All posts14 July 2026

Does the EU AI Act apply to UK companies?

Yes, when you place an AI system on the EU market or its output is used in the EU. The dated timeline for a UK company selling into Europe, with what moved.

W. Akram14 min readai · regulation

General information, not legal advice. Regulatory duties need your own competent advice.

Yes, if Europe is a market for you. The Act binds anyone who places an AI system on the EU market, and anyone outside the EU whose system produces output that is used inside it. Being established in London exempts you from nothing. What varies is which obligations land on you, and when.

The EU AI Act applies on the basis of where an AI system is used, not where the company using it is registered. That test sits in Article 2, which covers providers placing systems on the Union market irrespective of where they are established, and providers and deployers in a third country where the output the system produces is used in the Union. A Manchester company selling a hiring tool to a Dutch employer is inside the perimeter. So is a London studio running a support assistant on an Irish client's website. Which duties follow then depends on whether you are the provider or the deployer of that system, and most UK SMEs are deployers.

Who the Act reaches, and where the UK sits

The UK has no AI statute and no AI regulator. Five cross-sector principles (safety, security and robustness; transparency and explainability; fairness; accountability and governance; contestability and redress) are applied on a non-statutory basis by whichever regulator already covers your sector, with DSIT setting direction rather than enforcing anything, as set out in the CMS AI regulation scanner for the United Kingdom. Nothing in that arrangement carves a British company out of the EU regime. For most UK software firms the AI Act will be the only AI-specific statute they ever meet, and it will reach them through their customers rather than through Westminster.

Reach follows the market, not the registered office. For a small UK company that usually resolves into one of a handful of situations: you sell a product with an AI feature to customers in the EU, or you build software for a client who then sells it there. The one people forget is the quieter case. You run a tool yourself, from an office in London, and an EU entity uses what it produces. That is enough to bring the system into scope.

The awkward part is that the answer is per system, not per company. Every time we have run this exercise on a real product, the hard part has not been the risk tier. It is that a single product turns out to hold more than one AI system and the answers differ between them. There is usually a vendor assistant the company deploys, a feature built in-house on a hosted model, and somewhere further down a classifier that predates the whole conversation and that nobody in the room thinks of as AI. That last one is the one people miss, and it is often the one making the most consequential decision.

The compliance timeline, and what the Omnibus moved

DateWhat appliesWho it reaches
1 August 2024The AI Act enters into forceNobody directly. Every date below counts from here
2 February 2025Prohibited practices (Article 5) and AI literacy (Article 4)Every provider and deployer at every risk tier, including a company whose only AI use is staff on a chatbot
2 August 2025Governance rules and general-purpose AI model obligationsProviders of GPAI models. Most SMEs are customers of those providers, not providers themselves
2 August 2026General application, including the Article 50 transparency dutiesAnyone whose system talks to people in the EU, generates synthetic media, runs emotion recognition or biometric categorisation, or publishes AI-written text on matters of public interest
2 December 2026Machine-readable marking brought into conformity for generative systems already on the EU market before 2 August 2026Providers of those pre-existing generative systems
December 2026Prohibition on AI-generated non-consensual intimate imagery and child sexual abuse materialEveryone
2 August 2027Every member state must run at least one AI regulatory sandboxSMEs and start-ups wanting supervised testing, which the Act prices at zero for them
2 December 2027Stand-alone high-risk obligations under Annex III, moved back from 2 August 2026Providers and deployers of high-risk systems in biometrics, critical infrastructure, education, employment, migration, asylum and border control
2 August 2028High-risk AI embedded in regulated products under Annex IMakers of products already covered by EU product safety law, such as machinery, lifts and toys

Dates from the European Commission's AI Act page, which carries the current application timeline. The high-risk moves and the one-year sandbox delay come from the Digital Omnibus on AI, summarised by Gibson Dunn on 27 May 2026. The European Parliament endorsed the package on 16 June 2026 and the Council of the EU gave it the final green light on 29 June 2026.

The Omnibus has been reported almost everywhere as a delay to the AI Act, and the shorthand is doing real damage. What moved is the high-risk tier. What did not move is 2 August 2026. The Article 50 transparency duties arrive on the original date and most of the transparency package was left untouched. The single reprieve went to providers whose generative systems were already on the EU market before that date, who have until 2 December 2026 to bring machine-readable marking into conformity. If you read one thing about the Omnibus and concluded you had until 2027, you read the wrong thing.

Are you a provider or a deployer?

The Act hands out duties by role rather than by size, and the roles are defined in Article 3. A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trade mark. A deployer uses an AI system under its own authority in the course of a professional activity. Licensing a tool and switching a feature on makes you a deployer. Putting your own name on something and selling it makes you a provider, even when the model underneath belongs to somebody else.

Most UK SMEs are deployers. Most published guidance is written for providers, which is why so much of it reads as frightening and irrelevant at the same time. Deployer duties are lighter, and they are still duties: the Article 50 obligations on emotion recognition, biometric categorisation and deepfake disclosure sit on deployers, not on the people who built the model.

The trap is that roles attach to systems and can shift under you. Fine-tune a model, ship the result under your own brand, and the question of which role you are in stops being obvious. Article 25 governs when responsibility moves along the value chain, and it is worth reading before anyone in your company describes a customisation as "just prompting". The specific tests, applied to the ordinary cases most SMEs are in, are set out in provider or deployer under the EU AI Act.

Is your AI system high-risk?

Probably not. The high-risk tier is the expensive one and most small British software companies are nowhere near it, though almost all the published guidance is written as though the answer were yes. The stand-alone high-risk uses live in Annex III, which the Commission's application timeline groups as biometrics, critical infrastructure, education, employment, migration, asylum and border control. Annex I is a different list: AI embedded in products already regulated for safety, such as machinery, lifts and toys.

Purpose is what puts a system in Annex III, so the same technology sits on both sides of the line. A ranking feature inside an HR product is employment. The same ranking code applied to restaurant reviews is not. A scheduling tool, an invoicing product, a document summariser and an internal search index are not high-risk because of what they are made of.

The Omnibus bought that tier two and a half years, to 2 December 2027 for Annex III and 2 August 2028 for Annex I, which is a genuine reprieve for anyone who is in it. It is not a reason to defer the classification. A system classified late is a system re-architected late, and the classification question turns up in buyer due diligence long before a regulator asks it. Working through Annex III without a lawyer takes the categories one at a time, using ordinary business software as the worked example rather than the facial recognition scenarios that dominate the guidance.

What applies to nearly every company, right now

Two obligations reach almost everyone in scope and neither depends on the risk tier. One of them has been in force since before most companies started paying attention.

Article 4 applied from 2 February 2025. It requires providers and deployers to take measures to ensure a sufficient level of AI literacy among their staff and anyone else operating AI systems on their behalf. It binds a ten-person company whose only AI use is people pasting things into a chatbot. There is no obligation to measure literacy levels, no required AI officer and no mandated governance structure, which is exactly why it has been quietly ignored ever since. No fine attaches to Article 4 directly, but Latham & Watkins point out that from 2 August 2025 civil liability can follow where AI use by inadequately trained staff harms customers or business partners. Keeping a written record of what training happened, and when, is most of the practical compliance.

Article 50 is the one that lands on 2 August 2026, and it has four limbs. Providers of systems intended to interact directly with people must ensure those people are told they are dealing with an AI, unless it is obvious from the circumstances. Providers of generative systems must mark outputs in a machine-readable format so they are detectable as artificially generated. Deployers of emotion recognition or biometric categorisation must inform the people exposed to it. Deployers must disclose deepfakes, and AI-generated text published to inform the public on matters of public interest.

The carve-outs matter as much as the limbs, and the Article 50 guide published on artificialintelligenceact.eu in May 2026 sets both out together. Obviously fantastical content is exempt, as is AI that performs assistive editing rather than generating anything. So is detection and investigation of criminal offences. The exemption most companies will reach for is the last one: text that a person has reviewed, with somebody taking editorial responsibility for it, does not need the disclosure.

The chatbot disclosure itself is a small piece of work: one line of copy above the input, and an hour of somebody's time including the review. What takes longer is the argument about wording, because the product team wants it to sound warm and the honest version sounds like a warning. Our position is that the plain sentence wins. A disclosure the user has to interpret is not a disclosure.

Penalties, and the cap that applies to small companies

Article 99 sets three penalty tiers. Prohibited practices under Article 5 carry up to €35m or 7% of worldwide annual turnover. Most operator obligations, transparency included, carry up to €15m or 3%. Supplying incorrect, incomplete or misleading information to authorities carries up to €7.5m or 1%.

For SMEs, start-ups included, each of those is capped at whichever of the fixed amount or the percentage is the lower figure. That is the reverse of the general rule, and it is the part of Article 99 that owner-managed companies almost never hear about. On €4m of turnover, 3% is €120,000, and the €15m ceiling never enters the arithmetic. The headlines quoted the ceiling.

There is a caveat worth stating plainly. The cap is on the size of the fine, not on the obligation, and an SME that ignores Article 50 is still in breach on 3 August.

The cap is not the only relief. Regulatory sandboxes have to give SMEs and start-ups priority access free of charge, under procedures the Act requires to be simple and clear, per the EU AI Act small business guide; every member state must run at least one, and the Omnibus moved that deadline to 2 August 2027. Since 8 October 2025 the Commission has run an AI Act Service Desk and Single Information Platform with an interactive Compliance Checker that will tell you, at no cost, whether a described system is in scope and at which tier. Run it before you pay anybody for an assessment.

The Omnibus also extends the simplified compliance framework beyond SMEs to small mid-cap companies. The size thresholds for that are being reported second-hand across briefing notes, so check them against the Official Journal text rather than against a summary, including this one.

What to do this quarter

With 2 August 2026 less than three weeks away, the work worth doing beforehand is small and mostly clerical.

Start with an inventory. List every AI system the company uses or ships, including the ones that arrived as a feature of something you bought for another reason. Against each, write down what it does, who supplies it, whether you are provider or deployer, and whether any of its output reaches the EU. Everything else is built on that list, and the first pass takes an afternoon.

After that, run the Commission's Compliance Checker against each entry. It gives you a self-assessment rather than a ruling, and we would not treat its output as a defence, but it is free and it asks the Commission's own questions in the Commission's own order.

That leaves the two obligations that are already live. If anything you run talks to people, put the disclosure into the interface before 2 August rather than after it. If your staff use AI at all, start the AI literacy record: a short note of who was trained on what, and when, is enough to evidence that measures were taken.

The rest is documentation, and compliance is the weakest reason to write it. The same pack answers a buyer's security questionnaire and most of an investor's diligence list, and writing it under deadline is how it ends up wrong. We keep the AI documentation pack beside the architecture notes in the repository rather than in a compliance folder, because a document nobody opens goes stale, and a stale model inventory is worse than no model inventory.

If you have no internal rules at all, the fastest useful move is an AI use policy sized for a small company: scope, approved tools, what data may go into them, when disclosure is required, and how often the whole thing gets reviewed. It doubles as the cheapest evidence you have that Article 4 measures exist.

Common questions

Does it apply if we only use ChatGPT?

Partly. Internal staff use of a general chatbot does not place a system on the EU market, so most of the Act stays out of reach. Article 4 does not. The AI literacy duty binds every deployer at every risk tier and has applied since 2 February 2025. A written training record is the practical response.

What happens on 2 August 2026?

General application, and with it the Article 50 transparency duties. Systems that interact with people must say they are AI. Generative outputs must be machine-readable as artificial. Deployers must disclose deepfakes and AI-written public-interest text. The high-risk tier does not arrive on that date, whatever older guidance says.

Are there SME exemptions?

Reliefs rather than exemptions. Article 99 fines are capped for SMEs and start-ups at whichever of the fixed amount or the turnover percentage is lower. Regulatory sandbox access is free and prioritised. The Commission's Compliance Checker costs nothing. The underlying obligations still apply in full.

Did the Digital Omnibus delay the AI Act?

Part of it. Stand-alone Annex III high-risk obligations moved from 2 August 2026 to 2 December 2027, and Annex I embedded high-risk sits at 2 August 2028. The Council gave final approval on 29 June 2026. Transparency and general application stayed where they were, on 2 August 2026.

We are a UK company with no EU customers. Are we in scope?

Not on those facts. The position changes the day an EU customer signs, or an EU entity starts using output your system produced. UK obligations still apply through your existing sector regulator and through data protection law, neither of which the AI Act displaces.

Who decides whether we are a provider or a deployer?

You do, and you need to be able to show the reasoning. Licensing a tool and switching a feature on usually makes you a deployer. Selling something under your own name makes you a provider. Write the answer down for each system separately, because the roles attach to systems rather than to companies.

Let's talk

Ready to build the thing?

Book a free 30-minute call. We'll dig into your idea, your stack and your timeline, and give you an honest read on what it will take to build and launch. You'll leave with a clearer plan whether or not you hire us.

Free 30-min call. No pitch.