AI Governance From Day One: What Retrofitting Compliance Costs
AI regulation is converging. Firms that build AI governance in from day one avoid the GDPR-style retrofit trap that cost the last cohort several times more.

In June 2020, a 180-person UK distributor we will call Northbridge Trading paid £142,000 to retrofit GDPR. That bought a Records of Processing register, three DPIAs, a breach playbook, six vendor agreements and a privacy-by-design CRM rebuild that the same consultants benchmarked at £28,000 had it been designed in two years earlier. The Operations Director who signed those invoices is now staring at the same cliff with AI.
Quick Answer. The EU AI Act arrives on a staircase, not a cliff: Article 4 literacy and most prohibited practices apply since February 2025, Annex III high-risk obligations from 2 December 2027, and UK firms serving EU customers are in scope. Design AI governance in from day one; retrofitting later costs an estimated 2.7–8.1 times more.
The retrofit invoice nobody planned for
Northbridge Trading is a composite, stitched from four real engagements between 2019 and 2021. We changed the names. The numbers are real. The pattern matters, because it is about to repeat.
In May 2018 Northbridge shipped GDPR with a £200 policy template and a sense the work was done. In May 2020 the first subject access request landed. A near-miss breach in the payroll integration followed, and an ICO complaint arrived a fortnight later. By Q3 2020 the company had hired external counsel and a privacy engineer. Between them they built a processing activities register, three data-protection impact assessments, an incident-response playbook, six vendor Data Processing Agreements and a CRM rebuild with privacy-by-design controls retrofitted into already-live data flows. The bill ran to roughly five times the design-in baseline the same consultancy had costed against the 2017 architecture, paid under regulatory pressure.
Six years on, the same Operations Director runs three AI tools deployed through 2025: a CV-screening assistant, a sales-call summariser and a customer-support chatbot. No AI register, no use-case risk classification, no Article 26 documentation, no Article 4 literacy curriculum. The EU AI Act entered into force on 1 August 2024 1. The post-Omnibus timeline puts Annex III high-risk obligations at 2 December 2027, and Article 50 transparency live from 2 August 2026 2. The CV-screening tool sits in an Annex III use case, and whether it is high-risk turns on Article 6(3). UK GDPR has bound this firm since it began processing personal data; the ICO's AI guidance is the regulator's interpretation of how that statute applies to AI — not a statutory code, but the baseline the ICO will assess against 7. "I refuse," he tells us, "to write that cheque a second time."
The convergence: why 'wait and see' stopped being prudent in 2024
The 'global convergence' that drives the design-in argument is not a marketing slogan. In 2024 the regulatory volume became measurable and the shared technical spine became visible.
The numbers regulators don't want you to overlook
Stanford HAI's 2025 AI Index records 59 US federal AI regulations issued in 2024, more than double 2023, across twice as many agencies 3. US states passed 131 AI laws in a single year, up from 49 cumulative through 2023. Legislative AI mentions rose 21.3% across 75 countries in 2024. For an Operations Director deciding whether to act now or wait, that volume is not background noise. It is the signal.
Regulation (EU) 2024/1689 took effect on 1 August 2024 1. The Commission's phased timeline is the clearest published roadmap available. Most prohibited practices have been live since 2 February 2025, though Article 113(a) holds parts of Article 5 back to 2 December 2026, and GPAI obligations since 2 August 2025, with models already on the market given until 2 August 2027 by Article 111(3). Article 50 transparency applies from 2 August 2026; the governance and penalty chapters, Chapters VII and XII, have applied since 2 August 2025 with the exception of Article 101. Annex III high-risk obligations apply from 2 December 2027, and embedded high-risk products under Annex I follow by 2 August 2028 2. That is not a single cliff. It is a staircase. SMBs that wait until the top step have already missed two.

The shared anchor: OECD, NIST, ISO/IEC 42001
Underneath the volume sits a shared spine that makes governance designed in early durable across jurisdictions. The OECD AI Principles, revised May 2024, have been adopted by 47 or more countries 4. They form the explicit basis for EU, UK, US and G7 alignment. The NIST AI Risk Management Framework 1.0 organises obligations around four functions: Govern, Map, Measure and Manage 5. The EU AI Act's standards programme references that core. The UK AI Playbook (February 2025) codifies 10 principles for government AI and signals equivalent standards for its supply chain 6.
ISO/IEC 42001 has become the procurement-grade certification mid-market buyers now ask for. Those frameworks share a spine: risk classification by use case, human oversight, logging, documentation. Governance designed against it survives any single-regime tightening. The shared spine absorbs the variation.
Why does 'the vendor handles compliance' collapse under Article 26?
The hardest sentence to write in any vendor's marketing page is: 'We cannot outsource the deployer's job to you.' Under the EU AI Act, the provider-deployer boundary is explicit. It does not move because you bought an enterprise tier.
The shared-responsibility model in plain English
Article 16 sets what the provider must do: conformity assessment, technical documentation, post-market monitoring 1. Article 26 sets what the deployer must do: use the system as instructed, assign human oversight to natural persons who have the necessary competence, training and authority and the support to exercise it, keep input data relevant and sufficiently representative in view of the intended purpose to the extent you exercise control over it, and keep the logs the high-risk system generates automatically — to the extent those logs are under your control — for a period appropriate to the intended purpose and at least six months, unless Union or national law provides otherwise. Article 26(7) adds a separate duty: an employer deploying a high-risk system at the workplace informs workers' representatives and the affected workers before use. Article 4 places an AI-literacy duty on the provider and the deployer, not on individual staff: take measures that support the development of AI literacy among your own staff and the other people who operate or use these systems on your behalf, judged on their technical knowledge, experience, education and training, the context the systems are used in, and the people they are used on. It does not require you to guarantee any individual's level. Article 50 is not one duty across all risk tiers but four, split by role and subject to their own exceptions. Paragraph 1 is a provider design duty for systems intended to interact directly with people. Paragraph 2 is a provider duty to mark synthetic output in a machine-readable, detectable form. Paragraphs 3 and 4 fall on the deployer, for emotion-recognition and biometric-categorisation systems and for deep fakes and text published to inform the public.
Which of these binds you follows the role you occupy, not your size. Article 4 binds providers and deployers today; Article 50 from 2 August 2026; Article 26 binds deployers of Annex III high-risk systems from 2 December 2027. Article 16 is a provider duty, and an SMB that only deploys a bought-in tool does not acquire it. The Annex I product route is narrower than the Annex III one: under Article 2(2) an Annex I Section B system is reached only by Article 6(1), Article 60a and Articles 102–112, with Articles 57–59 on the stated integration condition. Whatever does sit with you, the DPA a vendor signs does not reassign it.
What ChatGPT Enterprise and Copilot don't outsource
A UK SMB that pastes a CV into ChatGPT to screen candidates is deploying an Annex III use case 1. Whether that makes it a high-risk deployer turns on Article 6(3): the system is outside high-risk only if it poses no significant risk of harm to health, safety or fundamental rights and meets one of the conditions that paragraph lists — and an Annex III system that performs profiling of natural persons is high-risk regardless. Establishing which of those applies is the deployer's call. OpenAI's Enterprise Privacy page covers model-side guarantees: no training on business data, encryption, audit logs. It does not classify your use case, write your human-oversight protocol, train your staff, or maintain your Article 26(6) deployer logs. When those duties apply, a 40-person SMB running CV-screening AI will carry the same Article 26 obligations as a FTSE 100 employer. Company size is not in the classification rule.
Under UK GDPR the data-controller relationship follows the same logic. Personal data in a prompt makes the SMB the controller. Data subject rights are not delegable to a vendor.
The ICO has been clear since 2023
The ICO's AI guidance covers how UK GDPR principles apply to AI processing personal data, including DPIA requirements, bias mitigation and automated decision-making 7. The guidance is under review following the Data (Use and Access) Act 2025 14. That Act gained Royal Assent on 19 June 2025 and commenced on 19 June 2026. The ICO AI auditing toolkit provides concrete checklists across governance, accountability, transparency and individual rights 8. Those checklists describe what the deployer needs before the ICO visits, not after. Northbridge's three tools have none of it. The vendor's DPA covers the vendor. The gap belongs to the deployer.
The GDPR retrofit cost evidence: what we know empirically
The empirical case for designing governance in early is not built on intuition. It is built on what happened to EU firms that treated GDPR as an afterthought in 2018.
MIT Sloan / Bessen et al. — the only large-N retrofit study we have
The MIT Sloan / Bessen, Janßen, Peukert and Seamans study compared EU and non-EU firms after May 2018 enforcement began. The findings are direct. EU firms cut stored data by 26% and computation use by 15%, relative to non-EU controls 9. The reduction concentrated in the cohort that had not designed for privacy from the outset, the retrofit cohort. These were not fines or legal fees. They were operational disruptions: products discontinued, marketing datasets purged, integrations rebuilt from scratch. Companies that had designed privacy in from 2016 absorbed the same regulation without those cuts.
Northbridge Trading followed the retrofit path. It shipped GDPR compliance in 2018 with a £200 policy template and discovered the real cost two years later. The MIT Sloan data describes exactly what it paid for. It is the architectural rework that comes when you pull compliance obligations into a system that was not designed to carry them.
The 2.4x retrofit multiplier
Industry retrofit-cost benchmarks reach the same conclusion from the cost side. Late-adopter SMBs paid roughly 2.4 times what design-in competitors paid, across ROPA, DPIAs, lawful-basis registers, breach processes, DPA renegotiation and CRM rework.
Each of those GDPR categories maps directly onto an AI Act analogue. The AI register is our recommended counterpart to the GDPR Article 30 ROPA — the Act imposes no deployer register duty, and Article 30(5) exempts organisations under 250 employees from the ROPA unless the processing is likely to result in a risk to rights and freedoms, is not occasional, or involves Article 9 or Article 10 data. A Fundamental Rights Impact Assessment under Article 27 builds on the GDPR DPIA. The AI Act itself says the two complement each other. Article 26(6) log retention sits alongside the breach log rather than superseding it. The categories are the same. The entanglement is deeper, because you now maintain both layers at once. AI models, prompts and workflows are architecturally coupled in ways that data flows were not. Pulling logging hooks or oversight controls out of a deployed AI pipeline is an engineering rewrite, not a policy document. That is why the Northbridge multiplier of roughly 5× is not an outlier.
Cost arithmetic: design-in vs retrofit, line by line
The retrofit multiplier and the MIT Sloan operational data are useful anchors. But an Operations Director needs numbers she can put in a board paper. Here is the arithmetic for a 180-person SMB running three AI tools.
Design-in baseline for a 180-person firm with 3 AI tools
Designing AI governance in from the start, spread across twelve weeks, costs on our engagement experience:
- AI register and use-case risk tiering: 4-6 days internal effort plus a £2,000-4,000 consultant review
- Article 4 literacy curriculum (90-minute baseline for all staff; half-day for power users; full-day for AI owners): £3,000-5,000
- Human-oversight protocol, and the engineering to retain what Article 26(6) will require: £4,000-6,000 engineering plus a 2-day legal review
- Vendor due-diligence pack covering DPAs, model cards and GPAI disclosure trail: £2,000-3,000
Indicative all-in design-in: £18,000-32,000 across twelve weeks.
Retrofit budget under enforcement pressure (Q3 2026)
Retrofitting the same set under Q3 2026 pressure runs substantially higher:
- External counsel scoping Annex III exposure post-incident: £15,000-25,000
- FRIA (Article 27) and DPIA refresh on three already-deployed tools: £20,000-35,000
- Logging retrofit and human-oversight workflow rebuild: £40,000-70,000
- Worker consultation, transparency notices and customer disclosures: £8,000-12,000
Indicative all-in retrofit: £85,000-145,000 in six to twelve weeks of compressed remediation. Against the design-in range that is a multiplier of roughly 2.7× at the low end and 8.1× at the high end. Northbridge itself ran at about 5×, inside that span.
Why the multiplier is worse than GDPR
Three structural reasons push the AI retrofit multiplier above the GDPR figure. First, AI workflows are entangled. Prompts, model versions and downstream automated actions are coupled by design, so the refactor surface is larger than rewiring data flows. Second, procurement rebuilds run alongside the regulator deadline. An SMB losing RFPs while remediation runs pays both costs simultaneously. Third, the penalty ceiling is higher. Article 99 sets fines for prohibited practices at up to €35 million or 7% of total worldwide annual turnover, whichever is higher 1. The civil-liability route the Commission once proposed alongside it no longer exists: the AI Liability Directive proposal was withdrawn in October 2025 15.
For a UK SMB on £25 million annual turnover, Article 99(4) sets, for the non-compliance it lists — which includes the Article 26 deployer obligations — a fine of up to €15,000,000 or 3% of total worldwide annual turnover, whichever is higher. Article 99(6) then makes the percentage or the fixed amount, whichever is lower, the ceiling for an SME, so for this firm the 3% figure governs: roughly £750,000 1. That is a ceiling rather than a starting point. The design-in cost is not a compliance overhead. It is a hedge against a fine that is a multiple of itself.

The seven artefacts of day-one AI governance
Day-one AI governance for a 50-500 employee SMB is not abstract. It is seven artefacts you can stand up in a fortnight.
1-3: Inventory and classification
Artefact 1 — AI register. A one-page schema: system name, vendor, model, use case, data classes, risk tier, owner, oversight protocol and review date. It does not require a consultant to build. It requires discipline to maintain.
Artefact 2 — Use-case risk-tiering decision tree. Mapped to Annex III categories: employment screening, credit scoring, education access, biometric identification and critical infrastructure 1. A tool enters Annex III only when its exact intended use matches one of those entries and the entry's own conditions; Article 6(3) then decides whether it is high-risk, and an Annex III system that performs profiling of natural persons is high-risk regardless.
Artefact 3 — Vendor due-diligence pack. Data Processing Agreement, model card, GPAI disclosure, conformity-assessment summary and sub-processor list. The GPAI Code of Practice signatory status of the underlying provider matters here 13.
4-5: Operate and protect
Artefact 4 — Human-oversight protocol. Article 26(2) requires the deployer to assign oversight to natural persons who have the necessary competence, training and authority, and the support to exercise it 1. The capabilities those people need — to interpret the output, to disregard or override it, to stop the system — are the ones Article 14(4) says the oversight measures must enable, as appropriate and proportionate. Article 14(3) supplies the two routes to them: measures the provider builds into the system where that is technically feasible, and measures the provider identifies as appropriate for you to implement. Naming an individual is our recommendation, not the Act's requirement. The protocol specifies who that person is, the override workflow, escalation criteria and review cadence.
Artefact 5 — Article 4 AI-literacy curriculum. Our recommended shape: a 90-minute baseline for all staff, half a day for power users, a full day for AI owners, refreshed annually. Article 4 prescribes no curriculum, duration or cadence. It requires measures that support the development of AI literacy, judged on technical knowledge, experience, education and training, the context of use and the people the systems are used on 1.
6-7: Document and respond
Artefact 6 — Logging and incident process. Article 26(6) asks a deployer to keep the logs the high-risk system generates automatically, to the extent they are under its control, for a period appropriate to the intended purpose and at least six months unless other law provides otherwise. Around that we recommend model-drift monitoring and the security lifecycle controls from the NCSC's Guidelines for Secure AI System Development, joint guidance with CISA and 21 international cyber agencies 10. Build the log into the architecture. Policy documents without engineering hooks fail at audit.
Artefact 7 — Transparency and worker-information pack. The Article 50 disclosures that fall on you for the systems you actually run — paragraph 3 and 4 duties as a deployer, and paragraphs 1 and 2 only where you are the provider — Article 26(7) worker information where you deploy a high-risk system at the workplace as an employer, and a clear complaint route 1.
Anchored to regulator-blessed frameworks
Each artefact maps to the ICO AI auditing framework's governance and accountability checklists 8 and the NIST AI RMF core: Govern, Map, Measure and Manage 5. ISO/IEC 42001 maps onto the same seven-artefact set. Build these once and they satisfy multiple regimes simultaneously.
Procurement is the enforcement mechanism your customers brought forward
Every SERP result frames AI Act enforcement through the regulator-fines lens. None mention what UK SMBs selling into mid-market and enterprise are already finding in 2026. The buyer's questionnaire got there first.
What mid-market and enterprise buyers now ask for
Vendor questionnaires in late-stage UK RFPs now reference ISO/IEC 42001 control families and the NIST AI RMF four-function core 5. They ask for evidence of an AI register and use-case risk tiering, a documented human-oversight protocol against Article 26(2) 1, and sub-processor disclosure with GPAI model lineage. That means which foundation model, which provider, which Code of Practice signatory 13. Procurement teams are not waiting for enforcement guidance. They are protecting their own supply chains against the liability that flows upstream when a vendor's AI tool triggers an incident.
The seven artefacts from the previous section are exactly what a Section 9 vendor questionnaire asks for.
Northbridge loses an RFP in Q2 2026
Northbridge Trading tendered for a £420,000 three-year contract with a regulated mid-market customer in Q2 2026. Section 9 read: 'Maintain an AI register, FRIA process and human-oversight protocol — provide evidence.' Northbridge could not answer. The contract went to a competitor with a one-page register and a NIST-shaped policy stack. The procurement-driven rebuild now sits on top of the regulator deadline. Both clocks are running.
Public-sector inheritance
UK SMBs selling into government face the same standard through a different channel. The government's AI Playbook published in February 2025 sets out 10 principles covering ethical use, accountability, transparency and lifecycle management, and suppliers inherit them as contract conditions 6. The DSIT AI Opportunities Action Plan, accepted in full in January 2025, reinforces responsible AI deployment as a supply-chain expectation 11. The CMA AI Foundation Models Initial Report adds a consumer-protection and competition lens that overlays any foundation-model deployment 12.
Staying below the regulator's radar does not save you from the buyer's questionnaire. Northbridge found that out the expensive way.
What the Digital Omnibus does — and does NOT — defer
The November 2025 Digital Omnibus headline ('EU delays AI Act') does not survive a careful read of the actual text. The confusion is understandable. The headline is not accurate.
What the Omnibus did not defer
Four obligations already apply and the Omnibus deferred none of them. That is a narrower claim than saying it left them untouched: Regulation (EU) 2026/1744 rewrote the wording of Article 4 without moving its date, which is why the literacy duty described earlier in this article is the current one rather than the 2024 text. Most of the prohibited-practices ban has been live since 2 February 2025 2; Article 113(a) holds Article 5(1) points (ba) and (bb) and Article 5(1a) and (1b) back to 2 December 2026, so that part is not yet in force and is not what this paragraph is about. The Article 4 AI-literacy duty has been live since 2 February 2025 1. The GPAI provider obligations and Code of Practice regime went live on 2 August 2025, though Article 111(3) gives models placed on the market before that date until 2 August 2027. And UK GDPR is already binding on every UK organisation processing personal data, SMBs included; the ICO's AI and data protection guidance is the regulator's interpretation of how that statute applies to AI systems — not a statutory code, but the practical compliance baseline the ICO will assess against 7.
What the Digital Omnibus actually defers
The Omnibus defers the Annex III high-risk regime — the conformity assessment, technical documentation and EU-database-registration requirements for providers, together with the deployer-side duties that ride with it, Article 26 obligations and FRIA documentation under Article 27 — to 2 December 2027. It does not defer Article 50 transparency requirements or Article 4 literacy duties, and it does not touch those prohibited practices and GPAI obligations that are already in force. Those obligations remain on the published schedule.
The Digital Omnibus is no longer a proposal. The European Parliament endorsed it on 16 June 2026, the Council gave its final approval on 29 June 2026, and the act was signed on 8 July 2026 under procedure 2025/0359(COD). Regulation (EU) 2026/1744 was published in the Official Journal on 24 July 2026 16, and the consolidated AI Act carries the 27 July 2026 version date 1, so the deferred dates — 2 December 2027 for Annex III high-risk systems and 2 August 2028 for Annex I embedded systems — are settled. Plan against them; the direction of travel is not in doubt. SMBs that read 'postponed to 2027' and deferred governance design based on that reading are already behind the duties that never moved.
The stable core the Omnibus did not defer
Three things the Omnibus did not defer: the GDPR DPIA, the Article 4 literacy duty — whose wording it rewrote without moving its application date — and Article 50 transparency from 2 August 2026. The rest of what an SMB thinks of as the core — Annex III risk classification, Article 26 oversight and log retention, the Article 27 FRIA — is precisely what the deferral moves to 2 December 2027, that being the Article 6(2)/Annex III route to which Article 27 belongs. What the deferral changes is when those obligations bite, not whether an SMB is better off with a register, an oversight protocol and an incident process before they do.
How can a small business build AI governance in 12 weeks?
Twelve weeks is enough to deliver governance designed in from the start if the work is sequenced. Here is the week-by-week plan for a 50-500 employee SMB starting from zero.
Weeks 1-3 — Inventory and classify
Discover every AI tool in use, including shadow AI: Copilot embedded in Microsoft 365, browser-extension AI, niche SaaS modules with AI features your procurement team never explicitly evaluated. Stand up the AI register and assign an owner per system. Run the use-case risk-tiering tree against Annex III and flag any exposure in HR screening, credit scoring, education, biometric identification or critical infrastructure 1. Run a quick legal-basis review under UK GDPR for each system processing personal data 7.
Weeks 4-7 — Operate and document
Draft the human-oversight protocol for each high-risk and limited-risk system: named human, override workflow, escalation criteria, review cadence (Artefact 4). Retain the logs your high-risk platforms generate automatically, so far as those logs are under your control, for a period appropriate to the purpose and at least six months unless other law says otherwise — that is what Article 26(6) asks. Where a platform generates none, building your own log is our recommendation rather than the Article's demand. Do not leave this to policy documents 8. Run the Article 4 AI-literacy curriculum: 90-minute all-staff baseline first, then power-user and AI-owner depth sessions 1. Refresh DPIAs against the ICO toolkit where UK GDPR applies. Refresh the Article 27 FRIA separately — the toolkit does not cover it — and only where Article 27 binds you: it names its deployer classes and Annex III categories, and Article 35 turns on processing likely to result in a high risk to rights and freedoms.
Weeks 8-12 — Procurement-ready and review
Build the vendor due-diligence pack: DPAs, model cards, GPAI lineage, sub-processor lists and Code of Practice signatory status for each foundation-model provider 13. Publish the Article 50 disclosures that fall on you, checking whether each system makes you the provider or the deployer; where you deploy a high-risk system at the workplace as an employer, inform workers' representatives and affected workers under Article 26(7) 1. Map the seven artefacts against the procurement questionnaire format mid-market buyers send: ISO/IEC 42001 control families and NIST AI RMF functions 5. Schedule the first quarterly governance review and appoint a senior-management accountable owner per the ICO toolkit requirement 8.
Two anti-patterns to avoid
First: buying a £40,000 tooling subscription before the register is filled. Tooling without governance scope is theatre. The tool surfaces risks the SMB has not defined yet.
Second: treating Article 4 literacy as a one-off webinar. The duty has no discharge event, and it is judged on the factors Article 4 lists rather than on role alone 1. A 90-minute launch session satisfies our baseline; it does not satisfy the annual refresh or the deeper sessions for AI owners. The architectural rewrite that GDPR retrofitters paid for came because policy documents were written and engineering was skipped. The same pattern, applied to AI, produces the same result.
Lesson learned
The lesson Northbridge already paid for
In June 2020 the Northbridge Operations Director signed £142,000 of invoices to retrofit GDPR against a £28,000 design-in baseline. That was not a procurement failure. It was what happens when a competent operator treats compliance as something to layer on once the product works. The MIT Sloan data turns that experience into a pattern: EU firms cut stored data 26% and computation 15% post-2018, with the impact heaviest among firms that had not built privacy in from day one 9. The AI Act is about to teach that lesson a second time.
AI governance retrofits run worse because logging, human oversight and prompts are entangled with workflow architecture. Procurement is enforcing the Act before regulators do. The seven artefacts cost £18,000-32,000 to design in; they cost £85,000-145,000 to retrofit under enforcement and procurement pressure together. The arithmetic is not subtle.
Summary
AI governance from day one — why retrofitting costs more │ ├─ The retrofit trap │ ├─ GDPR precedent — one SMB paid ~5x to bolt it on late │ ├─ AI Act is worse — prompts & logs entangle with workflow │ └─ The numbers — design-in £18-32k vs retrofit £85-145k │ ├─ You can't outsource it │ ├─ Article 26 — the deployer's job stays with the SMB │ └─ Buying Copilot — vendor covers the model, not your use case │ └─ Act now, not in 2027 ├─ Procurement first — RFP questionnaires enforce before fines ├─ Omnibus myth — it defers providers, not deployer duties └─ Seven artefacts — register, oversight, logging, literacy
Related insights
- Local LLM vs Cloud LLM Data Security: The Wrong Question (2026) — the data-classification and DLP control set that the seven governance artefacts assume is already in place.
- Human-in-the-Loop Isn't Oversight. It's a Design Discipline. — how the Article 26 human-oversight duty becomes a working threshold system rather than a sign-off ritual.
- 50 Questions to Ask Before Implementing AI: SMB Buyer's Guide — buyer-stage diligence that surfaces governance artefact gaps before the procurement signature, not after.
Last updated: 3 September 2026.
Frequently Asked Questions
When does the EU AI Act take effect for UK firms, and what obligations are already live?
How much does it cost to retrofit AI governance versus designing it in for a 180-person firm?
Does buying ChatGPT Enterprise or Microsoft Copilot transfer EU AI Act compliance to the vendor?
What does day-one AI governance actually look like?
Does the November 2025 Digital Omnibus delay the EU AI Act enough that you can wait?
What is a Fundamental Rights Impact Assessment (FRIA) under EU AI Act Article 27, and who must conduct one?
Will ISO 42001 certification help with EU AI Act readiness, or are they separate compliance tracks?
Sources
- 1.Regulation (EU) 2024/1689 — Artificial Intelligence Act, consolidated text of 27 July 2026 — European Parliament and Council of the European Union · 2026
- 2.Regulatory Framework on AI — European Commission · 2024
- 3.2025 AI Index Report — Chapter 6: Policy and Governance — Stanford Institute for Human-Centered AI (HAI) · 2025
- 4.AI Principles (revised May 2024) — OECD · 2024
- 5.Artificial Intelligence Risk Management Framework (AI RMF 1.0) — NIST · 2023
- 6.Artificial Intelligence Playbook for the UK Government — UK Government Digital Service / DSIT · 2025
- 7.Guidance on AI and Data Protection — Information Commissioner's Office (ICO) · 2023
- 8.AI and Data Protection Risk Toolkit / AI Auditing Framework — Information Commissioner's Office (ICO) · 2023
- 9.GDPR's Effects on Firm Data and Computation Use (Bessen, Janßen, Peukert, Seamans) — MIT Sloan · 2022
- 10.Guidelines for Secure AI System Development — National Cyber Security Centre (NCSC) · 2023
- 11.AI Opportunities Action Plan — UK Department for Science, Innovation and Technology (DSIT) · 2025
- 12.AI Foundation Models: Initial Report — Competition and Markets Authority (CMA) · 2023
- 13.Guidelines for Providers of General-Purpose AI Models — European Commission · 2024
- 14.One year on: marking the 12-month commencement of the Data (Use and Access) Act — Information Commissioner's Office · 2026
- 15.Withdrawal of the proposal for an AI Liability Directive (2022/0303/COD), 6 October 2025 — European Commission · 2025
- 16.Regulation (EU) 2026/1744 amending Regulation (EU) 2024/1689 — European Parliament and Council of the European Union · 2026
Want this run on your business?
AI Foundation Audit — a structured assessment of your AI footprint: integration risks, governance gaps, ROI opportunities. Delivered as a comprehensive report you can act on.
You receive your AI Opportunity Report and Implementation Brief — tailored to your business and delivered immediately.