The EU AI Act for UK Organisations: What Applies and When
The UK has no single AI law, so it is easy to assume the EU AI Act is someone else's problem. It reaches further than that. If you sell AI into the EU, or the output of your AI is used there, parts of it can apply to you. And the timetable moved in July 2026. Here is a practical guide to what applies and when.
The EU AI Act can apply to UK organisations that place AI systems on the EU market or whose AI output is used in the EU. Prohibited practices and the AI literacy duty have applied since February 2025, rules for general purpose AI models since August 2025, and transparency rules since August 2026. After the Digital Omnibus entered into force on 27 July 2026, obligations for high risk AI apply from 2 December 2027, or 2 August 2028 for AI built into regulated products. Most enterprises are deployers rather than providers, which narrows but does not remove their duties.
This is practical guidance to help you work out where you stand, drawn from the European Commission's own summary and published analysis. It is not legal advice. For decisions about your specific obligations, involve your legal advisers. We work alongside them on the technology and vendor side.
Does it apply to a UK organisation?
The Act applies to providers that place AI systems on the EU market, and it also reaches AI whose output is used in the EU. European Commission, AI Act. Leaving the EU did not take UK organisations outside that. A UK firm that sells an AI enabled product to EU customers, or uses AI to make decisions about people in the EU, should work through the Act rather than assume it is out of scope. A UK organisation using AI only for UK operations, on UK data and UK people, is far less likely to be affected, though UK data protection and sector regulation still apply.
Provider or deployer: the distinction that matters most
The Act puts most obligations on providers, the organisations that develop an AI system or have it developed and place it on the market under their name. Deployers, the organisations that use an AI system in their work, carry lighter but real duties. Most enterprises buying Copilot, ChatGPT or an AI feature inside a business application are deployers. You can become a provider without meaning to, for example by putting your own name on an AI system or substantially modifying one, so it is worth deciding deliberately which role you hold for each system.
The timeline, after the Digital Omnibus
| Date | What applies |
|---|---|
| 1 August 2024 | The Act entered into force |
| 2 February 2025 | Prohibited AI practices banned, and the AI literacy duty applies |
| 2 August 2025 | Obligations for providers of general purpose AI models |
| August 2026 | Transparency rules, such as telling people when they are interacting with an AI system |
| 2 December 2026 | New prohibition on AI generated non consensual intimate content, and the end of the grace period for marking synthetic content from systems already on the market |
| 2 December 2027 | Obligations for high risk AI in sensitive areas such as employment, education, credit and critical infrastructure |
| 2 August 2028 | Obligations for high risk AI built into regulated products |
Sources: European Commission, AI Act; Orrick, Digital Omnibus changes, July 2026.
The Digital Omnibus, which entered into force on 27 July 2026, moved the high risk deadlines back from August 2026 and August 2027, added the new prohibition, and extended some support to a new category of small mid cap companies. It did not move the transparency rules, so organisations running chatbots or generating content for EU audiences are already in that phase. Orrick, Digital Omnibus changes, July 2026.
What it means in practice for most enterprises
AI literacy, already in force
Providers and deployers are expected to take measures so that staff working with AI have sufficient AI literacy for their role. If your people use AI on work that touches the EU, a proportionate training and guidance programme is the starting point, and it is also good practice regardless of the law.
Transparency, now applying
People should know when they are interacting with an AI system such as a chatbot, and AI generated or manipulated content of certain kinds should be identifiable as such. Check customer facing assistants and any content generation aimed at EU audiences.
High risk use, from December 2027
The areas classed as high risk include employment, such as screening candidates or managing workers, access to essential services and credit, and education. If you deploy AI in those areas affecting people in the EU, expect duties such as using the system as the provider instructs, human oversight, monitoring and keeping logs. The extra time is for preparation, not postponement: inventory those uses now.
Your AI vendors carry most of the provider duties, but your contract decides what you can prove. Ask vendors for the documentation and information the Act requires them to give deployers, and make sure your contracts oblige them to keep providing it as the rules phase in. Our guide to negotiating the AI purchase covers getting commitments into the contract.
Practical steps
- Build an inventory of the AI systems you use and provide, including AI features inside business applications, and note where their outputs are used.
- Mark the EU touchpoints: EU customers, EU staff, EU data subjects and EU markets.
- Decide your role for each system: provider, deployer or neither.
- Classify the use: prohibited, high risk, transparency obligations, or minimal risk.
- Run an AI literacy programme proportionate to how people use AI.
- Review vendor contracts for the documentation and support you will need.
- Fold it into AI governance rather than running it as a separate compliance project. Our guide to AI governance sets out the structure.
How we help
We help organisations build the AI inventory, work out where EU touchpoints are, put governance and controls in place, and get the right commitments from AI vendors, working alongside your legal advisers rather than instead of them.
Working out where the AI Act touches you?
Tell us which AI systems you use or provide and where your EU exposure is. We will help you build the inventory, put the governance in place and get the right commitments from your vendors, alongside your legal advisers.
Prefer email? Reach us directly at hello@c4cgroup.co.uk.
Frequently asked questions
Does the EU AI Act apply to UK companies?
It can. The Act applies to providers placing AI systems on the EU market and reaches AI whose output is used in the EU, so a UK organisation selling AI enabled products to EU customers or using AI on people in the EU may be in scope. A UK organisation using AI only for UK operations is far less likely to be affected. Take legal advice on your specific position.
When do the EU AI Act high risk rules apply?
After the Digital Omnibus entered into force on 27 July 2026, obligations for high risk AI in sensitive areas such as employment, credit and education apply from 2 December 2027, and for high risk AI built into regulated products from 2 August 2028. Prohibitions, AI literacy, general purpose AI rules and transparency rules already apply.
What is the difference between a provider and a deployer?
A provider develops an AI system, or has it developed, and places it on the market under its own name, and carries most of the obligations. A deployer uses an AI system in its own work and has lighter but real duties. Most enterprises buying AI tools are deployers, though putting your name on a system or substantially modifying it can make you a provider.
What did the Digital Omnibus change?
It moved the high risk deadlines from August 2026 and August 2027 to 2 December 2027 and 2 August 2028, added a prohibition on AI generated non consensual intimate content from 2 December 2026, and extended some support to small mid cap companies. It did not move most transparency obligations.
What should a UK organisation do first?
Build an inventory of the AI systems you use and provide, mark where they touch the EU, decide whether you are a provider or deployer for each, and classify each use by risk. Then run a proportionate AI literacy programme and check your vendor contracts give you the documentation you will need.