Guide
EU AI Act compliance for enterprises
The risk tiers, the obligations they trigger, and why an owned, auditable model makes compliance simpler.
By James Drayson
In short
The EU AI Act regulates AI by risk tier, from minimal to unacceptable, with the heaviest obligations on high-risk systems: transparency, data governance, human oversight, and documentation. Owning an auditable model deployed in your perimeter makes these obligations easier to meet than relying on an opaque third-party API.

The risk tiers
- Unacceptable risk: Banned uses (e.g. certain manipulative or social-scoring systems).
- High risk: Systems in sensitive domains, subject to the strictest obligations.
- Limited risk: Transparency duties, e.g. telling users they're interacting with AI.
- Minimal risk: Most general applications, with light or no specific obligations.
Core obligations for high-risk systems
- Data governance: Documented, quality-controlled training data.
- Transparency & documentation: Technical records of how the system works.
- Human oversight: Meaningful human control over outcomes.
- Robustness & logging: Accuracy, security, and traceable operation.
How owning the model simplifies compliance
Many obligations, data governance, documentation, traceability, are far easier when you hold the weights, training data, and logs. With an owned model you can evidence exactly what it learned and how it behaves; with an opaque hosted API, you depend on a vendor's disclosures. Ownership turns compliance from a black box into something you can document and audit.
What this looks like with Locai
Compliance is far easier to evidence when the machine, the model and the logs are all things you own, not things a vendor describes in a whitepaper.
Locai Labs builds Locai One, an on-prem AI appliance. It is one machine that arrives with everything already in it: the hardware, our open-weight Locai Juno models, and Locai OS, the operating system that serves the models and handles users, access and monitoring. You plug it into a mains socket and your network, and your team is working in about 15 minutes. No cloud account, no per-token bill, and nothing leaving the building.
The reason a data-centre-class model fits in a box on your floor is SPACE, our compression algorithm. Instead of asking how much of a model can be cut while keeping it broadly similar, SPACE asks what the model needs to be good at, preserves the subnetworks behind those capabilities and strips back the rest. The result is a smaller specialist rather than a shrunken generalist, tuned to the exact hardware it ships on.
Locai One starts at £29,950 for a team, and Locai One Pro at £49,950 for an organisation, bought once and owned outright. Both run air-cooled on standard mains power and work fully air-gapped. Any compatible open-weight model runs alongside Juno, and if you need a model trained on your own proprietary data we can post-train one and deploy it on the same machine.
Frequently asked questions
What is the EU AI Act?
The EU's regulation of AI by risk tier, imposing the strictest obligations (transparency, data governance, oversight, documentation) on high-risk systems.
Who must comply?
Providers and deployers of AI systems used in the EU, with obligations scaled to the system's risk tier.
How do I prepare?
Classify your systems by risk, then put data governance, documentation, oversight, and logging in place. Owning an auditable model makes each step easier.
Does owning the model help?
Yes. Holding the weights, data, and logs lets you evidence governance and traceability directly, rather than relying on a third party's disclosures.
Book a sovereign AI briefing
A 30-minute session on owning your model: deployment options, the data path, and a clear cost range for your use case.
