eCommerceNews UK - Technology news for digital commerce decision-makers
United Kingdom
EU AI Act pushes firms towards stronger governance

EU AI Act pushes firms towards stronger governance

Thu, 30th Jul 2026 (Today)
Sofiah Nichole Salivio
SOFIAH NICHOLE SALIVIO News Editor

Technology and financial services firms are preparing for a new phase of the EU Artificial Intelligence Act, as key transparency and governance provisions begin to take effect. Executives across Europe say the rules are already shaping how organisations build and manage AI systems.

The emerging regime is pushing businesses beyond legal checklists and toward deeper questions about how they deploy AI. That shift is especially visible in sectors that handle sensitive data, including finance and customer communications, where automation is advancing faster than regulation.

Austin Cowan, EMEA Agentic AI Lead at Workato, said organisations often underestimate the scale of the governance challenge within their own operations.

"The biggest misconception about the EU AI Act is that it's a legal problem for compliance to handle, when really it's a governance problem. Most organisations can't answer basic questions about their own AI estate: which models are running, what data they can touch, who's accountable when something goes wrong. That gap is exactly how data leaks happen, not through a dramatic breach, but an AI agent quietly pulling sensitive data into a context nobody's monitoring.

"For UK organisations serving international markets, the Act is the benchmark for responsible AI governance, not a box-ticking exercise for EU exposure. Even businesses with minimal EU footprint should watch closely - this is shaping the template other regulators will copy. Recent deadline extensions buy time, not safety. Organisations should build a governance layer before a leak, not after."

Consultants and in-house leaders describe the Act as a turning point in how companies structure AI oversight. They point to rising board-level scrutiny of model inventories, data lineage and accountability frameworks as regulators finalise guidance and enforcement approaches.

For smaller businesses, the legislation is likely to shape buying decisions as they adopt off-the-shelf tools and embedded AI services. Bilal Ahmed, Chief AI & Data Officer at team.blue, drew a parallel with earlier data protection rules.

"As the AI Act comes into effect, AI is becoming part of the digital foundations that businesses rely on every day. Much like GDPR did for data protection, the AI Act establishes a common framework for trustworthy AI across Europe.

"For SMBs, this isn't simply about compliance. It's about knowing the AI they use is transparent, accountable and fit for purpose. Rather than slowing AI adoption, the Act should encourage businesses to adopt it more deliberately. Ultimately, success with AI won't come from adopting every new tool, but from building trusted digital foundations that help businesses adapt, remain visible and grow with confidence in an AI-driven economy."

Financial services firms face a distinct set of pressures as they experiment with generative models and decisioning engines. Long-standing core systems are colliding with new expectations for explainability, auditability and real-time monitoring.

Adrian Congiu, VP, Head of Product Management at Mambu, said extended implementation timelines do not ease those underlying technical constraints.

"The implementation delay gives banks more time to prepare. It doesn't compel AI developers to slow down. Financial institutions should use this window to modernise the technology foundations that trustworthy AI depends on.

"Governing AI means being able to show where data came from, how decisions were reached and who is accountable when something goes wrong. As AI becomes more deeply embedded in banking, some are discovering that the foundations that carried them through the past few decades are starting to creak under these new demands.

"AI governance is, at the end of the day, an architectural challenge, and trustworthy AI depends on foundations that many organisations have struggled to modernise. The EU AI Act won't be the last word on AI governance. Standards are still being developed, guidance will evolve and AI itself won't stand still.

"However, financial institutions shouldn't wait to be pushed by regulation. The biggest risk isn't missing the next regulatory deadline. It's spending the next two years preparing for yesterday's AI and deferring the benefits that a compliant AI capability can deliver for a modern financial institution."

In corporate back offices and customer-facing processes, executives expect trust and explainability to become commercial differentiators. That is especially true in areas such as payments, lending and expense management, where automated outputs carry direct financial consequences.

Marija Nakevska, Chief Product & Technology Officer at Pleo, linked regulatory readiness to broader efforts to maintain user confidence as automation grows.

"As AI becomes embedded in everyday business processes, trust will become just as important as capability. The AI Act marks an important milestone because it encourages organisations to think beyond AI adoption alone.

"Businesses increasingly need to understand where AI is being used, how decisions are made and where human oversight remains essential. That's particularly important in finance, where every automated action needs to be transparent, explainable and accountable.

"But greater autonomy also requires stronger governance. Organisations that build transparency, clear audit trails and human oversight into their AI systems from the outset will be better prepared for the AI Act, build greater trust and ultimately unlock more value from AI."

Customer Transparency

The AI Act's first operational test will come in customer communications. New transparency rules cover systems such as chatbots, voice assistants and automated notification tools, affecting both providers and deployers of these services.

Alexandros Koronakis of Twilio highlighted the impact on day-to-day interactions between companies and end users.

"A moment of truth for AI-to-customer interactions is arriving on August 2, 2026, when the AI Act's transparency obligations come into force across the European Union. This is not just another deadline. It signals that AI compliance is shifting into the operational core of every company that interacts with customers through artificial intelligence systems.

"For years, the regulatory debate has been dominated by data protection and high-risk models. The challenge companies now face is how to achieve compliance without introducing friction. AI is fundamentally an asset for improving customer experience, but to make customers feel completely comfortable engaging, organisations must pair transparent communication with appropriate disclosure mechanisms so customers understand they are dealing with AI.

"For innovative leaders strategically bringing AI into customer relationships, these transparency obligations are much more than a regulatory issue to manage. They are an opportunity to redefine the customer experience by operationalising a vision in which AI serves trust and eliminates friction to drive a better overall customer experience. In a context where digital trust is becoming a strategic asset, leaders who move early do not merely aim to be compliant. They set the standard."

Governance Framework

Vendors that design and run AI systems for clients are also adjusting product development and oversight processes. Many expect the Act's risk-based model to influence AI governance well beyond the EU.

Paul Roehrig, Chief Strategy and Marketing Officer at Ascendion, said the legislation is reshaping internal frameworks across the AI lifecycle.

"At Ascendion, we view the EU AI Act not merely as a compliance obligation but as a defining framework for responsible AI-led transformation. As an AI-native technology and engineering services company operating across the globe, we are committed to embedding the risk-based principles - transparency, human oversight and accountability - into every stage of AI solution design, deployment and governance.

"We believe organisations that proactively align their AI strategies with the legal framework will be better positioned to build durable trust with customers, regulators and partners."