The EU AI Act
The EU AI Act classifies AI systems by risk: unacceptable (banned), high-risk (regulated), limited (transparency obligations), minimal. UK GDPR and the Algorithmic Accountability principles apply in parallel.
- EU AI Act came into force August 2024; phased obligations from 2025–2027.
- High-risk AI (HR tools, credit scoring, medical) requires conformity assessment.
- UK approach: principles-based, sector-led — lighter touch than EU in 2024.
---
GDPR and AI
AI that processes personal data triggers GDPR obligations: lawful basis, data minimisation, right to explanation for automated decisions. Most enterprise AI tools need a DPIA.
- Automated decisions with legal/significant effects require human review under GDPR Art. 22.
- Training AI on customer data without explicit consent is a GDPR risk.
- DPIA (Data Protection Impact Assessment) is mandatory for high-risk AI processing.
---
Intellectual Property and AI
AI-generated content ownership is unsettled. UK copyright law does not protect purely AI-generated work. Training AI on copyrighted works without licence is legally contested globally.
- UK IPO: AI-generated works with 'no human author' are not copyrightable.
- Getty Images vs Stability AI: landmark case on training data IP rights.
- Document your AI contribution to creative work for IP clarity.
---
Hallucination Risk Management
AI confidently produces wrong facts. In client-facing or regulated contexts, unverified AI output is a reputational and legal risk. Implement systematic verification for high-stakes outputs.
- LLM hallucination rates: 3% on simple factual queries, up to 20% on complex ones.
- Mitigation: RAG (cited sources), output confidence scores, mandatory human review.
- Legal and medical AI tools: always require expert sign-off before use.
---
Cybersecurity and AI
AI introduces new attack vectors: prompt injection (manipulating AI via malicious inputs), model poisoning (corrupting training data), and deepfake social engineering. Your security posture needs updating.
- Prompt injection is the #1 attack on AI systems in 2024.
- AI-generated phishing emails are 40% more effective than human-written ones.
- Deepfake audio fraud: executives impersonated in £20M+ wire transfer fraud cases.
---
Building an AI Governance Framework
A governance framework covers: approved use cases, prohibited uses, data handling policies, audit requirements, and escalation paths. It should be documented, trained, and reviewed annually.
- 79% of organisations have no formal AI governance policy (Gartner 2024).
- Components: AI registry, risk classification, ethics review board, incident response.
- Governance frameworks reduce AI-related incidents 60% in organisations that implement them.
---
Ethics Committees and AI Review
High-impact AI deployments benefit from cross-functional ethics review: legal, HR, technology, and business leads. This is not bureaucracy — it's risk management that catches issues before they become headlines.
- Walmart, HSBC, and Unilever all have formal AI ethics review boards.
- Ethics review catches 80% of foreseeable harms at spec stage vs. 20% post-deployment.
- Include diverse voices — bias in AI often reflects the homogeneity of the team building it.
---
Insurance and Liability for AI
Who is liable when AI makes a wrong decision? Product liability, professional indemnity, and D&O insurance policies need updating for AI-assisted decisions. Your broker may not know this yet.
- UK product liability law is evolving to cover AI-related harms.
- Professional indemnity: check whether AI-assisted advice is covered in your policy.
- First AI-related class action lawsuits against corporates filed in US courts in 2023.
Sign in to track your progress and earn a certificate.
Sign in