What the EU AI Act means for UK businesses
The EU AI Act is the world’s first comprehensive horizontal regulation on artificial intelligence. It's designed to ensure AI development within the EU is ethical, trustworthy and safe. For UK leaders, that means "business as usual" is over – global operations require immediate alignment. Most provisions of the EU AI Act will be applicable by August 2026, which means now is the time to act. But organisations that choose to comply with the framework only out of necessity risk missing the bigger opportunity. Embedding trust into your core AI infrastructure is the new baseline for competitive advantage.
Why the EU AI Act matters to your UK business?
The EU AI Act regulates artificial intelligence across the European Union, balancing fundamental rights and public safety with technological innovation. Effectively, the goal is to end the 'Wild West' era of AI. And for those that don't comply, there are hefty fines.
Although your business may be non-EU-based, the EU AI Act is extraterritorial. It applies to your business if you:
- Provide AI systems for use within the EU.
- Have AI system outputs that are used within the EU.
- Serve clients based in the EU.
The legislation is now live, and compliance for "high-risk" AI systems will be enforced from August 2026. Penalties will be imposed for identified breaches.
Key points to note:
- The EU AI Act has extraterritorial reach. If your AI output is used within the EU, this legislation applies to you.
- EU AI Act prohibitions are already live. High-risk requirements land in August 2026.
- HR and Finance are key "high-risk" categories.
- Fines reach up to €35M or 7% of global annual turnover.
'The global competition for Artificial Intelligence leadership is often framed as a race for speed, where those with the fewest rules get ahead. However, a different narrative is emerging from Europe: one where trust, responsibility and regulatory foresight provide a competitive advantage.'
– Daniel Pell, in conversation with best-selling author and AI expert Bernard Marr and Workday EMEA lead Graham Abell.
For more on this topic, check out this Workday blog post: Europe AI opportunity: why trust and regulation are the new engines of innovation.
What is the EU AI Act?
The EU AI Act categorises AI applications into four risk levels: prohibited, high risk, limited and minimal.
- Prohibited – systems that are deemed an unacceptable risk to the safety, livelihoods and fundamental rights of people. This includes social scoring systems that lead to unfavourable treatment, manipulative AI that causes significant harm, and untargeted scraping of images for facial recognition.
- High risk – systems that have the potential to significantly harm a person's health, safety or fundamental rights. Examples include tools used in recruitment and employee management, and systems to determine credit scores or financial risk. You can only use these systems with strict controls in place.
- Limited risk – systems where the risk of harm is low. This includes chatbots, and systems that generate and manipulate audio, image and video content.
- Minimal risk – systems that pose a negligible risk to someone's safety or fundamental rights. Examples include: spam filters; AI for inventory management; AI for internal productivity use, such as drafting non-sensitive documents or generating presentations.
By their nature, AI finance and HR systems should be treated as high-risk.
The origins of the EU AI Act
The EU AI Act first came about in 2021 with a European Commission proposal to regulate AI within the EU. Its aim was to create a risk-based framework with the goal of fostering trustworthy AI.
The text of the Act was provisionally agreed on in December 2023. It was finally approved by the European Council in May 2024, and was put into force on 1 August 2024. It outlined a series of enforcement and compliance milestones to come into force between 2025 and 2027.
How the EU AI Act impacts core business functions.
The next key EU AI Act deadline is August 2026. From this date, if your AI systems are classed as high-risk, you're expected to be fully compliant with your obligations. You must have risk management, technical documentation and human oversight in place by this date. The fines for non-compliance can be up to €35m or 7% of your company's turnover.
Key areas to prepare for include:
Impact on HR and people strategy
AI tools for HR represent a significant opportunity for your business. But if you use them, the EU AI Act mandates that you must include strict transparency and bias mitigation rules. You must also include effective human oversight. Areas to consider include:
- recruitment and CV screening.
- assessments and interviews.
- appraisal and promotion decisions.
- workplace management systems.
As an HR leader, it's your responsibility to ensure compliance through good data management and protection. It's also mandatory to deliver AI literacy training to relevant team members, and have transparent communication with your workforce about how you're using AI.
To learn more about Workday's responsible AI HR solutions, read our AI in HR blog post, or ask for a demo of our Talent Optimisation and Workforce Management tools.
Impact on recruiting and talent acquisition
The EU AI Act categorises AI recruitment systems as high risk. So, if you use them, you must implement the following steps:
- Candidate transparency: tell candidates if you are using an AI screening tool as part of your recruitment process.
- High-quality data management: ensure all the datasets you use for training, validation and testing are relevant and representative. It's critical to ensure they're free of any errors that could lead to discriminatory outcomes for anyone with a protected characteristic..
- Continuous bias monitoring: regularly audit and test any AI tools you use for recruitment, and actively check for any evidence of bias against protected groups. If you find any evidence of bias, you must correct it immediately, documenting what you found and how you resolved it.
- Prohibited AI technologies: since February 2025, some AI technologies have been prohibited for workplace use. This includes AI systems that categorise candidates based on sensitive or protected characteristics. It also includes AI systems for emotion recognition.
Impact on finance and spend management
Under the EU AI Act, systems for credit scoring and risk assessment are also in the high-risk category. The Act requires the following:
- Credit scoring and risk assessment: if you're using AI for these purposes, you must have a risk management system to identify and eliminate discriminatory biases. You must also have regular human oversight built into your system, and maintain technical documentation that supports this.
- Transparency and 'explainable AI': financial models can no longer operate as un-auditable black boxes. If an AI platform flags a treasury anomaly or generates a risk score, compliance mandates a clear ledger of algorithmic intent. You must be able to explain and audit every automated forecast or spend optimisation.
Considerations for IT and security
Under the EU AI Act, if you're using a high-risk AI system, then your IT team must maintain and document strict, auditable and technical compliance standards. This must include details of the system design, training datasets and intended purpose. The documents must be regularly updated for as long as you're using your high-risk AI.
The ISO 42001 standard provides a useful management framework for you to generate and maintain these systems.
Disclosure rules for generative AI use
If you're using AI to generate content such as text, images, audio or video, you must clearly label this content as being AI-generated.
For synthetic audio and video media (often known as deepfakes), wherever it's technically feasible, you should include a digital watermark or other marker that indicates the content's AI origin. You should also include machine-readable markers that identify the AI creator.
Did you know?
A 2025 study from LSE estimated that using AI in the workplace can boost productivity by the equivalent of one day per worker per week.
https://www.lse.ac.uk/news/ai-boosts-productivity-by-the-equivalent-of-one-workday-per-week-new-report-finds
Strategic advantages of early adaptation to the EU AI Act
As well as ensuring your business is protected from fines for non-compliance, getting ready for the EU AI Act could benefit you in lots of ways.
Building digital trust with candidates and employees
By embedding compliance-by-design principles into your core framework today, you build verifiable trust with your employers and attract high-quality talent.
Future-proofing your global operating model
Even if you're not operating in the EU right now, proactive compliance sets you up for future expansion.
Enhancing data quality through rigorous governance
Enhance your business's data quality and improve decision-making with rigorous overall governance.
With our help, you can learn how to turn regulatory compliance into a competitive advantage. Have a look at the Workday AI Governance Playbook to get started.
Navigating the barriers to compliance
The 'black box' problem and explainability
AI models are complex, and many people find them intimidating or even threatening. It's important to explain to everyone involved in using AI exactly how the models work, and what steps are being taken to ensure they're fair. This is one area where the EU AI Act can help your business – explainability is a key requirement if you're using AI for high-risk systems.
The cost of continuous technical documentation
Maintaining the documents you need to demonstrate compliance takes time and resources. To overcome these systemic documentation barriers, you need automated architecture. Organisations must move away from manual compliance checklists and embrace centralised data engines that automatically log model training datasets, testing parameters, and human oversight interventions.
Closing the AI literacy gap in the C-suite
Looking for a readable, business-focused guide to help your senior team get up to speed? The Workday GO AI Opportunity eBook helps everyone get their heads around the opportunities and challenges of the AI revolution.
A five-step roadmap for compliance
1. Inventory your AI systems and identify risk tiers.
Do a thorough audit of every part of your business that uses AI. Categorise all the AI systems into high risk, limited risk and minimal risk. We can help you create a structured, risk-based approach that prioritises key actions to ensure you're in full compliance.
2. Establish a cross-functional AI Governance team
Remember that compliance with the EU AI Act is a company-wide responsibility. Everyone needs to understand their roles and responsibilities.
3. Audit your third-party vendors
Make sure you and your vendors are all operating to the principles of Compliance by Design – proactively integrating legal, regulatory and security requirements from the very start of the design process. Our centralised platform for AI Risk Management and Vendor Assessments makes it simple to stay on top of everything.
4. Implement Fundamental Rights Impact Assessments (FRIAs)
These are processes you need to implement before deploying AI to proactively check that your system is not at risk of violating anyone's fundamental rights. If you find any risks or violations, you must develop, implement and document mitigation measures before deployment. Completing FRIAs and acting on what you learn before deployment is mandatory under the EU AI Act. Talk to us about our planning and documentation tools to support you and your team.
5. Monitor and log AI performance for traceability.
Compliance with the EU AI Act is not a one-off action but an ongoing duty. Make sure you keep thorough and robust records of how any AI you use is performing in the market, and conduct regular audits to check it's continuing to operate without bias.
Did you know?
In its 2025 AI report, McKinsey found that the share of respondents who said their organisations were using AI in at least one business function had increased to 88%, compared to 78% the previous year.
How Workday can help?
- Built-in responsible AI: Our core platform is designed with transparency and human oversight at its centre. Our risk‑based AI evaluation processes are mapped to the EU AI Act high-risk categories and prohibited AI practices. This means our AI systems are assessed against EU‑inspired criteria before launch and throughout their lifecycle.
- Workday GO for SMBs: Workday GO simplifies your HR and finance systems with affordable, pre-configured AI compliance. We provide an all-in-one cloud platform that combines, streamlines and automates your core back-office functions.
- Bias mitigation tools: We have what you need to proactively identify the risk of disparate impacts in AI recruitment.
- Automated documentation: We'll simplify the record-keeping burden for high-risk systems. Think automated evidence collection and ready-to-use reports built with real-time data. For bespoke advice on how we can help, reach out to our team.
- Explainable finance: We can help you move beyond 'black box' forecasting to clear, actionable financial insights. Our systems are made to identify key drivers, explain the logic behind risk assessments, and allow for real-time human-led adjustments.
Putting the EU AI Act into action
The EU AI Act is live now, and enforcement will commence from August 2026. At the same time, AI represents a major opportunity for you to grow and optimise your business. Don't let regulation stall your innovation. Talk to a Workday expert today about our AI-ready platform.
AI resources for you
- Demo for Workday Workforce Management
- Whitepaper on responsible AI
- What is AI in HR?
- Ready to turn AI compliance into action? Get in touch.