The EU AI Act is the world's first comprehensive AI regulation — and it applies to UK businesses that trade with Europe. Fines reach up to €35 million. We help you understand your obligations and build a clear path to compliance.
Plain-English guidance. No legal jargon. A practical roadmap your team can actually follow — from a Milton Keynes AI consultancy that works exclusively with small and medium-sized businesses.
Four deadlines have already passed. Standalone high-risk system obligations — the ones most UK SMEs face — arrive in August 2027.
maximum fine for deploying prohibited AI systems — or 7% of global annual turnover
Source: EU AI Act, Article 99deadline for standalone high-risk AI compliance — recruitment, credit scoring, healthcare tools (Annex III)
Source: EU AI Act, Article 113of SMBs using AI tools are unaware they may have high-risk compliance obligations
Source: European CommissionThe regulation is being phased in. Here's what applies when.
The regulation was published in the Official Journal of the EU and became binding law. The EU AI Office was simultaneously established as the central enforcement and coordination body.
Chapter II prohibitions took effect. Unacceptable-risk systems — including social scoring, real-time biometric surveillance in public spaces, subliminal manipulation, and emotion recognition in workplaces — must be withdrawn or modified.
The EU AI Office published the final General-Purpose AI Code of Practice. Providers of GPAI models (including LLMs) are expected to adhere to the Code as the primary compliance pathway for Chapter V obligations.
Chapter V rules for general-purpose AI models took full effect. Providers must maintain technical documentation, publish summaries of training data used, and — for systemic-risk models — conduct adversarial testing and report serious incidents to the AI Office.
Compliance now required for AI safety components in regulated products (machinery, medical devices, vehicles). Article 50 transparency obligations also apply: AI-generated content — including deepfakes, synthetic audio, and AI-written text — must be labelled as machine-generated. Notified-body and market-surveillance rules are in effect.
The critical deadline for most UK SMEs. Full compliance required for standalone high-risk AI in recruitment, credit scoring, education, healthcare triage, and critical infrastructure. Legacy systems already deployed before August 2026 also have until this date.
The EU AI Act classifies every AI system into one of four risk categories. Your compliance obligations depend entirely on which tier your systems fall into.
AI systems that pose a clear threat to fundamental rights are prohibited outright.
Examples
Systems used in critical areas must meet strict requirements before deployment.
Examples
Transparency obligations apply — users must know they are interacting with AI.
Examples
Most AI applications fall here. No mandatory obligations, but best practice is encouraged.
Examples
High-risk AI systems must meet six core requirements before deployment. We assess your readiness against each one.
High-risk AI systems must maintain detailed technical documentation covering design, development, and intended purpose.
Users must be informed when interacting with AI. High-risk systems must be explainable to affected individuals.
High-risk systems must allow humans to monitor, intervene, and override AI decisions at all times.
Training, validation, and testing data must meet quality standards and be free from discriminatory bias.
AI systems must achieve appropriate levels of accuracy and be resilient to errors, faults, and adversarial inputs.
High-risk systems require a formal conformity assessment before market placement or deployment.
A structured five-step process that takes you from uncertainty to documented compliance — in plain English, without the legal fees.
We map every AI system your business uses or plans to deploy — including third-party tools, SaaS platforms with embedded AI, and custom-built models.
Each system is assessed against the EU AI Act's four-tier risk framework to determine your compliance obligations and exposure.
We compare your current practices against the Act's requirements — covering technical documentation, human oversight, data governance, and transparency.
A prioritised action plan to close compliance gaps, with clear ownership, timelines, and estimated effort for each remediation task.
We help you create or update the required technical documentation, conformity assessments, and internal AI governance policies.
A financial services firm based in the East Midlands came to us after their legal team flagged that their AI-powered credit assessment tool was almost certainly classified as high-risk under the EU AI Act. With the August 2027 Annex III deadline approaching, they had no documentation, no risk register, and no clear owner for AI governance.
Our compliance assessment confirmed the high-risk classification and identified three additional AI tools in use across their operations — a CV screening integration, an automated customer communications system, and an AI-assisted fraud detection module — none of which had been assessed for compliance.
Within four weeks we delivered a complete AI system register, risk classification for all four tools, a gap analysis against the Act's requirements, and a prioritised remediation roadmap. The firm's legal team described it as "the clearest compliance brief we've received on any regulation in five years."
Common questions about EU AI Act compliance for UK businesses.
Yes. If your business deploys AI systems that affect EU citizens, or if you sell products or services into the EU market, the EU AI Act applies to you regardless of where your business is based. UK businesses trading with Europe must comply.
Fines are tiered by violation type: up to €35 million or 7% of global annual turnover for prohibited AI practices; up to €15 million or 3% for other violations; up to €7.5 million or 1.5% for providing incorrect information to regulators. The EU AI Office coordinates enforcement across member states.
The EU AI Office was established in August 2024 as the central body responsible for overseeing the EU AI Act. It enforces rules for general-purpose AI models, coordinates national market surveillance authorities, maintains the EU AI database, and published the GPAI Code of Practice in May 2025. For UK businesses, the AI Office is the primary point of contact for GPAI model compliance.
Under Article 50, any AI-generated content — including deepfake images and videos, synthetic audio, and AI-written text intended to appear human-authored — must be clearly labelled as machine-generated. Businesses using AI to create marketing content, customer communications, or media must ensure appropriate disclosure. This applies from 2 August 2026.
High-risk AI includes systems used in recruitment, credit scoring, education, healthcare, critical infrastructure, law enforcement, and border control. Many off-the-shelf SaaS tools used in HR and finance fall into this category. If you are unsure, our risk classification assessment will give you a definitive answer.
Yes. The EU AI Act places obligations on both providers (who build AI) and deployers (who use AI in their business). If you use a high-risk AI system, you have compliance obligations even if you didn't build it. This includes SaaS platforms with embedded AI features.
For most small businesses, our EU AI Act compliance assessment takes 3–4 weeks from initial scoping to final report. The timeline depends on the number of AI systems in use and the complexity of your operations.
GDPR governs personal data processing. The EU AI Act governs AI systems specifically — their development, deployment, and use. The two regulations overlap significantly, particularly around automated decision-making, and compliance with one does not guarantee compliance with the other.
Related services
AI Readiness Audit →
Understand your AI maturity and compliance exposure before the deadline.
AI Governance Training →
Build internal capability to manage AI risk and regulatory obligations.
AI Literacy Training →
Equip your team to use AI responsibly and within compliance boundaries.
AIOS →
A compliant AI Operating System built and managed for your business.
The Annex I safety-component deadline passed in August 2026. Standalone high-risk AI compliance (Annex III) — the obligation most UK SMEs face — arrives in August 2027. That's less than 12 months away. Book a free consultation now and we'll tell you exactly which obligations apply to your systems and what you need to do.
Serving businesses in Milton Keynes, across the UK, and those trading with the EU.