AI Act UK Equivalence: The Complete Board Implementation Guide 2026
Please verify you’re human to continue.
AI Act UK Equivalence: The Complete Board Implementation Guide 2026
The EU AI Act is now in force. UK firms with EU operations, EU customers, or AI systems deployed in EU markets are directly in scope. This briefing provides the complete board implementation framework — what the Act requires, how it maps to existing UK AI governance guidance, and the specific actions each board role must take before enforcement begins.
Why UK boards are in scope despite Brexit
The EU AI Act has extraterritorial reach comparable to GDPR. A UK firm is in scope if it places an AI system on the EU market, puts an AI system into service in the EU, or deploys AI systems that affect persons in the EU — regardless of where the provider is established. This captures the overwhelming majority of FTSE 350 firms with European operations.
Additionally, the UK government’s AI governance framework — published by DSIT and the ICO — tracks the EU Act closely. Boards that implement EU AI Act compliance frameworks will simultaneously satisfy UK domestic AI governance expectations, making dual compliance the most efficient approach.
The AI Act’s four-tier risk classification
Every AI system your organisation deploys, procures, or develops must be classified against the Act’s four-tier risk hierarchy. This classification determines the compliance burden.
| Risk tier | Examples relevant to FTSE/AIM firms | Board implication |
|---|---|---|
| Prohibited | Social scoring; real-time biometric surveillance in public spaces; subliminal manipulation | Board must confirm none deployed. Legal sign-off required. |
| High risk | AI in recruitment/HR decisions; credit scoring; insurance risk assessment; safety-critical infrastructure control; medical devices | Full compliance obligations: conformity assessment, human oversight, bias testing, registration in EU database |
| Limited risk | Chatbots; AI-generated content; emotion recognition tools | Transparency obligations only — users must be informed they are interacting with AI |
| Minimal risk | Spam filters; AI-powered search; recommendation engines | No mandatory obligations; voluntary code of conduct recommended |
The GPAI tier — general-purpose AI models
A significant addition to the Act is the General-Purpose AI (GPAI) model tier, which captures large language models and foundation models. If your firm develops or fine-tunes GPAI models with more than 10^25 FLOPs of compute, additional obligations apply including systemic risk assessments and adversarial testing. Most firms are GPAI users rather than developers, but procurement teams need to ensure GPAI providers can demonstrate compliance.
High-risk AI: the full compliance requirements
If your organisation deploys any high-risk AI system, the following obligations apply from August 2026 (for new systems) or August 2027 (for existing deployed systems):
- Risk management system — a documented, iterative process identifying and mitigating risks throughout the AI lifecycle
- Data governance — training, validation, and testing datasets must meet quality criteria; bias monitoring is mandatory
- Technical documentation — detailed documentation of system design, capabilities, limitations, and performance
- Transparency and user information — users must receive information enabling them to interpret outputs
- Human oversight — systems must be designed to allow human intervention; operators must assign oversight responsibility to named individuals
- Accuracy, robustness, and cybersecurity — tested performance standards with ongoing monitoring
- EU database registration — high-risk AI systems must be registered in the EU’s public AI database before deployment
- Conformity assessment — either self-assessment or third-party audit, depending on the application area
What the board must own directly
The AI Act places obligations on “providers” (those who develop or place AI on the market) and “deployers” (those who use AI under their own authority). Most UK corporates are deployers. Deployer obligations include:
- Assigning human oversight of high-risk AI to competent, empowered individuals
- Ensuring staff using AI have sufficient AI literacy (a board-level training obligation from February 2025)
- Monitoring for drift, degradation, and unexpected outcomes in deployed high-risk AI
- Maintaining logs of high-risk AI system operation for at least six months
- Notifying the provider and competent authority of serious incidents or malfunctions
The AI literacy obligation is already in force. Article 4 of the AI Act requires all providers and deployers to “take measures to ensure, to their best extent, a sufficient level of AI literacy of their staff” — effective February 2025. Boards that have not audited AI literacy across their workforce are already non-compliant.
Mapping AI Act obligations to existing UK frameworks
UK boards operating across multiple frameworks can rationalise compliance by mapping AI Act obligations to existing requirements:
- GDPR / UK GDPR — AI Act data governance and bias requirements largely overlap with GDPR data quality and automated decision-making obligations under Article 22. A joint compliance programme is more efficient.
- FCA Consumer Duty — AI systems used in customer-facing financial services must already meet Consumer Duty fairness standards. AI Act transparency and human oversight obligations reinforce this.
- UK Corporate Governance Code 2024 — Provision 29’s internal controls declaration should now include AI governance controls where material AI systems are deployed.
- SMCR (financial services firms only) — Boards at FCA/PRA-regulated firms should designate a Senior Manager as accountable for AI governance, reflected in their Statement of Responsibilities. Non-financial services boards should adopt equivalent accountability mechanisms suited to their governance structure.
Enforcement timeline
Phase 1: Inventory and classify (complete by Q3 2026)
- Commission an AI system inventory across all business lines — every AI system procured, developed, or deployed
- Classify each system against the four-tier risk hierarchy
- Identify all high-risk AI systems and initiate conformity assessment processes
- Confirm no prohibited AI practices are in use — obtain legal sign-off
- Audit AI literacy across staff who interact with AI systems — remediate gaps
Phase 2: Assign accountability (Q3 2026)
- Designate a Senior Manager (or equivalent) as accountable for AI governance — update SoRs
- Assign human oversight officers for each high-risk AI system
- Establish an AI governance committee or extend the remit of the Risk or Audit Committee
- Ensure AI governance appears as a standing agenda item at board or committee level
Phase 3: Build compliance infrastructure (Q4 2026)
- Implement risk management systems for high-risk AI (can align with existing ERM framework)
- Establish incident reporting protocols for AI malfunctions or serious incidents
- Register high-risk AI systems in the EU AI database
- Implement operational logging for high-risk AI (minimum 6-month retention)
- Review GPAI provider contracts to ensure they can provide required compliance documentation
Questions to put to management now
- Has a complete AI system inventory been completed? Which systems are classified as high-risk?
- Has the AI literacy obligation (Article 4, February 2025) been assessed and remediated?
- Who is the named Senior Manager accountable for AI Act compliance?
- Have our GPAI provider contracts been reviewed for AI Act compliance documentation requirements?
- What is the estimated cost and timeline for conformity assessments on high-risk AI systems?
