EU AI Act 2026: What UK Businesses Need to Know and Do Now

EU AI Act 2026: What UK Businesses Need to Know and Do Now
Last updated: August 2026

The EU AI Act has reached one of its most important implementation points.

On 2 August 2026, the majority of applicable rules reached their main application milestone. Article 50 transparency requirements also started to apply, and enforcement began for applicable rules at both EU and national level.

Just days earlier, on 27 July 2026, the Digital Omnibus on AI entered into force. It changed parts of the original timetable, simplified some requirements and extended deadlines for high-risk AI systems. Rules covering high-risk systems listed in Annex III are now due to apply from 2 December 2027, while requirements for certain high-risk AI systems embedded in regulated products covered by Annex I are due to apply from 2 August 2028.

For businesses, this means the EU AI Act is no longer something to prepare for at some point in the future. Some requirements are already in force, enforcement has started, and organisations need to understand which parts of the Act apply to the AI systems they use, provide or develop.

For UK businesses, there is another important point.

Being outside the EU does not necessarily mean being outside the scope of the EU AI Act.

What does the EU AI Act mean for UK organisations?

The EU AI Act has reach beyond organisations established within the EU. Under Article 2, it can apply to providers placing AI systems or general-purpose AI models on the EU market, regardless of whether the provider itself is based in the EU or in another country. It can also apply to providers and deployers established outside the EU where the output produced by an AI system is used within the EU.

For a UK organisation, that could include a technology company providing an AI system to customers in the EU. It could also include a business operating AI outside the EU where the output is then used by an EU office, employee, client or operation.

Using AI solely within a UK business does not, on that fact alone, automatically bring the organisation within the EU AI Act. But UK data protection law and other sector or professional rules may still apply. The ICO continues to provide specific guidance for organisations developing and using AI that processes personal information.

The practical point is simple: Do not assess EU AI Act exposure only at company level. Assess the individual AI systems and use cases. Where is the system provided? Who uses it? Where is its output used? What role does your organisation play?

Those questions can lead to very different answers across the same business.

What changed in August 2026?

The EU AI Act entered into force on 1 August 2024, but its requirements have been introduced in stages. Prohibited practices, definitions and AI literacy provisions began applying from 2 February 2025. Rules covering general-purpose AI models and EU governance followed from 2 August 2025.

On 2 August 2026, the Act reached its largest implementation milestone so far.

The majority of rules became applicable. Article 50 transparency requirements came into effect. Enforcement also started for applicable provisions covering areas including prohibited practices, general-purpose AI models, transparency and AI literacy.

However, one important change happened immediately before this date. The Digital Omnibus on AI entered into force on 27 July 2026. Among other changes, it extended the deadlines applying to high-risk AI. Annex III high-risk systems now move to 2 December 2027, while certain AI embedded within products covered by Annex I moves to 2 August 2028.

This matters because older articles, internal compliance plans and AI Act summaries may still refer to the original deadlines. Businesses should make sure they are working from the current timetable, not a version prepared before the July 2026 amendments.

Source

Does the EU AI Act apply to your business?

There is no useful company-wide answer to this question without first understanding how your organisation uses AI. One AI tool may sit outside the stricter requirements of the Act. Another system used by the same organisation could have transparency requirements. A third could fall into a high-risk category because of the purpose for which it is being used.

The EU AI Act uses a risk-based framework, with requirements varying according to the type of system, its intended purpose, how it is used and the organisation's role in relation to it. The Act includes prohibited uses, high-risk systems and specific transparency requirements, alongside many systems that do not fall within its stricter categories.

That means that thestarting point should be: “What AI are we using, how are we using it and which rules apply to each use case?”

Start with an AI audit

Before deciding what needs to change, you need a clear picture of what is already happening. For many organisations, this may be more difficult than expected. AI is no longer limited to standalone tools bought by IT teams. AI capabilities can be built into existing platforms and software, while individual teams may be experimenting with additional tools independently.

Create an inventory of significant AI systems across the organisation. For each system, understand its purpose, who uses it, which business process it supports, what data it accesses, where it operates and where its outputs are used.

You should also establish your role.

The EU AI Act distinguishes between providers, deployers, importers, distributors and other operators. Different responsibilities can apply depending on that role. A business using an AI system supplied by another company may have different responsibilities from a business developing an AI product and placing it on the EU market. Without this initial view, it is difficult to make sensible decisions about risk, compliance or governance.

Understand the risk level

Once you know what AI is being used, assess the risk associated with each important system or use case. Some practices are prohibited under the AI Act. Others can be treated as high-risk because of their intended use and potential impact on safety or fundamental rights.

Annex III includes certain AI uses in areas such as employment and recruitment, education, biometrics, essential services, law enforcement and migration. The rules for these Annex III high-risk systems are now due to apply from 2 December 2027 following the Digital Omnibus.

This does not mean that every use of AI in these areas is automatically high-risk. Classification needs to be assessed against the Act's criteria and the intended use of the particular system. For businesses, this is another reason to avoid broad labels such as “our HR AI” or “our customer service AI”.

The use case matters.

An AI assistant that helps an employee rewrite an internal email is very different from a system used to analyse job applications and rank candidates.

Review your transparency requirements

Transparency is one of the areas where requirements are already applicable.

Article 50 has applied since 2 August 2026 and creates requirements covering certain interactive AI systems and AI-generated or manipulated content.

For example, providers of certain directly interactive AI systems need to ensure people are informed when they are interacting with AI. Providers also have requirements relating to machine-readable marking of certain synthetic content.

Deployers can have separate disclosure requirements covering areas including deepfakes, emotion-recognition systems, biometric categorisation and certain AI-generated text on matters of public interest. Exceptions and more detailed conditions apply.

For organisations using customer-facing or employee-facing AI, this means transparency should be reviewed as part of the design of the experience, rather than added at the end.

Ask whether users understand when AI is involved, whether content needs to be identified as AI-generated and whether current notices and interfaces meet the relevant requirements.

Understand what happens to your data

AI governance cannot be separated from data governance. For UK organisations processing personal information through AI, UK data protection law remains relevant. ICO guidance covers areas including accountability, transparency, lawfulness, fairness, accuracy, security, data minimisation and individual rights.

Start with the data entering your AI systems.

  • What personal information is included?
  • Is confidential or commercially sensitive information being uploaded?
  • Where is that information processed?
  • Is it stored? Can it be used by a supplier for training?
  • Who can access it?

For professional services organisations, the questions can go further.

Client confidentiality, privileged information, professional duties and contractual responsibilities may all need to be considered alongside data protection law.

This is why a general policy saying “employees can use approved AI” is not enough. Organisations need rules that reflect the types of information their people actually work with and the risks attached to those activities.

Review your AI suppliers

Many organisations will use AI through third-party suppliers rather than building models themselves.

That does not remove the need for due diligence.

Understand which models are being used, where information is processed, whether data is retained or used for training, which sub-processors are involved, how security is managed and what happens when the supplier changes its model or service. The ICO's specific contracts and third parties guidance for AI covers supplier and contractual controls.

You should also understand the contractual relationship and which responsibilities sit with the supplier and which remain with your organisation.

For important systems, supplier reviews should not be treated as a one-off purchasing exercise. AI products can change rapidly. New models, features, integrations and data practices can alter the risk profile of a system after it has been introduced.

Governance therefore needs to cover both initial approval and ongoing review.

Put clear ownership around AI

Someone needs to know who is responsible. Establish clear responsibility for decisions around AI strategy, approval, data, security, legal risk, suppliers, monitoring and incidents. The ICO's governance and accountability in AI guidance addresses organisational responsibilities, governance and oversight for AI processing personal information.

The right model will vary by organisation. In some businesses, responsibility may sit across technology, legal, risk and operational teams. In others, an existing governance group may be able to take responsibility for AI.

What matters is that ownership is clear.

  • If a new AI tool appears in the business, who decides whether it is approved?
  • If client information is being entered into it, who reviews the data risk?
  • If the supplier changes its terms, who checks them?
  • If an AI-generated output causes a problem, who owns the response?

These are operational questions, not theoretical governance exercises.

Build practical AI literacy

AI literacy is also part of the Act.

Article 4 applies to providers and deployers of AI systems and requires them to take measures supporting the development of AI literacy among staff and other people operating AI on their behalf. The 2026 amendments make the requirement more flexible. There is no single mandated level of AI literacy that every individual has to achieve. Organisations should consider factors such as people's knowledge, experience, training and the context in which AI is used.

That makes a one-size-fits-all training session a weak response.

Someone using an approved AI assistant for basic administrative work does not need the same knowledge as someone designing an AI-supported recruitment process, handling client data or overseeing a high-risk system.

AI literacy should reflect people's roles.

Teams need to understand which tools they can use, what information they can share, where human review is required, what AI can get wrong and when concerns should be escalated. For organisations deploying high-risk AI systems, specific human oversight training requirements can also apply.

The aim is not to turn every employee into an AI specialist. It is to make sure people understand enough to use the systems available to them responsibly.

The EU AI Act should not stop AI innovation

There is a risk that organisations respond to regulation by becoming more cautious about AI altogether.

That would miss the point.

Good governance should help a business understand where it can use AI confidently, not simply where it cannot.

If you know which systems you are using, what data they access, which risks matter, who is responsible and where human oversight is required, you are in a much stronger position to make decisions about AI investment.

At Calls9, this is how we approach AI adoption through AI Fast Lane. We start by understanding the organisation, its existing AI use, challenges and opportunities. That includes considering risks, data, regulation, security and governance alongside the business case for AI. From there, organisations can prioritise the right use cases, create their strategy and move into building, testing and improving AI solutions.

*This article provides general information and is not legal advice. The requirements that apply will depend on the specific AI system, your organisation's role, how and where the system is used and any sector-specific duties. Check current official guidance and seek specialist advice where required.

* This articles' cover image is generated by AI