Guides

The EU AI Act in 2026: What UK Businesses Actually Need to Do

The EU AI Act's high-risk rules slipped to 2027, but transparency duties still bite on 2 August 2026. What that means for UK businesses, in plain English.


If you read anywhere — including, until we updated it, our own mid-2026 roundup — that “the EU AI Act becomes fully applicable on 2 August 2026,” that is no longer the full story. In the space of a few weeks this summer, Brussels quietly moved the goalposts. A last-minute simplification package called the Digital Omnibus deferred the Act’s headline high-risk obligations by more than a year — but left a different set of duties, the transparency rules, firmly in place for 2 August 2026.

The upshot is a mess of dates that’s easy to get wrong, and getting it wrong cuts both ways: some firms are scrambling to meet a deadline that has moved, while others assume “it’s all been delayed” and miss the bit that hasn’t. This guide untangles it for a UK audience — what actually applies on 2 August 2026, what slipped to 2027 and 2028, whether a UK business is even in scope, and the short list of things worth doing now.

A note on dates: this is a fast-moving area and we’ve dated every claim. It’s accurate as of 16 July 2026, drawn from the European Commission and Council, the official AI Act text, and analysis by Sidley, Gibson Dunn, DLA Piper and Travers Smith. If you have a genuinely high-risk deployment, take proper legal advice — this is orientation, not a legal opinion.

What the Digital Omnibus changed

The EU AI Act became law in 2024 with a staged timeline. Two milestones have already passed: the ban on prohibited practices took effect on 2 February 2025, and obligations for general-purpose AI (GPAI) models applied from 2 August 2025. The big remaining date was 2 August 2026, when the demanding rules for high-risk AI systems were due to land.

Then the timeline moved. The Commission proposed the Digital Omnibus on 19 November 2025; negotiators reached a provisional deal on 7 May 2026; the European Parliament endorsed it on 16 June; and the Council gave its final green light on 29 June 2026. The law enters into force shortly after publication in the EU’s Official Journal. In plain terms: the high-risk obligations have been deferred, but not scrapped.

Here’s the corrected timeline that matters now:

DeadlineWhat applies
2 Feb 2025 (in force)Ban on prohibited AI practices (social scoring, manipulative systems, most real-time biometric ID)
2 Aug 2025 (in force)Obligations for general-purpose AI (GPAI) model providers
2 Aug 2026Article 50 transparency obligations — the live deadline for most businesses
2 Dec 2026New Article 5 prohibitions (e.g. “nudifier” apps and CSAM generators); transparency marking for some legacy synthetic-content systems
2 Dec 2027High-risk obligations for stand-alone (Annex III) systems — deferred from Aug 2026
2 Aug 2028High-risk obligations for AI embedded in regulated products (Annex I)

So the scary, paperwork-heavy part — conformity assessments, CE marking, quality management systems, the EU database registration — is what moved to December 2027 and August 2028. The part that stayed put is lighter, but far more broadly applicable.

The bit that hasn’t moved: transparency (2 August 2026)

Article 50 is the obligation that catches ordinary businesses, because it applies to everyday uses of AI, not just exotic high-risk ones. From 2 August 2026 you must be transparent in four main situations:

  1. Chatbots and AI that talks to people. If your AI system interacts directly with a person, that person must be told they’re dealing with an AI — unless it’s already obvious.
  2. AI-generated content must be marked. Providers of generative AI must mark synthetic audio, image, video or text as artificially generated or manipulated, in a machine-readable way.
  3. Deepfakes must be disclosed. If you deploy AI to create a deepfake — content resembling real people, places or events that could pass as authentic — you must disclose that it’s artificially generated.
  4. AI-written public-interest text must be flagged. If you publish AI-generated text to inform the public on matters of public interest, you generally have to say so.

The information has to be “clear and distinguishable,” provided at the latest at the point of first interaction or exposure. (One small wrinkle the Omnibus added: the specific marking obligation for synthetic-content systems that were already on the market before 2 August 2026 is pushed to 2 December 2026. New systems get no such grace.)

For most UK firms, this is the practical crux: a customer-service chatbot, an AI image or video used in marketing, an AI-drafted article — these are the things that need a disclosure, and the clock is running.

Does this even apply to a UK business?

This is the question we get most, and the honest answer is: more often than people assume. The AI Act is extraterritorial. It reaches a business outside the EU where an AI system is placed on the EU market, or — the wide one — where the system’s output is used in the EU. If you have EU customers, EU users, or you publish AI-generated content that EU residents see, you can be in scope for at least the transparency rules, Brexit notwithstanding.

Meanwhile the UK itself still has no dedicated AI statute. As of mid-2026 there is no UK “AI Act” in force; AI is governed through existing law and regulators — the ICO under UK GDPR, Ofcom under the Online Safety Act, the FCA under Consumer Duty, and so on. That means a UK business often faces two regimes at once: UK GDPR for how it handles personal data (which we cover in how to use AI without violating GDPR), and the EU AI Act’s transparency duties for any AI touching the EU market. They’re separate obligations; meeting one doesn’t discharge the other.

What non-compliance costs

The penalties are tiered by severity under Article 99, and they are not trivial:

BreachMaximum fine
Prohibited practices (Article 5)€35m or 7% of global annual turnover, whichever is higher
Other obligations (incl. transparency, high-risk duties)€15m or 3% of global turnover
Supplying misleading information to regulators€7.5m or 1% of global turnover

There’s a genuine bit of relief for smaller players: for SMEs and start-ups, the cap is inverted — the fine is the lower of the fixed sum or the percentage, not the higher. A small firm won’t face a €15m fine on a £2m turnover. But “unlikely to be fined €15m” is not the same as “exempt,” and enforcement runs through national regulators in each member state, coordinated for GPAI by the European AI Office.

A practical checklist for UK teams

You don’t need a compliance department to get the transparency basics right. Before 2 August 2026:

  1. Inventory where AI touches your customers. Chatbots, AI email or content generation, AI images and video in marketing, AI-assisted phone lines. You can’t disclose what you haven’t mapped.
  2. Add clear AI disclosures. Label chatbots as AI at first contact. Mark AI-generated images, audio and video. Flag AI-written public-facing text where the rules require it. “Clear and distinguishable” is the standard — a buried footnote won’t do.
  3. Check your tools’ labelling features. Many providers now embed content credentials or watermarks in generated media — see the provenance discussion in our AI image generators comparison. Use them; they help you meet the marking obligation.
  4. Don’t forget UK GDPR in parallel. Where you’re feeding personal data into a tool, the data questions still bite regardless of the AI Act. Our UK/EU data-residency picks and ChatGPT GDPR guide cover that side.
  5. Diarise the 2027/2028 dates if you build high-risk systems. If you develop AI for recruitment, credit scoring, education, essential services or similar Annex III uses, the heavy obligations are coming — deferred, not cancelled. Start the groundwork; conformity assessments aren’t a last-week job.
  6. Keep an eye on the text. The Omnibus only just cleared its final vote; secondary guidance and standards are still landing. This is a “check the date on your source” area — which is exactly why we date ours.

The good news is that the tools themselves are broadly usable under all this — ChatGPT, Claude and Gemini can all be deployed compliantly. The Act regulates how you use and disclose AI, not whether you may use it at all.

Frequently asked questions

Is the EU AI Act delayed? Partly. The Digital Omnibus, finalised by the Council on 29 June 2026, deferred the high-risk obligations — standalone (Annex III) systems now from 2 December 2027, embedded (Annex I) systems from 2 August 2028. But the transparency obligations under Article 50 were not delayed and still apply from 2 August 2026.

What do I actually have to do by 2 August 2026? Mainly, be transparent: tell people when they’re talking to an AI, mark AI-generated content, and disclose deepfakes. If you run a customer chatbot or use AI-generated media that reaches EU users, that’s the obligation to focus on.

Does the EU AI Act apply to UK companies after Brexit? It can. The Act applies where an AI system is placed on the EU market or its output is used in the EU. A UK business with EU customers, users or audiences may be in scope for at least the transparency rules.

Is there a UK AI Act? Not as of mid-2026. The UK regulates AI through existing laws and regulators (UK GDPR/ICO, Ofcom, FCA) rather than a single AI statute. UK GDPR still governs any personal data you put into AI tools.

What are the fines? Up to €35m or 7% of global turnover for prohibited practices; up to €15m or 3% for most other breaches (including transparency); up to €7.5m or 1% for misleading regulators. SMEs get the lower of the fixed or percentage figure.

Final thoughts

The Digital Omnibus took some of the pressure off — the genuinely onerous high-risk compliance work now lands in 2027 and 2028, which is a real reprieve for anyone building serious AI systems. But it would be a mistake to read “delay” and switch off. The transparency rules arrive on schedule on 2 August 2026, they apply to the everyday AI most businesses actually use, and they reach UK firms serving the EU. Map where AI touches your customers, add honest disclosures, and keep the data side clean under UK GDPR — do that, and you’re most of the way there.

Want a hand auditing where AI sits in your business and whether your disclosures are up to scratch? Get in touch — we’re always happy to help.

Last updated: 16 July 2026. Deadlines reflect the Digital Omnibus as finalised by the Council on 29 June 2026 and may be refined by secondary guidance; drawn from the European Commission and Council, the official AI Act text, and analysis by Sidley, Gibson Dunn, DLA Piper and Travers Smith. This is general information, not legal advice. See our editorial standards.