Skip to content

Applied AI

EU AI Act readiness for UK businesses

EU AI Act readiness is the work of classifying each AI system against the Act’s risk tiers, and building the risk management, technical documentation, logging, human oversight and post-market monitoring that high-risk systems must have before their deadline. Following the Digital Omnibus, standalone high-risk systems in hiring, credit, insurance, education and critical infrastructure must comply by 2 December 2027; AI inside regulated products by 2 August 2028; prohibited practices have applied since February 2025. Hexploits does the engineering side of readiness, and is the core team behind swarmd.ai, an EU AI Act readiness platform for governing AI agents in regulated industries.

A named engineer replies within one working day. A written scope and an indicative price within two.

  • UK businesses whose AI output is used in the EU, or who sell AI-enabled software to EU customers.
  • Deployers of hiring, credit-scoring, insurance-pricing, education or triage AI, bought or built.
  • Providers of AI products and agents who carry the Act’s heavier provider obligations.
  • Compliance functions asked to sign off systems they did not build.

Deliverables, not slogans. Each one appears in the statement of work.

  • An inventory of every AI system, bought or built, with its risk classification under the Act and the reasoning written down.
  • Provider or deployer determination per system, including whether fine-tuning or modification has made you a provider under Article 25.
  • For high-risk systems: risk management records, technical documentation, automatic logging, human-oversight procedures and a post-market monitoring plan.
  • Fundamental Rights Impact Assessment support where Article 27 requires it (credit scoring and life/health insurance pricing deployers, public bodies).
  • Bias testing against your own data, with results, for systems that make or narrow decisions about people.
  • Transparency notices for the people your systems decide about, and AI-literacy material for staff.
  • A dated plan to each applicable deadline, and a completed AI section for customer due-diligence questionnaires.

Our engineers work across the major languages, frameworks and cloud platforms. We build on the stack you already run, with technology choices explained in writing before work begins.

The same four stages as every Hexploits engagement, applied to this capability.

  1. Stage 1

    Inventory and classify

    Two to four weeks. Every AI system is listed, its use mapped to the Act’s categories and prohibitions, and its role (provider or deployer) determined. Most systems turn out to be limited or minimal risk; the ones that are not get a dated plan.

  2. Stage 2

    Gap analysis

    Current controls and documentation are compared with what the Act requires for each high-risk system, alongside ISO 42001 where certification is the goal, and gaps are prioritised by deadline and exposure.

  3. Stage 3

    Build the controls

    Logging, oversight, testing and documentation are built into the systems and the release process, so the evidence is produced by the system running rather than assembled before an audit.

  4. Stage 4

    Monitor and maintain

    Post-market monitoring, incident handling and periodic review under managed support, with the inventory kept current as systems and guidance change.

We are the core engineering team behind swarmd.ai

swarmd.ai is an EU AI Act readiness platform for governing AI agents in highly regulated industries: policy enforced on every action an agent takes, tamper-evident audit trails a regulator will accept, per-tenant isolation and customer-owned identity. Hexploits designed and built it end to end in six months. The same patterns are what we apply to a client’s own systems.

Every engagement agrees its measures and the measurement period in writing before work starts.

  • Every AI system classified, with the reasoning a regulator or customer can be shown.
  • High-risk systems with complete documentation and logging before their applicable deadline.
  • Bias and performance testing results on file, refreshed on a schedule.
  • Customer and partner due-diligence questionnaires answered from evidence rather than assertion.

Case studies with numbers, and reviews linked to Google where they were left there.

  • Director, IO Solutions

    Fantastic to work with. High level of attention to detail and flawless communication throughout. Would recommend to anyone looking to develop or improve a software product.

    Christian LorzaDirector, IO SolutionsRead the review
  • Director, JobVantage

    Working with Hexploits has genuinely been a pleasure, and I see them as my scaling partner for the foreseeable future as JobVantage grows. If you’re looking for a development team who combine strong AI/engineering capability with honesty, flexibility and a real interest in your business, I’d strongly recommend them.

    Brandon BowdenDirector, JobVantageRead the review
Does the EU AI Act apply to a UK company?
Yes, where an AI system’s output is used in the EU, or where a UK business places AI on the EU market or supplies it to EU customers. UK firms placing candidates into EU roles, lending or insuring EU customers, or selling AI-enabled software into the EU are commonly in scope.
What are the deadlines?
Prohibited practices since 2 February 2025; general-purpose model obligations since 2 August 2025; transparency duties from 2 August 2026; standalone high-risk (Annex III) systems from 2 December 2027 after the Digital Omnibus; AI that is a safety component of products already under EU safety law, including medical devices, from 2 August 2028.
Which systems are high-risk?
Annex III names, among others: CV screening, candidate ranking and interview scoring; credit scoring and life or health insurance pricing; admissions, grading and exam proctoring; emergency triage; safety components in critical infrastructure; and several public-sector uses. Scoring emotion from biometric data in the workplace or education is prohibited outright.
Are we a provider or a deployer?
A provider develops or places the system on the market; a deployer uses it. Deployers carry lighter obligations, but retraining or substantially modifying a vendor’s model can make you a provider under Article 25. We determine this per system during inventory.
Is this legal advice?
No. We do the engineering and operational side of readiness and work alongside your legal counsel, who sign off the legal position. Our sector-by-sector insight series is written on the same basis.
What is swarmd.ai and how is it relevant?
swarmd.ai is an EU AI Act readiness platform for governing AI agents in regulated industries. Hexploits is its core engineering team. Building it means we have already solved policy enforcement, audit, isolation and identity for agents at production scale, and we bring those patterns to client systems.

Sectors where this is most often needed

Reading

Request a proposal.

Tell us about the system and the sector. A named engineer replies within one working day. A written scope and an indicative price within two working days of a short scoping call.