The EU AI Act Is Here. Is Your Team Ready?
· Regulation · By Chris Latham, Founder of Optimus Consulting
Since August 2025, the EU AI Act has required businesses to ensure staff have sufficient AI literacy. From August 2026, full risk-based compliance kicks in. Here is what UK businesses actually need to do.
Governance and human-in-the-loop sit at the centre of our ethical AI position and SOS framework.
Disclaimer: This article is general guidance, not legal advice.
Your team is almost certainly using AI already. Whether it is official policy or not, someone in your business is pasting customer data into ChatGPT, using Copilot to draft emails, or running reports through an AI tool they found online. That is not a criticism. It is just reality.
The problem is that since August 2025, the EU AI Act has required every business using AI to ensure its staff have sufficient AI literacy. Not awareness. Not a vague familiarity. Literacy. And from August 2026, the full risk-based compliance framework kicks in.
If you are a UK business thinking "that is EU legislation, it does not apply to us," you might want to read on.
Why should UK businesses care about EU legislation?
The EU AI Act applies to any business that places AI systems on the EU market or uses AI systems that produce effects within the EU. If you have EU-based clients, partners, or any operational touchpoint with Europe, you are likely caught.
Even if you operate purely in the UK, the direction of travel is the same. The UK Government's own AI regulation programme is tracking closely with the EU approach. DSIT (the Department for Science, Innovation and Technology) has been consulting on AI governance frameworks throughout 2025 and 2026. The principles are the same: transparency, accountability, human oversight.
Waiting for the UK to publish its own rules before acting is like waiting for the fire alarm before checking the smoke detectors. The requirements are coming. The only question is whether you will be ready or scrambling.
What does "AI literacy" actually mean?
The literacy requirement is the part most businesses are underestimating. It does not mean running a one-hour awareness session and ticking a box.
Under Article 4 of the EU AI Act, providers and deployers of AI systems must ensure that their staff and other persons dealing with AI on their behalf have a sufficient level of AI literacy. The assessment of what counts as "sufficient" takes into account the person's technical knowledge, experience, education, the context in which the AI is used, and the people it affects.
For a UK service business, this translates into three practical questions.
Do your people know what the AI is doing?
Not at a technical level, but functionally. If a handler is using an AI tool to draft client correspondence, do they understand whether the tool is generating from its training data or retrieving from verified sources? Do they know when the output might be unreliable? If the answer is "they just paste in the details and send what comes back," that is a literacy gap.
Do your people know when to override?
AI outputs require human review. Review without understanding is just rubber-stamping. The person reviewing needs to know what to check, what to question, and when to reject the output entirely. This requires training that is specific to the tool and the task, not generic AI awareness.
Can you prove it?
If a regulator, a client, or a court asks how your team uses AI and what training they have received, you need a documented answer. A policy document, training records, and a clear description of what tools are approved and how they are supervised. "We told people to be careful" is not going to cut it.
The risk is not abstract
This is not a compliance exercise for its own sake. The risks are real and they are already showing up.
In legal services, the SRA has flagged AI-generated content as a competence concern. Solicitors submitting AI-drafted arguments with fabricated case law citations have faced professional consequences. The same logic applies to any regulated or client-facing function where accuracy matters.
In insurance, handlers using general-purpose AI to draft claim responses risk including information that is plausible but wrong. A hallucinated policy reference, an incorrect coverage position, a fabricated precedent. These are not theoretical risks. They are the predictable result of using tools that generate from training data rather than retrieving from verified sources.
The EU AI Act's risk categories classify AI systems used in employment, insurance, and access to essential services as "high risk." High-risk systems face the strictest obligations: risk assessments, quality management, human oversight, transparency requirements, and conformity assessments.
If your business operates in any of these sectors, the compliance bar is higher than you think.
Five things to do now
You do not need to become an AI regulation expert. You do need a basic framework in place before the full obligations land in August 2026. Here is where to start.
- Audit what your team is actually using. Not what is in the IT policy. What people are actually doing. If handlers are using personal AI accounts to process client data, that is a data protection issue today and a compliance issue tomorrow. You cannot manage what you have not mapped.
- Approve specific tools for specific tasks. A blanket "do not use AI" policy is unrealistic and counterproductive. A blanket "use whatever you like" policy is reckless. The middle ground is a short list of approved tools, matched to specific use cases, with clear guidance on what data can and cannot be submitted.
- Train your team on the tools they actually use. Generic AI awareness training is a start, but it is not sufficient under the Act. Training needs to cover the specific tools in use, their limitations, when human oversight is required, and what to do when something looks wrong. Document it.
- Check your data flows. Where does the data go when your team uses an AI tool? Is it processed in the UK or overseas? Is it used to train the provider's models? Is it retained after the session? Under UK GDPR, you need clear answers to these questions. Under the AI Act, you need them documented.
- Review quarterly. AI regulation is moving fast. What counts as best practice today may be a minimum requirement in six months. Build in a regular review cycle so you are adjusting to the landscape rather than reacting to it.
The competitive angle
Here is the part that gets missed in the compliance conversation. The businesses that get this right early will not just avoid risk. They will win work.
Clients are starting to ask questions. "How do you use AI?" is appearing in tender documents and due diligence questionnaires. "What safeguards do you have?" is becoming a standard procurement question. The businesses that can answer these questions clearly, with documented policies, approved tools, and trained staff, will stand out from those that cannot.
Compliance is not just a cost. It is a differentiator. The companies that treat AI governance as a strategic investment rather than a regulatory burden will find it opens doors rather than closing them.
Where Optimus fits
This is exactly the kind of challenge Optimus was built for. Not the technology. The adoption. The practical, operational work of getting AI into a business properly, with the right tools, the right training, and the right governance.
Our AI Strategy Workshops help leadership teams map their current AI usage, identify gaps, and build a practical compliance framework. Not a 50-page policy document that sits in a drawer. A working plan that the team actually follows.
If the EU AI Act has you thinking "we should probably get ahead of this," you are right. And you do not need to figure it out alone.
Frequently Asked Questions
Does the EU AI Act apply to UK businesses?
Yes, in many cases. The EU AI Act applies to any business that places AI systems on the EU market or uses AI systems that produce effects within the EU. UK businesses with EU-based clients, partners, or operational touchpoints are likely caught. Even UK-only operators should expect comparable UK rules to follow closely.
What does AI literacy mean under the EU AI Act?
Under Article 4, providers and deployers of AI must ensure staff have a sufficient level of AI literacy, judged against their technical knowledge, experience, the context of use, and who is affected. In practice, your people need to know what the AI is doing, when to override it, and you need documented evidence that they have been trained on the specific tools they use.
When does full EU AI Act compliance kick in?
The literacy requirement under Article 4 has applied since August 2025. The full risk-based compliance framework, including obligations on high-risk AI systems, applies from August 2026.
What counts as a high-risk AI system?
AI systems used in employment, insurance, access to essential services, education, law enforcement, and critical infrastructure are typically classified as high-risk. These systems face the strictest obligations: risk assessments, quality management, human oversight, transparency, and conformity assessments.
What are the first practical steps to take?
Audit what your team is actually using, approve specific tools for specific tasks, train staff on the tools they actually use, check your data flows under UK GDPR, and review your policy quarterly. Document each step.