The EU AI Act is the European Union’s risk-based legal framework for AI. It places different obligations on providers, deployers and other actors depending on the system, role and context, and it can apply to organisations established outside the EU.
Why a UK organisation may be affected
The Act includes territorial provisions that can reach outside the EU, including circumstances involving placing AI systems or models on the EU market and where output produced by a system is used in the EU. Group structure, customers, users, distribution and contractual roles can all matter. A legal scope decision should be made system by system.
The application timetable is phased
| Date | Position |
|---|---|
| 2 February 2025 | Prohibited-practice provisions and AI-literacy obligations began to apply. |
| 2 August 2025 | Governance rules and obligations for general-purpose AI models began to apply. |
| 2 August 2026 | Many remaining provisions apply, subject to exceptions and amended transitional dates. |
| 2 December 2027 | Following the May 2026 political agreement, rules for systems in certain high-risk areas are scheduled to apply. |
| 2 August 2028 | Rules for high-risk systems embedded in regulated products are scheduled to apply. |
Primary source: European Commission, AI Act overview and implementation timeline.
Start with role and inventory, not a generic deadline
An organisation needs to know which AI systems and embedded features it uses, whether it provides or deploys them, who is affected, where the system or output is used and whether a high-risk category may be relevant. Without that inventory, a deadline statement has little operational value.
Questions for UK organisations
- Do we supply, distribute or use AI systems in connection with the EU market?
- Are outputs used in the EU, even if the system is operated from the UK?
- What contractual role do customers and suppliers assign to us?
- Could any use fall within a prohibited or high-risk category?
- Are staff who operate AI systems appropriately literate for their role?
- What technical documents, logs, notices or oversight evidence can we produce?
The UK position is different
The UK has used a principles-led framework applied through existing regulators rather than reproducing the EU Act as a single cross-sector law. The five published principles are safety, security and robustness; transparency and explainability; fairness; accountability and governance; and contestability and redress. Sector-specific law and regulator guidance remain important.
Primary source: GOV.UK, implementing the UK’s AI regulatory principles.
A practical response
- Build a proportionate inventory of AI systems and material embedded features.
- Record the organisational and legal role for each important use.
- Identify affected people, data, geography and decisions.
- Separate confirmed obligations from unresolved legal questions.
- Assign owners and retain evidence of decisions.
- Review the position when the system, supplier, use or law changes.
An independent AI governance audit can help establish the operational evidence and gaps. It is not a substitute for legal advice.