Guide · AI Governance & Compliance
The EU AI Act: A UK Business Guide
Key takeaways
- The EU AI Act can apply to a UK business, whether or not you have any EU presence, if your AI touches people in the EU.
- Most businesses are not building the high-risk systems the Act is toughest on, establishing that clearly is often most of the work.
- The toughest deadlines were pushed back in 2026: high-risk obligations now land December 2027 and August 2028, not August 2026 as originally planned.
- The bans on prohibited practices and the rules for general-purpose AI models, covering tools like ChatGPT and Claude, are already in force today.
Table of Contents
The basics
What the EU AI Act actually is
The EU AI Act, formally Regulation (EU) 2024/1689, is the first comprehensive AI regulation anywhere in the world. It entered into force on 1 August 2024, though its obligations arrive in phases rather than all at once, which is a large part of why it causes confusion. Because it can reach beyond the EU’s own borders, many UK businesses now refer to it informally as “the UK AI Act question”, even though there is no separate UK AI Act, the UK currently regulates AI through existing law and sector-specific guidance rather than a single dedicated statute.
The Act does not ban AI, and it does not require a licence to use it. Instead it takes a risk-based approach: nearly every use of AI is permitted, and the question the law asks is how much autonomy the AI has, in what context, and how much it could affect a person’s rights, safety or opportunities. Systems judged higher risk carry more obligations; most everyday business uses of AI sit well below that threshold.
The regulation is genuinely significant, but for most UK businesses the practical work is establishing where you sit, not undertaking a huge compliance programme. A large share of businesses discover, correctly, that their AI use falls into the lower-risk categories with comparatively light obligations.
The number one anxiety question
Does the EU AI Act apply to UK businesses?
The framework
The four risk tiers, explained
| Tier | What it covers | What it means for you |
|---|---|---|
| Unacceptable risk | Banned outright: social scoring by public authorities, exploiting vulnerabilities of children or vulnerable groups, most real-time biometric surveillance in public spaces, emotion recognition in workplaces and schools | Already banned since February 2025. Almost no ordinary business is anywhere near this tier |
| High risk | AI used in things like recruitment decisions, credit scoring, critical infrastructure, medical devices, and law enforcement | The heaviest obligations: documentation, testing, human oversight, conformity assessment. Deadlines pushed to December 2027 / August 2028 |
| Limited risk (incl. general-purpose AI) | Chatbots, AI-generated content, and general-purpose models like the ones behind ChatGPT and Claude | Mainly transparency duties: telling people they are interacting with AI, labelling AI-generated content. Already in force since August 2025 for GPAI providers |
| Minimal risk | The vast majority of everyday business AI use: spam filters, recommendation features, most internal productivity tools | No specific obligations beyond general good practice. Most SME use of AI sits here |
Keep this bit current
The timeline, and what changed in 2026
Act enters into force
- 1 Aug 2024
Prohibited practices banned
- 2 Feb 2025
General-purpose AI rules apply
- 2 Aug 2025
Enforcement begins in earnest
- 2 Aug 2026
High-risk obligations (Annex III)
- 2 Dec 2027 (changed in 2026)
High-risk obligations (Annex I, product-integrated)
- 2 Aug 2028 (changed in 2026)
The practical question
What a UK business should actually do
Work out if it applies to you
Map what AI you actually use
Classify honestly
Address what is already in force
Plan for what is coming, calmly
Get it checked properly
What is at stake
Penalties for non-compliance
The fines are structured to make GDPR’s penalties look modest. Breaching the ban on prohibited AI practices carries fines of up to €35 million or 7% of global annual turnover, whichever is higher. Most other breaches carry fines of up to €15 million or 3% of global turnover. These are maximums, not typical outcomes, but they signal how seriously the framework is meant to be taken.
For most UK SMEs, the realistic risk is not a dramatic fine out of nowhere. It is the more mundane cost of an unclear position: a client or partner asking during due diligence whether your AI use is compliant, and not having a clear answer. That is usually the moment this becomes urgent, and it is entirely avoidable with a proper assessment done in advance.
Frequently asked
Questions people ask about the EU AI Act
The EU AI Act, formally Regulation (EU) 2024/1689, is the world's first comprehensive law regulating artificial intelligence. It uses a risk-based approach, sorting AI systems into four tiers, unacceptable, high, limited and minimal risk, with obligations that scale according to how much the AI could affect people's rights, safety or opportunities. It entered into force on 1 August 2024, with obligations phased in over several years.
It can. The Act has extraterritorial scope, similar to GDPR, applying based on where the AI's effects land rather than where the company is based. A UK business offering an AI-powered product or service to people or organisations in the EU can be in scope, even with no EU presence. A UK business using AI purely internally on UK data generally is not.
It entered into force on 1 August 2024, but obligations arrive in phases. Prohibited practices were banned from February 2025, general-purpose AI rules applied from August 2025, and enforcement began in earnest on 2 August 2026. The toughest high-risk obligations were pushed back during 2026 to December 2027 and August 2028. This page is kept updated as those dates move.
Yes, in part. The ban on prohibited practices and the rules for general-purpose AI models are already in force and being enforced. The high-risk obligations, the heaviest part of the Act, are not yet in force; they were deferred to December 2027 and August 2028 by a 2026 reform.
It regulates AI systems by risk tier: banning unacceptable-risk uses outright, imposing strict requirements on high-risk uses such as AI in recruitment or credit decisions, requiring transparency for limited-risk uses like chatbots and general-purpose AI models, and leaving minimal-risk uses, the majority of everyday business AI, largely unregulated beyond general good practice.
Most UK SMEs should at minimum work out honestly whether the Act applies to them and, if so, which risk tier their AI use falls into. If you use general-purpose AI tools, checking the transparency obligations in force since August 2025 are being met is worthwhile now. Anything in the high-risk category has a realistic runway to December 2027 or August 2028 to prepare properly.