Tech News
31 July 2026
The EU AI Act is Regulation (EU) 2024/1689, a risk-based legal framework for artificial intelligence. It entered into force on 1 August 2024 and applies in stages rather than all at once. The basic idea is the stricter the risk posed by an AI use case, the stricter the legal obligations. The European Commission describes four broad levels in practice: unacceptable risk, high-risk, transparency risk, and minimal or no risk.
That matters because the Act is not a blanket ban on “AI” as a whole. Most AI uses are not prohibited. Some are banned outright, some are tightly regulated, some mainly trigger transparency duties, and many ordinary uses remain subject to little or no AI-specific regulation under the Act. For example, the Commission says spam filters and AI-enabled video games generally fall into the minimal or no-risk category.
For searchers asking “what does the EU AI Act do?”, the answer is this: it creates a single EU rulebook for certain AI systems and general-purpose AI models, with extra scrutiny where health, safety, fundamental rights, or public trust are most at stake.
A UK address does not, by itself, keep you outside the Act. The Commission’s guidance says the legal framework applies to public and private actors both inside and outside the EU if they place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, or use it in the EU. Separate Commission guidance on AI literacy also says the framework applies outside the EU where the AI system is placed on the Union market, used in the Union, or its use has an impact on people located in the EU. In other words, if your AI product, service, or output crosses into the EU market, the Act can cross the Channel too.
For a UK-based IT company, that can cover more situations than people first assume. Selling an AI-powered recruitment product to an EU client, offering a customer-facing chatbot to EU users, providing AI-assisted credit assessment in the EU, or placing a general-purpose model on the EU market can each trigger different parts of the regime.
It also helps to know your role. The Act distinguishes between providers and deployers, and those roles matter because the obligations are different. A business that builds and markets its own system is often a provider; a business that uses someone else’s AI in its operations is often a deployer. For general-purpose AI models, the Commission also says companies outside the EU that place such models on the Union market are in scope, and providers established outside the EU must appoint an authorised representative in the Union before placing the model on the market.
One more nuance worth knowing: not every company that fine-tunes a model becomes a full-blown model provider under the Act. The Commission’s 2026 guidance says only significant modifications bring provider obligations for general-purpose AI models into play; most minor modifications and ordinary fine-tuning do not. That is helpful news for teams adapting existing models, though it does not remove the need to assess what exactly you are changing and how it is being used.
The easiest way to understand the Act is to start with use case, not buzzword. An AI system does not become “high-risk” merely because it sounds impressive or uses a large model. According to the Commission, classification depends on the intended purpose of the system. In broad terms, a system is high-risk if it is a safety component in a regulated product or if it is intended for one of the high-risk uses listed in Annex III, such as certain uses in education, employment, access to essential services, law enforcement, migration, justice, democratic processes, or particular biometric uses.
At the top end are prohibited practices, sometimes called unacceptable-risk AI. The Commission lists banned practices including harmful manipulation and exploitation of vulnerabilities, social scoring, individual predictive policing based solely on profiling, untargeted scraping of internet or CCTV footage to build facial-recognition databases, certain emotion recognition in workplaces and education, certain biometric categorisation, and real-time remote biometric identification for law enforcement in public spaces subject to narrow exceptions. These prohibitions have applied since February 2025.
Then there is high-risk AI. This is where many business-relevant systems sit. The Commission’s examples include AI used to analyse and filter job applications, evaluate candidates, score learning outcomes, assess creditworthiness, price life and health insurance, or operate as safety components in critical infrastructure or medical products. Providers of high-risk systems must carry out a conformity assessment before placing the system on the EU market or putting it into service, and the requirements cover areas such as risk management, data quality, documentation and traceability, transparency, human oversight, accuracy, cybersecurity, and robustness. Providers also need quality management systems, EU database registration, and lifecycle responsibilities including incident handling and cooperation with authorities.
There is also a transparency layer that matters to many ordinary digital services. The Commission says that, from 2 August 2026, people in the EU must be informed when they are interacting with certain AI systems or exposed to certain AI-generated or manipulated content. In practical terms, that includes informing people when they are interacting with AI, adding machine-readable marks for AI-generated or manipulated content, and disclosing deepfakes, certain AI-generated public-interest text, emotion recognition, and biometric categorisation in the situations covered by Article 50. So yes, a website chatbot can be a transparency issue rather than a high-risk issue, which is a useful distinction when someone in a meeting says “it’s definitely all illegal now” and everyone else quietly reaches for coffee.
General-purpose AI models have their own rule set. Since 2 August 2025, providers of such models must, among other things, keep technical documentation, provide information to downstream AI system providers, implement a policy to comply with EU copyright law, and publish a sufficiently detailed summary of the content used for training. Providers of general-purpose AI models with systemic risk face additional duties, including risk assessment and mitigation, model evaluations, serious incident reporting, and adequate cybersecurity protections. The AI Office supervises and enforces these obligations.
The headline dates are worth knowing because search intent around the EU AI Act is often really a timeline question in disguise. The Act entered into force on 1 August 2024. Prohibited practices, the AI system definition, and AI literacy provisions started to apply on 2 February 2025. Governance rules and obligations for general-purpose AI models became applicable on 2 August 2025. The Commission also says the transparency obligations in Article 50 apply from 2 August 2026.
AI literacy is easy to overlook, but businesses should not. The Commission’s FAQ says providers and deployers of AI systems must take measures to ensure a sufficient level of AI literacy for staff and others dealing with AI on their behalf, taking into account their technical knowledge, training, the context of use, and the people affected. That obligation has already applied since 2 February 2025, although supervision and enforcement by national market surveillance authorities starts from August 2026.
The moving part in mid-2026 is high-risk timing. The Commission’s AI Act page says a political agreement on the so-called AI Omnibus was reached on 7 May 2026 and sets a revised implementation timeline for high-risk systems: 2 December 2027 for certain stand-alone high-risk systems in areas such as biometrics, critical infrastructure, education, employment, migration, asylum and border control, and 2 August 2028 for high-risk AI embedded in regulated products such as lifts or toys. The Commission links that delay to the need for support tools such as standards. At the same time, the Commission notes that harmonised standards are voluntary but important because they can give providers a presumption of conformity and were not ready in the original timetable.
For general-purpose AI models, the timetable is firmer. The Commission’s 2026 guidance says the obligations have applied since 2 August 2025, Commission enforcement powers start from 2 August 2026, and providers of models placed on the market before 2 August 2025 must comply by 2 August 2027.
Penalties are significant enough to concentrate minds. The Commission’s FAQ says Member States must set effective, proportionate, and dissuasive penalties for AI system infringements, with thresholds that can reach up to €35 million or 7% of worldwide annual turnover for prohibited practices or certain data-related breaches, up to €15 million or 3% for other non-compliance, and up to €7.5 million or 1.5% for supplying incorrect, incomplete, or misleading information. For general-purpose AI model obligations enforced by the Commission, fines can reach up to €15 million or 3% of worldwide annual turnover.
The practical starting point is an AI inventory. If you do not know which systems use AI, where they are used, who uses them, what data they touch, and whether EU users are in scope, everything else becomes guesswork with better branding. That is an inference from the Act’s structure. It follows directly from the fact that obligations depend on your role, the intended purpose, and whether the system or model is placed on the EU market or used in the EU.
Next, work out whether you are mainly a provider, a deployer, or both. Many organisations are deployers of third-party tools and providers of their own internal or client-facing systems at the same time. That matters for contractual allocation of responsibilities, access to technical documentation, incident reporting, and who does what if a system falls into a high-risk or transparency category. For businesses using general-purpose models in downstream products, the Commission specifically emphasises information flow between model providers and downstream system providers.
Then screen your actual use cases. Recruitment, worker management, education, credit, insurance, certain biometric uses, and safety-critical systems deserve immediate scrutiny because they are the places where high-risk analysis is most likely. Customer-facing AI interactions, AI-generated content, deepfake-like outputs, and public-interest text need a transparency review ahead of the August 2026 obligations.
Do not treat staff training as optional housekeeping. The AI literacy requirement already applies, and the Commission is clear that simply handing employees the manual is often not enough. Organisations are expected to tailor literacy measures to role, context, and risk, especially where people are expected to exercise human oversight over AI systems.
If you build on top of external models, look closely at supplier terms and technical documentation. If you build or place a general-purpose model on the EU market yourself, the obligations become much heavier, including documentation, downstream information sharing, copyright policy, training-data summaries, and additional duties for systemic-risk models. The Commission has also launched an AI Act Service Desk and Single Information Platform, including a compliance checker, specifically to help organisations work out whether they are in scope and what they need to do.
The sensible takeaway for most UK businesses is not panic, and not complacency either. The Act is detailed, but its logic is understandable. Know your role, know your use case, know your geography, and keep enough evidence to show you are acting responsibly. If your AI touches EU users, workers, applicants, customers, or public-facing content, this is no longer a “we’ll deal with it later” topic.