Board directors of UK financial services firms have been told, correctly, that the EU AI Act's Article 50 obligations apply from 2 August. Most have been told it in the language of compliance: a European regulation, a set of disclosure requirements, a project for the technology and compliance functions to complete. That framing is accurate and insufficient, and the gap between those two words is where director-level exposure now sits.
Article 50 requires deployers of AI systems to disclose when a natural person is interacting with an AI system, to label deepfakes, and to flag AI-generated content published on matters of public interest. Taken alone, these read as operational tasks. A board might reasonably conclude that its duty is discharged by confirming that a workstream exists and that management has reported progress.
A UK regulated firm cannot stop there, because a domestic regime reaches further. Under the Senior Managers and Certification Regime, accountability for each area of the firm's activity is mapped to a named senior manager in a Statement of Responsibilities filed with the FCA. The regime does not care whether a decision was made by a person or materially shaped by an AI system. The senior manager who owns the decision area owns the decision. From 2 August, that means a named individual inside the firm carries personal regulatory accountability for obligations most boards have been treating as a technical project.
The board question this raises is not whether the firm has an Article 50 workstream. It is whether the person named in the firm's own regulatory filings can evidence that they reviewed the obligation before it applied.
A policy document asserts intent. A committee structure describes process. Neither answers the question a regulator actually asks after an incident, which is what this person knew, what they decided, and on what date. If the record supporting the answer was assembled after the question was asked, it is not evidence of governance. It is evidence of reconstruction.
Directors should also be clear that this standard does not arrive from Brussels alone. Companies Act 2006 section 174 tests a director's care, skill and diligence against what they actually did, evidenced and dated. DORA Article 5 places responsibility for ICT risk management with the management body itself rather than a delegated function. The instruments differ in origin and scope. They agree on the point that matters: accountability that cannot produce contemporaneous evidence is an assertion, and assertions are tested, not accepted.
One agenda item for the next board meeting
There is a practical version of this for the next board meeting, and it fits in one agenda item.
None of this requires a board to become expert in the mechanics of AI systems. It requires the board to apply a discipline it already understands from financial reporting: decisions of consequence are evidenced at the time they are made, by the person accountable for them, in a form that can be produced later without reconstruction. The firms that will be comfortable in the post-deadline environment are the ones that treated 2 August as a governance date rather than a technology date.
The deadline arrives on Sunday. The named individual was accountable before it did. The only question a director needs to settle this week is whether the evidence agrees.
Otopoetic's Governance Classification Briefing locates a board's current position across accountability, exposure, control, regulation and maturity, and identifies where the evidential gaps sit before a regulator does.
Implementation support at otopoetic.comDownload the governance reference card for the board pack.