Home » AI Governance & EU AI Act Compliance

AI Governance & EU AI Act Compliance

Most AI projects do not fail a compliance review because the model was wrong. They fail because nobody can explain how a decision was reached, who signed it off, what data went in, or what happens when it gets something wrong. We build systems that can answer those questions from day one, because we design for them before we write anything.

Why this has become urgent for UK businesses

If you only serve UK customers, there is no single AI statute to comply with yet — but you are already covered by UK GDPR, by sector regulators, and by the duty to explain automated decisions that materially affect people. If you serve customers or employ people in the EU, the EU AI Act reaches you regardless of where you are based, and obligations bite according to how risky the use case is rather than how large your company is.

The practical effect for a mid-sized business is that AI has moved from an IT question to a governance question. Buyers now ask about it in security questionnaires. Insurers ask about it. Boards ask about it. And retrofitting an audit trail onto a system that was never designed to keep one is expensive and often impossible.

What we do about it

Classify before you build

The first job is working out honestly what category a use case falls into. A tool that drafts internal summaries is not the same as one that influences who gets hired, who gets credit, or who gets escalated. We map the intended use, the people affected and the decisions involved before any design work starts, because that determines what the system has to be able to prove later.

Design for explanation, not just accuracy

Every consequential output should come with the reasoning and the evidence behind it, in language a non-technical reviewer can follow. That is a design decision made early. It is very hard to bolt on afterwards.

Keep the record automatically

Data lineage, model and prompt versions, human review points, overrides and outcomes recorded as a matter of course rather than as a special exercise when someone asks. If producing your audit trail requires a project, you do not really have one.

Watch for drift and bias in production

Systems change behaviour as the world around them changes. Monitoring is part of what we run for you, not a report you have to commission.

Keep a human meaningfully in the loop

Meaningful oversight means the reviewer has the information and the authority to disagree, and that disagreement is captured. A rubber stamp is not oversight, and it will not survive scrutiny.

Proof that we hold ourselves to this

Our own product, Idonara, operates in one of the most heavily scrutinised areas there is: AI in recruitment. Every shortlisting decision is explained, bias is monitored in real time, and the regulatory obligations are handled as part of the product rather than left to the employer. We built it to the standard we apply to client work.

Where to start

A good first step is a straightforward review of what you already have running, or are about to commission: what it does, who it affects, what it records and what would happen if a regulator, a client or a claimant asked you to justify an output. We do that as part of a free AI-readiness teardown, and we will tell you plainly if you are in better shape than you feared.

If you are earlier than that and simply want to scope a system properly from the outset, start a design conversation and we will build the governance requirements into the fixed price rather than treating them as an extra.

Explore our services

A full index of what we do is on the AI services page. The individual services are:

Where we work

We deliver across the United Kingdom from our Glasgow studio, with on-site time included: London, Manchester, Birmingham, Edinburgh, Glasgow.

AI Services

Where we work

Company

Latest writing

AI Applied Ltd, Technology House, 9 Newton Place, Glasgow G3 7PR. Registered in Scotland SC806963. support@aiapplied.uk · +44 141 465 5233