The EU AI Act explained: what applies to UK businesses and when

The EU AI Act explained, Regulation (EU) 2024/1689 as amended by the Digital Omnibus, Bratby Law data protection header

In short: the EU AI Act explained for UK businesses: Regulation (EU) 2024/1689 applies to UK companies that place AI systems or models on the EU market, or whose systems produce output used in the EU. The prohibitions, transparency duties and general-purpose AI rules already apply. The high-risk duties apply from 2 December 2027 (Annex III) and 2 August 2028 (Annex I).

By Rob Bratby, Managing Partner, Bratby Law. Recognised in the Lexology Index as a Thought Leader for data privacy and protection. Chambers UK Band 2 (Telecommunications). Legal 500 Leading UK Telecoms Partner. 30+ years in telecoms and data protection regulation, including Oftel and senior operator roles.

A UK company does not sit outside the EU AI Act by being outside the EU. Sell an AI-enabled product into the EU market, or let the output of your system be used there, and the Act applies, with an authorised representative duty that an EU competitor does not carry. Most of the Act is already in force. The amendment made in July 2026, the Digital Omnibus on AI, moved the high-risk compliance dates back to December 2027 and August 2028 and left the prohibitions, the transparency duties and the general-purpose AI duties on their original dates. The new dates are fixed, and only a further regulation can move them.

What is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the EU’s single rulebook for artificial intelligence. It entered into force on 1 August 2024 and applies in stages set by Article 113. It regulates by risk: a short list of prohibited practices (Article 5), a high-risk tier carrying the full compliance programme (Articles 8 to 27), transparency duties for chatbots, generated content and deepfakes (Article 50), a separate regime for general-purpose AI models (Articles 51 to 56), and, beyond a general duty to support AI literacy (Article 4), no tier-specific obligations for anything else.

The Act has been amended once, by Regulation (EU) 2026/1744, the Digital Omnibus on AI, in force since 27 July 2026. The amendment is analysed in detail in Digital Omnibus on AI: the amended EU AI Act timetable. The UK has no equivalent statute: UK law governs AI through the UK GDPR, sector regulators and existing regimes, a position set out in Is there a UK AI Act?. A UK business therefore runs two separate compliance analyses, one for its EU-facing activity under the Act and one for its UK activity under UK law.

Does the EU AI Act apply to UK businesses?

Yes, where there is an EU connection. Article 2(1) applies the Act to providers placing AI systems or general-purpose AI models on the EU market, or putting AI systems into service in the EU, irrespective of where the provider is established, and to providers and deployers located in a third country where the output produced by the AI system is used in the EU. A provider is the person who develops a system or model and places it on the market under its own name; a deployer is the person who uses an AI system under its own authority in a professional context. Importers, distributors and product manufacturers that sell a product with an embedded AI system under their own trade mark are also within scope.

A UK deployer with no EU establishment, no EU entity and no EU marketing is still within scope where its system’s output is used in the EU. In addition, before making a high-risk AI system available on the EU market a UK provider must appoint an authorised representative established in the EU by written mandate (Article 22), and a UK provider must do the same before placing a general-purpose AI model on the EU market (Article 54). The Article 54 duty carries an exception for models released under a free and open-source licence with their weights, architecture and usage information made publicly available, unless the model carries systemic risk.

What does the AI Act prohibit?

The Article 5 prohibitions have applied since 2 February 2025. They cover subliminal, manipulative and deceptive techniques causing significant harm, exploitation of vulnerability, social scoring, predicting criminal offending solely from profiling or personality traits, untargeted scraping of facial images to build recognition databases, emotion inference in workplaces and education (save for medical or safety reasons), biometric categorisation to deduce race, political opinions, trade union membership, religious or philosophical beliefs, sex life or sexual orientation, and real-time remote biometric identification in publicly accessible spaces for law enforcement, subject to narrow exceptions.

From 2 December 2026 the Digital Omnibus on AI adds two prohibitions: AI systems that generate or manipulate realistic sexually explicit material of identifiable people without their consent (new Article 5(1)(ba)) and AI systems that generate or manipulate child sexual abuse material (new Article 5(1)(bb)). For placing a system on the market, the prohibition applies where such generation is the system’s intended purpose, or where it is a reasonably foreseeable and reproducible outcome and the system lacks adequate technical safeguards, so an image-generation system with effective guardrails falls outside that limb unless generation of such material is its purpose. For use, the prohibition applies only where the deployer uses the system for the purpose of generating such material, and breach of any Article 5 prohibition attracts the top penalty tier.

When do the high-risk duties apply?

The high-risk duties apply from 2 December 2027 for the standalone use cases listed in Annex III, and from 2 August 2028 for AI embedded in products regulated under the legislation listed in Annex I. Article 6 sets out two routes to classification. A system is high-risk where it is a safety component of a product, or is itself a product, covered by the EU product legislation in Annex I and subject to third-party conformity assessment (Article 6(1)); and a system is high-risk where it falls within the use cases listed in Annex III, such as employment, credit, essential services and biometrics (Article 6(2)). A derogation in Article 6(3) is available where the system does not pose a significant risk of harm and performs one of four listed narrow functions, with documentation and registration still required, and it is not available at all where the system profiles natural persons.

Both dates come from the Digital Omnibus on AI, which replaced point (c) of the third paragraph of Article 113 so that Chapter III Sections 1 to 3 apply from those dates rather than from 2 August 2026 and 2 August 2027 as originally enacted. Article 6(5), the Commission’s duty to publish classification guidelines with a list of high-risk and not-high-risk use cases, is excepted from the deferral. The dates are fixed calendar dates: Article 113 is not among the provisions the Commission can amend by delegated act, so only a further amending regulation can move them. The Omnibus also narrowed the classification tests: systems used solely for non-safety related aspects of user assistance, performance optimisation, service efficiency, automation, convenience or quality control are not safety components unless their failure would endanger health and safety, and a product that needs third-party assessment solely for reasons other than health and safety, such as radio spectrum, does not meet the condition in Article 6(1)(b).

High-risk classification carries the full programme: risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity requirements (Articles 8 to 15), the operator obligations (Articles 16 to 27) and, for certain deployers, a fundamental rights impact assessment under Article 27 that may now cross-refer to an existing GDPR data protection impact assessment.

What already applies: transparency and general-purpose AI

The Article 50 transparency duties have applied since 2 August 2026, and the Digital Omnibus did not defer them. Providers must ensure people are told they are interacting with an AI system unless that is obvious, and providers of generative systems must mark outputs in a machine-readable format detectable as artificially generated or manipulated. Deployers of emotion recognition and biometric categorisation systems must inform the people exposed to them. A deployer of a system that generates or manipulates a deepfake must disclose that the content is artificially generated or manipulated, whatever the subject matter, with a lighter duty for evidently artistic and satirical work; a deployer publishing AI-generated text to inform the public on a matter of public interest must disclose the generation unless the text has had human review and editorial control. The duties are examined in AI Act transparency obligations. The one transitional applies to the machine-readable marking duty alone: generative systems placed on the market before 2 August 2026 have until 2 December 2026 to comply with Article 50(2) (new Article 111(4)). A system placed on the market on or after 2 August 2026 complies from the outset.

The general-purpose AI regime has applied since 2 August 2025. Every GPAI provider must operate a copyright policy that respects rights reservations and publish a training content summary; providers must also maintain technical documentation and give downstream system providers the information they need, unless the model is released under a free and open-source licence with publicly available parameters and carries no systemic risk (Article 53). Providers of models carrying systemic risk have additional evaluation, mitigation, incident reporting and cybersecurity duties (Article 55). The European Commission published the General-Purpose AI Code of Practice on 10 July 2025 as a compliance route pending harmonised standards. The Commission’s power to fine GPAI providers up to 3 per cent of annual total worldwide turnover in the preceding financial year or €15 million, whichever is higher, under Article 101 has been exercisable since 2 August 2026, a shift covered in GPAI enforcement: a year of duties, and now the power to fine. Models placed on the market before 2 August 2025 have until 2 August 2027 to comply.

The AI Act compliance dates

The key AI Act compliance dates for a UK business are set out below. The European Commission publishes the full timetable on its AI Act implementation timeline.

ObligationApplies fromProvision
Prohibited practices and AI literacy2 February 2025Article 5; Article 4; Article 113, third paragraph, point (a)
General-purpose AI model duties2 August 2025Articles 53 to 55; Article 113, third paragraph, point (b)
Transparency duties2 August 2026Article 50; Article 113, second paragraph
Commission fines on GPAI providers2 August 2026Article 101
New prohibitions: sexually explicit deepfakes and CSAM2 December 2026Article 5(1)(ba) and (bb); Article 113, third paragraph, point (a), as amended
Machine-readable marking for generative systems on the market before 2 August 20262 December 2026Article 111(4)
High-risk duties: Annex III use cases2 December 2027Article 113, third paragraph, point (c)(i), as amended
High-risk duties: Annex I product-embedded AI2 August 2028Article 113, third paragraph, point (c)(ii), as amended
Legacy GPAI models (on the market before 2 August 2025)2 August 2027Article 111(3)

What are the penalties under the AI Act?

AI Act penalties are set by Article 99 in three tiers, unchanged in amount by the Digital Omnibus: up to €35 million or, for an undertaking, up to 7 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher, for breach of the Article 5 prohibitions; up to €15 million or 3 per cent, whichever is higher, for breach of the obligations listed in Article 99(4), which cover providers, authorised representatives, importers, distributors, deployers, notified bodies, the initial-provider handover duties in Article 25(2) and (4) and the Article 50 transparency duties; and up to €7.5 million or 1 per cent for supplying incorrect or misleading information. SMEs pay the lower of the percentage and the fixed amount across all three tiers. The Omnibus extended that cap to small mid-cap enterprises for the second and third tiers only, so an SMC in breach of an Article 5 prohibition faces the full top tier.

Enforcement architecture changed in July 2026. The AI Office, the Commission body that supervises the Act centrally, is now exclusively competent for two classes of system: those built on the provider’s own general-purpose model, including where model and system come from the same corporate group, and those that constitute or are integrated into very large online platforms and search engines designated under the Digital Services Act. That competence applies to providers, extends to deployers only where the deployer is also the provider or part of the same undertaking, and carries carve-outs, including for Annex I products, critical digital infrastructure, certain law enforcement and financial institution systems, and the administration of justice. The AI Office holds inspection, commitment and fining powers modelled on competition procedure, with periodic penalty payments of up to 5 per cent of average daily income or worldwide annual turnover in the preceding financial year for each day of non-compliance. The scope of that competence is examined in AI Office enforcement: the AI Act’s new powers over platform AI. Everything else stays with national market surveillance authorities, appointed per Member State, so a UK provider selling across the EU can deal with more than one.

Where this leaves a UK business

Classification decides everything else: which tier each system falls in, and which role the business holds for it (provider, deployer, importer or product manufacturer). A UK provider selling AI-enabled products into the EU is already subject to the transparency duties and, if it provides a general-purpose model, the GPAI regime; the high-risk programme does not apply until December 2027 or August 2028; and the authorised representative duty arises before a high-risk system is made available, or a GPAI model placed, on the EU market at all. Where a product’s classification is unclear, the assessment is set out on our AI and data governance advice page.

The Omnibus also inserted a new Article 4a into the AI Act, permitting the processing of special category data for bias detection and correction subject to six cumulative conditions that apply in addition to the EU GDPR. It has no counterpart in UK law. A UK data controller running the same bias testing needs a condition in Schedule 1 to the Data Protection Act 2018, and the nearest, paragraph 8 of Part 2, covers only four categories of special category data, does not permit processing for measures or decisions about a particular data subject, and carries a written objection right. A group relying on Article 4a for its EU processing cannot read the same analysis across to its UK processing: that is a data protection question for AI-enabled products, not an AI Act one.

Viewpoint

The misreading I encounter most often is that the AI Act has been delayed. The Digital Omnibus deferred only the high-risk programme: the prohibitions, the general-purpose AI duties and the transparency duties all apply from their original dates, and for a UK business selling AI-enabled products into the EU the transparency and GPAI analysis is where the immediate exposure sits. The deferral gives time to build the high-risk compliance programme. The amended Article 113 also gives the two high-risk routes different dates without saying which governs a system that qualifies under both; the amended Article 43(3) routes the conformity assessment procedure for such a system to the Annex I sectoral legislation but says nothing about the application date, and until the Commission or the AI Office addresses the point, the prudent working assumption for a dual-qualified system is the earlier date, 2 December 2027.

Frequently asked questions

Does the EU AI Act apply in the UK?

The EU AI Act is not part of UK law and no UK equivalent exists. It applies to UK businesses through its scope rules: a UK provider placing an AI system or general-purpose model on the EU market is within scope, as is a UK provider or deployer whose system’s output is used in the EU (Article 2(1)).

Has the EU AI Act been delayed?

Only the high-risk duties moved. Regulation (EU) 2026/1744 deferred Chapter III Sections 1 to 3 to 2 December 2027 for Annex III use cases and 2 August 2028 for Annex I product-embedded AI. The prohibitions, the general-purpose AI regime and the Article 50 transparency duties apply now, on their original dates.

Do UK companies need an EU authorised representative?

A UK provider must appoint an authorised representative established in the EU before making a high-risk AI system available on the EU market (Article 22), and before placing a general-purpose AI model on the EU market (Article 54), subject to an exception for free and open-source models with publicly available weights and no systemic risk. Deployers do not need one.

What are the maximum fines under the EU AI Act?

Up to €35 million or, for an undertaking, 7 per cent of total worldwide annual turnover for the preceding financial year, whichever is higher, for breach of the Article 5 prohibitions. Breach of the operator and transparency obligations listed in Article 99(4) carries up to €15 million or 3 per cent, and supplying misleading information up to €7.5 million or 1 per cent.


For advice on how the EU AI Act applies to your product, or on data protection for AI-enabled products, contact Rob Bratby at Bratby Law.

Select topics of interest

Similar Posts