While many UK organisations are assessing what the EU AI Act may mean for their operations, (particularly where AI systems are developed, deployed, or supplied into EU markets), there are a few early governance areas that are often worth looking at.
The points below are best read as areas to consider, rather than a checklist of actions.
-
Identifying where AI is used
A sensible starting point is simply understanding where AI already exists in the organisation. That can include:
- In-house-developed AI
- Third-party tools used by teams (including ‘shadow AI’ adopted informally)
- AI features built into products
- AI used in customer-facing services or internal decision-making
Having a clearer picture helps organisations see which systems are business-critical, which are experimental, and where AI adoption may be growing faster than expected.
-
Understanding risk and use contexts
Because the EU AI Act is based on risk, it can help to look at AI systems in context, not just by name or vendor. This usually means being clear about what the system is for, who it affects, what decisions it supports, and whether the outputs could materially impact individuals.
It may also be relevant to consider whether the AI falls within a regulated activity (for example, financial services or healthcare), what could go wrong (such as errors, bias, misuse, or unexpected behaviour), and its real-world consequences.
-
Making accountability and evidence clearer
Compliance often becomes more tangible at the documentation stage, as organisations may need to demonstrate how AI systems are governed, monitored, and controlled, particularly where regulatory obligations apply. Some businesses find it helpful to record why a system is used, what data it relies on, who is responsible for it day to day (from a business, technical, and risk perspective), how changes are approved, and what monitoring is in place.
The goal is not paperwork for its own sake, but clearer ownership and a trail of evidence that supports oversight.
-
Putting governance around AI use
Governance can sound abstract, but in practice, it often comes down to roles, rules, and review. For some organisations, that means agreeing on who can approve new AI use cases, what ‘acceptable use’ looks like, and how higher-impact use cases are assessed before they go live. It also includes practical operational readiness, such as how issues are escalated, how incidents are handled, and how third-party suppliers are assessed, where AI is bought in rather than built.
-
Checking whether data governance is fit for AI
Many AI risks are closely linked to data risks, including poor data quality, unclear provenance, privacy concerns, or bias introduced through datasets. With that in mind, organisations may want to consider whether their data governance supports transparency, whether controls are applied consistently across teams and vendors, and whether decisions and approvals can be evidenced. In higher-impact use cases, those ‘behind the scenes’ data controls can become a key part of demonstrating responsible oversight.