Moving People Podcast: Understanding the EU AI Act for EU and non-EU businesses
The EU Artificial Intelligence Act marks a significant moment in the global regulation of AI. As the world’s first comprehensive legal framework for artificial intelligence, it introduces a risk-based approach to the development, sale and use of AI systems across the EU, and, in some circumstances, beyond it.
In a recent episode of Spencer West’s Moving People podcast, James Clark, Partner specialising in data protection and digital regulation, including AI, in the UK, and Dr Peter Schneidereit, IT, data and cyber Partner in Germany, discussed what the AI Act means in practice for businesses operating in the UK and across Europe.
A law with reach beyond the EU
Although the AI Act is an EU regulation, businesses outside the EU should not assume it is irrelevant to them. As James explains, the Act can apply on an extraterritorial basis where a non-EU business places an AI system on the EU market or where the output of an AI system used outside the EU affects individuals in the EU.
For example, a UK-headquartered business selling an AI-enabled product into the EU, or using AI to make HR decisions affecting EU-based employees, may find itself within scope. For UK companies with European customers, employees or operations, this makes the AI Act a practical compliance issue rather than a purely European legal development.
Understanding the risk-based framework
The AI Act does not regulate every AI system in the same way. Instead, it uses a risk-based model. Certain AI practices are prohibited outright, including social scoring, some forms of biometric surveillance and systems designed to manipulate behaviour or infer emotions in the workplace.
The most significant obligations apply to “high-risk” AI systems. These include AI systems used as safety components in regulated products, such as medical devices, and systems used in areas such as recruitment, credit decisions, insurance and other contexts where AI may materially affect people’s rights, safety or access to essential services.
For businesses, the first step is therefore to map which AI systems they develop, buy, sell or deploy; identify whether they are acting as a provider or deployer; and classify each system by risk level. Only then can organisations determine which obligations apply.
Why GDPR compliance is not enough
While comparisons have been made between GDPR and the EU AI Act, Peter highlights an important distinction that the AI Act is not, at its core, a data protection law. While data protection remains highly relevant, particularly where personal data is used to train or operate AI systems, the AI Act is closer to product safety regulation. Its focus is on whether AI systems are designed, deployed and monitored safely.
That means existing GDPR programmes may be useful, but they will not provide a complete roadmap. Organisations – particularly those in regulated sectors – should instead look to their product safety, risk management, quality assurance and post-market surveillance frameworks, then assess what AI-specific controls need to be added.
Transparency and generative AI
The Act also introduces transparency obligations for certain AI systems, including generative AI tools and so-called deepfakes. Providers may need to ensure AI-generated content can be detected through machine-readable marking, while deployers may need to provide clear, human-readable notices where AI-generated or manipulated content is presented to the public.
As Peter notes, the definition of a deepfake under the AI Act is broader than many businesses may expect. It can extend beyond celebrity impersonations or false statements to AI-generated images, video or audio that portray people, places, objects or events in ways that did not actually occur.
The UK’s different approach
The UK has not adopted an equivalent to the EU AI Act. Instead, its approach is decentralised and regulator-led, with existing regulators such as the ICO, FCA, Ofcom and CMA expected to apply AI principles within their own remits. These principles include safety, transparency, fairness, accountability and contestability.
For businesses operating in both the UK and EU, however, there will often be significant practical overlap. The governance steps required for AI Act compliance – mapping systems, assessing risk, documenting controls, ensuring human oversight and managing data protection issues – are also likely to support good practice under UK regulatory expectations.
Practical next steps
James and Peter say that businesses should start by building an inventory of AI systems and use cases, identifying whether they are providers or deployers, classifying systems by risk, and reviewing existing governance frameworks. For high-risk systems, organisations should assess gaps in areas such as risk management, data quality, technical documentation, human oversight, incident reporting and audit readiness.
As James and Peter emphasise, the AI Act is still a developing area. The wording is broad in places, guidance is evolving and enforcement will depend partly on national authorities in each EU member state. A pragmatic, documented and risk-based approach will therefore be essential.
To hear the full discussion, including practical examples for UK businesses, EU-regulated sectors and deployers of AI systems, listen to the full podcast here.