Skip to main content
Download free report
Softblues
Softblues
Back to Blog
AI Strategy & Consulting
July 29, 202611 min read

EU AI Act for UK Companies: What Applies in 2026 and What to Do Next

The EU AI Act reaches UK companies that sell into the EU, and 2 August 2026 is still a live date. Here is what applies now, what moved to 2027 and 2028, and the six things to do in the next 90 days.

EU AI Act for UK Companies: What Applies in 2026 and What to Do Next

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude and Gemini implementations for finance, legal and healthcare teams across the UK and Ireland.

The EU AI Act reaches UK companies whose AI systems are placed on the EU market, or whose output is used inside the EU, even with no office there. From 2 August 2026 the transparency duties apply. Most high-risk obligations have moved to 2 December 2027 and 2 August 2028 under a 2026 amendment.

That last sentence is the one that changed. The high-risk rules were originally due on 2 August 2026, and by late 2025 the implementation was visibly behind, so the European Commission tabled the Digital Omnibus on AI on 19 November 2025 and the institutions reached a provisional political agreement on 6 May 2026 (Gibson Dunn, 27 May 2026). At SoftBlues, an AI consulting firm working with regulated mid-market companies across the UK and Ireland, we get asked the same question by every board that reads a headline about it: does this land on us, and when. This is the practical answer, not legal advice, and your counsel should see anything you act on.

Key facts

  • The AI Act entered into force on 1 August 2024. The prohibitions and the AI literacy duty have applied since 2 February 2025, and the rules for general-purpose AI models since 2 August 2025 (EU AI Act implementation timeline).
  • 2 August 2026 remains a live date. The Article 50 transparency obligations, including telling people when they are dealing with an AI system, proceed as scheduled (Gibson Dunn, May 2026).
  • High-risk obligations were deferred: stand-alone Annex III systems to 2 December 2027, and AI embedded in regulated products under Annex I to 2 August 2028 (Gibson Dunn, May 2026).
  • Those amended dates take legal effect only once the Omnibus is formally adopted and published in the Official Journal, which was expected before 2 August 2026. Check the current status before you plan around them.
  • Penalties run up to €35 million or 7% of worldwide annual turnover for breaching the prohibitions, and up to €15 million or 3% for most other obligations (Article 99).
  • The UK has no equivalent Act. Existing regulators apply existing law, with the ICO covering the personal-data side under UK GDPR (ICO guidance on AI and data protection).
  • Who this is for, and who it isn't

    Written for a COO, CFO, general counsel or Head of IT at a 50 to 500 person UK or Ireland firm that sells into the EU, employs people there, or serves EU customers, and that has AI somewhere in a product or an internal process. Recruitment screening, credit decisions, insurance triage and anything customer-facing are the areas where the question gets sharp.

    Skip it if you have no EU exposure at all and no AI in a customer-facing product, because your obligations sit with UK data protection law and your sector regulator instead. Skip it too if you want a clause-by-clause legal analysis. We build the systems and the controls around them; your solicitors interpret the text.

    Does the EU AI Act apply to a UK company?

    Often, yes. The Act follows the market rather than the letterhead. A UK provider that places an AI system on the EU market falls in scope, as does a UK provider whose system output is used in the EU, and a UK company acting as a deployer through an EU subsidiary. Ireland matters here for a lot of our clients, because an Irish entity or an Irish customer base puts you inside the EU perimeter directly. The high-level summary of the Act sets out the scope, and the Commission's own page on the framework is the primary reference.

    Important
    Being out of scope is a conclusion, not an assumption. Write down why you are out of scope, with the entity, the market and the data flow named. That single page is what a client's procurement team will ask for.
    Timeline figure showing the phased application of the EU AI Act, from entry into force through the prohibitions and general-purpose AI rules, the transparency duties in August 2026, and the deferred high-risk obligations in late 2027 and 2028.

    What dates now matter?

    DateWhat appliesStatus
    1 August 2024Act enters into forceIn force
    2 February 2025Prohibited practices, AI literacy dutyIn force
    2 August 2025General-purpose AI model obligations, AI Office operationalIn force
    2 August 2026Article 50 transparency obligationsLive, largely unchanged
    2 December 2026Watermarking grace period ends for systems already on the marketNew under the Omnibus
    2 December 2027High-risk obligations for stand-alone Annex III systemsDeferred from August 2026
    2 August 2028High-risk obligations for AI embedded in Annex I regulated productsDeferred from August 2027

    Dates and status per the Gibson Dunn client alert of 27 May 2026 and the official implementation timeline. The Annex III category is the one most mid-market firms trip over, because it covers recruitment, credit scoring and education tools rather than anything that feels like heavy industry.

    Are you a provider or a deployer?

    The obligations differ sharply, and most UK mid-market firms are deployers who occasionally become providers without noticing.

    ProviderDeployer
    Who this isYou develop an AI system, or put your name on one, and place it on the marketYou use an AI system in the course of your business
    Main duties for high-risk useRisk management, data governance, technical documentation, conformity assessment, registrationUse it per the instructions, assign human oversight, keep logs, inform affected workers
    Where firms get caughtFine-tuning or substantially modifying a bought system can make you the provider of itAssuming the vendor's compliance covers your deployment. It does not
    Best forSoftware companies and anyone embedding AI in a productFirms buying AI tools for internal processes
    Warning
    If you build your own screening, scoring or triage tool on top of a general model, you are likely the provider of that system. That is a materially heavier set of duties than buying one.

    What about the UK's own rules?

    There is no UK AI Act and none on the legislative timetable. The 2023 white paper set five non-statutory principles and asked existing regulators to apply them inside their existing remits, and the government's emphasis since the AI Opportunities Action Plan of January 2025 has been on adoption rather than a new statute. In practice, that means your AI is already regulated, by the rules you were already following.

    EU AI ActUK approach
    InstrumentOne horizontal regulation, risk-tieredExisting sector law plus data protection
    Who enforcesAI Office and national market surveillance authoritiesICO, FCA, Ofcom, sector regulators
    What triggers dutiesThe risk class of the systemThe activity, the personal data, the sector
    Practical effect for a UK firmApplies if you touch the EU marketApplies to everything you do, today

    For a UK financial services firm the live constraints are FCA rules and SM&CR accountability. For a legal practice in England and Wales it is the SRA. For healthcare in England it is the CQC, with clinical safety standards DCB0129 and DCB0160, and MHRA if the software might be a medical device. Across all of them the ICO covers personal data under UK GDPR and the Data Protection Act 2018. We set out how to build the internal side of this in our guide to AI governance for UK mid-market companies.

    What are the penalties?

    Up to €35 million or 7% of worldwide annual turnover for the prohibited practices, whichever is higher. Up to €15 million or 3% for most other breaches, including the high-risk and transparency obligations. Up to €7.5 million or 1% for supplying incorrect information to authorities (Article 99). Member States set the detail of their own penalty regimes.

    The commercial risk usually arrives before any regulator does. A large EU customer sends a procurement questionnaire asking which AI systems touch their data and how you classify them, and a firm with no answer loses the renewal. That is the version of enforcement most of our clients meet first.

    Four-card figure showing the practical steps a UK company can take now: build an inventory of AI systems in use, classify each one by risk and by role, add transparency notices, and put named human oversight in place.

    What should you do in the next 90 days?

    1. Build the inventory. List every AI system in use, including the ones bought on a departmental card. Name the owner, the systems it touches, whether personal data is involved, and whether any EU entity or customer is in the picture. In our engagements firms typically find between fifteen and forty tools, and a meaningful share of them are unknown to IT (our data, indicative, July 2026). Shadow AI is already in your building.

    2. Classify by role and by risk. For each system, are you provider or deployer, and does the use case sit anywhere near Annex III. Recruitment, creditworthiness, insurance pricing, education and worker management are the ones to look at hard.

    3. Fix transparency first. The 2 August 2026 duties are the nearest real deadline. Where a person interacts with an AI system, or where content is generated, say so plainly in the interface and in your notices.

    4. Assign human oversight with a name on it. Not "the operations team". A person, with the authority to overrule the system and a record that they did. Our note on human-in-the-loop AI workflows covers where to put that control so it does not become a rubber stamp.

    5. Get logging you can hand over. Which user, which action, which record, when, with what output. If your AI tooling cannot produce that, it cannot support a regulated process.

    6. Push it into procurement. Ask vendors for their own classification, their conformity position and their documentation. Our AI vendor security questionnaire is a reasonable starting template.

    💡Tip
    The deferral to 2027 and 2028 is real headroom, and the wrong lesson to take from it is to wait. An inventory takes two weeks. A governance framework your auditors accept takes months.

    What this looks like in a regulated firm

    For a financial-advice business we scoped an automated monthly file review, where an assistant reads client files against the firm's own suitability checklist and flags gaps for a compliance officer to judge. The design decisions that mattered were the boring ones: the assistant recommends and never concludes, every flag carries the passage it came from, and the reviewer's decision is the record. That work is documented as a discovery and proposal for compliance file review automation, and it is a proposal rather than a live deployment, so treat the design as the proof and not the results.

    The pattern generalises. Keeping the human as the decision-maker is both the compliance answer and the reason these systems get signed off internally at all.

    Red flags

    A vendor who tells you the AI Act does not apply because you are British has not read Article 2. A consultant offering "AI Act certification" is selling something that does not exist for most systems, because conformity assessment for high-risk systems is mostly self-assessment against harmonised standards that are still being written.

    Be equally wary of the opposite move: a firm using the Act to sell you a compliance programme far heavier than your risk class warrants. Most mid-market deployers need an inventory, transparency notices, oversight and logging. That is weeks of work, not a year of it.

    Questions to ask on the call, and what a good answer sounds like

    Which of our AI systems would you classify as high-risk, and why? A good answer walks specific systems against Annex III categories. A poor one says "it depends" and moves on.

    Are we the provider or the deployer of each one? You want a system-by-system answer, with the fine-tuning question addressed explicitly.

    What do we need in place by 2 August 2026? The right answer is transparency, and it is narrow. Anyone quoting you full high-risk conformity work for that date is either behind on the amendment or overselling.

    How does this connect to what the ICO already expects? UK data protection is the live obligation today. A partner who treats the AI Act as separate from UK GDPR will duplicate your work.

    Where are we already compliant without knowing it? Firms under FCA or SRA supervision usually have more of the governance scaffolding than they realise. A good partner finds it rather than rebuilding it.


    Frequently asked questions

    Does the EU AI Act apply to UK companies after Brexit?

    It can. Scope follows the EU market, so a UK provider placing an AI system on the EU market is caught, as is a UK provider whose system output is used in the EU. An Irish subsidiary or an EU customer base brings you in directly.

    What happens on 2 August 2026?

    The Article 50 transparency obligations apply, including disclosure that a person is interacting with an AI system and marking of generated content. The high-risk obligations originally set for that date were deferred under the Digital Omnibus agreement (Gibson Dunn, May 2026).

    Are the deferred deadlines final?

    They bind once the Omnibus is formally adopted and published in the Official Journal, which was expected before 2 August 2026. Verify the current position before you build a plan on the 2027 and 2028 dates.

    Is using ChatGPT or Claude internally a high-risk use?

    Using a general assistant for drafting or research is not, in itself. The risk class attaches to the use case. Screening job applicants, scoring creditworthiness or making decisions about people can be, whichever model is underneath.

    Does the UK have its own AI Act coming?

    There is no UK AI Act and none on the legislative timetable. Sector regulators apply existing rules within their remits, and the ICO covers AI that processes personal data.

    What is the smallest credible thing we can do this quarter?

    An inventory of AI systems with owners and data flows, plus transparency notices where users interact with AI. Two weeks of focused work, and it answers the first three questions any regulator or enterprise customer will ask.

    Who should own this internally?

    One named executive, usually the COO or general counsel, with IT and the DPO supporting. Splitting it across a committee is the reliable way to have nothing finished by the deadline.


    We are a registered Anthropic Partner Network member and a registered partner with Google Cloud and Microsoft, and we build AI for regulated UK and Ireland firms with the governance attached rather than bolted on afterwards. Production in 90 days, fixed price, money back if the proof of concept fails. If you want the inventory and classification done properly, book a discovery call. If the problem you are solving is process automation with compliance built in, start with our business automation service.

    See it in production

    Systems we have built and run for clients, with the numbers that came out of them.

    Browse all case studies

    Related Articles