Back to Blog
AI Ethics

EU AI Act Explained: What Businesses Must Do Before the August 2026 Deadline

/api/uploads/1783612476113-EU AI Act Explained.webp

The EU AI Act is entering its final compliance phase. Learn what it means for your business, key 2026 deadlines, risk categories, penalties, and the steps to take now.

Quick Overview

What it is

The world's first comprehensive law regulating artificial intelligence

Who it affects

Any business that builds, sells, or uses AI systems that reach people in the EU, including UK and US companies

Key deadline

Most obligations apply from 2 August 2026

Penalties

Up to €35 million or 7% of global annual turnover, whichever is higher

Main authority

The EU AI Office, alongside national regulators in each member state

Action needed now

Identify which AI systems you use, classify their risk level, and close governance gaps before enforcement begins

If your business builds, sells, or simply uses AI tools, and any part of that reaches customers or users in the European Union, a new set of rules is about to apply to you. It's called the EU AI Act, and it is the first law of its kind anywhere in the world, designed specifically to manage the risks of artificial intelligence rather than adapting older rules to fit it.

The Act has already been in force since August 2024, but 2026 is the year that matters most. This is when the bulk of its obligations become enforceable, and regulators across the EU are actively building the systems, guidance, and enforcement bodies needed to apply it. Businesses that wait until the deadline to start preparing are likely to find themselves scrambling.

This guide breaks down what the EU AI Act actually requires, who it applies to, the important dates you need on your calendar, and the practical steps you can take today to get ahead of it, in plain language, without the legal jargon.

What Is the EU AI Act?

The EU AI Act is a regulation, meaning it applies directly across all EU member states without needing to be separately passed into national law in each one. It was formally adopted by the European Parliament in March 2024, published in the EU's Official Journal in July 2024, and entered into force on 1 August 2024. From there, a transition period was built in to give businesses time to prepare, with different parts of the law taking effect in stages through to 2027.

The goal of the Act is to make sure AI systems used in the EU are safe, transparent, and respect people's fundamental rights, while still leaving room for innovation. Regulators point to real-world concerns like biased hiring algorithms, opaque credit scoring, and manipulative use of generative AI as the kind of harms the Act is designed to catch before they scale (European Commission, Shaping Europe's Digital Future).

Does It Apply to Businesses Outside the EU?

Yes, and this is the part that catches many non-EU businesses off guard. The AI Act works in a similar way to GDPR: it applies based on where your AI system's output or impact lands, not where your company is registered.

In practice, this means:

  • A UK or US company selling AI-powered software to EU customers is in scope.

  • A business using an AI model to generate reports, content, or decisions that affect people in the EU is in scope, even if no EU office or server is involved.

  • A chatbot on a non-EU company's website that EU users can access can bring that company within scope too.

Legal commentary on the Act notes that this broad, extraterritorial reach mirrors GDPR closely enough that companies already familiar with GDPR compliance will recognise the pattern immediately (Bird & Bird / Punter Southall Law FAQ).

The Four Risk Categories

The Act sorts AI systems into four tiers based on the level of risk they pose to people's safety and rights. Your obligations depend entirely on which tier your system falls into.

1. Unacceptable risk, banned outright

This includes things like social scoring systems, manipulative AI designed to distort behaviour, and real-time biometric identification in public spaces. These practices have been banned since 2 February 2025.

2. High risk, heavily regulated

This covers AI used in recruitment and HR decisions, credit scoring, insurance underwriting, education assessment, critical infrastructure, and law enforcement support. Providers must complete conformity assessments, maintain technical documentation, register the system in an EU database, and monitor it after launch.

3. Limited risk, transparency required

AI Tools like chatbots fall here. Users simply need to be told they're interacting with an AI system rather than a human.

4. Minimal risk, largely unregulated

Spam filters and AI-enabled video games are common examples. No specific obligations apply, though good practice still encourages transparency.

Key Dates to Know

The EU AI Act does not apply all at once. It rolls out in stages, and each stage brings a different set of obligations into force. Here is what each key date actually means for your business.

1 August 2024: The Act Enters Into Force

This is the date the EU AI Act was formally published and took legal effect. It marked the starting point of the transition period, giving businesses time to prepare before the main obligations became enforceable.

2 February 2025: Ban on Unacceptable-Risk AI Practices

From this date, AI practices classed as "unacceptable risk" became illegal across the EU. This includes social scoring systems, manipulative or exploitative AI, and real-time biometric identification in public spaces. Any business still using these practices is already in breach.

2 August 2025: Rules for General-Purpose AI (GPAI) Models

This date brought rules for general-purpose AI models, the kind of foundation models that power tools like chatbots and content generators, into force. Providers of these models must now maintain technical documentation, respect copyright rules, and publish a summary of the data used to train their models. This is also when EU member states were required to appoint their national competent authorities.

2 August 2026: Most Remaining Obligations Apply

This is the deadline that affects the largest number of businesses. From this date, the bulk of the high-risk system requirements take effect, including conformity assessments, quality management systems, technical documentation, and EU database registration. If your business has not started preparing yet, this is the date to work backwards from.

2 August 2027: Rules for AI in Regulated Products

The final stage of the rollout applies to AI systems embedded as safety components in products that are already regulated under separate EU product safety laws, such as medical devices or industrial machinery. These systems become subject to third-party conformity assessments from this date.

This staged rollout gives businesses time to prepare, but the window is closing. The 2 August 2026 deadline remains the one that will affect the largest number of organisations, since it covers the bulk of the high-risk category rules (Lexology summary of BDO's AI Act guide).

What Happens If You Don't Comply?

Penalties under the AI Act are steep and scale with the severity of the breach. For the most serious violations, such as deploying banned AI practices, fines can reach up to €35 million or 7% of a company's total global annual turnover, whichever amount is higher. Less severe breaches still carry meaningful financial penalties, alongside reputational damage that can be just as costly for businesses that rely on customer trust.

Who Enforces the AI Act?

Enforcement runs on two levels. At the EU level, the AI Office within the European Commission coordinates supervision of general-purpose AI models and works to keep enforcement consistent across the bloc. It also chairs a Cooperation Forum that meets regularly with enforcement bodies from each member state.

At the national level, every EU country is required to set up or designate its own competent authorities, typically a mix of central coordinating bodies and existing sector regulators. Ireland, for example, is establishing a new AI Office of Ireland to act as the main point of contact, while also relying on existing regulators such as the Central Bank and the Health Products Regulatory Authority to oversee AI use in their respective sectors. These bodies will have real powers, including the ability to demand documentation, conduct investigations, order corrective action, and issue fines.

Businesses can also get direct answers from regulators through the AI Act Service Desk, a support platform staffed by experts working alongside the AI Office. It's currently available in English, French, and German, with all 24 EU languages planned before the August 2026 deadline.

What Should Your Business Do Right Now?

Regulatory advisors are consistent in their advice here: don't wait for enforcement to begin before you start preparing. The practical first steps are:

Map your AI use

Build a full inventory of every AI system your business uses or provides, including third-party tools and embedded features you might not think of as "AI" day to day.

Classify the risk level

Work out where each system sits across the four risk tiers, since this determines what you actually need to do.

Identify your role

You could be a provider, a deployer, or both, and each role carries different obligations.

Close governance gaps

Look at your existing documentation, risk assessments, and internal processes, and align them with what the Act expects before the deadline arrives.

Get expert input early

Given the scale of potential fines and the complexity of cross-border rules, specialist legal or risk advisory support is worth the investment for any business with meaningful EU exposure.

Frequently Asked Questions

Does the EU AI Act apply to UK businesses?

Yes. If a UK company sells AI systems into the EU, deploys AI that affects people in the EU, or produces AI-generated output used in the EU, it falls within scope regardless of where the company is based.

When does the EU AI Act fully apply?

Most obligations take effect from 2 August 2026, with the final set of rules for AI in regulated products applying from 2 August 2027.

What are the maximum fines under the EU AI Act?

Up to €35 million or 7% of a company's global annual turnover, whichever is higher, for the most serious violations.

Is there a UK equivalent to the EU AI Act?

Not currently. The UK has taken a different, principles-based approach, relying on existing regulators like the ICO, FCA, and Ofcom to apply AI-related expectations within their own sectors, rather than introducing one single AI law.

Note: This article is intended as general guidance and reflects the regulatory position as of mid-2026. AI Act requirements and enforcement guidance continue to evolve, so businesses should confirm current obligations with a qualified legal or compliance advisor before making decisions.

Comments (0)

No comments yet. Be the first to share your thoughts!

Leave a Reply