Skip to main content

The AI Works

Applied Artificial Intelligence

AI Use Policy

Currently in Force

  1. Control personal data: Comply with existing UK and EU GDPR rules for any personal data processed by your AI systems.

February 2025

  1. Decommission banned AI: Immediately stop using systems flagged as an unacceptable risk.
  2. Educate your workforce: Deliver targeted AI literacy training to relevant staff and securely retain evidence of their understanding.
  3. Put an AI policy in place: Establish internal governance rules detailing acceptable AI use.

2 August 2026

  1. Apply transparency labels: Explicitly inform users when they are interacting with an AI system, such as a chatbot.

2 December 2026

  1. Implement watermarking: Apply machine-readable watermarks to AI-generated synthetic content.

Before High-Risk Deployment (Hard deadlines of 2 December 2027 for standalone systems, and 2 August 2028 for embedded systems)

  1. Inventory all AI tools: Catalogue every AI system your business uses, builds, or buys.
  2. Classify your systems: Map each tool against the AI Act’s risk tiers.
  3. Update vendor contracts: Renegotiate supplier agreements to guarantee access to compliance documentation and audit rights.
  4. Execute impact assessments: Complete Fundamental Rights Impact Assessments (FRIAs) and Data Protection Impact Assessments (DPIAs).
  5. Establish technical controls: Ensure high-risk systems have active automated event logging and up-to-date technical documentation.
  6. Assign human oversight: Appoint trained personnel to actively monitor high-risk AI with the authority to override it.
  7. Set up incident reporting: Create an internal pipeline to report serious AI incidents to authorities within 72 hours.