Anaiya Algorithm
In an era of relentless technological change, leadership has never been more complex. The pressure to adopt AI, leverage data, and drive digital transformation is immense, but the path forward is often obscured by hype, buzzwords, and a lack of practical guidance. For leaders, the questions are profound: How do you build for tomorrow without losing sight of the people, principles, and purpose that define your organization? How do you govern the "black box" with intention and turn it into a source of strength?
Welcome to The Anaiya Algorithm, the podcast for leaders who are ready to move beyond the hype and start building the future, intentionally.
Hosted by Magdalene Amegashitsi, a Data & AI Executive and founder of the strategic consultancy Anaiya Group, this show is your essential briefing on modern leadership and responsible innovation. With over 15 years of experience advising FTSE leaders and guiding multi-million pound data transformations, Magdalene brings a rare, battle-tested perspective on what it truly takes to succeed.
Each week, The Anaiya Algorithm convenes the world's leading minds—the C-suite executives, visionary founders, pragmatic investors, and pioneering technologists who are shaping our world. These are not theoretical discussions; they are candid, strategic conversations that deconstruct the real-world playbooks for success. We get to the heart of the challenges and opportunities that matter most to you.
What to expect from each episode:
- Actionable Frameworks: Move beyond theory with practical models for implementing AI governance, building data-driven cultures, and leading through complex change.
- Real-World Case Studies: Learn from the successes and, just as importantly, the failures of top organizations across various industries.
- Expert Perspectives: Gain insights from diverse viewpoints, from the boardroom to the startup garage, on topics including:
- Digital, Data abd AI Strategy & ROI
- Data Governance & Ethics
- Leadership & Culture
- Pragmatic Adoption
If you are a leader, innovator, or strategist tasked with making high-stakes decisions about technology and the future of your business, The Anaiya Algorithm is your indispensable guide.
Join us to get the clarity, frameworks, and inspiration you need to lead with confidence and shape the future, intentionally. Subscribe now and be part of the conversation.
Anaiya Algorithm
Veridian: Episode 4_EU AI Act Explained: What Every Organization Needs to Know
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Most organizations are underestimating the EU AI Act’s true scope—and the consequences of ignoring it could be game-changing. If your AI influences decisions on employment, credit, or access to essential services in the EU, you need to act now.
This episode reveals how a comprehensive legal framework is transforming AI governance, with insights on what high-risk systems really mean—and how to stay compliant without slowing innovation. In just 25 minutes, Magdalene cuts through the legal noise to show you exactly what your organization must do to navigate the EU AI Act’s labyrinth of risk tiers. You’ll discover how this regulation applies globally—impacting UK firms and multinational enterprises alike—regardless of where your team is based. She unpacks the four risk levels, with a deep dive into high-risk categories relevant to financial services, insurance, and enterprise systems, from credit scoring to biometric identification.
We break down the six key obligations for high-risk AI—risk management, data governance, technical documentation, transparency, human oversight, and cybersecurity—highlighting why static compliance isn’t enough. These are continuous practices that demand real-time monitoring and layered governance across frameworks like DORA, GDPR, and the Cyber Resilience Act. Magdalene shares actionable tactics to build resilient, auditable infrastructure that keeps you ahead of enforcement deadlines and hefty fines—up to 35 million euros or 7% of global turnover.
If you’re leading in AI-driven industries, understanding these regulations isn’t just legal compliance—it’s a strategic advantage. Those who get their governance in place now will differentiate themselves through trust, transparency, and sustained innovation, while laggards risk costly penalties and reputational damage. Magdalene introduces Veridian—a platform that automates ongoing AI compliance across multiple frameworks, providing peace of mind and a competitive edge.
This isn’t just about regulations; it’s about redefining how AI builds trust with regulators, customers, and investors. Perfect for AI leaders, compliance officers, and innovators ready to future-proof their operations, this episode equips you with the knowledge to turn regulatory risk into a strategic advantage. Stay ahead of the curve—listen now and turn the EU AI Act from obstacle to opportunity.
Resources:
- Veridian on Azure Marketplace: marketplace.microsoft.com/en-gb/product/anaiyagroup.veridian-ai-governance
- Veridian: veridian.anaiya.org
- Connect with Magdalene: anaiya.org
So the EU AI Act is a hundred and forty-four pages long. I've read all of them, so you do not have to. In the next 25 minutes, I'm going to tell you exactly what your organization needs to do in plain English with no legal jargon and no unnecessary complexity. I'm Madeleine and today we decode the regulation. Let me start with what the EU AI Act actually is, because there is a lot of noise around it and I want to cut through that immediately. The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. It was adopted by the European Parliament in 2024 and is being phased in through 2026. It does not regulate the technology, it regulates the risk the technology creates. That distinction matters enormously. The EU AI Act does not care what model you're using, who built it, or how it works under the hood. It cares about what your AI system does to people. If it makes or influences decisions that affect someone's employment, their access to credit, their ability to get insurance, their immigration status, that system is regulated heavily. And here is the part that surprises most UK-based organizations I speak to. The EU AI Act is not just an EU regulation, it applies to any organization whose AI systems affect people in the EU, regardless of where that organization is based. If you are a UK financial services firm with European customers, this regulation applies to you. And if you are a global enterprise with any operations touching EU nationals, this regulation applies to you. Brexit did not create a boundary here. The people your AI affects are the boundary. The EU AI Act organizes AI systems into four risk tiers. Understanding these is the foundation of everything else. So the first tier is unacceptable risk. These are AI systems that are simply banned, no exceptions, nowhere currents, social scoring systems, subliminal manipulation, real-time biometric surveillance of public spaces by law enforcement with very narrow exceptions. If your system does any of these things, it cannot operate in the EU. Full stop. The second tier is high risk. This is where most organizations in regulated industries need to pay close attention. High risk AI systems are not banned, but they carry significant obligations. They must be assessed, documented, monitored, and evidenced before and throughout deployment. The third tier is limited risk. These are systems that primarily carry transparency obligations. If your AI system interacts with customers and they might not know they are talking to an AI, you have to tell them. Not in the small print, but clearly. The fourth tier is minimal risk. Everything else, the vast majority of AI tools, spreadsheet assistance, spam filters, recommendation engines, they fall here in this category. No specific EU AI Act obligations, though GDPR and other frameworks still apply. So for almost every regulated financial services firm listening to this, the tier that matters is high risk. So let me spend some time there. High risk AI systems are defined in annex three of the EU ALI Act. There are eight categories. I'm going to walk through the ones that are most relevant to financial services, insurance, and enterprises. The first is employment and HR. If you use AI to screen CVs, to score candidates, to predict performance, to allocate work, to make decisions about pay or promotions, that is high risk. Most large enterprises are running high risk AI systems in their HR functions right now. Many do not know it. The second is access to essential services. So this is the category that covers credit scoring, insurance pricing, benefit assessment, literally any AI system that influences whether a person can access a financial product or service. If your underwriting model, your credit decisioning engine or your fraud detection system affects individual customers, it is almost certainly high risk. The third is critical infrastructure. AI systems used in the management of utilities, transport, financial infrastructure. If your AI system sits inside the operational layer of a regulated financial institution, managing liquidity, routing transactions, assessing operational risk, this category must apply. And then there is biometric identification. So that is facial recognition, voice recognition used to identify individuals, and AI used in education, law enforcement, migration, and justice. The question I would ask every leader listening to this is do you know which of your AI systems fall into these categories? Not which ones you think might, which ones actually do. Because the answer for most organizations is that they have more high-risk systems than they initially assumed. And the obligations to govern those systems is now. Let me now be more specific about what the EU AI Act actually requires for high-risk systems. There are six key obligations. So I'll start with Article 9, which is all about the risk management. You must have a documented ongoing process for identifying and managing the risk of your AI system, not a one-time assessment. An ongoing process that runs throughout the system's operational lifeline. Now let's look at Article 10, which is the data governance. Your training data must meet quality standards. You must know where it came from, how it was processed, and whether it introduces bias. This is not just a data team concern, it is a compliance obligation with regulatory teeth. So on to Article 11, which is all about the technical documentation. You must maintain detailed documentation about how your system works, its purpose, its design, its performance characteristics, its limitations in enough detail that a competent authority could evaluate it. Then Article thirteen is about transparency. Users must understand they are interacting with an AI system and have enough information to understand how it works. Not an impenetrable privacy notice, meaningful transparency. Article fourteen is about the human oversight. The EU AI Act does not just say that humans should be evolved. It says there must be meaningful human oversight, the genuine ability to understand, monitor and intervene in the AI system's operation, not rubber stamping, but actual oversight. Article 15 is all about the accuracy, robustness and cybersecurity. Your system must perform consistently and securely throughout its life cycle. It must be resilient to attempts to manipulate it. And its performance must be monitored continuously. Now, here is what I want you to notice about those six obligations. They're not things you do once before deployment and then you forget. They are ongoing. That is why static compliance documents cannot meet these obligations. They just capture a moment. The EU AI Act requires a continuous posture and layered on top of the EU AI Act for financial services firms specifically, you have DORA, which is the Digital Operational Resilience Act, the Cyber Resilience Act, and GDPR. These frameworks do not operate in parallel, they overlap. A single, high-risk AI system can sit under all four simultaneously. Your governance posture needs to address all of them in one place with one evidence trail. The regulation is not coming, it is here. But the enforcement obligations are being phased in and I want to be precise about the timeline. The prohibited AI practices, the unacceptable risks here have been in force since February 2025. The governance obligations for general purpose AI models came into force in August 2025, and the obligations for high risk AI systems, i.e. Article 9 through 15, everything I have just described, those come into force on 2nd August 2026. The fines are real. Up to 35 million euros or 7% of global and alternative for prohibited practices, up to 15 million or 3% for violations of the high risk obligations. The organizations that face the first enforcement actions will be the cautionary tales cited in boardrooms for years. The organizations that had their governance infrastructure in place will be the ones that watched those actions from the sidelines. I know which side of that I would rather be on. Every obligation I've just described, the risk management system, the technical documentation, the human oversight mechanisms, the continuous monitoring, and then the incident reporting. Viridian addresses directly. It classifies your AI systems continuously against the EU AI Act, DORA, the Cyber Resilience Act, GDPR, ISO forty two thousand one and NIST, giving you one integrated compliance picture. It runs the monitoring continuously, it generates the evidence automatically, and it produces the Article seventy three serious incident report from documentation that has been building since day one. Viridian is available today on Microsoft Azure Marketplace. The link is in the show notes. You can register your first AI system the same day you subscribe. The EU AI Act is not a reason to slow down AI adoption. It is the framework that makes AI adoption sustainable. The organizations that understand it and build governance infrastructure around it now will have a fundamentally different conversation with their regulators, their boards and their customers than those that do not. So next week, episode five is all about shadow AI, the governance crisis nobody's talking about. If you think the EU AI Act only applies to the AI systems your IT team knows about, that episode is essential listen. Until then, keep leading intentionally. Thank you.