Book a call
By LegalEdge News

Does the EU AI Act apply to your business?


The EU AI Act is in force. Obligations are already live. More are coming. 

Our experienced in-house counsel, Claire Pattie and Alex Sumner, explain what you need to know, and what you need to do.

Does the EU AI Act apply to your business?

Probably, yes, even if you are a UK business with no EU office. The EU AI Act has broad extraterritorial reach; if you develop or sell AI to EU customers, or use AI tools that affect people in the EU, you’re likely in scope. The key question isn’t whether it applies, it’s what role you play, because that determines what you need to do.

Provider or Deployer?

“Providers” build and place AI systems on the market – they carry the heaviest obligations. “Deployers” use AI systems in a professional context – that’s now a lot of businesses. Deployer obligations are lighter, but they are still real. 

Watch out: if you substantially modify or rebrand a third-party AI tool, you can shift from deployer to provider, with a significant jump in responsibility.

The obligations break down into three timeframes: what’s binding today, what lands this summer, and what’s been pushed further out. Here’s how they stack up.

What’s Already in Force 

Prohibited practices. Certain uses of AI are banned outright. The full list of prohibited practices is broader than is often reported, and includes:

  • systems that manipulate people subliminally or exploit vulnerabilities to cause significant harm;
  • social scoring by public or private actors;
  • untargeted scraping of facial images to build recognition databases;
  • inferring emotions in workplace or educational settings (except for medical or safety reasons);
  • biometric categorisation to infer sensitive attributes such as race, political opinions, or sexual orientation;
  • predictive policing based solely on profiling or personality traits; and
  • real-time remote biometric identification in publicly accessible spaces.

If you are using AI in any of these ways, stop, and check what is permitted and what is not. 

AI literacy training. This is the obligation most businesses are underestimating, but is one that can and should be addressed now. Businesses must ensure staff and anyone involved in operating AI systems have an adequate level of AI literacy. In practice this means:

  • Training that covers the risks to the business, employees, customers, and anyone the AI is deployed on;
  • Role-based content – a one-size-fits-all doesn’t cut it i.e. HR needs different training to customer success;
  • Empowering staff to spot, solve, and escalate issues – this does not mean making them AI experts (and there is no requirement for anyone to actually use AI).

AI literacy should act as a practical risk management tool, not a tick-box.

What’s Coming Soon

Transparency Obligations. From 2 August 2026, businesses must:

  • tell users when they are interacting with an AI system (e.g. chatbots, virtual assistants);
  • label AI-generated content appropriately, including deepfakes and AI-generated material on matters of public interest;
  • ensure disclosures are clear and visible at the point of interaction – burying a note in your T&Cs won’t be sufficient.

If you’re using AI-facing tools with customers or employees, now is the time to audit your disclosure practices and make sure they’re fit for purpose. This is the area where a lot of businesses are investing time.

High-Risk AI: Deferred to December 2027, but Start Preparing Now

If your AI system falls into a high-risk category (such as recruitment, performance management, credit scoring, education, healthcare, law enforcement), there are more demanding obligations that will be placed on your business, particularly if you are the provider of the system, covering risk management systems, technical documentation, human oversight, conformity assessments, and registration in the EU database. This requires a genuine risk governance framework, not just a policy document.

The most demanding obligations (those applying to high-risk AI systems), have been deferred to 2 December 2027 for standalone systems (and 2 August 2028 for AI embedded in regulated products). This delay has now been formally agreed by the EU Council and Parliament as part of the EU’s Digital Omnibus package, with publication in the Official Journal expected shortly.

The deferral gives businesses more time to prepare. But being high-risk doesn’t mean you can ignore it.

The current challenge is that the EU Commission only published draft classification guidelines in May 2026, and final guidance hasn’t been issued yet. The December 2027 deferral was partly an acknowledgment of that. But don’t wait; at a minimum, map your AI systems now and identify what might be high-risk. You can start planning how you will build governance structures and be on top of new guidance as it is released.

Don’t Forget Data Protection Law

The EU AI Act isn’t the only framework in play. If your AI systems process personal data, and most do, data protection law applies in parallel, and in some areas it’s more restrictive.

The clearest example is automated decision-making.

Under EU GDPR Article 22, there is a general prohibition on decisions about individuals based solely on automated processing that produce legal or similarly significant effects – think hiring, credit, insurance and performance assessments. The exceptions are narrow, and meaningful human intervention is required.

The UK has diverged: the Data (Use and Access) Act 2025 has replaced the UK’s equivalent under the UK GDPR with a more permissive framework, allowing automated decisions on a wider range of lawful bases provided four safeguards are in place (including the right to request human review). However, this liberalisation applies only to significant automated decisions that do not involve special category data (such as health, biometric, or racial/ethnic origin data). For those categories, the stricter controls remain in place. 

If AI is influencing significant decisions about people, ask not just ‘does this comply with the EU AI Act?’ but ‘does this comply with data protection law?’ The gaps between the two frameworks are where real legal exposure lives.

Why It’s Hard Right Now

Getting to grips with the EU AI Act is genuinely difficult, and for legitimate reasons: final guidance on high-risk classification still hasn’t been issued; dates keep shifting; the Act cuts across legal, HR, IT and product with no obvious single owner; many businesses are still discovering what AI tools they actually use; and multiple legal frameworks apply simultaneously. None of that is an excuse to wait, but it is a reason to be systematic rather than panicked.

Where to Start

  1. Map your AI systems – what tools are you using, who built them, what are they being used for?
  2. Identify your role – provider, deployer, or both?
  3. Get your AI literacy training in place – it’s in force now and is the most actionable step you can take, with wider benefits for the business.
  4. Audit your transparency practices – ahead of the August 2026 deadline, review how you disclose AI use to customers and employees. This is the area where we are seeing more businesses seek specialist advice – if you haven’t considered transparency yet, this should be a business priority. 
  5. Check your automated decision-making – if AI influences significant decisions about individuals, review your position under both the EU AI Act and the applicable data protection law (remember, the UK and EU positions are now different).
  6. Flag potential high-risk systems – start identifying which tools might be high-risk and begin building governance structures.
  7. Build cross-functional ownership – this isn’t just a legal problem; get legal, HR, IT and product in the room together.

The EU AI Act is navigable. The businesses that struggle will be those that wait until deadlines are imminent. The ones that manage it well will be those that start now and treat it as an ongoing programme, not a one-off project.

If you need help mapping your AI systems, working out whether you are a provider or deployer, putting AI literacy training in place, auditing transparency disclosures, or assessing automated decision-making and high-risk AI, our team can help you turn the AI Act into a practical compliance plan. Get in touch at info@legaledge.co.uk.

Back To Blog Our Services
  • Share:

What do our clients think?