About EU AI Act
AI is moving into products, operations, customer support, marketing, hiring, education, analytics, and decision-making faster than most organisations can establish clear rules for its use. The opportunity is real -but so are the questions: Which AI systems are in use? What risks do they create? Which rules apply? Who is accountable? What data is involved? How are people informed, protected, and able to challenge important outcomes?
The EU AI Act introduces a risk-based approach to AI governance. Some practices are prohibited. Some systems are subject to stringent requirements because they are classified as high risk. Other systems carry transparency obligations. At the same time, every organisation using or providing AI needs practical governance that connects legal, ethical, security, privacy, data, product, and human factors.
Boxfish Labs helps teams move beyond generic AI policies. We work with you to understand your AI landscape, identify material use cases and risks, establish proportionate guardrails, and build the documentation, responsibilities, review processes, and learning needed to use AI with greater confidence.
Who this is for
- Startups and scaleups building AI-enabled products, features, platforms, agents, or services
- Founders and product leaders who need to understand how the EU AI Act affects their roadmap or market strategy
- Organisations adopting generative AI, analytics, automation, decision-support tools, or AI assistants internally
- Teams using personal, sensitive, proprietary, customer, employee, student, or other high-impact data in AI systems
- Educators, learning providers, HR teams, and organisations using AI in contexts that can affect people’s access, opportunities, assessments, or decisions
- Businesses selling into the EU, serving EU users, or working with customers that require trustworthy-AI evidence and governance
- Security, privacy, compliance, risk, and technology teams that need a common operating model for responsible AI
What the EU AI Act means in practice
The EU AI Act applies a risk-based approach. Your obligations depend on factors such as the type of AI system, intended purpose, role in the value chain, market, users, and potential impact on people.
In practical terms, organisations need to understand:
- Which AI systems, models, providers, data sources, and AI-enabled features they use or offer
- Whether they act as a provider, deployer, importer, distributor, authorised representative, or another role
- Whether any practices are prohibited or whether a use case may fall into a high-risk category
- Which transparency, documentation, human-oversight, logging, monitoring, data-governance, accuracy, robustness, cybersecurity, or quality-management expectations may apply
- How AI interacts with GDPR, intellectual-property, consumer, sector, employment, education, accessibility, security, and contractual obligations
- Who can approve, monitor, change, pause, or retire an AI use case -and how concerns or incidents are handled
The right response is rarely a single document. It is a governance system that lets your organisation make informed decisions as AI use evolves.
Challenges we help solve
You do not know which AI systems are in use
We help create an AI inventory across products, internal tools, vendors, teams, models, data sources, workflows, and customer-facing features. This gives you a factual starting point for governance.
You need to classify AI use cases and prioritise risk
We help assess intended purpose, users, impact, data, decision context, level of automation, and human involvement to identify prohibited practices, potential high-risk use cases, transparency duties, and priorities for further review.
Your product roadmap is moving faster than governance
We help product, engineering, legal, privacy, security, and leadership teams establish lightweight review points and decision criteria that support innovation without leaving critical questions until after launch.
You use personal or sensitive data in AI systems
We connect AI governance to GDPR, data protection, DPIAs, data minimisation, vendor and processor arrangements, transparency, retention, access, and data-subject rights.
You rely on external models or AI vendors
We help assess supplier dependencies, contractual terms, data flows, training or inference arrangements, security, access, logging, monitoring, service changes, concentration risk, and exit options.
People need clear guidance on responsible AI use
We create human-centred learning and practical guidance for employees, developers, product teams, leaders, educators, and customer-facing teams -so AI use is not governed by informal experimentation alone.
You need credible answers for customers, investors, or partners
We help create a clear governance narrative and evidence base for due diligence, procurement, customer questions, partnerships, audits, and stakeholder trust.
A practical AI governance roadmap
01 - Create an AI inventory
Identify AI-enabled products, features, internal tools, vendors, models, data sources, automated workflows, users, countries, owners, and intended purposes. Include experimental uses that may have bypassed formal procurement or product review.
02 - Classify use cases and assess risk
Review the role, impact, autonomy, data, users, decision context, potential harms, transparency needs, security exposure, and regulatory relevance of each priority use case. Identify prohibited, high-risk, transparency-sensitive, or otherwise material situations.
03 - Define governance and accountability
Establish roles, decision rights, approval points, risk acceptance, documentation standards, product and vendor review processes, monitoring responsibilities, incident escalation, and policies for internal AI use.
04 - Build safeguards and evidence
Implement proportionate measures such as data governance, access controls, human oversight, user information, testing, logging, monitoring, documentation, vendor due diligence, security controls, DPIAs, training, and complaint or issue-handling mechanisms.
05 - Monitor, learn, and adapt
AI systems, vendor capabilities, regulations, and use cases change quickly. Review performance, incidents, feedback, drift, supplier changes, data use, risks, and governance effectiveness on a recurring basis.
Key AI governance areas
AI inventory and use-case classification
A maintained view of AI systems, providers, owners, purposes, users, data, jurisdictions, and potential impact. This is the foundation for deciding what needs deeper review or governance.
Risk assessment and impact on people
A practical assessment of potential harms, including unfair outcomes, privacy impact, security risks, manipulation, misinformation, exclusion, loss of human control, errors, and harm arising from inappropriate reliance on AI outputs.
Human oversight
Meaningful human involvement in decisions and workflows: clear responsibility, understandable escalation, the ability to question or override outputs where appropriate, and safeguards against automation bias or blind reliance.
Data governance and privacy
Clear decisions about data sources, quality, personal data, special-category data, minimisation, retention, access, purpose limitation, transparency, rights, DPIAs, and provider arrangements.
Security, robustness, and resilience
Protection against unauthorised access, data leakage, prompt injection, model misuse, insecure integrations, supply-chain issues, compromised accounts, failures, and other AI-specific or amplified cybersecurity risks.
Transparency and documentation
Clear records of intended purpose, system behaviour, limitations, data and vendor arrangements, risk decisions, controls, user information, governance actions, monitoring, and incident handling.
Vendor and model-provider governance
Due diligence and ongoing oversight of model, API, platform, data, and tool providers: contracts, service changes, subprocessing, security, data location, reliability, logging, export, and exit arrangements.
AI literacy and organisational learning
Role-relevant guidance and learning so people understand what AI can and cannot do, how to use it responsibly, what information not to share, how to identify concerns, and when to escalate.
Outcomes
- A clearer, shared view of the AI systems and use cases operating across your organisation
- Proportionate classification and prioritisation of AI-related regulatory, privacy, security, product, and human risks
- Practical governance that supports innovation while establishing accountability and guardrails
- Better AI product and vendor decisions, including stronger data, security, transparency, and human-oversight practices
- More credible answers to customer, investor, procurement, partner, and stakeholder questions about trustworthy AI
- Role-aware AI literacy and safer everyday AI use across teams
- A governance foundation that can evolve as AI capabilities, business models, and EU requirements develop