AI REGULATION

EU AI Act: What UK Businesses Need to Know in 2026

The EU AI Act is in force and phasing in. It is EU law, but like GDPR it reaches UK businesses through their customers and their markets. This page explains what applies, what does not, and what to do now.

Book a conversation

The short answer

The EU AI Act does not regulate UK companies the way a UK law would. It reaches you if you provide or use AI systems that are placed on the EU market or whose outputs are used in the EU. That extraterritorial reach mirrors GDPR: a UK business selling AI-enabled products into Europe, or serving EU customers, can fall within scope even though the Act never names the UK.

Who it applies to for UK businesses

The Act draws its heaviest obligations around two roles. A provider develops an AI system and places it on the EU market. A deployer uses an AI system in a professional capacity within the EU. A UK software firm selling an AI feature to European customers is likely a provider; a UK company using an AI tool through an EU subsidiary may be a deployer. Either way, EU customers under their own obligations will increasingly pass requirements down to you through contracts and questionnaires, exactly as they do with NIS2.

The risk tiers

The Act regulates by risk, not by technology. Understanding which tier your use falls into is the first practical step.

  • Unacceptable risk: a small set of uses, such as social scoring, are banned outright
  • High risk: systems in areas like recruitment, credit, biometrics and critical infrastructure carry strict obligations on risk management, data quality, documentation and human oversight
  • Limited risk: systems like chatbots carry transparency duties, such as telling people they are interacting with AI
  • Minimal risk: most business software falls here and is largely unaffected

When the rules take effect

The Act entered into force in August 2024 and applies in phases. The bans on unacceptable-risk uses and the AI literacy duty applied from February 2025, and the rules for general-purpose AI models and the governance framework from August 2025. The high-risk obligations were originally due from August 2026, but under the European Commission’s Digital Omnibus proposals that deadline is being pushed back, with the core high-risk rules now expected to apply later, provisionally around the end of 2027. The direction of travel has not changed, only the timing, so the sensible response is to keep classifying and governing your AI use rather than treating a moving deadline as breathing space.

What UK businesses should do now

The work is governance before it is legal. Build an inventory of where AI is actually used in the business, classify each use by the Act’s risk tiers, and put oversight around the high-risk ones. That is the same discipline that controls shadow AI and underpins a workable AI policy. The UK has taken a lighter, pro-innovation stance with no single AI Act of its own, relying on existing regulators such as the ICO and DSIT, but that does not remove the EU’s reach or the governance duty. Our AI governance work puts the framework in place.

Why Starkhorn

Starkhorn is led by Daniel J. Jacobs, who has spent over 20 years in technology and security, 15 of them in leadership roles, including Interim Group Technology Director at VetPartners, the BC Partners-backed veterinary group, and CIO and CISO at Jardine Motors Group. He is the author of The Strategy Bridge and holds PRINCE2, ITIL Foundation and full membership of the Institute of Interim Management.

Daniel governs AI adoption the way a board needs it governed: as a risk and accountability question, not just a capability one, translating the regulatory picture into an inventory, a policy and the oversight that stands up to scrutiny.

Frequently asked questions

Does the EU AI Act apply to UK businesses?

It can. The Act is EU law but reaches UK firms that provide or use AI systems placed on the EU market or whose outputs are used in the EU. Like GDPR, its extraterritorial scope means a UK business serving EU customers can fall within it, and EU customers will pass obligations down through contracts.

What are the risk tiers in the EU AI Act?

Four: unacceptable-risk uses are banned; high-risk systems in areas like recruitment, credit and biometrics carry strict obligations; limited-risk systems such as chatbots carry transparency duties; and minimal-risk uses, which cover most business software, are largely unaffected.

When do the EU AI Act rules take effect?

The Act entered into force in August 2024 and phases in. Bans and AI literacy applied from February 2025 and the general-purpose AI and governance rules from August 2025. The high-risk obligations were set for August 2026 but are being delayed under the Digital Omnibus proposals, with the main rules now expected around the end of 2027. The timing is shifting; the obligations are not going away.

What should a UK business do now?

Build an inventory of where AI is used, classify each use by the Act’s risk tiers, and put oversight around the high-risk ones. That governance work also controls shadow AI and underpins a usable AI policy, so it is worth doing regardless of exactly how the regulation lands.

Does the UK have its own AI Act?

Not as a single statute. The UK has taken a lighter, pro-innovation approach, relying on existing regulators such as the ICO and DSIT rather than one comprehensive law. That does not remove the EU AI Act’s reach for UK firms with EU customers or operations.

NEXT STEP

Where is your AI exposure, and what should you fix first?

The free AI Readiness check shows where your AI use creates risk and the one thing to address before it becomes a problem. When you want to talk it through, a conversation is the next step.

AI Readiness check Book a conversation