EU AI Act for UK businesses: what you must do before 2 August 2026

The EU AI Act reaches UK businesses whose AI systems touch the EU market. This is what the 2 August 2026 milestone means, what changed in 2026, and the steps to take now.

Yes, the EU AI Act can apply to your UK business, even with no office in the EU. The Act reaches any company that places an AI system on the EU market, or whose AI system produces output used inside the EU. A UK firm selling AI-enabled software to EU customers is caught. So is a UK business deploying an AI system whose results are used by an EU office, partner or customer. What decides it is reach into the EU market, not where you happen to be registered.

That single point catches most UK exporters by surprise, because the Act borrows its extraterritorial logic from the GDPR. If you sell into Europe, you have probably met this shape of rule before.

Does the EU AI Act apply to UK businesses?

The test is about where the AI touches the market, not where your company is registered. Three triggers matter for UK firms.

You are a provider if you develop an AI system, or have one developed, and put it on the EU market or into service in the EU under your own name. You are a deployer if you use an AI system under your own authority and that use happens in the EU. And you are caught if you sit outside the EU entirely but the output your AI system produces is used in the EU.

A worked case makes it concrete. A UK manufacturer uses an AI tool to score and rank job applicants for roles across its UK and German sites. The German use brings that system inside the Act's scope, and recruitment screening is a listed high-risk area. The same firm using AI to draft marketing emails for a UK campaign is almost certainly outside the high-risk tier. The deciding factors are what the system does and who its output affects.

What happens on 2 August 2026, and has it changed?

2 August 2026 was set as the date the obligations for high-risk AI systems under Annex III became enforceable, alongside the governance and penalty machinery that gives national authorities teeth.

This is where you need current information rather than last year's headline. On 7 May 2026, EU lawmakers reached political agreement to defer the Annex III high-risk obligations to 2 December 2027, as part of the Digital Omnibus simplification package (Travers Smith, May 2026). That deferral still has to be formally adopted by the Council and Parliament, so it is firming up rather than finished as of June 2026.

A later deadline is not a reason to stop. Two things still hold. The parts of the Act already in force stay in force: the ban on prohibited practices since 2 February 2025, and the rules for general purpose AI models since 2 August 2025. And the work that makes you compliant, knowing what AI you run and who owns it, takes months, not weeks. Firms that treated the original date as the trigger are the ones now in good shape, deferral or not.

What counts as a high-risk AI system?

Annex III of the EU AI Act lists the high-risk areas. The ones UK businesses meet most often are recruitment and worker management, access to essential private and public services, creditworthiness and credit scoring, and biometric identification. If an AI system makes or materially shapes a decision about a person in one of those areas, it is high risk and carries the heaviest documentation and oversight duties.

Most day-to-day marketing and sales AI sits below that line. Lead scoring, content drafting, campaign reporting and chat support are usually limited-risk or minimal-risk, which brings lighter transparency duties rather than the full high-risk regime. The trap is assuming everything you run is low risk. Recruitment screening and credit decisions are the two that quietly pull ordinary businesses into the high-risk tier.

If you are unsure where a given tool sits, that uncertainty is itself the finding. It means you do not yet have an AI inventory, which is the first gap to close.

What are the penalties for getting it wrong?

The Act sets three fine tiers under Article 99. Prohibited practices, the banned uses such as social scoring and untargeted facial scraping, carry up to 35 million euro or 7 percent of global annual turnover, whichever is higher. High-risk and transparency breaches carry up to 15 million euro or 3 percent. Giving authorities misleading information carries up to 7.5 million euro or 1 percent.

The 7 percent figure is the one that gets a board's attention, because it is a share of worldwide turnover, not EU turnover or profit. For a mid-sized exporter, that is a number worth an afternoon of senior time to rule out.

What does the ICO expect from UK businesses?

The UK has chosen not to pass a single AI law. It regulates AI through existing statutes and existing regulators. For most businesses the relevant one is the Information Commissioner's Office, which oversees AI that processes personal data under UK GDPR and the Data Protection Act 2018, and publishes guidance on AI and data protection covering fairness, transparency and accountability.

So a UK business that sells into the EU faces two regimes at once: the ICO's expectations on data protection at home, and the EU AI Act on any AI that reaches the EU market. The practical answer is to build one governance approach that satisfies both, rather than running two parallel sets of paperwork. The overlap is large. Both want you to know what AI you use, why, on what data, and with what human oversight.

This is also where infrastructure choices help. Running AI on data that stays in a UK or EU region, for example using a model host in a UK region such as AWS Bedrock UK South, keeps your data residency story simple for both regulators.

What you must do before 2 August 2026

Most organisations have the same four gaps: no AI inventory, no governance owner, no documentation, and no AI literacy across the team (RMOK Legal, June 2026). Closing them is the work, and it maps to a short list.

  1. Build an AI inventory. List every AI system in use, including the tools individuals adopted without asking. Note what each does, what data it touches, and whether its output reaches the EU. You cannot govern what you have not counted.
  2. Name an owner. Give one senior person accountability for AI risk and compliance. This is the gap that stalls everything else, because without an owner the inventory goes stale and no one signs anything off.
  3. Classify by risk. Sort each system into prohibited, high risk, limited risk or minimal risk against the Act's categories. Most will be low. The point is to find the few that are not.
  4. Document the high-risk ones. For anything high risk, record the risk assessment, the data used, the human oversight in place, and how you monitor it. This is the paperwork the Act actually asks for.
  5. Build AI literacy. The Act expects staff who use AI to understand it well enough to use it responsibly. A short, practical training programme closes this gap and improves the work at the same time.

None of this needs a large team. It needs someone senior to own it and a method to work through. If you want a structured starting point, our practical 2026 framework for implementing AI in a B2B business sets out the wider programme this compliance work sits inside, and what an AI readiness audit is, and how to know if you need one covers how to surface those four gaps in a single pass.

For the governance and training side, our AI implementation services cover inventory, ownership and documentation, and our marketing training and consultancy closes the AI literacy gap with sessions built around how your team actually works.

FAQ

Does the EU AI Act apply to UK businesses? Yes, it can. The EU AI Act applies to any business, wherever it is based, that places an AI system on the EU market or whose AI system produces output used in the EU. A UK company with no EU office is still caught if it sells AI-enabled products to EU customers, or if it is the provider or deployer of an AI system whose output is used inside the EU.

Has the 2 August 2026 EU AI Act deadline been delayed? Partly. On 7 May 2026, EU lawmakers reached political agreement to defer the high-risk obligations under Annex III to 2 December 2027, as part of the Digital Omnibus package (Travers Smith, May 2026). The change still needs formal adoption. Other parts of the Act remain in force, including the ban on prohibited practices since 2 February 2025 and the general purpose AI rules since 2 August 2025.

What are the penalties under the EU AI Act? There are three tiers. Prohibited AI practices carry fines of up to 35 million euro or 7 percent of global annual turnover, whichever is higher. High-risk and transparency breaches carry up to 15 million euro or 3 percent. Supplying misleading information to authorities carries up to 7.5 million euro or 1 percent (Article 99, EU AI Act).

Does the UK have its own version of the EU AI Act? No. The UK has no single AI statute. It regulates AI through existing law and existing regulators, with the Information Commissioner's Office (ICO) overseeing AI that processes personal data under UK GDPR and the Data Protection Act 2018. UK businesses selling into the EU still have to meet the EU AI Act on top of UK rules.

How do I know if my company uses a high-risk AI system? Check your use against Annex III of the EU AI Act, which lists high-risk areas such as recruitment and worker management, access to essential services, credit scoring, and biometric identification. If an AI system makes or materially influences decisions about people in one of those areas, treat it as high risk and document it. Most marketing and sales automation sits below that bar, but recruitment screening and credit decisions often do not.

Need a more tailored conversation with our team?

Get In Touch
Contact Us