Abstract artificial intelligence graphic in blue and purple light

The EU AI Act Applies to UK Businesses: What Is Live Now and What Comes in 2027

September 11, 2026

2 August 2026.

That was the date most of the EU AI Act was meant to switch on. Then, 6 days before it arrived, Brussels moved the biggest part of it.

The high-risk rules, the ones that cover AI in recruitment, credit scoring and staff management, now apply from 2 December 2027. AI built into regulated products like medical devices gets until 2 August 2028.

So a lot of UK businesses have filed the whole thing under "not our problem" and "not yet".

Both are wrong.

I have spent over 10 years as a DPO, and I watched the same thing happen with GDPR in 2017. "We're not in the EU" turned into "we sell to the EU" turned into a very expensive summer of 2018. The AI Act is running the same play, and the first obligations are already live.

Why an EU law reaches a business in Leeds

The Act does not care where your company is registered. Article 2 applies it to providers and deployers in third countries "where the output produced by the AI system is used in the Union".

Read that again. Output used in the EU.

Not "servers in the EU". Not "an office in the EU". Output.

Some examples of UK businesses that are in scope right now:

→ A UK recruitment agency screening CVs with an AI tool for a client hiring in Dublin.

→ A UK SaaS company whose product includes an AI feature, and 1 customer in Germany.

→ A UK e-commerce site with a customer service chatbot that EU shoppers can talk to.

→ A UK consultancy using AI to draft reports it delivers to an EU client.

If that sounds familiar, it should. It is the same "offering goods or services to people in the EU" logic that put UK GDPR on your agenda 8 years ago. If you needed an EU representative under GDPR, assume you need to look at this.

Person reviewing and signing a legal document at a desk

What is already in force

The Act has been switching on in stages since 1 August 2024.

2 February 2025: the prohibitions and the AI literacy duty. Banned practices include social scoring, emotion recognition in the workplace, and scraping faces off the internet to build a facial recognition database. Yes, some businesses were doing that.

2 August 2025: rules for general-purpose AI models. This one mostly lands on the OpenAIs and Googles of the world, not on you.

2 August 2026: the transparency rules in Article 50, and enforcement. This is the date that matters for most UK SMEs.

From 2 August 2026, if you deploy an AI system that talks to people, you must tell them they are talking to AI. A chatbot on your website. A voice agent answering your phones. An AI that replies to enquiries in your inbox. Unless it is obvious from context, the user has to be told.

If you publish AI-generated images, audio or video that look like real people or real events, you have to label them as artificial.

If you use emotion recognition or biometric categorisation on people, you have to tell them it is happening.

Providers of the tools have their own duties, including marking synthetic content so it can be detected as AI-generated. Systems already on the market before 2 August 2026 have until 2 December 2026 to sort the marking. The duty to tell people they are talking to a machine has no grace period.

Translation: if you switched on an AI chatbot in 2025 and never told anyone, you have been in breach since August.

What the delay actually changed

The Digital Omnibus on AI, Regulation (EU) 2026/1744, was published on 24 July 2026 and came into force on 27 July 2026.

It moved 2 dates:

→ High-risk systems listed in Annex III (recruitment, worker management, credit, education, essential services): 2 December 2027.

→ High-risk AI embedded in products already covered by EU safety law (machinery, medical devices, vehicles): 2 August 2028.

It softened the AI literacy duty. Providers and deployers now have to "take measures to support" staff AI literacy rather than guarantee a sufficient level. You still need to show you did something.

It added a new prohibition, from 2 December 2026, on AI built to generate non-consensual intimate images and child sexual abuse material.

And it gave small and mid-sized businesses lighter documentation, proportionate quality management requirements and reduced penalties.

What it did not do is delay the prohibitions, the transparency rules, or the fines.

Engineer working at a laptop with code on screen

The fines

3 tiers.

→ Prohibited practices: up to €35 million or 7% of global annual turnover, whichever is higher.

→ Most other breaches, including the transparency rules: up to €15 million or 3%.

→ Giving regulators incorrect or misleading information: up to €7.5 million or 1%.

For SMEs and start-ups the rule flips. You pay whichever of the 2 figures is lower. That is a real concession, and 3% of turnover is still a number that ends businesses.

Enforcement sits with national regulators in each member state, and with the EU AI Office for general-purpose models. No ICO involvement. If an Irish or Dutch regulator wants to talk to you, they will find you.

What "high-risk" will mean for you in December 2027

If you develop or sell an AI system that falls into Annex III, you become a provider, and providers carry the heaviest load: risk management, data governance, technical documentation, logging, human oversight, accuracy testing, conformity assessment and registration in an EU database. A non-EU provider also has to appoint an authorised representative inside the EU under Article 22, before the system goes on the market.

Most UK SMEs will not be providers. They will be deployers. You bought the tool, you use the tool.

Deployer duties are lighter, and still real:

→ Use the system in line with the provider's instructions.

→ Assign trained human oversight.

→ Keep the logs.

→ Tell workers and their representatives before you use high-risk AI on them.

→ Tell individuals when a high-risk system is making or helping make decisions about them.

December 2027 sounds a long way off. The businesses that got GDPR right did not start in April 2018.

Meanwhile, in the UK

The UK has no AI Act and no plan for one. Ministers said in February 2025 that AI should be regulated at the point of use by existing regulators, and that is where it has stayed.

That does not mean nothing changed.

On 5 February 2026 the Data (Use and Access) Act rewrote the automated decision-making rules in UK GDPR. Article 22 became Articles 22A to 22D. Fully automated decisions about people are now permitted by default, provided you have the safeguards in place: tell people it is happening, let them ask for a human review, and let them contest the outcome. "Permitted" is not the same as "unregulated".

On 12 May 2026 the ICO picked up a statutory duty to produce a code of practice on AI and automated decision-making. Courts will have to take it into account. The ICO consulted on updated automated decision-making guidance between 31 March and 29 May 2026, and the code is expected in 2027.

And UK GDPR still applies to every AI tool that touches personal data. That means a DPIA before you deploy it, a lawful basis for the training and the processing, and a privacy notice that mentions the AI. Fines there are £17.5 million or 4% of turnover, and the ICO is a lot closer to home than the Dutch DPA.

So a UK business selling into Europe is now dealing with 2 regimes that overlap without matching. The EU cares about the AI system. The UK cares about the personal data flowing through it. You need both.

Two people shaking hands across a meeting table

5 things to check this month

→ Do you have an inventory of every AI tool your business uses, including the ones staff signed up for on a company card? You cannot assess what you cannot list.

→ Does any AI output reach people in the EU? Customers, candidates, users, clients. If yes, you are in scope.

→ Does your chatbot, voice agent or AI email assistant tell people it is AI? If not, fix it this week.

→ Does any tool make or shape decisions about people: hiring, performance, credit, access to services? Flag it now for the December 2027 high-risk deadline, and check your UK Article 22A to 22D safeguards today.

→ Have you done a DPIA and given staff any AI training at all? Both regimes now expect it.

"We're not in the EU" is not a defence. "It's been delayed" is not a defence either.

I work with UK businesses as their outsourced DPO, and AI governance is now a standard part of that work. If you want a plain-English review of where your business stands under both regimes, drop me a message. Happy to have a no-obligation chat.

References

European Commission AI Act Service Desk, Timeline for implementation of the EU AI Act

White & Case, EU AI Omnibus enters into force, amending the AI Act (Regulation (EU) 2026/1744, published 24 July 2026)

Lewis Silkin, The Digital Omnibus on AI enters into force today

Gibson Dunn, EU AI Act Omnibus Agreement: Postponed High-Risk Deadlines and Other Key Changes

Pinsent Masons, Rules on 'high-risk' AI to be delayed under EU 'omnibus' deal

Regulation (EU) 2024/1689, Article 2 (Scope), Article 22 (Authorised representatives), Article 50 (Transparency obligations) and Article 99 (Penalties)

Arnold & Porter, The UK ICO's New Statutory Duty to Produce an AI Code of Practice

Scaffold Digital, UK AI Regulation in 2026: What's in Force, What's Coming

Policy Pros, EU AI Act and UK Businesses: What You Need to Do

Alex Goodman
Alex Goodman|DPO and GDPR expert|LinkedIn logo icon
Alex Goodman has over 10 years of experience in data protection. He has handled compliance for organisations across financial services, SaaS, healthcare, enforcement, charity, and children's data, first inside large regulated businesses and now as an independent adviser. He holds practitioner certifications in Data Protection Impact Assessments and Subject Access Requests, and is an accredited Counter Fraud Investigator.
Back to Blog

Alex Goodman is an experienced GDPR consultant and outsourced Data Protection Officer working with UK businesses to improve their DPO and GDPR compliance.

© 2026 - GDPR Consultant - All Rights Reserved.

Driven by expertise and personalised service, we’re here to guide you towards GDPR compliance every step of the way.

© 2026 - GDPR Consultant - All Rights Reserved.