AI GOVERNANCE & COMPLIANCE · SERVICENOW AI CONTROL TOWER · IRM / GRC · ENTERPRISE SERVICE MANAGEMENT · PROCESS RE-ENGINEERING · EU AI ACT · ISO/IEC 42001 · UK GDPR & DPIAs · AI GOVERNANCE & COMPLIANCE · SERVICENOW AI CONTROL TOWER · IRM / GRC · ENTERPRISE SERVICE MANAGEMENT · PROCESS RE-ENGINEERING · EU AI ACT · ISO/IEC 42001 · UK GDPR & DPIAs ·
EU AI Act · 14 min read

What Is the EU AI Act, and Does It Apply to Your Business?

The EU AI Act is the world's first comprehensive legal framework for artificial intelligence. In 2026 the EU agreed a simplification package that moved its biggest compliance deadline back by more than a year and added a brand-new prohibition. This is the current, accurate picture: the complete phased timeline, who the Act actually binds, what each risk tier requires, and what the extra time is really for.

What Is the EU AI Act?

The EU AI Act (formally Regulation (EU) 2024/1689) is a regulation passed by the European Union that sets out legal requirements for the development, deployment and use of artificial intelligence systems. It entered into force on 1 August 2024 and applies in phases, with different obligations switching on at different dates rather than all at once. It is the world's first comprehensive AI law: no other jurisdiction has legislation of this scope and reach currently in force.

The Act is built on a risk-based approach. Not all AI carries the same stakes, so the obligations attached to a given system depend on the potential harm it could cause. A spam filter and an AI hiring tool sit in entirely different compliance categories, and the Act treats them accordingly.

Who Does the EU AI Act Bind?

The Act has extraterritorial reach. Under Article 2, it applies to providers who place AI systems on the EU market or put them into service in the EU, and to deployers (organisations using AI systems) where those systems are used inside the EU. Crucially, this covers organisations based outside the EU: if your AI, or the output of your AI, reaches users or affects people in EU member states, the Act can reach you.

For UK businesses, that creates a specific question: does your business touch the EU market? If you export products into the EU, provide services to EU customers, run platforms accessed by EU users, or use AI in hiring or credit decisions that cover EU individuals, then yes, the Act is hard law for you across those activities. The relevant obligations and their current deadlines are in the timeline below.

For a purely domestic UK business with no EU exposure, the picture is different. The EU AI Act does not bind you as a matter of EU law. Your legal obligations sit in UK GDPR, the Data (Use and Access) Act 2025, the Equality Act 2010 and your sector regulator. Many UK firms nonetheless choose to apply the EU AI Act's risk framework voluntarily, and there are good reasons: it is the most mature AI governance framework in existence, the UK government's own AI Management Essentials initiative (since shelved) was modelled on it, and it positions you well if your business ever expands into EU markets. We cover the full UK-vs-EU decision in UK vs EU: which AI rules apply?

The Full Application Timeline

The Act applies in phases. The table below shows the current schedule, reflecting the 2026 Digital Omnibus changes. Every date on this page agrees with our live AI regulation tracker.

Date What applies Status
2 Feb 2025 Bans on unacceptable-risk AI practices (Article 5) and the AI literacy duty (Article 4) In force
2 Aug 2025 Obligations for general-purpose AI model providers (the GPAI chapter) In force
2 Aug 2026 Transparency duties (Article 50): disclosing when people interact with AI or see AI-generated content. This date did not move in the Digital Omnibus. Upcoming
Dec 2026 Watermarking grace period ends (machine-readable marking under Article 50). New Digital Omnibus prohibition on AI systems that generate non-consensual intimate imagery or nude depictions of real people also applies from this date. Upcoming
2 Dec 2027 High-risk obligations for stand-alone systems in Annex III (recruitment, credit scoring, healthcare, law enforcement, education and more). Deferred from 2 August 2026 by the Digital Omnibus. Upcoming
2 Aug 2028 High-risk obligations for AI embedded in already-regulated products (Annex I: machinery, medical devices, vehicles, toys and similar). Deferred from 2 August 2027 by the Digital Omnibus. Upcoming

The August 2026 transparency duties are worth highlighting: they did not move and they arrive in weeks. If you operate a chatbot, publish AI-generated content at scale, or use deepfake-adjacent AI in any customer-facing context, you need disclosures in place before 2 August 2026 if you serve EU users.

What the Digital Omnibus Changed, and Why

The Digital Omnibus is the name given to the EU's 2026 simplification package that amended the AI Act. The political logic was straightforward: the original high-risk deadlines were too tight for many businesses to meet properly, and the EU judged that a measured, well-resourced compliance journey was better than a wave of rushed, low-quality programmes that would satisfy the form without delivering the substance.

The European Parliament adopted the changes in plenary on 16 June 2026 and the Council gave its final adoption on 29 June 2026. The amendments enter into force three days after publication in the EU Official Journal. As of 3 July 2026, both co-legislators have adopted the package but it has not yet been published in the Official Journal; publication is expected in July 2026. We will update this page and the regulation tracker as soon as that happens.

The substantive changes are:

  • Annex III high-risk deadline deferred: from 2 August 2026 to 2 December 2027, giving businesses an additional 16 months to build high-risk compliance for stand-alone AI systems such as recruitment tools and credit-scoring models.
  • Annex I high-risk deadline deferred: from 2 August 2027 to 2 August 2028, for AI embedded in regulated products including medical devices and machinery.
  • New prohibition added: the Digital Omnibus introduced a ban on AI systems that generate non-consensual intimate imagery or nude depictions of real people. This applies from December 2026 and sits in the same outright-ban category as social scoring and mass biometric surveillance.

"The deadline moving is not a reason to do nothing. It is breathing room to do it properly, instead of buying rushed compliance you did not need yet."

The deferral buys time on the heaviest paperwork. It does not suspend the prohibitions already in force since February 2025, and it does not delay the August 2026 transparency duties. Those obligations are unaffected.

How the Act Classifies AI Risk

The EU AI Act uses a four-tier risk model. Which tier a system falls into determines the obligations attached to it and when they apply.

Unacceptable risk: outright banned

A small category of AI applications is banned outright because the EU has judged that no legitimate use case justifies the harm they create. These bans have applied since 2 February 2025. The banned practices include:

  • Social scoring systems that rank or classify people based on their behaviour, social status or personal characteristics
  • Real-time remote biometric identification in publicly accessible spaces (with narrow, strictly defined law-enforcement exceptions)
  • AI that uses subliminal or manipulative techniques to distort behaviour or decision-making in ways that cause harm
  • AI that exploits vulnerabilities related to age, disability or socioeconomic status
  • Untargeted scraping of facial images from the internet or CCTV to build or expand biometric databases
  • AI used to infer emotions in the workplace or in educational settings (with exceptions for safety and medical purposes)
  • AI-based prediction of criminal or reoffending risk based solely on profiling without individual assessment
  • From December 2026: AI systems that generate non-consensual intimate imagery or nude depictions of real people (added by the Digital Omnibus)

If your business operates in adjacent areas: biometrics, behavioural analytics, generative media, or synthetic imagery, these bans are worth examining carefully. The list is specific and enforcement bodies in the EU are already building capacity around the categories named in Article 5.

High risk: strict obligations before and during deployment

High-risk AI is the category where most compliance work concentrates. A system is high-risk under the Act if it falls into one of the Annex III use cases, or if it is AI embedded as a safety component in a regulated product under Annex I.

Annex III use cases include:

  • AI in recruitment, CV screening, candidate ranking and employment decisions
  • AI used in creditworthiness assessments and credit scoring for individuals
  • AI in healthcare diagnostics, treatment decisions and medical devices (where not already in Annex I)
  • AI used to assess eligibility for social benefits and services
  • AI in law enforcement (risk assessment, predictive policing, evidence evaluation)
  • AI in educational admissions and assessment
  • AI managing critical infrastructure (energy, water, transport networks)
  • AI used in border control and immigration decisions

Annex I covers AI embedded as a safety component in products that are already regulated under existing EU law: medical devices, machinery, vehicles, aviation equipment, toys, lifts and similar categories.

For high-risk AI systems, the Act requires the following obligations to be met before deployment and maintained on an ongoing basis:

  • Risk management system: a documented, ongoing process to identify, estimate and evaluate risks for each specific high-risk system throughout its lifecycle
  • Data governance: training, validation and testing datasets must meet defined quality standards and be examined for possible biases before use
  • Technical documentation: a full technical file demonstrating that the system meets all high-risk requirements (comparable to a product safety technical dossier, but for AI)
  • Automatic logging: the system must generate logs enabling post-market traceability of its operation and outputs
  • Transparency to deployers: providers must give deployers enough information to use the system in compliance, including instructions for human oversight and intervention
  • Human oversight: the system must be designed so that a responsible person can understand its outputs, monitor its operation, intervene when necessary and halt it if required
  • Accuracy, robustness and cybersecurity: defined performance standards appropriate to the intended use, including resilience against adversarial inputs and errors
  • Conformity assessment: for most Annex III systems, a self-assessment against all requirements; for certain high-sensitivity uses (such as biometric identification and critical infrastructure) a third-party audit is required
  • EU database registration: stand-alone high-risk systems must be registered in the EU AI Office's publicly accessible database before they are placed on the EU market

The deadline for all of this for Annex III systems is 2 December 2027. For Annex I systems it is 2 August 2028. These are not aspirational targets: they are the dates from which national supervisory authorities can bring enforcement action.

Limited risk: transparency obligations from August 2026

AI systems in this category carry specific transparency duties under Article 50, applying from 2 August 2026. The core requirements are:

  • Chatbots and AI assistants that interact with people must inform users they are talking to an AI, not a person (at the start of the first interaction)
  • Deepfakes (AI-generated or manipulated images, video or audio depicting real people) must carry a clear and visible disclosure
  • AI-generated text, images, audio and video that could be mistaken for human-produced content must be marked as machine-generated (the watermarking obligation has a grace period to December 2026)

If you operate a customer-facing AI assistant, use generative AI to produce content at scale, or deploy AI avatars in video or voice, these obligations apply to you from 2 August 2026 for any EU-facing use. The disclosure duty is the primary obligation; the watermarking mechanic has until December 2026.

Minimal risk: no specific obligations

AI that does not fall into the categories above faces no specific obligations under the Act. Spam filters, basic recommendation engines, inventory forecasting tools and similar applications sit here. The Act does not prevent industry groups from developing voluntary codes of conduct for minimal-risk AI, and many are doing so; but there is no compliance requirement attached to this tier.

General-Purpose AI Models

The Act includes a dedicated chapter for general-purpose AI (GPAI) models: the large foundation models (including the large language models that underpin AI assistants and coding tools) that can be adapted for a wide range of tasks. Obligations for GPAI model providers have applied since 2 August 2025.

GPAI providers must maintain technical documentation, comply with copyright law and publish summaries of the data used for training. The largest GPAI models (those trained above a defined compute threshold) carry additional requirements including systemic-risk assessments and incident reporting to the EU AI Office.

For most UK SME readers this chapter is relevant as context rather than direct duty: you are almost certainly a deployer of a GPAI model (using an API or an AI product built on a foundation model), not a provider of one. As a deployer, your obligations run through the risk classification of the specific system you deploy and how you use it, not through the GPAI chapter. If you are building AI products on top of foundation models and offering them to customers in the EU, however, you may be acting as a provider for purposes of the Act, and the analysis changes. Our EU AI Act Rapid Audit covers provider-vs-deployer classification as part of its scope.

What Happens If You Don't Comply?

The Act's enforcement powers are significant. Under Article 99, penalties are set at whichever is higher in each case:

  • Prohibited AI practices (the outright bans): up to EUR 35 million or 7% of total global annual turnover
  • Breaches of high-risk obligations and other Act provisions: up to EUR 15 million or 3% of total global annual turnover
  • Supplying incorrect, incomplete or misleading information to notified bodies or national competent authorities in reply to a request: up to EUR 7.5 million or 1% of total worldwide annual turnover

These are maximum penalties; actual enforcement takes into account the nature, gravity, duration and effects of the breach, the firm's size, remedial action taken, and the degree of cooperation with supervisory authorities. But they are EU-level maxima comparable to GDPR fines, and should be treated as real exposure by any business with material EU market presence.

Beyond financial penalties, non-compliance carries reputational risk: particularly for businesses selling to enterprise customers, operating in regulated sectors, or bidding for public sector contracts where AI compliance is increasingly a procurement requirement.

Which UK Businesses Are Most Affected?

Remember the threshold: the Act is hard law for you only if your AI is used inside the EU market. If any of the following is true, the timeline above applies to you:

  • You sell products or provide services to EU customers or users
  • Your AI's output affects individuals in the EU, including EU employee or candidate populations
  • You use AI developed or supplied by an EU provider in ways that make you a deployer under the Act

Where that threshold is met, the sectors with the highest high-risk exposure are:

  • Manufacturing and engineering: AI in quality control, production line automation and supply chain management, particularly where systems are used in EU facilities or sold as embedded components in regulated products
  • Healthcare: AI in diagnostics, patient triage and workforce scheduling used in or sold to EU healthcare providers
  • Financial services: AI in credit scoring, fraud detection and recruitment screening applied to EU individuals
  • Logistics and transport: AI in route optimisation, demand forecasting and automated warehouse management operating in the EU
  • HR technology and SaaS: UK software businesses whose platforms include AI-assisted hiring, performance assessment or employee monitoring and are used by EU customers

If your business uses AI in any of these contexts and touches the EU market, the December 2027 high-risk deadline is the one to plan around, with the transparency duties landing sooner in August 2026.

"The extra time is finite and it is not free. The firms that use it to build proper governance will be ready. The firms that treat December 2027 as 'later' will be in the same scramble, just eighteen months from now."

What Do You Need to Do?

For high-risk AI systems, a sequenced approach is more useful than a single compliance sprint:

  • Scope first: map every AI system you use or provide, assess whether any cross the Annex III or Annex I threshold, and confirm whether the Act binds you at all. This is the foundation for everything else and it is where most businesses find they have over-estimated or under-estimated their real exposure.
  • Address August 2026 now: transparency duties for EU-facing AI arrive in weeks. If you operate chatbots, publish AI-generated content, or use deepfake-adjacent AI in customer-facing contexts, disclosures need to be in place.
  • Build governance, not just documentation: the high-risk requirements are not a form-filling exercise. Risk management systems, data governance, human oversight and logging need to be part of how your AI actually operates, not retrospective paperwork about something you hope was already happening.
  • Use the frameworks: ISO/IEC 42001 and the NIST AI RMF both map well to the Act's requirements. Building on an established standard means you are not starting from a blank page, and you end up with an evidence base that is credible to regulators. Our ISO/IEC 42001 pathway guide explains how.
  • Register where required: stand-alone high-risk systems must be registered in the EU AI Office database before deployment. Factor this into your planning well ahead of December 2027.

Maintain a register of all AI systems in use, conduct risk assessments for each system, implement human oversight controls, maintain technical documentation and audit logs, ensure transparency and explainability for automated decisions, and register certain AI systems with the EU AI Office. For most businesses, the first step is understanding which of their AI systems fall within the high-risk classification, and whether the Act binds them at all. That is exactly what our EU AI Act Rapid Audit delivers, in two to three weeks, from engagement to written report.

Frequently Asked Questions

Does the EU AI Act apply to UK companies?

It depends on whether your AI touches the EU market. If your AI systems, or their output, are used within the EU: by EU customers, EU employees, or through EU-facing products and services, then yes, the Act applies to you as a provider or deployer, regardless of where your business is incorporated. For a purely domestic UK business with no EU market exposure, the Act is voluntary best practice, not law. Your hard legal duties sit in UK GDPR, the Data (Use and Access) Act 2025, the Equality Act and your sector regulator. See UK vs EU: which AI rules apply? for the full decision framework.

What is the current high-risk deadline after the Digital Omnibus?

The headline deadline for stand-alone high-risk AI systems in Annex III (recruitment tools, credit-scoring models, healthcare AI, law enforcement tools and similar) is now 2 December 2027. This was moved from the original 2 August 2026 date. High-risk AI embedded in regulated products (Annex I) has a deadline of 2 August 2028, moved from 2 August 2027. Neither the August 2026 transparency duties nor the prohibitions already in force are affected by these deferrals.

What did the Digital Omnibus change?

The Digital Omnibus is the EU's 2026 simplification package amending the AI Act. It made two substantive changes. First, it deferred the Annex III high-risk deadline by 16 months (from August 2026 to December 2027) and the Annex I deadline by 12 months (from August 2027 to August 2028). Second, it added a new outright ban on AI systems that generate non-consensual intimate imagery or nude depictions of real people, which applies from December 2026. The European Parliament and Council both adopted the changes in June 2026; they take effect three days after Official Journal publication, expected July 2026.

What counts as a high-risk AI system?

A system is high-risk if it falls into one of the Annex III use cases (recruitment and employment decisions, creditworthiness assessment, healthcare diagnostics, law enforcement tools, educational admissions, critical infrastructure management, border control and social-benefits decisions), or if it is AI embedded as a safety component in an Annex I regulated product (medical devices, machinery, vehicles, toys and similar EU-regulated categories). If your system falls into neither annex, it is either limited-risk (transparency obligations only from August 2026) or minimal-risk (no specific obligations under the Act).

What are the penalties under the EU AI Act?

Penalties under Article 99 reach up to EUR 35 million or 7% of global annual turnover for prohibited practices (the outright bans), whichever is higher. For breaches of high-risk obligations and other provisions the ceiling is EUR 15 million or 3%, whichever is higher. A lower ceiling of EUR 7.5 million or 1% covers supplying incorrect, incomplete or misleading information to authorities in reply to a request. All three tiers are enforced by national supervisory authorities in each EU member state, coordinated by the EU AI Office.

Is the EU AI Act law in the UK?

No. The EU AI Act is not UK domestic law. The UK did not carry over the AI Act when it left the EU, and the UK government has not introduced an equivalent primary AI law. UK businesses are subject to UK rules: UK GDPR, the Data (Use and Access) Act 2025, the Equality Act 2010, and sector regulators including the FCA, MHRA and ICO. The EU AI Act becomes a hard legal obligation for a UK business only where that business has EU market exposure, in which case it applies as EU law governing their EU-facing activities.

What should a UK business do first?

The most useful first step is to establish your scope: does the Act bind you, and if so, which of your AI systems are potentially high-risk? That assessment shapes everything else. The free AI Readiness Scorecard gives you an initial read in ten minutes, including whether the Act is likely to apply to you at all. For businesses with confirmed EU market exposure, our EU AI Act Rapid Audit delivers a full scope assessment, risk classification, gap analysis and prioritised action plan in two to three weeks. If the Act does not bind you, the audit confirms that too, and turns the conversation to the UK rules that do.

What Should You Do Next?

If you are not yet certain of your compliance position, the most useful thing you can do is get a clear picture of where you stand: whether the Act binds you at all, which systems are high-risk, and what the current timeline means for your plan. Our EU AI Act Rapid Audit does exactly that in two to three weeks, giving you a full risk assessment, a gap analysis and a prioritised action plan. Not sure yet where you stand? The free AI Readiness Scorecard takes ten minutes and will tell you whether the Act is likely to apply to you and where your most urgent governance gaps are.

The deadline moved. The work did not go away. It just got more doable.