What the EU AI Act Means for UK Compliance Teams in 2026
A practical guide to the AI Act's phased application, what UK-based deployers need to do before the August 2026 high-risk obligations kick in, and how to start your gap analysis without buying another tool.
The EU AI Act is now in force and its substantive obligations are landing on a phased timeline. By August 2026 the high-risk obligations (Annex III) and the GPAI (general-purpose AI) rules will apply — and UK-based deployers are not exempt, even though the UK is no longer in the EU.
This post is a practical, plain-English guide for UK compliance teams. It covers (1) the timeline, (2) whether the AI Act applies to you, (3) what you have to do before August 2026, and (4) how to start a gap analysis without buying another tool.
1. The phased timeline
The AI Act entered into force on 1 August 2024. The substantive obligations apply as follows:
- 2 February 2025 — banned practices (Article 5) and AI literacy obligations (Article 4) apply.
- 2 August 2025 — obligations on providers of GPAI models apply.
- 2 August 2026 — most of the remaining obligations, including the high-risk requirements in Annex III, apply.
- 2 August 2027 — the EU AI Act applies in full to systems embedded in safety components that are subject to third-party assessment under sectoral legislation.
2. Does the AI Act apply to UK-based deployers?
Yes, in three situations:
- The output of the AI system is used in the EU.
- Users of the AI system are in the EU.
- You are a provider of a GPAI model and your model is placed on the EU market, regardless of where you are based.
A UK fintech that uses an LLM to summarise contracts for EU-resident customers is in scope. A UK ad-tech company whose AI targets EU users is in scope. A UK-based model provider whose weights are downloaded by an EU customer is in scope.
3. What you have to do before August 2026
For high-risk systems, the substantive obligations are:
- Risk management system across the entire lifecycle (Article 9).
- Data governance — training, validation, and testing datasets must be relevant, representative, and free of errors (Article 10).
- Technical documentation per Annex IV before market placement (Article 11).
- Record-keeping — automatic logging of events over the lifecycle (Article 12).
- Transparency and instructions for use (Article 13).
- Human oversight (Article 14).
- Accuracy, robustness, and cybersecurity (Article 15).
- A quality management system (Article 17).
For deployers (organisations that use a high-risk system in their operations), the obligations are lighter but still real:
- Use the system in accordance with the instructions for use (Article 26).
- Maintain human oversight (Article 26(2)).
- Monitor the system for serious incidents and report them to the provider and the market surveillance authority (Article 26(5)).
- Conduct a fundamental-rights impact assessment for certain public-sector and essential-services uses (Article 27).
- Inform affected workers and their representatives before deploying a high-risk system in the workplace (Article 26(7)).
4. How to start a gap analysis
A gap analysis for the AI Act is materially different from a GDPR gap analysis. Three concrete steps:
- Inventory every AI system in production, including the model, the training data lineage, the provider, and the EU touchpoints. Use the team roster — every product team has at least one AI feature nobody told the compliance team about.
- For each system, classify it against the risk categories in Article 5 and Annex III. Most internal copilots and content-generation tools are limited-risk (transparency obligations only). Most HR, credit-scoring, and biometric systems are high-risk.
- For each high-risk system, build a single document that maps Article 9–15 obligations to your existing controls (ISO 27001, SOC 2, internal review board, etc.). The point is to find the gaps, not to repeat what you already do.
5. What to read next
- The AI Act itself: eur-lex.europa.eu (search for Regulation 2024/1689).
- The European AI Office's implementation pages: digital-strategy.ec.europa.eu.
- Our /frameworks/eu-ai-act page for a plain-English overview of the binding text.
About the author
Lexradar is built and operated by TITADE Ltd (UK Companies House 17106008). We write about regulatory change, compliance workflows, and the day-to-day of building a UK SaaS company.