The EU AI Act Passed — Why It Matters in the Gulf

fairsystems insight on EU AI Act
Business

The EU AI Act Passed — Why It Matters in the Gulf

The European Parliament has adopted the AI Act, the first comprehensive attempt by a major jurisdiction to regulate artificial intelligence by risk category rather than by sector.

The immediate reaction among businesses in this region has largely been that it does not apply here. For a meaningful number of organisations, that is not accurate.

Extraterritorial reach is the point

The Act applies where an AI system’s output is used in the European Union, regardless of where the provider is established. If you supply a service to European customers, process European data, or provide a system that a European entity deploys, you are potentially in scope.

Regional groups with European subsidiaries, European investors, or European enterprise customers should be establishing the position now rather than when a customer’s procurement team asks.

The risk tiers are the useful part

Even for organisations firmly outside the scope, the structure is worth borrowing. The Act sorts systems by consequence: a small set of prohibited uses, a defined high-risk category with substantial obligations, limited-risk systems with transparency duties, and everything else.

Most organisations have no internal equivalent. They apply either no scrutiny or uniform scrutiny, and both are wrong. A tiered framework is the single most useful thing to take from this regardless of jurisdiction.

Obligations follow the role, not the technology

The Act distinguishes between those who build systems and those who deploy them, with different duties attached. Many organisations will be deployers of systems built elsewhere.

That distinction matters commercially. If you are buying AI capability, the contract should establish who holds which obligations. A vendor unable to answer that question is telling you something about their own readiness.

Documentation is the practical burden

For high-risk systems the requirements centre on things most organisations do not currently produce: risk management processes, data governance evidence, technical documentation, logging, human oversight arrangements and post-market monitoring.

None of this is exotic. It is close to what a well-run model risk function already does for statistical models. The gap for most businesses is that AI systems were never brought inside that perimeter.

What to do now

Build an inventory of the AI systems you use or provide, including the ones embedded in software you bought rather than built. That inventory almost never exists and is the prerequisite for every other step.

Then classify by consequence rather than by technology, and establish who in your organisation owns the question of whether a given system is fit to deploy. Whether or not European rules bind you, that capability is becoming a condition of doing business with customers who are bound by them.