for AI governance that creates auditable inventories, mapped controls and board-ready evidence for EU AI Act key duties.
-

A Spreadsheet Alternative for AI Governance
Choose a spreadsheet alternative for AI governance that creates auditable inventories, mapped controls and board-ready evidence for EU AI Act key duties.
-

AI Data Residency for European Compliance Teams
AI data residency affects GDPR transfers, supplier risk and AI governance. Learn what to evidence, test and monitor for audit-ready control in practice.
-

Audit-Ready AI Evidence for EU AI Act Audits
Build audit ready AI evidence that connects inventory, risk, controls and approvals into a defensible record for EU AI Act and ISO 42001 assurance work.
