Glossary

EU AI Act

The EU AI Act is the European Union's law regulating artificial intelligence, in force since 1 August 2024. It sorts AI systems by risk level and sets rules accordingly. It can bind UK organisations even without an EU presence, wherever their AI system's output is used in the EU.

Last updated

Part of our topic guide on AI Governance & Data Strategy.

The EU AI Act is the European Union's law regulating artificial intelligence, in force since 1 August 2024. It sorts AI systems by risk level and sets rules accordingly. It can bind UK organisations even without an EU presence, wherever their AI system's output is used in the EU.

Can it really reach a UK business with no EU office?

Yes, and that catches more UK employers than most expect. The Act's reach follows the AI system, not the company registration: a UK company with no EU office can still fall under it if its AI system's output is used in the EU, or if it places an AI system on the EU market. So the first question isn't "are we based in the EU?" but "does anything our AI produces land there?". A UK employer can therefore be watching two different pictures at once: no domestic AI Act, but live EU exposure.

The timeline, as it stands

The Act phases in by provision, so what applies depends on the date:

  • 1 August 2024: the Act entered into force.
  • 2 February 2025: banned practices (Article 5) and AI literacy duties (Article 4) started applying.
  • 2 August 2025: obligations for general-purpose AI (GPAI) models, plus governance and penalty provisions.
  • 2 August 2026: most remaining provisions apply.
  • High-risk (Annex III) obligations: originally due 2 August 2026, but under the EU's "Digital Omnibus on AI" this is being pushed back, provisionally to around December 2027 (or August 2028 for high-risk systems built into product safety components). As of mid-2026 this change is provisionally agreed but not yet formally adopted by the European Parliament and Council, so treat the later date as expected rather than settled, and check the latest position before relying on it.

What the UK has instead

There's no equivalent UK law. The UK regulates AI through existing sector regulators (bodies like the ICO, CMA, FCA and Ofcom) under a principles-based approach, rather than one dedicated AI statute. That asymmetry is exactly why the Act is worth understanding even if you never trade in the EU: it has become the reference point other regimes define themselves against.

What to do with all this

Our view: this is exactly why capability has to sit ahead of the tools. A team that understands what an AI system does, what data feeds it and what "high-risk" means in practice can spot exposure long before a compliance audit does. Buying a governance checklist doesn't fix that gap: building the judgement to use it does.