The EU Artificial Intelligence Act entered into force in August 2024 and represents the world's first comprehensive legal framework for artificial intelligence. While the Act is EU legislation, its reach extends well beyond EU borders. Any organization placing AI systems on the EU market or deploying AI systems that affect people in the EU must comply, regardless of where the organization is incorporated.
For UK enterprises, the EU AI Act operates similarly to UK GDPR in that it applies based on where AI systems are used rather than where the developer or deployer is based. A UK financial services firm deploying an AI credit scoring model that affects EU residents, or a UK technology company selling AI-powered products into the EU market, will be subject to the Act's requirements.
For Nigerian enterprises, the EU AI Act is relevant in three scenarios: organizations with EU operations or subsidiaries; organizations exporting AI-enabled products or services to EU markets; and organizations seeking to align with international AI governance best practice in anticipation of emerging Nigerian AI regulation.
The EU AI Act uses a risk-based classification system to determine which requirements apply to a given AI system. Unacceptable-risk AI systems including social scoring systems and real-time biometric identification in public spaces are prohibited entirely. High-risk AI systems including AI used in credit decisions, employment, critical infrastructure, and education face the most stringent requirements including conformity assessments, technical documentation, human oversight measures, and registration in an EU database.
NIST AI RMF provides the most operationally useful framework for implementing AI governance in practice. Its four core functionsβ Govern, Map, Measure, and Manage provide a structured approach to identifying AI risks, implementing controls, and maintaining ongoing oversight. FortressPoint uses the NIST AI RMF as the primary implementation framework for AI governance engagements, mapped to EU AI Act requirements where EU compliance is in scope.
Organizations should begin their EU AI Act compliance journey with an AI inventory cataloguing all AI systems in use or development, classifying each system under the Act's risk tiers, and identifying the compliance obligations that apply. FortressPoint's AI Governance practice supports organisations through this process, providing both the regulatory expertise to interpret the Act's requirements and the technical understanding to assess AI systems accurately.
Speak with a FortressPoint consultant β we engage with specific questions, not just general enquiries.