The EU AI Act entered a new phase on 2 August 2026. Scope for UK companies, what was deferred, what is live now, and who should own it.
Plenty of UK boards had 2 August 2026 in the diary as the day the EU AI Act's high-risk rules landed. The day arrived and the expected thing did not happen.
High-risk obligations were deferred. Something else took effect on exactly that date: transparency duties and the penalty regime. The second one reaches the AI most UK organisations are actually running today.
This article is not legal advice. It is written so the person in the meeting can ask a sharper question. If you need a compliance position, speak to counsel; what follows is the frame that makes that conversation shorter.
The deferral first. The European Parliament voted on 16 June 2026, the Council on 29 June. The text was published in the Official Journal on 24 July and entered into force on 27 July 2026 as Regulation (EU) 2026/1744, the Digital Omnibus on AI.
It pushed the high-risk timeline back:
Category | Previous date | New date |
Annex III standalone systems (recruitment, credit scoring, education, border control) | 2 August 2026 | 2 December 2027 |
Annex I product-embedded systems | 2 August 2027 | 2 August 2028 |
So risk management systems, conformity assessment, registration, data governance and human oversight now sit sixteen months further out.
What did not move is the part that touches customer-facing AI. From 2 August 2026 three things are live:
Article 50 transparency duties. If a person is interacting with an AI system, they have to be told. AI-generated or manipulated content has to be marked and machine-detectable.
Enforcement powers. The Commission's AI Office and member state authorities are now actively supervising. The Office holds direct powers over general-purpose AI models.
The penalty regime. Breaches of Article 50 carry a ceiling of 15 million euros or 3 per cent of total worldwide annual turnover, whichever is higher. Prohibited practices carry 35 million euros or 7 per cent.
One more date worth pencilling in: 2 December 2026 brings two new prohibited practices into force, both concerning the generation of realistic intimate imagery.
Article 2 sets the scope, and it was drafted the way GDPR was drafted. Leaving the single market did not take UK organisations out of reach.
Three triggers:
You are in scope if you place an AI system on the EU market, wherever you are established. Reaching an EU business or consumer through a website, an API or a distribution channel counts as placing it there.
You are in scope if you are a deployer established or located in the Union.
And the broadest one: you are in scope if the output of your system is used in the Union. The system can run in London, the data can sit in a UK region, the servers can never leave the country. If the output touches a decision, a process or a person inside the EU, the Regulation sees you.
No physical presence is required. For most UK organisations with EU customers, EU subsidiaries, EU-based staff or a European parent, that third trigger is the one that bites.
Providers of high-risk systems established outside the EU also have to appoint an authorised representative inside it. That sits in Article 22.
There is no UK AI Act. The UK made a deliberate choice to go the other way from Brussels: rather than one horizontal statute, existing regulators apply existing powers within their own remits.
In practice that means the ICO, Ofcom, the FCA, the CMA and the CQC, working on top of UK GDPR. A proposed AI Bill has been discussed, but as of mid-2026 the sectoral model is the operative reality rather than a comprehensive act.
That machinery has become noticeably more active through 2026. The ICO has issued AI-specific guidance. The Digital Regulation Cooperation Forum is consulting on AI risk-management tools until 2 September 2026. AI Growth Labs are putting regulators inside product testing, starting with legal services. In January 2026 Ofcom opened an investigation into an AI companion chatbot service, and a separate one concerning an AI chatbot on X.
So the honest summary for a UK board is this. At home you face sector-specific expectations rather than one rulebook. Abroad, if your output reaches the EU, you face the rulebook in full. Being lightly regulated in your own jurisdiction says nothing about your position in someone else's.
Article 50 reads abstract. Its footprint is not.
Customer service chatbots. If an EU customer is talking to your bot, they need to be told they are talking to a machine. Expecting them to work it out is not the standard.
AI-generated marketing content. Images, video or copy published into the EU need to be marked and detectable as artificially generated.
Screening and assessment tools. These fall under Annex III, so the heavy obligations moved to December 2027. The transparency side and the penalty regime apply now.
Internal tools built on general-purpose models. Supervision of the model provider is active today, which is reason enough to read your supplier contracts again.
None of these questions can be answered without an inventory. Which systems use AI, where the output goes, who owns each one. Most organisations do not have that list. The first step in a compliance programme is not reading the statute. It is seeing your own estate.
The most common cause of delay we see is not legal difficulty. It is an ownership gap.
Legal reads the text and does not know which systems are running. Technology knows the systems and not the obligations. The business unit waits for neither and stands up a tool.
Sixteen extra months does not fix that triangle. On an unowned topic, sixteen months is simply sixteen months of drift.
Where ownership does get established, the pattern is consistent. The topic enters the board agenda as a standing item rather than a one-off briefing, with an inventory behind it, a named decision-maker and a refresh rhythm. The rules are moving; the Omnibus is the proof.
Demand in this area concentrates in two formats. Short, decision-focused briefings for boards and executive teams. Longer sessions that put legal, technology and the business in the same room and produce a shared vocabulary. Neither is compliance consultancy. The point is to get the organisation to the stage where it can ask its own question properly.
If you need the groundwork first, our six-step AI literacy programme covers how organisations build that vocabulary, and leadership in the AI era covers the competencies this shift asks of senior teams.
2 August was not a finish line. It was a change of phase. The heavy obligations moved to 2027. The visible ones started working.
For a UK organisation the real question is not when Westminster legislates. It is where your output goes. That question can be answered this week, and the answer is not in the statute. It is in your own system inventory.
What to do now:
1. List the systems that use AI and answer one question for each: does the output touch a decision or a person inside the EU?
2. Check every customer-facing AI touchpoint for disclosure. Chatbots, generated content, automated replies.
3. Name an owner. Responsibility shared between legal, technology and the business is, in practice, responsibility held by nobody.
→ Enquire about an AI governance briefing for your board
---
It can. Article 2 sets three triggers: placing an AI system on the EU market, being a deployer established in the Union, and having the output of your system used in the Union. The third is the broadest. A system running entirely in the UK is still in scope if its output touches a decision inside the EU. Physical presence is not required.
What moved is the heavy machinery: risk management, conformity assessment, registration. Annex III systems now have until 2 December 2027. What did not move is Article 50 transparency and the penalty regime, both live since 2 August 2026. Customer-facing chatbots and AI-generated content are in scope today.
Breaches of the Article 50 transparency duties carry a ceiling of 15 million euros or 3 per cent of total worldwide annual turnover, whichever is higher. Prohibited practices carry 35 million euros or 7 per cent. These are maximums; actual enforcement is scaled to the nature of the breach.
No. The UK chose a sectoral route, asking existing regulators to apply existing powers. The ICO, Ofcom, the FCA, the CMA and the CQC operate on top of UK GDPR. An AI Bill has been under discussion, but as of mid-2026 the sectoral model is what applies in practice rather than a comprehensive statute.
No, they regulate different things. UK GDPR governs personal data processing. The AI Act governs the AI system itself, including uses that involve no personal data at all. There is overlap around automated decisions and human oversight, but GDPR compliance does not carry across.
With an inventory. Which processes use AI, where the output goes, who owns each system. Legal assessment cannot happen before that list exists, because there is nothing defined to assess. Once you have it, take it to counsel. This article is a frame for that conversation, not a substitute for it.