Board Perspective · Governance Advisory

Why 2 August Matters in the Boardroom of a Regulated Firm

29 July 2026 UK Financial Services EU AI Act · FCA SM&CR

Board directors of UK financial services firms have been told, correctly, that the EU AI Act's Article 50 obligations apply from 2 August. Most have been told it in the language of compliance: a European regulation, a set of disclosure requirements, a project for the technology and compliance functions to complete. That framing is accurate and insufficient, and the gap between those two words is where director-level exposure now sits.

Article 50 requires deployers of AI systems to disclose when a natural person is interacting with an AI system, to label deepfakes, and to flag AI-generated content published on matters of public interest. Taken alone, these read as operational tasks. A board might reasonably conclude that its duty is discharged by confirming that a workstream exists and that management has reported progress.

A UK regulated firm cannot stop there, because a domestic regime reaches further. Under the Senior Managers and Certification Regime, accountability for each area of the firm's activity is mapped to a named senior manager in a Statement of Responsibilities filed with the FCA. The regime does not care whether a decision was made by a person or materially shaped by an AI system. The senior manager who owns the decision area owns the decision. From 2 August, that means a named individual inside the firm carries personal regulatory accountability for obligations most boards have been treating as a technical project.

The board question this raises is not whether the firm has an Article 50 workstream. It is whether the person named in the firm's own regulatory filings can evidence that they reviewed the obligation before it applied.

A policy document asserts intent. A committee structure describes process. Neither answers the question a regulator actually asks after an incident, which is what this person knew, what they decided, and on what date. If the record supporting the answer was assembled after the question was asked, it is not evidence of governance. It is evidence of reconstruction.

Directors should also be clear that this standard does not arrive from Brussels alone. Companies Act 2006 section 174 tests a director's care, skill and diligence against what they actually did, evidenced and dated. DORA Article 5 places responsibility for ICT risk management with the management body itself rather than a delegated function. The instruments differ in origin and scope. They agree on the point that matters: accountability that cannot produce contemporaneous evidence is an assertion, and assertions are tested, not accepted.

One agenda item for the next board meeting

There is a practical version of this for the next board meeting, and it fits in one agenda item.

01
Confirm identity
The person named on the Statement of Responsibilities for the relevant decision area should be the same person the firm identifies as accountable for Article 50 readiness. If one accountability has been split across a filed senior manager and a working technical function, close that split deliberately rather than let a regulator discover it by reading both documents.
02
Confirm the record
The named senior manager should hold a dated record of having reviewed the specific obligations, created before they applied. Not a policy asserting that reviews occur. A record of this person, this obligation, this date.
03
Confirm the anchor
A date the organisation asserts about itself is a weaker evidentiary category than a date fixed by something outside its control. The version that survives challenge is the one someone else could vouch for.

None of this requires a board to become expert in the mechanics of AI systems. It requires the board to apply a discipline it already understands from financial reporting: decisions of consequence are evidenced at the time they are made, by the person accountable for them, in a form that can be produced later without reconstruction. The firms that will be comfortable in the post-deadline environment are the ones that treated 2 August as a governance date rather than a technology date.

The deadline arrives on Sunday. The named individual was accountable before it did. The only question a director needs to settle this week is whether the evidence agrees.

Otopoetic's Governance Classification Briefing locates a board's current position across accountability, exposure, control, regulation and maturity, and identifies where the evidential gaps sit before a regulator does.

Implementation support at otopoetic.com

Download the governance reference card for the board pack.

Regulatory references: EU AI Act Article 50 · FCA Senior Managers and Certification Regime (SYSC, FCA Handbook) · Companies Act 2006 section 174 · DORA Article 5