SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
EU AI Act forces global firms to rethink compliance

EU AI Act forces global firms to rethink compliance

Wed, 12th Aug 2026 (Today)
Mark Tarre
MARK TARRE News Chief

The latest set of obligations under the EU AI Act has taken effect for companies building and deploying artificial intelligence systems in the bloc.

The rules expand requirements for high-risk AI, transparency and data governance for providers whose systems or outputs reach users in the EU.

Providers outside the EU also fall within scope if they offer AI systems in the European market or if organisations in the bloc use their outputs. Legal experts say this approach mirrors earlier digital laws such as the General Data Protection Regulation, which focused on the location of users and data rather than corporate headquarters.

Kalyan Kumar, President of HCLSoftware, said the law's extraterritorial reach is already reshaping design choices for global platforms.

"The EU AI Act makes one point unmistakable: AI regulation follows the market and the use of the output, not simply the location of a company's headquarters. Start with clarity of where is the system being offered, where is it deployed, where are its outputs used, and what data crosses borders? For a global software company, the answer cannot be a separate architecture for every jurisdiction. It has to be glocal and sovereign by design. We need a common control plane for security, transparency, data governance and auditability, delivered through platform-based services with the deployment choice to meet local sovereignty and regulatory requirements. Global standards and local control have to work together, and choice is what makes that possible. When they do, compliance becomes an enabler of trust and scale, not a constraint on innovation," said Kalyan Kumar, President, HCLSoftware.

Executives at software and cloud providers now face decisions over how far to regionalise their infrastructure and controls as regulatory approaches diverge between the EU, UK and other major markets. Many are weighing the cost of building country-specific stacks against the risk that a single design may not satisfy local sovereignty or supervision demands.

The EU AI Act classifies systems by risk and sets different obligations for each category. Compliance duties vary across prohibited uses, high-risk systems, general-purpose AI and tools subject to transparency requirements.

Jay Fitzhenry, vCTO for AI at Node4, said classification is now a critical governance decision for users and vendors.

"The latest EU AI Act obligations came into force on August 2nd, marking another step in the EU's phased approach to AI regulation. The most important feature of the Act is its risk-based framework. Whether a system falls into the prohibited, high-risk, transparency or general-purpose AI categories determines which obligations apply. Misclassify your system and you either over-engineer for nothing or get blindsided by obligations you didn't know applied," said Jay Fitzhenry, vCTO for AI, Node4.

He pointed to a growing tension between regulatory certainty and the burden of compliance, particularly for smaller vendors and buyers.

"It is important to get it right because, although guidelines are important, over-regulation can risk stifling growth. The evidence splits both ways: Clear, proportionate rules build trust and can accelerate adoption, with legal certainty itself valuable to buyers. But heavy, badly calibrated rules measurably raise costs and favour whoever can afford compliance headcount, squeezing smaller players out. The EU's decision to revisit parts of its implementation timetable suggests policymakers themselves recognise the difficulty of balancing innovation with regulation," Fitzhenry said.

Divergence between Brussels and London is adding further complexity for companies operating across both jurisdictions. The UK has so far relied on sector regulators and non-statutory principles instead of a comprehensive AI law.

"Meanwhile, the UK continues to favour a principles-based approach through existing regulators, rather than introducing a single law. The two regimes are diverging further as the UK loosens some of its own rules post-Brexit. But, if you sell into the EU at all, you must build to the EU standard," Fitzhenry said.

Practitioners say some of the most immediate exposure lies in how organisations supervise automated decisions and track the data that underpins them.

"Human oversight is where many organisations are most exposed. Genuine oversight means someone can meaningfully intervene before a decision causes harm, not simply review outputs afterwards. That's what catches drift, bias and unexpected behaviour before it becomes a business problem," Fitzhenry said.

Data governance has emerged as a central focus as regulators scrutinise provenance, quality and bias controls across training and operational datasets. Firms must identify data sources, document transformations and assign accountability across each stage of the lifecycle.

"Compliance starts with data governance. Requirements around provenance, quality, bias management and lineage require genuine operational capability, not just policy documents. Organisations need to know where data originated, how it has been transformed, and who is accountable for it," Fitzhenry said.

Many businesses are still in the early stages of preparing for later EU AI Act milestones. Internal discovery exercises are revealing fragmented AI usage, often embedded in third-party software.

"As organisations prepare for the next stages of implementation, businesses must act now to ensure they are compliant. Unfortunately, most organisations still don't have a complete inventory of the AI they're using, particularly where AI capabilities are embedded into everyday software. That creates both governance and commercial risk because you cannot manage what you cannot see. Two priorities should be immediate: AI literacy training and transparency obligations for AI-generated content. Both are achievable, relatively low-cost, and demonstrate real intent. From there, organisations should use the time before the more demanding requirements arrive to build sustainable data governance, oversight and risk management capabilities, rather than scrambling to assemble evidence when regulators come knocking," Fitzhenry said.