EU AI Act for UK Companies: What Applies in 2026 and What to Do Next
The EU AI Act reaches UK companies that sell into the EU, and 2 August 2026 is still a live date. Here is what applies now, what moved to 2027 and 2028, and the six things to do in the next 90 days.

By Ivan Pylypchuk, CEO of SoftBlues. Has led Claude and Gemini implementations for finance, legal and healthcare teams across the UK and Ireland.
The EU AI Act reaches UK companies whose AI systems are placed on the EU market, or whose output is used inside the EU, even with no office there. From 2 August 2026 the transparency duties apply. Most high-risk obligations have moved to 2 December 2027 and 2 August 2028 under a 2026 amendment.
That last sentence is the one that changed. The high-risk rules were originally due on 2 August 2026, and by late 2025 the implementation was visibly behind, so the European Commission tabled the Digital Omnibus on AI on 19 November 2025 and the institutions reached a provisional political agreement on 6 May 2026 (Gibson Dunn, 27 May 2026). At SoftBlues, an AI consulting firm working with regulated mid-market companies across the UK and Ireland, we get asked the same question by every board that reads a headline about it: does this land on us, and when. This is the practical answer, not legal advice, and your counsel should see anything you act on.
Key facts
Who this is for, and who it isn't
Written for a COO, CFO, general counsel or Head of IT at a 50 to 500 person UK or Ireland firm that sells into the EU, employs people there, or serves EU customers, and that has AI somewhere in a product or an internal process. Recruitment screening, credit decisions, insurance triage and anything customer-facing are the areas where the question gets sharp.
Skip it if you have no EU exposure at all and no AI in a customer-facing product, because your obligations sit with UK data protection law and your sector regulator instead. Skip it too if you want a clause-by-clause legal analysis. We build the systems and the controls around them; your solicitors interpret the text.
Does the EU AI Act apply to a UK company?
Often, yes. The Act follows the market rather than the letterhead. A UK provider that places an AI system on the EU market falls in scope, as does a UK provider whose system output is used in the EU, and a UK company acting as a deployer through an EU subsidiary. Ireland matters here for a lot of our clients, because an Irish entity or an Irish customer base puts you inside the EU perimeter directly. The high-level summary of the Act sets out the scope, and the Commission's own page on the framework is the primary reference.
What dates now matter?
| Date | What applies | Status |
|---|---|---|
| 1 August 2024 | Act enters into force | In force |
| 2 February 2025 | Prohibited practices, AI literacy duty | In force |
| 2 August 2025 | General-purpose AI model obligations, AI Office operational | In force |
| 2 August 2026 | Article 50 transparency obligations | Live, largely unchanged |
| 2 December 2026 | Watermarking grace period ends for systems already on the market | New under the Omnibus |
| 2 December 2027 | High-risk obligations for stand-alone Annex III systems | Deferred from August 2026 |
| 2 August 2028 | High-risk obligations for AI embedded in Annex I regulated products | Deferred from August 2027 |
Dates and status per the Gibson Dunn client alert of 27 May 2026 and the official implementation timeline. The Annex III category is the one most mid-market firms trip over, because it covers recruitment, credit scoring and education tools rather than anything that feels like heavy industry.
Are you a provider or a deployer?
The obligations differ sharply, and most UK mid-market firms are deployers who occasionally become providers without noticing.
| Provider | Deployer | |
|---|---|---|
| Who this is | You develop an AI system, or put your name on one, and place it on the market | You use an AI system in the course of your business |
| Main duties for high-risk use | Risk management, data governance, technical documentation, conformity assessment, registration | Use it per the instructions, assign human oversight, keep logs, inform affected workers |
| Where firms get caught | Fine-tuning or substantially modifying a bought system can make you the provider of it | Assuming the vendor's compliance covers your deployment. It does not |
| Best for | Software companies and anyone embedding AI in a product | Firms buying AI tools for internal processes |
What about the UK's own rules?
There is no UK AI Act and none on the legislative timetable. The 2023 white paper set five non-statutory principles and asked existing regulators to apply them inside their existing remits, and the government's emphasis since the AI Opportunities Action Plan of January 2025 has been on adoption rather than a new statute. In practice, that means your AI is already regulated, by the rules you were already following.
| EU AI Act | UK approach | |
|---|---|---|
| Instrument | One horizontal regulation, risk-tiered | Existing sector law plus data protection |
| Who enforces | AI Office and national market surveillance authorities | ICO, FCA, Ofcom, sector regulators |
| What triggers duties | The risk class of the system | The activity, the personal data, the sector |
| Practical effect for a UK firm | Applies if you touch the EU market | Applies to everything you do, today |
For a UK financial services firm the live constraints are FCA rules and SM&CR accountability. For a legal practice in England and Wales it is the SRA. For healthcare in England it is the CQC, with clinical safety standards DCB0129 and DCB0160, and MHRA if the software might be a medical device. Across all of them the ICO covers personal data under UK GDPR and the Data Protection Act 2018. We set out how to build the internal side of this in our guide to AI governance for UK mid-market companies.
What are the penalties?
Up to €35 million or 7% of worldwide annual turnover for the prohibited practices, whichever is higher. Up to €15 million or 3% for most other breaches, including the high-risk and transparency obligations. Up to €7.5 million or 1% for supplying incorrect information to authorities (Article 99). Member States set the detail of their own penalty regimes.
The commercial risk usually arrives before any regulator does. A large EU customer sends a procurement questionnaire asking which AI systems touch their data and how you classify them, and a firm with no answer loses the renewal. That is the version of enforcement most of our clients meet first.

What should you do in the next 90 days?
1. Build the inventory. List every AI system in use, including the ones bought on a departmental card. Name the owner, the systems it touches, whether personal data is involved, and whether any EU entity or customer is in the picture. In our engagements firms typically find between fifteen and forty tools, and a meaningful share of them are unknown to IT (our data, indicative, July 2026). Shadow AI is already in your building.
2. Classify by role and by risk. For each system, are you provider or deployer, and does the use case sit anywhere near Annex III. Recruitment, creditworthiness, insurance pricing, education and worker management are the ones to look at hard.
3. Fix transparency first. The 2 August 2026 duties are the nearest real deadline. Where a person interacts with an AI system, or where content is generated, say so plainly in the interface and in your notices.
4. Assign human oversight with a name on it. Not "the operations team". A person, with the authority to overrule the system and a record that they did. Our note on human-in-the-loop AI workflows covers where to put that control so it does not become a rubber stamp.
5. Get logging you can hand over. Which user, which action, which record, when, with what output. If your AI tooling cannot produce that, it cannot support a regulated process.
6. Push it into procurement. Ask vendors for their own classification, their conformity position and their documentation. Our AI vendor security questionnaire is a reasonable starting template.
What this looks like in a regulated firm
For a financial-advice business we scoped an automated monthly file review, where an assistant reads client files against the firm's own suitability checklist and flags gaps for a compliance officer to judge. The design decisions that mattered were the boring ones: the assistant recommends and never concludes, every flag carries the passage it came from, and the reviewer's decision is the record. That work is documented as a discovery and proposal for compliance file review automation, and it is a proposal rather than a live deployment, so treat the design as the proof and not the results.
The pattern generalises. Keeping the human as the decision-maker is both the compliance answer and the reason these systems get signed off internally at all.
Red flags
A vendor who tells you the AI Act does not apply because you are British has not read Article 2. A consultant offering "AI Act certification" is selling something that does not exist for most systems, because conformity assessment for high-risk systems is mostly self-assessment against harmonised standards that are still being written.
Be equally wary of the opposite move: a firm using the Act to sell you a compliance programme far heavier than your risk class warrants. Most mid-market deployers need an inventory, transparency notices, oversight and logging. That is weeks of work, not a year of it.
Questions to ask on the call, and what a good answer sounds like
Which of our AI systems would you classify as high-risk, and why? A good answer walks specific systems against Annex III categories. A poor one says "it depends" and moves on.
Are we the provider or the deployer of each one? You want a system-by-system answer, with the fine-tuning question addressed explicitly.
What do we need in place by 2 August 2026? The right answer is transparency, and it is narrow. Anyone quoting you full high-risk conformity work for that date is either behind on the amendment or overselling.
How does this connect to what the ICO already expects? UK data protection is the live obligation today. A partner who treats the AI Act as separate from UK GDPR will duplicate your work.
Where are we already compliant without knowing it? Firms under FCA or SRA supervision usually have more of the governance scaffolding than they realise. A good partner finds it rather than rebuilding it.
Frequently asked questions
Does the EU AI Act apply to UK companies after Brexit?
It can. Scope follows the EU market, so a UK provider placing an AI system on the EU market is caught, as is a UK provider whose system output is used in the EU. An Irish subsidiary or an EU customer base brings you in directly.
What happens on 2 August 2026?
The Article 50 transparency obligations apply, including disclosure that a person is interacting with an AI system and marking of generated content. The high-risk obligations originally set for that date were deferred under the Digital Omnibus agreement (Gibson Dunn, May 2026).
Are the deferred deadlines final?
They bind once the Omnibus is formally adopted and published in the Official Journal, which was expected before 2 August 2026. Verify the current position before you build a plan on the 2027 and 2028 dates.
Is using ChatGPT or Claude internally a high-risk use?
Using a general assistant for drafting or research is not, in itself. The risk class attaches to the use case. Screening job applicants, scoring creditworthiness or making decisions about people can be, whichever model is underneath.
Does the UK have its own AI Act coming?
There is no UK AI Act and none on the legislative timetable. Sector regulators apply existing rules within their remits, and the ICO covers AI that processes personal data.
What is the smallest credible thing we can do this quarter?
An inventory of AI systems with owners and data flows, plus transparency notices where users interact with AI. Two weeks of focused work, and it answers the first three questions any regulator or enterprise customer will ask.
Who should own this internally?
One named executive, usually the COO or general counsel, with IT and the DPO supporting. Splitting it across a committee is the reliable way to have nothing finished by the deadline.
We are a registered Anthropic Partner Network member and a registered partner with Google Cloud and Microsoft, and we build AI for regulated UK and Ireland firms with the governance attached rather than bolted on afterwards. Production in 90 days, fixed price, money back if the proof of concept fails. If you want the inventory and classification done properly, book a discovery call. If the problem you are solving is process automation with compliance built in, start with our business automation service.
See it in production
Systems we have built and run for clients, with the numbers that came out of them.
Related Articles

AI Total Cost of Ownership: What UK Mid-Market Companies Actually Spend on AI in 2026
