The EU AI Act Is Now Enforceable: Can You Prove Your AI Is Governed?
On 2 August 2026, applicable EU AI Act provisions became enforceable. This article explains why UK organisations still need evidence-based AI governance, how obligations depend on context and classification, and how CyConex supports the full AI Act compliance lifecycle with a defensible Assurance Pack.

Artificial intelligence has moved from experimentation into everyday business operations.
Organisations are using AI to review documents, answer customer questions, detect fraud, screen candidates, write software, make recommendations, prioritise risks and automate operational decisions. In many cases, these systems have been introduced faster than the governance structures needed to control them.
The European Union’s Artificial Intelligence Act is intended to change that.
On 2 August 2026, the European Commission’s AI Office and national authorities began enforcing applicable provisions of the Act. New transparency requirements also came into effect, including requirements for certain interactive AI systems to disclose that users are interacting with AI and for some AI-generated or manipulated content to be identifiable or labelled.
The legislation introduces a risk-based framework covering prohibited practices, general-purpose AI models, transparency, AI literacy and, over an extended implementation period, high-risk AI systems.
For organisations, however, the central challenge is not simply understanding what the legislation says.
It is being able to demonstrate that AI systems have been identified, classified, governed, tested, monitored and used responsibly.
That requires evidence.
The EU AI Act can affect UK organisations
The UK has left the European Union, but UK organisations should not assume that the AI Act is therefore irrelevant to them.
The Act can apply to organisations outside the EU where they place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, use it in the EU or produce outputs intended to be used within the EU.
A UK software company may therefore fall within scope if it supplies an AI-enabled service to European customers. A UK organisation may also become part of an affected supply chain when its customers require evidence that an AI product, model or service meets EU expectations.
The effect will extend beyond organisations that are directly regulated. Large customers, public bodies and regulated businesses are likely to pass requirements down through contracts, supplier-assurance processes and procurement questionnaires.
Even a UK organisation that has no immediate EU customers should pay attention.
The UK is unlikely simply to reproduce the EU AI Act word for word. Its approach has so far been more sector-based, principles-led and focused on enabling innovation. However, the underlying direction is increasingly similar: AI systems should be accountable, transparent, secure, appropriately overseen and supported by credible assurance.
The UK government has described safe and trusted AI as a precondition for growth and public-service transformation. It is investing in AI evaluation, developing an AI assurance ecosystem and supporting the growth of independent AI assurance providers.
The UK has also published an AI Cyber Security Code of Practice containing baseline security principles for organisations that develop and deploy AI. The Code is intended to inform an international technical standard through ETSI.
Alongside this, the Information Commissioner’s Office is developing a statutory code of practice covering artificial intelligence and automated decision-making under the UK’s evolving data-protection framework.
The precise legal mechanisms may differ, but the direction is clear.
UK organisations should expect increasing demands to demonstrate what AI systems they use; why those systems are being used; what risks they create; how data is obtained and governed; how decisions are reviewed; how security and resilience are maintained; how suppliers and models are controlled; how problems are detected and corrected; and what evidence supports the organisation’s claims.
Preparing for those expectations now is more effective than attempting to reconstruct the evidence after a regulator, customer or auditor asks for it.
The AI Act is not a single checklist
A common mistake is to treat the AI Act as one universal list of controls.
The requirements that apply depend on several factors, including whether the organisation is a provider, deployer, importer or distributor; whether it develops a model or integrates one supplied by another party; the intended purpose of the AI system; where it is marketed and used; whether the system falls into a prohibited, high-risk, transparency or lower-risk category; and whether personal data or significant individual decisions are involved.
The implementation timetable is also phased.
Prohibited-practice and AI-literacy provisions began applying in February 2025. Obligations for providers of general-purpose AI models began applying in August 2025. Transparency provisions became applicable on 2 August 2026. Following the 2026 simplification changes, requirements for high-risk systems in certain sensitive areas are scheduled to apply from December 2027, while requirements for high-risk systems embedded in regulated products are scheduled for August 2028.
This means that compliance starts with context.
An organisation cannot determine its obligations until it understands what AI it has, how each system is used and what role it performs in relation to that system.
Yet many organisations do not possess a reliable AI inventory. AI capabilities may be embedded in software-as-a-service platforms, productivity tools, recruitment systems, security products, customer-support services and development environments without being recorded centrally.
Without that inventory, meaningful governance is impossible.
Governance claims must be supported by evidence
An AI policy is important, but it is not evidence that individual AI systems are governed effectively.
A risk assessment may exist, but it may not reflect how the system is now being used. Human oversight may be described in a procedure, while operational teams routinely accept AI-generated recommendations without meaningful review. A supplier may state that its model is secure, while providing no evidence about testing, monitoring or incident management.
The real compliance question is therefore not: “Do we have an AI policy?”
It is: “Can we demonstrate that the required governance operates for every relevant AI system?”
That requires a traceable chain from the applicable obligation to the control, implementation evidence, assessment rationale and conclusion.
How CyConex supports the full AI Act compliance lifecycle
CyConex provides an evidence-based assurance environment in which organisations can assess AI systems against structured legal, regulatory and governance requirements.
It does not replace legal interpretation, nor does it substitute for technical controls that must exist within the AI product itself. For example, if an AI system must label synthetic content, that capability must be implemented by the relevant provider or deployer.
CyConex provides the governance and assurance layer around those controls. It identifies what must be demonstrated, gathers and assesses the evidence, exposes unsupported claims and creates a defensible record of compliance.
This allows CyConex to support every major evidence and assurance domain within the Act.
1. AI system inventory and scope
CyConex can maintain a structured record of AI systems used or supplied by the organisation.
Each record can capture system name and owner; intended purpose; business process supported; model and technology provider; affected users and individuals; geographic use; data processed; integrations and dependencies; deployment status; applicable legal entity; and provider, deployer or other regulatory role.
Supporting documents, architecture diagrams, contracts, data-flow records and supplier information can be linked directly to the system.
This creates an evidence-backed inventory rather than a spreadsheet containing unsupported declarations.
2. Regulatory classification
The Act’s obligations depend heavily on classification.
CyConex can guide users through contextual questions and assess available evidence to determine whether an AI system may involve a prohibited practice; a high-risk use case; a transparency obligation; a general-purpose AI model; a system presenting limited or minimal risk; or additional data-protection, cyber-security or sector-specific requirements.
The platform can record the classification decision, the reasoning behind it, the evidence considered and any assumptions requiring legal review.
Classification therefore becomes a reviewable decision rather than an undocumented opinion.
3. Risk management
High-risk AI governance requires an ongoing risk-management process rather than a one-time assessment.
CyConex can connect each AI system to identified risks, affected stakeholders, critical business services, risk appetite and unacceptable outcomes.
Evidence may include AI impact assessments; data-protection impact assessments; threat models; safety assessments; misuse scenarios; testing results; red-team findings; control designs; risk-acceptance decisions; and remediation records.
CyConex evaluates whether risks have merely been identified or are supported by implemented and tested controls. It can also identify when risk assessments have become stale because the system, model, data or intended use has changed.
4. Data governance and provenance
AI assurance depends on understanding the data used to train, test, fine-tune and operate systems.
CyConex can assess evidence covering data sources and ownership; lawful and permitted use; relevance and representativeness; quality and completeness; bias and fairness testing; data lineage; retention and deletion; access control; intellectual-property considerations; personal and sensitive information; and validation and testing datasets.
For organisations using third-party models, CyConex can also capture limitations in the evidence available from the provider.
This prevents uncertainty from being hidden. A lack of provenance information becomes an explicit assurance gap requiring treatment.
5. Technical documentation and traceability
AI governance often involves large volumes of disconnected material.
CyConex can ingest policies, system descriptions, model cards, architecture records, test reports, supplier documentation, operational procedures and change records. It then maps relevant passages to the applicable requirements.
Instead of presenting an assessor with an unstructured document repository, CyConex creates traceability between requirement, control, evidence, assessment rationale and conclusion.
Human reviewers can inspect the source evidence, challenge the AI-assisted assessment and approve or amend the result.
6. Logging and record-keeping
Organisations need to demonstrate how AI systems behave in operation and how significant decisions, interventions and changes are recorded.
CyConex can assess whether suitable evidence exists for model and configuration changes; prompts and system instructions; access and administrative actions; user interactions where appropriate; automated outputs and decisions; human approvals or overrides; incidents and unexpected behaviour; monitoring alerts; corrective actions; and version and release history.
CyConex does not replace the operational logging platform. It verifies that appropriate logging exists, assesses whether it meets the relevant obligation and preserves the evidence needed for assurance.
7. Transparency
The transparency provisions applying from August 2026 include requirements relating to AI interaction and certain generated or manipulated content.
CyConex can assess evidence that the required transparency mechanisms have been implemented, including user-interface notices; chatbot disclosures; content labels; machine-readable markings; privacy information; explanations of AI-assisted decisions; customer documentation; exceptions and justifications; and testing demonstrating that notices appear correctly.
This enables an organisation to prove that transparency is not merely described in policy but implemented in the relevant product or service.
8. Human oversight and accountability
Human oversight must be meaningful.
CyConex can record the accountable system owner; governance and approval bodies; designated human reviewers; reviewer competence and authority; escalation thresholds; circumstances requiring intervention; override and shutdown mechanisms; decisions accepted against AI recommendations; and management risk acceptance.
Assessment can then distinguish between nominal human involvement and a control that genuinely enables people to understand, challenge and intervene in AI-assisted activity.
9. Accuracy, robustness and cyber security
The organisation must be able to demonstrate that AI systems perform appropriately for their intended purpose and remain resilient against error, misuse and attack.
CyConex can assess evidence from functional and performance testing; security assessments; adversarial testing; vulnerability management; model evaluation; prompt-injection testing; data-poisoning controls; access control; resilience testing; incident response; monitoring and alerting; and recovery procedures.
The UK AI Cyber Security Code of Practice further reinforces the expectation that AI systems should be protected throughout development, deployment, maintenance and end of life.
CyConex can map the same underlying evidence across EU AI Act, UK AI security, data-protection and organisational cyber-security requirements, reducing repeated assessment effort.
10. AI literacy and competence
The AI Act’s AI-literacy requirement has applied since February 2025.
CyConex can assess whether training and competence are appropriate to the roles people perform.
Evidence may include role-based training; developer security education; responsible-use guidance; model-risk training; records of completion; competency assessments; awareness communications; and training updates following incidents or regulatory change.
This moves the organisation beyond proving that “AI awareness training” occurred and towards demonstrating that relevant people possess the skills needed for their responsibilities.
11. Supplier and model assurance
Few organisations build every component of an AI system themselves.
CyConex can link AI systems to model providers, cloud platforms, data suppliers, software components and specialist service providers. It can then assess contracts, model documentation, security evidence, certifications, limitations, incident obligations and exit arrangements.
This is particularly important where responsibility is divided across an AI supply chain.
CyConex makes those dependencies visible and identifies where the organisation is relying on claims that have not been independently evidenced.
12. Monitoring, incidents and corrective action
AI compliance does not end when a system is approved.
CyConex can support periodic reassessment and identify when evidence should be reviewed because of a model update; a new use case; changed data; an incident; a material performance issue; a supplier change; a regulatory update; or an identified control failure.
Findings can be assigned to owners, prioritised according to risk and tracked through remediation.
This creates a living assurance position rather than a static assessment that becomes obsolete as the technology changes.
Creating a defensible AI Assurance Pack
The final benefit is the ability to produce a structured AI Assurance Pack.
Rather than sending customers or regulators hundreds of disconnected files, the organisation can present system scope and intended purpose; applicable regulatory role; classification and rationale; obligations assessed; risks and controls; evidence references; assessment conclusions; identified gaps; accepted limitations; corrective actions; and approval and review history.
This is where CyConex provides value beyond conventional governance tools.
It does not merely record that a requirement has been marked complete. It shows the evidence supporting the decision and allows the conclusion to be reviewed and challenged.
Preparing for regulatory convergence
The EU AI Act is now part of the regulatory environment for many UK organisations, whether through direct legal scope, European customers or supply-chain expectations.
The UK may continue to pursue a more flexible and sector-specific model, but flexibility does not remove the need for evidence. The UK government’s emphasis on trusted AI, third-party assurance, cyber-security standards and statutory data-protection guidance points towards stronger expectations of demonstrable governance.
Organisations therefore have a choice.
They can treat each new requirement as a separate compliance exercise, creating more spreadsheets, questionnaires and document repositories.
Or they can establish a reusable evidence model that connects AI systems, risks, controls, suppliers, decisions and assurance conclusions.
CyConex enables the second approach.
It provides the structured governance, evidence assessment, traceability, gap analysis and reporting needed to support the full AI compliance lifecycle. Where technical or operational controls must be implemented elsewhere, CyConex verifies that they exist and assesses whether the evidence is sufficient.
The objective is not simply to say that an AI system is responsible, transparent or secure.
It is to prove it.
In the emerging age of AI regulation, trust will belong to the organisations that can demonstrate how every significant AI decision is governed.