EU AI Act: Experiments to Regulated Business Operations
John Woolley

The EU AI Act is the world's first comprehensive law on artificial intelligence, and its timeline is now biting. Prohibited practices have applied since February 2025. Obligations for general-purpose AI models landed in August 2025. From August 2026, the substantive duties for high-risk AI systems apply in full.
The Act takes a risk-based view. A handful of uses are banned outright. A defined set of high-risk uses, spanning employment, access to essential services, education and more, carry real obligations. Most other AI carries lighter transparency duties. The reality is that the moment you let a model read, sort, label or route your documents, you are operating an AI system, and the standard of care regulators now expect is the high-risk standard.
AI use has moved from an experiment to an operating model and therefore demands provenance, logging, human oversight and data governance.
The Act asks a number of things from high risk AI systems.
Risk management. A live process that identifies where the system can go wrong and manages it, rather than a one time sign-off.
Data governance. Control over the data the system uses, its quality, its sensitivity and its lifecycle
Record-keeping and logging. Automatic, tamper-evident logs so events can be traced after the fact
Transparency. Enough information for the people using the system to understand and interpret its output
Human oversight. Real people who can review, override and stop the system, not a rubber stamp
Accuracy and robustness. Evidence that the system performs as claimed and improves over time.
If you sell products or services into Europe, or use AI in hiring or access to services for European customers, this law applies to you, even if you’re not based in the EU.
So for most businesses, this turns AI from experimental tooling into a regulated part of the operating model. Even if your system is not formally classified as high risk, customers and regulators will increasingly expect a high risk standard of care: clear provenance, logging, human oversight and data governance.

