The EU AI Act came into full force in August 2024 and its obligations are now binding. For UK businesses operating entirely domestically, the Act has no direct legal effect. But for any organisation that sells to EU customers, procures from EU suppliers, or processes data involving EU citizens, the implications are very real.
What the EU AI Act requires
The Act categorises AI systems by risk level — from minimal risk (such as spam filters) through to prohibited applications (such as real-time biometric surveillance in public spaces). High-risk AI systems, which include those used in employment decisions, credit scoring, and critical infrastructure management, face significant compliance obligations: mandatory risk assessments, human oversight requirements, and registration in the EU's AI database.
How ISO 42001 fits in
ISO 42001:2023 — the international standard for AI Management Systems — is not legally mandated by the EU AI Act, but it is widely recognised as a practical framework for demonstrating compliance with many of the Act's requirements. Organisations that have implemented ISO 42001 will find that their risk assessment processes, documentation practices, and governance structures map closely to what the Act requires.
For UK businesses seeking to demonstrate trustworthy AI governance to EU customers or partners, ISO 42001 certification is becoming an increasingly credible signal — much as ISO 27001 became the de facto proof of information security competence in the years following GDPR.
What to do now
If your business develops, deploys or procures AI systems that interact with EU customers or markets, the steps to take are straightforward. First, identify which AI systems you use or develop, and assess their risk category under the Act. Second, review whether any of those systems interact with EU customers or are embedded in EU supply chains. Third, consider whether ISO 42001 implementation would provide a practical compliance framework and a credible differentiator.
Anacruses has been working with ISO 42001 since its publication and is actively involved in the BSI BridgeAI standards community. If you would like to understand what ISO 42001 implementation would involve for your business, get in touch for a free initial conversation.
Frequently asked questions
Does the EU AI Act apply to UK businesses?
The EU AI Act applies to any organisation that places AI systems on the EU market or puts AI systems into service in the EU — regardless of where the organisation is based. UK businesses that sell to EU customers, process data involving EU citizens, or operate in EU supply chains may have obligations under the Act, even though the UK is no longer an EU member state.
What is a high-risk AI system under the EU AI Act?
High-risk AI systems are those used in specific sectors and use cases listed in Annex III of the Act, including AI used in employment and recruitment decisions, credit scoring and financial services, critical infrastructure management, biometric identification, and education or vocational training. High-risk systems face significant compliance obligations including mandatory risk assessments, human oversight, and registration in the EU AI database.
How does ISO 42001 help with EU AI Act compliance?
ISO 42001:2023 is not legally mandated by the EU AI Act, but its framework maps closely to many of the Act's requirements. Organisations that have implemented ISO 42001 will find that their AI risk assessment processes, documentation practices, and governance structures align well with what the Act requires — making it an efficient route to demonstrating compliance, particularly for high-risk AI systems.
What should UK businesses do now about the EU AI Act?
UK businesses with EU exposure should first identify which AI systems they develop, deploy, or procure, and assess their risk category under the Act. Second, review whether any of those systems interact with EU customers or are embedded in EU supply chains. Third, consider whether ISO 42001 implementation would provide a practical compliance framework and a credible differentiator.
Ready to talk about your business?
Book a free, no-obligation call. We will tell you exactly what certification would involve for your size, sector, and starting point.
