[governance]

The EU AI Act for teams shipping AI

What the regulation means in practice for organisations deploying AI in Europe, and how to build so compliance is inherited rather than retrofitted.

6 min read · 2026-09-14

A risk-based framework

The Act classifies AI systems by risk. Most business applications fall into limited or minimal risk, but systems used in credit, employment, essential services, and certain public-sector contexts can be high risk, with obligations on documentation, data governance, human oversight, and monitoring.

General-purpose models

Organisations building on foundation models from providers such as OpenAI, Anthropic, and Google inherit some obligations from the provider and take on others as deployers. Knowing which is which matters for procurement as much as for engineering.

What deployers must be able to show

A record of what the system does, what data it uses, how it is evaluated, how humans oversee it, and how incidents are handled. None of this is exotic. All of it is expensive to reconstruct after the fact.

Build so controls are inherited

A portfolio-level governance framework means each new use case starts with documentation templates, evaluation harnesses, and monitoring already in place. Compliance becomes a property of the platform rather than a project per system.

Sector rules still apply

Financial services, telecommunications, and public bodies have existing regulators with existing expectations. The Act adds to these; it does not replace them. We design to the stricter of the two.

A note on this page

This is general information for practitioners, not legal advice. We work alongside clients' legal and compliance teams on the specific classification of each system.

Ready to move from pilots to P&L?

Tell us about the decision or workflow you want to change. We'll come back with an honest view on whether it's worth proving, and what it would take.

Start a conversation