The most expensive AI mistake can begin with an ordinary purchase decision. A customer-service team buys a drafting assistant. HR switches on an applicant-ranking feature. Someone asks whether it is compliant, and the answer comes back: “The supplier says it is. There is a human in the loop.”
Those statements may describe an intention. They do not establish which requirements apply, what the system actually does, or whether the safeguards work. That gap is where AI governance becomes business-critical.
For organisations working in the UK and EU, the consequences can include regulatory penalties, harmed customers or applicants, disrupted operations and difficult questions from clients. Practical AI Governance and Compliance by Edward Omoba addresses the skills behind those questions: understanding a use, examining evidence, building controls and explaining a defensible decision.
The penalties deserve attention—and precision
The EU AI Act has several penalty tiers. Under Article 99, prohibited-practice infringements can attract fines of up to €35 million or 7% of the preceding financial year's worldwide annual turnover for an undertaking, whichever is higher. Specified other breaches can reach €15 million or 3%; supplying incorrect, incomplete or misleading information to the relevant authorities can reach €7.5 million or 1%. For SMEs, including start-ups, the Article 99 ceilings use the lower of the relevant amount and percentage. These are maximums, not automatic bills for every mistake. The applicable provision, actor and circumstances matter. Read the official Article 99 explanation and text.
UK organisations also face substantial exposure when AI processing breaches data-protection requirements. The higher UK GDPR maximum is £17.5 million or, for an undertaking, 4% of the preceding year's worldwide annual turnover, whichever is higher; the standard tier is £8.7 million or 2%. The infringement determines the tier. These are data-protection penalties, not a universal UK “AI fine”. The ICO explains the statutory ceilings.
A useful governance review therefore starts with the activity and its legal context. It asks what information enters the tool, what decisions its outputs influence, who supplies and uses it, and which entity is responsible. The number on a penalty headline cannot answer those questions.
The operational bill may arrive before a fine
Imagine a generated customer reply gives an incorrect cancellation deadline. The immediate problem is the customer's position. The business then needs to identify affected messages, preserve records, correct information and investigate why review failed. Staff time, complaint handling and lost confidence can accumulate while the legal assessment is still underway.
Or consider an applicant-ranking tool that misses relevant qualifications in an alternative application format. An overall accuracy figure may look respectable while a particular group of applicants is disadvantaged. Discovering that after deployment can mean reassessing decisions and rebuilding a workflow that should have been examined earlier.
These are illustrative risk pathways, not claims that every AI deployment produces harm. They show why the commercial costs can extend beyond a regulator's decision: remediation, service interruption, supplier disputes, contractual exposure and weakened trust. A policy document offers limited protection if nobody can demonstrate the control it describes.
UK and EU work needs separate, connected analysis
The book makes this distinction concrete through Northstar Services, a fictional workplace. ReplyAssist anchors an English customer-service case; CandidateBrief anchors an Irish recruitment case. Sharing a model does not make the two activities legally identical. A supplier's hosting location is also insufficient to settle the scope of an entire regulatory regime.
The EU timetable is another reason to examine the actual duty. Following the July 2026 amendments, the Commission's current explanation identifies 2 December 2027 for the Annex III high-risk rules and 2 August 2028 for high-risk systems embedded in regulated products. Relevant transparency requirements already apply, subject to their conditions and transitions. A later high-risk milestone does not postpone existing privacy, equality or contractual responsibilities. See the Commission's current enforcement overview.
That is the practical value of a UK and EU learning approach: it trains the reader to record entity, purpose, role, source and timing before making a conclusion. It also distinguishes legislation from guidance, voluntary frameworks, contracts and internal policies.
Why this book helps turn concern into useful work
Practical AI Governance and Compliance develops that method across 30 chapters in five parts. It moves from understanding the work to requirements, system assessment, controls, operation and a final integrated capstone.
Its examples explain how a decision is built. Early on, a supplier brochure establishes that an accuracy claim was made; it does not establish accurate performance in Northstar's workflow. Later, the reader examines testing coverage, data copies, supplier commitments, human oversight and the evidence needed for a deployment recommendation.
The book also teaches supported progress. Sufficient, matched evidence can justify recommending a narrow monitored pilot. Missing evidence or a changed system can justify further investigation. That balance matters to a business trying to use AI responsibly while keeping work moving.
Nine appendices and 36 reusable template structures support the learning. They include an obligations register, risk and treatment records, a vendor assessment, an oversight procedure, a deployment decision pack and incident-investigation records. The premium PDF package adds editable companion resources, worked examples, model answers, datasets and an offline resource reader.
Start with one AI use you can describe
A useful first step is to choose one activity and write down its owner, inputs, outputs, affected people and decision pathway. Then identify one important safeguard and ask what evidence shows it operates. That creates a clearer starting point than a general declaration that the organisation “takes responsible AI seriously”.
Build the skills to make that review useful. Explore Practical AI Governance and Compliance, inspect the sample pages and choose the premium PDF with companion resources. Prefer a printed book? View the newly published paperback on Amazon. Check the Amazon listing for its current price, edition and included materials; the PDF bundle is a separate purchase.
Published 9 October 2026. Educational information, not advice on a particular deployment. The book develops introductory practical skills; completing it does not confer certification or establish organisational compliance.