You've seen the headlines. The EU AI Act deadlines have shifted again. So it's tempting to file this one away for another year.
Here's the honest answer: some obligations have moved. Others are already live. And if you're using AI tools in your business right now — even standard off-the-shelf software — you may already be inside the scope of this regulation without realising it.
The EU AI Act (Regulation EU 2024/1689) entered into force on 1 August 2024. The first wave of obligations, including outright prohibitions on certain AI uses and staff AI literacy requirements, became enforceable in February 2025. Those aren't upcoming deadlines. They're already in effect.
The financial stakes are real too. Fines can reach EUR 35 million or 7% of global annual turnover, whichever is higher. For a small business, that's not a number you can afford to treat as abstract.
This article covers what the Act actually requires, whether it applies to your business, what the 2026 deadline changes mean in practice, and what you should have in place right now.
Does the EU AI Act Actually Apply to Your Business? {#does-it-apply} This is the right question to start with — and the answer isn't the same for every business.
It depends on your EU exposure.
The Act is extraterritorial. It applies to businesses outside the EU if their AI systems affect people inside the EU. For UK businesses, you're likely in scope if any of the following apply:
You have customers based in EU member states You process personal data belonging to EU residents You have a subsidiary, branch, or registered entity in the EU You supply products or services into the EU market If none of those apply — if your customers, suppliers, and operations are entirely UK-based — you have no EU AI Act obligations. Full stop.
The UK runs its own separate, lighter-touch framework built around cross-sector principles rather than a single binding statute. That sits alongside rules you may already be working within: UK GDPR, FCA Consumer Duty if you're in financial services, and any sector-specific requirements for your industry.
So before anything else, work out your EU exposure. If it's zero, focus on the UK framework. If it's anything other than zero, read on.
What the Risk Categories Mean in Plain English {#risk-categories} The EU AI Act doesn't treat all AI the same way. It sorts AI systems into four categories based on the risk they pose. Here's what each one means for a business like yours.
Forbidden AI (Prohibited Practices) These are AI uses the EU has banned outright — enforceable since February 2025.
Examples include AI that manipulates people without their awareness, systems that exploit vulnerable groups, and real-time biometric surveillance in public spaces. If you're running a standard SME in the East Midlands, you're almost certainly not doing any of this. But it's worth knowing the line exists.
High-Risk AI This is where most of the compliance complexity sits. High-risk systems include AI used in hiring and recruitment decisions, credit scoring, and access to essential services.
If you use AI tools to screen CVs, score job applicants, or make automated decisions that affect someone's access to employment or finance, you may be operating a high-risk system. The obligations here include documentation, human oversight, and conformity assessments.
The full high-risk requirements were originally due by 2 August 2026. Following the EU Digital Omnibus agreement on 7 May 2026, some of those deadlines have shifted to 2 December 2027 and 2 August 2028 for certain categories. More on what that actually means below.
Limited-Risk AI These are systems that interact with people in ways that require transparency. Chatbots are the clearest example. If you run an AI chatbot on your website, you need to tell users they're talking to an AI. That's the core obligation here.
Minimal-Risk AI The vast majority of AI tools fall into this category — spam filters, product recommendations, basic workflow automation. No specific obligations apply, though responsible use still matters.
Most SMEs in Northampton, Milton Keynes, Bedford, and across the UK sit in the limited-risk or minimal-risk categories. That's genuinely good news. But it doesn't mean you can ignore the Act entirely.
What the Deadline Extension Actually Changes — and What It Doesn't {#deadline-extension} The EU Digital Omnibus package, agreed on 7 May 2026, pushed back several high-risk AI obligations. Some categories now have compliance dates of 2 December 2027 and 2 August 2028, rather than the original 2 August 2026 deadline.
That's a meaningful extension. If you were preparing for high-risk compliance this year, you now have more time.
But here's what hasn't moved.
The prohibitions on banned AI practices have been enforceable since February 2025. The AI literacy obligations — requiring businesses to ensure staff who work with AI have an appropriate level of understanding — also came into force in February 2025. If you haven't done anything about staff AI training yet, you're already behind.
The extension doesn't reset the clock on obligations that are already live. It only affects high-risk system requirements that weren't yet due.
Don't use the extension as a reason to do nothing. Use it as breathing room to get the foundations right.
5 Things UK SMEs Should Have in Place Right Now {#five-things} Whether you're in scope of the EU AI Act or only the UK framework, these five steps are worth doing now. They're not complex. They don't require a legal team. And they protect you regardless of how the regulatory picture develops.
- Build an AI Register Write down every AI tool your business uses. That includes software with AI features built in — scheduling tools, email assistants, CRM automation, recruitment platforms. Note what each tool does, what data it touches, and who uses it.
It doesn't need to be elaborate. A spreadsheet works. The point is visibility. You can't manage risk you haven't mapped.
-
Name an AI Risk Owner Someone in your business needs to own AI risk. In a team of 5 to 50 people, that's usually a director or senior manager. It doesn't have to be a full-time role — but it does need to be a named person with clear responsibility for keeping the AI register current, reviewing new tools before adoption, and responding if something goes wrong.
-
Run Staff AI Literacy Training The AI literacy obligation under the EU AI Act has been live since February 2025. Even if you're not in scope of the EU Act, the UK framework expects responsible AI use — and that starts with your team understanding what the tools they're using actually do.
This isn't technical training. It means your staff can recognise when AI is involved, understand its limitations, and know when to apply human judgement. In our experience working with SMEs, a half-day session covers the essentials for most teams.
AI Advisers provides AI governance and literacy training designed specifically for non-technical teams. You can find out more at aiadvisers.co.uk.
- Do Vendor Due Diligence If you use third-party AI tools — and most businesses do — you need to know whether those vendors comply with the regulations that apply to you. Ask your software providers directly. Do they process EU personal data? Are they registered as providers under the EU AI Act? What documentation do they hold?
This matters because the Act assigns obligations to both providers (the companies that build AI systems) and deployers (businesses that use them). As a deployer, you're not off the hook just because someone else built the tool.
- Put an Incident Response Plan in Place What happens if an AI tool your business uses produces a harmful or discriminatory output? Who decides whether to stop using it? Who communicates with affected customers?
You don't need a 40-page document. A clear, short procedure that your named AI risk owner can follow is enough. Even a one-page outline is better than nothing.
These five steps form the core of what an AI readiness audit typically covers. If you're not sure where your business stands right now, that's a practical place to start.
How AI Advisers Can Help {#how-we-help} If you're based in Milton Keynes, Northampton, Bedford, Luton, or anywhere across the East Midlands, and you're not sure whether your current AI use is compliant — or even what tools you're actually running — that's a common starting point. You're not behind. You just need a clear picture.
AI Advisers works with SMEs to map their current AI use, identify gaps against UK and EU regulatory expectations, and put practical governance in place. No legal jargon, no consultant fees that assume you have a compliance team.
The barrier isn't technical knowledge anymore. It's knowing where to start.
Book a free initial conversation at aiadvisers.co.uk. No obligation, no sales pitch — just a clear picture of where you stand.
FAQs {#faqs} Does the EU AI Act apply to UK businesses after Brexit?
Yes, in many cases. The Act is extraterritorial. If your business has EU customers, processes data belonging to EU residents, or operates in the EU in any way, the Act applies to you. UK businesses with no EU exposure are not in scope.
What changed with the EU Digital Omnibus in May 2026?
The EU Digital Omnibus agreement, reached on 7 May 2026, extended some high-risk AI compliance deadlines to 2 December 2027 and 2 August 2028. Obligations that were already live — including the ban on prohibited AI practices and the AI literacy requirements — were not extended. Those have been enforceable since February 2025.
What is an AI literacy obligation and does my business need to comply?
The AI literacy obligation requires businesses to ensure that staff who work with AI tools have an appropriate level of understanding about those tools. It came into force in February 2025 under the EU AI Act. Even if you're not in scope of the EU Act, the UK's cross-sector AI principles expect responsible AI use, which includes staff awareness. Most SMEs can meet this with a short, practical training session.
What counts as a high-risk AI system for a small business?
High-risk systems include AI used in hiring and recruitment decisions, credit scoring, and access to essential services. If you use AI tools to screen CVs, rank job applicants, or make automated decisions that affect someone's employment or financial access, you may be operating a high-risk system. Full obligations for these systems have been extended to 2027 and 2028 for some categories, but documentation and oversight requirements still apply.
What are the fines for non-compliance with the EU AI Act?
Fines can reach EUR 35 million or 7% of global annual turnover, whichever is higher, for the most serious violations. Lower thresholds apply for other breaches. These are maximum figures — actual fines depend on the severity of the violation and the size of the business — but they're significant enough to take seriously.
My business only uses off-the-shelf software like a CRM or email tool. Does the Act still apply?
It can. Many standard business tools now include AI features. As a deployer — a business that uses AI tools rather than builds them — you carry obligations under the Act, including transparency requirements and, in some cases, oversight and documentation duties. The first step is knowing which tools you're using and what those tools actually do with your data.
Do I need a lawyer to comply with the EU AI Act?
Not necessarily, especially if your AI use sits in the limited-risk or minimal-risk categories. The five steps covered in this article — an AI register, a named risk owner, staff training, vendor due diligence, and an incident response plan — don't require legal expertise to put in place. A consultant who specialises in AI governance for SMEs can help you work through them practically and cost-effectively.

