EU AI Act Compliance

EU AI Act Compliance for UK Businesses — Milton Keynes

The EU AI Act is the world's first comprehensive AI regulation — and it applies to UK businesses that trade with Europe. Fines reach up to €35 million. We help you understand your obligations and build a clear path to compliance.

Plain-English guidance. No legal jargon. A practical roadmap your team can actually follow — from a Milton Keynes AI consultancy that works exclusively with small and medium-sized businesses.

Why EU AI Act Compliance Can't Wait

Four deadlines have already passed. Standalone high-risk system obligations — the ones most UK SMEs face — arrive in August 2027.

€35M

maximum fine for deploying prohibited AI systems — or 7% of global annual turnover

Source: EU AI Act, Article 99
Aug 2027

deadline for standalone high-risk AI compliance — recruitment, credit scoring, healthcare tools (Annex III)

Source: EU AI Act, Article 113
60%+

of SMBs using AI tools are unaware they may have high-risk compliance obligations

Source: European Commission

EU AI Act Timeline

The regulation is being phased in. Here's what applies when.

1 Aug 2024

EU AI Act entered into force

In effect

The regulation was published in the Official Journal of the EU and became binding law. The EU AI Office was simultaneously established as the central enforcement and coordination body.

2 Feb 2025

Prohibited AI practices banned

In effect

Chapter II prohibitions took effect. Unacceptable-risk systems — including social scoring, real-time biometric surveillance in public spaces, subliminal manipulation, and emotion recognition in workplaces — must be withdrawn or modified.

2 May 2025

GPAI Code of Practice finalised

In effect

The EU AI Office published the final General-Purpose AI Code of Practice. Providers of GPAI models (including LLMs) are expected to adhere to the Code as the primary compliance pathway for Chapter V obligations.

2 Aug 2025

GPAI model obligations apply

In effect

Chapter V rules for general-purpose AI models took full effect. Providers must maintain technical documentation, publish summaries of training data used, and — for systemic-risk models — conduct adversarial testing and report serious incidents to the AI Office.

2 Aug 2026

Annex I safety-component AI + transparency obligations

In effect

Compliance now required for AI safety components in regulated products (machinery, medical devices, vehicles). Article 50 transparency obligations also apply: AI-generated content — including deepfakes, synthetic audio, and AI-written text — must be labelled as machine-generated. Notified-body and market-surveillance rules are in effect.

2 Aug 2027

High-risk standalone AI systems must comply (Annex III)

Upcoming

The critical deadline for most UK SMEs. Full compliance required for standalone high-risk AI in recruitment, credit scoring, education, healthcare triage, and critical infrastructure. Legacy systems already deployed before August 2026 also have until this date.

The Four Risk Tiers Explained

The EU AI Act classifies every AI system into one of four risk categories. Your compliance obligations depend entirely on which tier your systems fall into.

Unacceptable Risk

AI systems that pose a clear threat to fundamental rights are prohibited outright.

Examples

  • Social scoring by governments
  • Real-time biometric surveillance in public spaces
  • Subliminal manipulation techniques
High Risk

Systems used in critical areas must meet strict requirements before deployment.

Examples

  • CV screening and recruitment tools
  • Credit scoring and loan decisions
  • Medical diagnosis and triage
  • Educational assessment tools
Limited Risk

Transparency obligations apply — users must know they are interacting with AI.

Examples

  • Chatbots and virtual assistants
  • AI-generated content
  • Emotion recognition systems
Minimal Risk

Most AI applications fall here. No mandatory obligations, but best practice is encouraged.

Examples

  • AI-powered spam filters
  • Recommendation engines
  • Inventory forecasting tools

Key Compliance Requirements

High-risk AI systems must meet six core requirements before deployment. We assess your readiness against each one.

Technical Documentation

High-risk AI systems must maintain detailed technical documentation covering design, development, and intended purpose.

Transparency & Explainability

Users must be informed when interacting with AI. High-risk systems must be explainable to affected individuals.

Human Oversight

High-risk systems must allow humans to monitor, intervene, and override AI decisions at all times.

Data Governance

Training, validation, and testing data must meet quality standards and be free from discriminatory bias.

Accuracy & Robustness

AI systems must achieve appropriate levels of accuracy and be resilient to errors, faults, and adversarial inputs.

Conformity Assessment

High-risk systems require a formal conformity assessment before market placement or deployment.

How We Help You Comply

A structured five-step process that takes you from uncertainty to documented compliance — in plain English, without the legal fees.

01

AI System Inventory

We map every AI system your business uses or plans to deploy — including third-party tools, SaaS platforms with embedded AI, and custom-built models.

Complete AI system register
02

Risk Classification

Each system is assessed against the EU AI Act's four-tier risk framework to determine your compliance obligations and exposure.

Risk classification report per system
03

Gap Analysis

We compare your current practices against the Act's requirements — covering technical documentation, human oversight, data governance, and transparency.

Compliance gap register with severity ratings
04

Remediation Planning

A prioritised action plan to close compliance gaps, with clear ownership, timelines, and estimated effort for each remediation task.

Prioritised remediation roadmap
05

Policy & Documentation

We help you create or update the required technical documentation, conformity assessments, and internal AI governance policies.

Compliance documentation templates
Client Example — UK Financial Services

From Compliance Panic to Documented Readiness in Four Weeks

A financial services firm based in the East Midlands came to us after their legal team flagged that their AI-powered credit assessment tool was almost certainly classified as high-risk under the EU AI Act. With the August 2027 Annex III deadline approaching, they had no documentation, no risk register, and no clear owner for AI governance.

Our compliance assessment confirmed the high-risk classification and identified three additional AI tools in use across their operations — a CV screening integration, an automated customer communications system, and an AI-assisted fraud detection module — none of which had been assessed for compliance.

Within four weeks we delivered a complete AI system register, risk classification for all four tools, a gap analysis against the Act's requirements, and a prioritised remediation roadmap. The firm's legal team described it as "the clearest compliance brief we've received on any regulation in five years."

4
AI systems identified and classified
4 wks
from scoping to full compliance report
0
compliance gaps left unaddressed

Frequently Asked Questions

Common questions about EU AI Act compliance for UK businesses.

Does the EU AI Act apply to UK businesses?

Yes. If your business deploys AI systems that affect EU citizens, or if you sell products or services into the EU market, the EU AI Act applies to you regardless of where your business is based. UK businesses trading with Europe must comply.

What are the fines for non-compliance?

Fines are tiered by violation type: up to €35 million or 7% of global annual turnover for prohibited AI practices; up to €15 million or 3% for other violations; up to €7.5 million or 1.5% for providing incorrect information to regulators. The EU AI Office coordinates enforcement across member states.

What is the EU AI Office and what does it do?

The EU AI Office was established in August 2024 as the central body responsible for overseeing the EU AI Act. It enforces rules for general-purpose AI models, coordinates national market surveillance authorities, maintains the EU AI database, and published the GPAI Code of Practice in May 2025. For UK businesses, the AI Office is the primary point of contact for GPAI model compliance.

What are the new transparency obligations that came into force in August 2026?

Under Article 50, any AI-generated content — including deepfake images and videos, synthetic audio, and AI-written text intended to appear human-authored — must be clearly labelled as machine-generated. Businesses using AI to create marketing content, customer communications, or media must ensure appropriate disclosure. This applies from 2 August 2026.

How do I know if my AI tools are high-risk?

High-risk AI includes systems used in recruitment, credit scoring, education, healthcare, critical infrastructure, law enforcement, and border control. Many off-the-shelf SaaS tools used in HR and finance fall into this category. If you are unsure, our risk classification assessment will give you a definitive answer.

We only use third-party AI tools — do we still need to comply?

Yes. The EU AI Act places obligations on both providers (who build AI) and deployers (who use AI in their business). If you use a high-risk AI system, you have compliance obligations even if you didn't build it. This includes SaaS platforms with embedded AI features.

How long does a compliance assessment take?

For most small businesses, our EU AI Act compliance assessment takes 3–4 weeks from initial scoping to final report. The timeline depends on the number of AI systems in use and the complexity of your operations.

What is the difference between the EU AI Act and GDPR?

GDPR governs personal data processing. The EU AI Act governs AI systems specifically — their development, deployment, and use. The two regulations overlap significantly, particularly around automated decision-making, and compliance with one does not guarantee compliance with the other.

Don't Wait Until August 2027

The Annex I safety-component deadline passed in August 2026. Standalone high-risk AI compliance (Annex III) — the obligation most UK SMEs face — arrives in August 2027. That's less than 12 months away. Book a free consultation now and we'll tell you exactly which obligations apply to your systems and what you need to do.

Serving businesses in Milton Keynes, across the UK, and those trading with the EU.