Glossary
EU AI Act
Last updated
Part of our topic guide on AI Governance & Data Strategy.
The EU AI Act is the European Union's law regulating artificial intelligence, in force since 1 August 2024. It sorts AI systems by risk level and sets rules accordingly. It can bind UK organisations even without an EU presence, wherever their AI system's output is used in the EU.
Can it really reach a UK business with no EU office?
Yes, and that catches more UK employers than most expect. The Act's reach follows the AI system, not the company registration: a UK company with no EU office can still fall under it if its AI system's output is used in the EU, or if it places an AI system on the EU market. So the first question isn't "are we based in the EU?" but "does anything our AI produces land there?". A UK employer can therefore be watching two different pictures at once: no domestic AI Act, but live EU exposure.
The timeline, as it stands
The Act phases in by provision, so what applies depends on the date:
- 1 August 2024: the Act entered into force.
- 2 February 2025: banned practices (Article 5) and AI literacy duties (Article 4) started applying.
- 2 August 2025: obligations for general-purpose AI (GPAI) models, plus governance and penalty provisions.
- 2 August 2026: most remaining provisions apply.
- High-risk (Annex III) obligations: originally due 2 August 2026, but the EU's "Digital Omnibus on AI" (Regulation (EU) 2026/1744, in force since 27 July 2026) pushed them back to 2 December 2027, or 2 August 2028 for high-risk systems built into regulated products. The same Omnibus softened the Article 4 AI-literacy duty above, from a duty to ensure staff literacy to one to support it, though its February 2025 start date was unchanged. Dates and detail can still move, so check the latest position before relying on it.
What the UK has instead
There's no equivalent UK law. The UK regulates AI through existing sector regulators (bodies like the ICO, CMA, FCA and Ofcom) under a principles-based approach, rather than one dedicated AI statute. That asymmetry is exactly why the Act is worth understanding even if you never trade in the EU: it has become the reference point other regimes define themselves against.
What to do with all this
Our view: this is exactly why capability has to sit ahead of the tools. A team that understands what an AI system does, what data feeds it and what "high-risk" means in practice can spot exposure long before a compliance audit does. Buying a governance checklist doesn't fix that gap: building the judgement to use it does.