Published: September 2, 2026 • 4 min read

The EU AI Act Is Your AI Strategy

Aerial view of a European city skyline in winter, mixing historic and modern buildings under a gray, overcast sky.
Talk to us

Two conversations are happening simultaneously in most large UK organisations right now.

The data governance team is working through regulatory obligations: cataloguing critical data elements, establishing ownership, documenting lineage, maintaining audit trails. Compliance work. Necessary, but rarely connected to the AI discussion happening three floors up.

Across the organisation, the AI team is running experiments that demo beautifully and then stall. Pilots get approved, early results look strong, and then nothing reaches production. Months pass. The initiative quietly shrinks.

The two teams share an organisation chart. They rarely share intelligence, or recognise that the problem one team is solving is identical to the infrastructure the other team needs.

This is the structural failure underneath most AI deployment challenges. It is commonly attributed to model quality, vendor limitations, or resourcing shortfalls. The actual cause is a framing error: treating data governance compliance and AI deployment as two separate workstreams, when they are the same workstream.

Why AI Programmes Stall in Regulated Environments

Every executive team in the UK is pushing the same directive: move faster on AI. Automate manual processes, accelerate decisions, reduce time spent on low-value work. The business case is well understood.

But the teams responsible for delivery keep running into the same wall. AI models are only as reliable as the data they run on. In large companies, that data is typically distributed across business units, frequently duplicated, often undocumented, and governed inconsistently. Put a model on that foundation and the outcome is predictable: strong demo results, accuracy failures in production, and teams that quietly shelve initiatives rather than put their name against outputs they cannot verify.

Gartner found that 60% of AI projects will be abandoned through 2026 in organisations lacking AI-ready data, based on a survey of more than 1,200 data management leaders. The primary cause: organisations lack the metadata practices and data quality infrastructure needed to feed production AI reliably. A companion Gartner survey found that 63% of organisations either do not have or are unsure whether they have the right data management practices for AI at all.

When production deployments fail, data governance is almost always the root cause, not model capability.

What The EU AI Act  Is Actually Asking You to Build

Data governance and risk-reporting regulations have been reshaping how organisations manage information for over a decade. Most compliance programmes built around these rules treat them as an ongoing documentation obligation: a standard to satisfy rather than infrastructure to build. That reading is not wrong. It is incomplete.

These regulations typically require organisations to establish comprehensive data architecture and lineage, ensure data accuracy and integrity, and demonstrate that critical information can be aggregated quickly and reliably across the organisation. Know what your critical data is, know who owns it, and be able to prove it is accurate and traceable under regulatory examination.

This is also, almost exactly, the specification for AI-ready data.

The fraud detection systems, risk models, clinical decision tools, and operational agents your organisation wants to run in production all require the same foundation: data that is documented, owned, trusted, and supported by governed business semantics. Existing data governance rules are not asking you to clear compliance first. They are asking you to build the thing that makes the AI work.

The EU AI Act makes this connection explicit. With substantive requirements taking effect from 2027, organisations deploying AI in European markets across financial services, healthcare, critical infrastructure, and beyond face binding obligations around AI transparency, governance, and risk management. That includes explainability requirements, human oversight provisions, and audit trail standards, all of which rest on the same data governance foundations that sector-specific regulations have required for years.

The data governance infrastructure your regulator already expects is not a precondition to the AI strategy. It is the AI strategy.

When Compliance Becomes Infrastructure

The manual effort involved in critical data element management is one of the most underestimated costs in financial services. Identifying CDEs from a regulatory filing is a slow, labour-intensive process: back-and-forth between governance and business teams, debate over what qualifies as critical, documentation cycles that most institutions repeat annually. Most organisations spend three to six months on each exercise.

That cost does not appear only in governance budgets. It shows up in delayed AI programmes, overstretched data teams, and leadership conversations that circle the same problem without resolution.

Leading companies are approaching this differently. CDE identification processes that once required months are being automated. Annual reports and regulatory filings that previously needed extensive manual review are producing prioritised CDE inventories in a fraction of the time. The staff who spent those months on documentation are being redeployed.

The Question Worth Asking Before the EU AI Act Lands

Regulatory expectations around AI are tightening across every major jurisdiction. The EU AI Act establishes binding requirements for firms operating in European markets, with substantive obligations taking effect from 2027. Supervisory expectations around model governance, AI explainability, and risk controls are increasing in parallel. For UK organisations, the window for informal AI governance is closing.

The organisations that will outpace their peers are not those treating each piece of regulatory guidance as a separate compliance task. They are the ones that have recognised a pattern: every data governance requirement your regulator sets describes the same foundation your AI programme needs. Compliance, lineage and ownership requirements, and critical data element management are not prerequisites to the AI strategy. They are the AI strategy.

Making that shift asks nothing extra of your organisation. The work is already mandated. The question is whether you build the foundation once, for two purposes, or twice.

For a framework on how leading organisations are turning data governance compliance into AI readiness, download Governing What Matters: Why Data Prioritisation Is Becoming the Foundation of AI-Ready Enterprises.

Sources

  1. Gartner, "Lack of AI-Ready Data Puts AI Projects at Risk" (February 2025) - https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk

  2. European Parliament, Regulation (EU) 2024/1689 - Artificial Intelligence Act (August 2024) - https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:32024R1689

  • AI
  • Alation News
  • Data Governance
  • Enterprise Data Catalog

Keep reading

More from the data desk

  • Is BI dead? A Former Tableau CPO Who Helped Build It Weighs In

    AI

  • BYOM

    Bring Your Own Model (BYOM): The Four Controls Regulated Enterprises Need

    AI

  • How the BBC Governs Data and AI When Trust Is Key

    AI

  • data products abstract image

    Data Governance Pilots: 4 Questions Before You Scale Enterprise AI

    Customer Stories

Let us help you get it right.