EU AI Act

The EU AI Act: what UK businesses need to know

The EU AI Act, Regulation (EU) 2024/1689, is the EU’s general law on artificial intelligence. It applies to UK businesses that supply AI products into the EU or whose AI output is used there, and its main enforcement powers became applicable on 2 August 2026. The UK has taken a different path, with no AI statute and no AI regulator, so a UK business building or using AI faces two regimes that resemble each other less each year. This page explains how the EU AI Act works, who is subject to which duties, what applies when, and where the UK position differs, with the sector detail for telecoms and payments.

How the EU AI Act works

The Act regulates by risk tier. A short list of practices is prohibited outright, including manipulation exploiting vulnerabilities, social scoring and, from 2 December 2026, AI systems that generate non-consensual intimate imagery or child sexual abuse material. A defined set of high-risk uses, listed in Annex III and covering areas such as recruitment, credit scoring, insurance pricing and critical infrastructure, attracts the heaviest compliance obligations: risk management, data governance, technical documentation, human oversight and conformity assessment. A transparency tier under Article 50 requires chatbots to be disclosed, AI-generated content to be marked in machine-readable form, and deepfakes to be labelled. Most AI applications fall into none of these tiers, and their providers and deployers have no obligations under the Act at all.

Separate duties apply to the providers of general-purpose AI models, the large models on which products are built. A model provider must maintain technical documentation, give the businesses building on the model the information in Annex XII, operate a copyright policy and publish a summary of training content, under Articles 53 to 55. The European Commission alone enforces those duties, through its AI Office, and may fine a model provider up to 3% of worldwide annual turnover or 15 million euros, whichever is higher, under Article 101.

Who is subject to which duties

The Act allocates duties by role, and almost every obligation depends on the role a business holds. A provider develops an AI system or model and places it on the EU market. A deployer uses an AI system in its business. A business that builds its product on a bought-in model is a downstream provider under Article 3(68), and provides an AI system rather than a model, so the Articles 53 to 55 duties apply to its supplier and not to it. Ordinary fine-tuning does not change that allocation. Which regulator supervises a given system also depends on these roles. Our post on AI Office enforcement sets out when the European Commission supervises an AI system directly, and our post on GPAI enforcement covers the model-side regime and what a business building on a model can require from its supplier.

What applies now, and what has been deferred

The Digital Omnibus on AI, Regulation (EU) 2026/1744, in force since 27 July 2026, deferred the high-risk obligations and left the rest of the timetable standing. The prohibitions, the general-purpose AI model duties and the Article 50 transparency duties all apply now or imminently; the high-risk compliance programme does not apply until December 2027 at the earliest. The deferral covers the high-risk tier only, and the remaining duties apply on the dates in the table below.

EU AI Act obligationApplies fromEnforceable from
Prohibited practices (Article 5, as adopted)2 February 2025Member State penalties from 2 August 2025; market surveillance from 2 August 2026
General-purpose AI model duties (Articles 53 to 55)2 August 20252 August 2026
Transparency: chatbot disclosure, deepfake labelling (Article 50)2 August 20262 August 2026
Machine-readable marking of synthetic content (Article 50(2))2 August 2026; systems on the market before that date have until 2 December 2026 (Article 111(4))From the date the duty applies to the system
New prohibitions: non-consensual intimate imagery, child sexual abuse material (Article 5(1)(ba), (bb))2 December 20262 December 2026
High-risk systems, Annex III (recruitment, credit, insurance, infrastructure)2 December 20272 December 2027
High-risk AI in regulated products, Annex I2 August 20282 August 2028

The UK position: no AI Act, and no plan for one

The UK regulates AI through existing law applied by existing regulators, under five cross-sector principles set out in the government’s February 2024 white paper response. There is no UK AI statute, no AI regulator, no UK equivalent of the general-purpose AI model duties, no marking requirement for AI-generated content and no statutory list of prohibited practices. The May 2026 King’s Speech contained no cross-sector AI bill, and the Secretary of State for Science, Innovation and Technology has said she is thinking “in terms of specific areas where we may need to act rather than a big all-encompassing bill”. What the King’s Speech did announce is a Regulating for Growth Bill, which includes the AI Growth Lab, a cross-economy sandbox in which firms could test AI products under modified regulatory requirements; it had not been introduced as at early August 2026.

The UK rules that most often apply to AI are data protection rules. Where an AI system processes personal data, the UK GDPR applies in full, including the automated decision-making safeguards in Articles 22A to 22D, which since 5 February 2026 require meaningful human involvement, information and a right to contest for significant automated decisions. The Information Commissioner is required by SI 2026/425 to prepare a statutory code of practice on AI and automated decision-making; no draft has yet been published, and the ICO has said its development is a focus for 2026/27.

A UK business therefore answers a split compliance question. For its EU-facing AI it is subject to EU AI Act duties on the timetable above, because the Act applies to providers placing AI on the Union market wherever they are established, and to third-country businesses whose AI system output is used in the Union. For its UK-facing AI it is subject to data protection duties and sector rules, and to nothing modelled on the AI Act. The two regimes share no thresholds, no definitions and no common timetable, and the divergence is widening. The wider pattern is covered on our UK/EU divergence page.

Telecoms: mostly outside the heavy tiers

Most operator AI is outside the EU AI Act’s heavy tiers. Network optimisation, traffic engineering, capacity planning and predictive maintenance are expressly excluded from the safety-component definition after the Digital Omnibus, under Article 6(1a), so they do not become high-risk through the critical-infrastructure category. An AI-enabled radio product does not become high-risk merely because its conformity assessment under the Radio Equipment Directive is driven by spectrum or interference requirements rather than health and safety, under Article 6(1c).

Two exceptions apply. Under Annex III point 2 an AI system used as a safety component in the management and operation of critical digital infrastructure is high-risk, and public electronic communications networks and services are within that definition through the Critical Entities Resilience Directive; whether AI whose failure would endanger health and safety, in areas such as emergency call routing or network resilience, is a safety component is a system-by-system question. And a telecoms business deploying chatbots or generating synthetic content for an EU audience is subject to the Article 50 transparency duties like anyone else. Ofcom, for its part, applies technology-neutral principles to AI under its Strategic Approach to AI 2026-2027 and imposes no AI-specific rulebook.

Payments: credit scoring is the live category

For payments and fintech businesses the operative category is Annex III point 5. AI used to evaluate the creditworthiness of natural persons or establish their credit score is high-risk, with an express exception for AI used to detect financial fraud. AI used for risk assessment and pricing of natural persons in life and health insurance is high-risk. Those duties apply from 2 December 2027, and when they do, the supervisor is the financial regulator itself: under Article 74(6) the market surveillance authority for high-risk AI used by regulated financial institutions is the relevant national financial supervisor, where the AI is in direct connection with the financial services.

By contrast, the FCA has said it will rely on existing frameworks rather than write AI rules, and is running AI Live Testing with a second cohort of eight firms announced in April 2026. A UK lender or insurer serving EU customers therefore faces a defined EU compliance programme with a fixed date, and at home a supervisory approach built on the Consumer Duty, existing systems and controls rules, and observation. Nothing in the EU AI Act disapplies DORA: operational resilience duties and AI Act duties apply cumulatively to the same systems.

Frequently asked questions

Does the EU AI Act apply to UK companies?

Yes, in two situations. It applies to a UK provider placing an AI system or a general-purpose AI model on the EU market, wherever the provider is established, and to a UK provider or deployer of an AI system whose output is used in the EU. The second limb covers AI systems only, not models.

We use AI tools bought from vendors. What applies to us?

As a deployer you are subject to the deployer duties for the tiers that apply to your use: transparency duties where your AI interacts with people or generates content for an EU audience, and from December 2027 the deployer obligations for any high-risk use. In the UK, the UK GDPR and the Articles 22A to 22D automated decision-making safeguards apply where personal data and significant decisions are involved.

Has the EU AI Act been delayed?

Only the high-risk tier. The Digital Omnibus on AI deferred the Annex III obligations to 2 December 2027 and the Annex I obligations to 2 August 2028. The prohibitions, the general-purpose AI model duties and the Article 50 transparency duties were not deferred, and the main enforcement powers over all of them became applicable on 2 August 2026.

Will the UK pass its own AI Act?

Nothing before Parliament suggests so. The May 2026 King’s Speech contained no cross-sector AI bill, and the government has said it is minded to act in specific areas rather than through a single statute. The Regulating for Growth Bill announced in the King’s Speech provides for a regulatory sandbox; it does not regulate AI. Lord Holmes’s private member’s Artificial Intelligence (Regulation) Bill remains at first reading.

For advice on how the EU AI Act applies to your product or your use of AI, on the UK rules that apply instead at home, or on sector questions in telecoms and payments, contact Rob Bratby at Bratby Law. Our AI, data and governance advice page sets out how we approach these questions.