AI governance and the law
Governance is what lets you use more AI, not less.
We are not here to tell anyone to stop. The businesses that get the most out of AI are the ones that can say what it is doing, who is accountable for it, on what evidence. That is what makes expansion defensible instead of risky.
The legislation below is already moving. Some of it is in force today. The rest arrives on dates that are now fixed. What follows is what applies, when, plus what a board is expected to be able to show.
The signature has not moved. The evidence behind it has.
Accountability for a decision does not transfer when the input to that decision starts being produced by a machine. The person who signs stays the person who signs.
What changes is that the evidence underneath the signature is now shaped by a tool the signer did not build, cannot inspect, often did not procure, frequently does not know is there. Your suppliers adopted it before you asked them to.
That is the governance problem. It is not a technology problem, which is why buying a better tool does not close it.
In force today
Three obligations that already apply.
AI literacy, Article 4
Applied from 2 February 2025. Anyone who operates or oversees an AI system must have sufficient AI literacy for their role. It is an obligation on the organisation, not on the individual.
Transparency, Article 50
Deployer-facing transparency obligations apply from August 2026. Machine-readable marking of generative output under Article 50(2) follows on 2 December 2026.
Deployer duties on high-risk systems, Article 26
Human oversight assigned to named people with the competence, training and authority to exercise it. Operational monitoring. Automatically generated logs retained for at least six months.
Fixed dates ahead
The deadline most boards have is the wrong one.
Boards that have looked at AI regulation usually found the AI Act, noted that the high-risk obligations were deferred, then moved on. The deferral is real. It is also not the first date that bites for a business that makes things.
EU Machinery Regulation 2023/1230
Safety components with fully or partially self-evolving behaviour, plus machinery with embedded systems of the same kind, move into third party conformity assessment. It catches manufacturers, importers, distributors, plus in some cases the integrator who changed the machine after it shipped.
AI Act Annex III high-risk systems
Standalone high-risk obligations. Deferred from August 2026 by the Digital Omnibus. Deferred, not cancelled.
AI Act Annex I, AI embedded in products
The product route. Machinery, medical devices, vehicles. Relevant to any business that manufactures rather than only uses.
The Machinery Regulation arrives nineteen months before the AI Act route that catches the same companies, through a conformity assessment their product already goes through. A manufacturer working to 2028 has the date wrong.
UK businesses operating abroad
The UK has no AI Act. That is not the same as being out of scope.
Since Brexit a UK company is a third country operator under the AI Act. It is caught where it places an AI system on the EU market. It is caught again where the output of its system is used by people in the EU, wherever the company itself is established.
A non-EU provider of a high-risk system must appoint an authorised representative inside the EU before making it available. A deployer must keep use within the documented scope, apply human oversight, ensure staff AI literacy and retain the logs.
Governance designed for one office does not hold across three. Where a business operates in several regions, the work is establishing which regime applies where, then building something that holds in all of them rather than in the headquarters.
Governance starts at the top, because that is where the accountability already sits.
Expectations set at board level are what filter into the workplace. Where they are not set, people adopt tools anyway. The organisation finds out afterwards.
The exposure is rarely technical. It is a director who cannot say which decisions in the business already rest on a machine-shaped input, in front of a regulator, an insurer, an acquirer or a board that has just been asked.
For a listed business, the UK Corporate Governance Code 2024 sharpens this. Provision 29 requires a board declaration on the effectiveness of material internal controls for financial years beginning on or after 1 January 2026, which makes 2026 the year the evidence gets built. It applies on a comply or explain basis to premium listed companies. For a private company it is not a duty, it is the standard your investors and acquirers measure you against.
The judgement a board needs is proportionality. Low risk and low value needs governance light enough to stay out of the way. High risk and high return needs more control, more mitigation and real investment, because that is where the return is. Knowing which one you are looking at is the skill.
The standards
Legislation says what. The standards say how.
ISO/IEC 42001:2023
The AI management system standard, the only one with an accredited certification route. A.7.5 requires data provenance. A.10.3 puts suppliers inside the system. A.6.2.4 covers verification and validation. A.5 is the impact assessment a board can actually read.
Annex D states that the management system is designed to plug into the ones you already run, naming ISO 9001, ISO/IEC 27001 and sector standards including ISO 22000. It is not a parallel system.
ISO 55001:2024
For asset-owning businesses, the 2024 revision already asks the question. Clause 7.6 is new and requires documented processes for managing data and information, with attributes, quality and sources specified. Clause 4.5 is new and requires a written framework for decision making.
If you hold 55001 you already owe an answer on where your data comes from. Clause 10.3, predictive action, is the same standard opening the door to the tools this page is about.
Integr8te works to these standards and helps write the guidance behind them. Our founder is a BSI Lead Auditor for ISO 9001 and ISO/IEC 42001, co-chairs OEUK’s Asset Integrity Technical Group alongside the HSE principal mechanical regulator, plus supports the writing of the Energy Institute guidance on the use of big data and AI in integrity data.
Where this lands hardest
High hazard, high commercial value, international where the legal position has to hold in more than one country. Manufacturing and machinery. Food, drink and alcohol, where the certificate rests on records. Marine and shipbuilding, where class signs on evidence produced by a supply chain the yard integrated but did not write. Energy, where the regime is hardest and where we have held the seat.
The signature has a different name in each of them. The problem underneath is the same one.
The first step is bounded on purpose.
The Undeclared AI Review maps where machine-shaped data already sits under decisions your people sign, who signs them today, plus what to fix in the next 90 days. It is remote, it runs in ten working days, it ends in a one page summary written for the board.
Fixed scope. Fixed price. A finding you own either way.
Integr8te advises on governance and compliance readiness. We do not provide legal advice. Dates on this page were verified on 29 August 2026 against the Digital Omnibus on AI, Regulation (EU) 2026/1744, in force 27 July 2026.