Glossary · AI governance and risk

EU AI Act

The European Union’s regulation on artificial intelligence, Regulation (EU) 2024/1689, which sets obligations according to the risk an AI system poses. It prohibits certain practices, imposes substantial requirements on high-risk systems, adds transparency duties for some others and regulates general-purpose AI models.

Why it matters

The Act applies beyond the EU’s borders: UK and other non-EU organisations can be in scope if they place AI systems on the EU market or if their systems’ outputs are used in the EU. Obligations differ for providers, deployers, importers and distributors, so organisations first need to know which role they play.

The Act entered into force in August 2024 and its obligations apply in phases, with some timelines subject to later revision. Leaders should track the current position and treat an AI inventory and risk classification as the starting point for readiness.

In practice

For example, a UK HR software company selling a candidate-screening feature to EU customers would need to assess whether the feature falls within the Act’s high-risk category for employment and, if so, plan for risk management, data governance, technical documentation, human oversight and conformity assessment.

Where Rodan fits

Rodan helps teams build the technical evidence that AI regulation expects, such as documentation, evaluation and oversight, into systems delivered through AI and Decision Systems. See also AI governance for mid-market companies.

Related terms