Guide · AI Governance & Compliance

The EU AI Act: A UK Business Guide

The EU AI Act is the world’s first comprehensive law regulating artificial intelligence, and it can apply to UK businesses even though the UK has left the EU. It works on a risk-based system: the more potential an AI use has to affect people, the more obligations it carries. As of August 2026, the ban on prohibited AI practices and the rules for general-purpose AI models are already in force; the toughest obligations, for high-risk systems, were pushed back by a 2026 reform and now land in December 2027 and August 2028. This guide explains what it means for a UK business in plain English, and we keep it updated as the timeline moves, because it has already moved once this year.

Key takeaways

Table of Contents

The basics

What the EU AI Act actually is

The EU AI Act, formally Regulation (EU) 2024/1689, is the first comprehensive AI regulation anywhere in the world. It entered into force on 1 August 2024, though its obligations arrive in phases rather than all at once, which is a large part of why it causes confusion. Because it can reach beyond the EU’s own borders, many UK businesses now refer to it informally as “the UK AI Act question”, even though there is no separate UK AI Act, the UK currently regulates AI through existing law and sector-specific guidance rather than a single dedicated statute.

The Act does not ban AI, and it does not require a licence to use it. Instead it takes a risk-based approach: nearly every use of AI is permitted, and the question the law asks is how much autonomy the AI has, in what context, and how much it could affect a person’s rights, safety or opportunities. Systems judged higher risk carry more obligations; most everyday business uses of AI sit well below that threshold.

The regulation is genuinely significant, but for most UK businesses the practical work is establishing where you sit, not undertaking a huge compliance programme. A large share of businesses discover, correctly, that their AI use falls into the lower-risk categories with comparatively light obligations.

The number one anxiety question

Does the EU AI Act apply to UK businesses?

Yes, it can, and this catches a lot of UK businesses off guard because it is easy to assume that leaving the EU means EU law no longer touches you. The EU AI Act has extraterritorial scope, similar in principle to GDPR: it applies based on where the AI’s effects land, not where the company is based. In practice, if your business offers a product or service that uses AI to people or organisations in the EU, or if the output of your AI system is used within the EU, the Act can apply to you, regardless of where your company is headquartered. A UK software company selling an AI-powered tool to EU customers is in scope. A UK retailer with no EU customers and no EU operations, using AI purely internally on UK data, generally is not. The honest, practical answer for most UK SMEs is: probably not yet, or only lightly, but it is worth checking properly rather than assuming. The businesses that do need to pay close attention are those selling AI-enabled products into the EU, processing EU customers’ data through AI, or operating AI systems that EU-based users interact with directly.

The framework

The four risk tiers, explained

Tier What it covers What it means for you
Unacceptable risk Banned outright: social scoring by public authorities, exploiting vulnerabilities of children or vulnerable groups, most real-time biometric surveillance in public spaces, emotion recognition in workplaces and schools Already banned since February 2025. Almost no ordinary business is anywhere near this tier
High risk AI used in things like recruitment decisions, credit scoring, critical infrastructure, medical devices, and law enforcement The heaviest obligations: documentation, testing, human oversight, conformity assessment. Deadlines pushed to December 2027 / August 2028
Limited risk (incl. general-purpose AI) Chatbots, AI-generated content, and general-purpose models like the ones behind ChatGPT and Claude Mainly transparency duties: telling people they are interacting with AI, labelling AI-generated content. Already in force since August 2025 for GPAI providers
Minimal risk The vast majority of everyday business AI use: spam filters, recommendation features, most internal productivity tools No specific obligations beyond general good practice. Most SME use of AI sits here
Most UK businesses using AI day to day, an assistant for drafting, a chatbot for support, an internal automation, sit in minimal or limited risk. High risk is a smaller, specific category: AI making or materially influencing decisions about people’s access to jobs, credit, essential services, or safety.

Keep this bit current

The timeline, and what changed in 2026

Act enters into force

The regulation becomes law, with obligations phased in over the following years rather than applying immediately.

Prohibited practices banned

The unacceptable-risk category, social scoring, manipulative AI, most public biometric surveillance, becomes illegal. Already in force.

General-purpose AI rules apply

Transparency obligations for GPAI providers, covering models behind tools like ChatGPT, Claude and Gemini, take effect. Already in force.

Enforcement begins in earnest

National authorities and the EU AI Office start actively enforcing what is already in force. This is where we are now.

High-risk obligations (Annex III)

Originally due August 2026, a 2026 simplification package (the “Digital Omnibus”) pushed this back by 16 months to give businesses more time to prepare.

High-risk obligations (Annex I, product-integrated)

For AI embedded in regulated products, medical devices, machinery, lifts, also pushed back by a year under the same reform.

The practical question

What a UK business should actually do

01

Work out if it applies to you

Do you serve customers or users in the EU with anything AI-powered? If not, your exposure is limited. If yes, it is worth a proper check rather than a guess.
02

Map what AI you actually use

You cannot assess risk tier by tier without a real inventory of the AI in use across the business, including tools staff have adopted informally.
03

Classify honestly

Most businesses find most of their AI use sits in minimal or limited risk. Establishing that clearly, and documenting why, is valuable in itself.
04

Address what is already in force

If you use GPAI-based tools, check the transparency obligations that have applied since August 2025 are actually being met.
05

Plan for what is coming, calmly

If you do have high-risk uses, you now have until December 2027 or August 2028. That is real time to prepare properly rather than scramble.

Get it checked properly

An AI compliance review gives you a clear, honest position rather than a guess.

What is at stake

Penalties for non-compliance

The fines are structured to make GDPR’s penalties look modest. Breaching the ban on prohibited AI practices carries fines of up to €35 million or 7% of global annual turnover, whichever is higher. Most other breaches carry fines of up to €15 million or 3% of global turnover. These are maximums, not typical outcomes, but they signal how seriously the framework is meant to be taken.

For most UK SMEs, the realistic risk is not a dramatic fine out of nowhere. It is the more mundane cost of an unclear position: a client or partner asking during due diligence whether your AI use is compliant, and not having a clear answer. That is usually the moment this becomes urgent, and it is entirely avoidable with a proper assessment done in advance.

Frequently asked

Questions people ask about the EU AI Act

The EU AI Act, formally Regulation (EU) 2024/1689, is the world's first comprehensive law regulating artificial intelligence. It uses a risk-based approach, sorting AI systems into four tiers, unacceptable, high, limited and minimal risk, with obligations that scale according to how much the AI could affect people's rights, safety or opportunities. It entered into force on 1 August 2024, with obligations phased in over several years.

It can. The Act has extraterritorial scope, similar to GDPR, applying based on where the AI's effects land rather than where the company is based. A UK business offering an AI-powered product or service to people or organisations in the EU can be in scope, even with no EU presence. A UK business using AI purely internally on UK data generally is not.

 

It entered into force on 1 August 2024, but obligations arrive in phases. Prohibited practices were banned from February 2025, general-purpose AI rules applied from August 2025, and enforcement began in earnest on 2 August 2026. The toughest high-risk obligations were pushed back during 2026 to December 2027 and August 2028. This page is kept updated as those dates move.

 

Yes, in part. The ban on prohibited practices and the rules for general-purpose AI models are already in force and being enforced. The high-risk obligations, the heaviest part of the Act, are not yet in force; they were deferred to December 2027 and August 2028 by a 2026 reform.

 

It regulates AI systems by risk tier: banning unacceptable-risk uses outright, imposing strict requirements on high-risk uses such as AI in recruitment or credit decisions, requiring transparency for limited-risk uses like chatbots and general-purpose AI models, and leaving minimal-risk uses, the majority of everyday business AI, largely unregulated beyond general good practice.

 

Most UK SMEs should at minimum work out honestly whether the Act applies to them and, if so, which risk tier their AI use falls into. If you use general-purpose AI tools, checking the transparency obligations in force since August 2025 are being met is worthwhile now. Anything in the high-risk category has a realistic runway to December 2027 or August 2028 to prepare properly.

 

Get a clear, honest position on where you stand

This guide gives you the general picture. A free consultation gets you a specific read on your business: whether the Act applies to you, what risk tier your AI use falls into, and what, if anything, you actually need to do.
Scroll to Top