Regulation
EU AI Act's High-Risk Rules Take Effect: What August 2026 Enforcement Means for UK Firms
London — Some AI Act deadlines slipped under the Digital Omnibus. The high-risk provisions did not. They are live now, and Brexit is not the exemption some UK boards assume.
By Laura Bennett · Economist & Contributing Author · Published
Last updated
The EU AI Act has been the subject of speculation and delay for long enough that it would be reasonable to assume its deadlines keep slipping indefinitely. They don't, entirely. This month, the Act's provisions covering high-risk AI systems became fully enforceable, which means any organisation — including UK businesses with no EU headquarters at all — deploying or supplying AI systems that touch the categories the Act defines as high-risk now needs to be able to demonstrate compliance, not just intend to get there eventually.
Brussels has, admittedly, been softening some of the Act's edges elsewhere. A separate package known as the Digital Omnibus has pushed back other AI Act deadlines by a year or more, a shift already covered by sister publication Czech Business Review in the context of what it means for Czech compliance timelines. It's worth being precise about what's actually happening here, because the two stories sit close together and are easy to conflate: some AI Act provisions have been delayed. The high-risk system rules are not among them. They are live, now, this month, and enforcement bodies have said as much clearly.
What counts as high-risk
"High-risk" under the Act isn't a vague category — it's defined reasonably specifically, and it's worth a UK business actually checking whether it applies rather than assuming the label belongs to someone else's industry. It covers AI systems used in employment decisions (recruitment screening, performance evaluation, promotion or termination decisions), credit scoring and access to essential financial services, biometric identification and categorisation, and systems touching critical infrastructure. If a UK company's AI-enabled HR software, credit-decisioning tool, or biometric access system is used by, or sold to, an organisation operating in the EU, that UK company is very plausibly inside the Act's reach — Brexit doesn't create the exemption some business leaders still assume it does.
Consultancies advising UK clients on AI deployment have a second layer of exposure worth flagging separately. A UK firm doing AI-strategy or AI-implementation work for a client with EU operations can find itself contractually and reputationally on the hook for whether the system it helped design meets high-risk obligations, even if the consultancy itself never touches EU soil. That's a genuinely new kind of professional exposure for an industry more used to worrying about the accuracy of its advice than the regulatory status of the systems that advice results in.
What to do now
Practically, there are a handful of concrete steps worth taking now rather than after a regulator asks about them. Data Protection Impact Assessments — already familiar to most UK organisations from GDPR — need extending specifically to cover AI systems that process personal data in a high-risk context, not treated as a box already ticked by existing GDPR paperwork. Audit trails documenting where and how AI is used across relevant systems need to exist and be retrievable, not reconstructed after the fact if a question arises. Contracts with suppliers and clients touching AI-enabled products should have liability terms that explicitly address AI-related failures, rather than relying on general professional-negligence language that predates the technology entirely. And any UK firm genuinely uncertain whether its systems fall into a high-risk category should treat that uncertainty as a reason to check, not a reason to assume they're in the clear.
Enforcement itself is being handled by a mix of national regulators across EU member states rather than a single central AI authority, which is its own source of complication for UK firms trying to work out exactly who they answer to. A UK company selling into multiple EU markets may, in practice, need to satisfy several different national regulators' interpretations of the same underlying rules, at least until enforcement practice settles into something more consistent across the bloc — which is unlikely to happen quickly given how new this phase of the Act's implementation actually is. Penalties for non-compliance with high-risk provisions are set at a level clearly intended to be taken seriously rather than treated as a cost of doing business, running into tens of millions of euros or a meaningful percentage of global turnover for the most serious breaches, whichever figure is higher.
Free newsletter
The British Business Brief
One email a week on UK business, regulation and capital: what moved, who paid for it, and what it means. No hype.
Two frameworks at once
All of this lands on UK businesses while the UK itself continues to take a different regulatory path entirely — there's still no single UK AI Act, and the government's approach remains the sector-by-sector model outlined in its regulation roadmap, covered previously on this site. That leaves UK firms with EU exposure navigating two philosophically different regulatory frameworks simultaneously: a principles-based, sector-specific UK approach, and a detailed, category-based EU one that just became considerably more binding. Firms operating only domestically can, for now, largely set the EU Act aside. Firms with any EU-facing AI system, client, or supply relationship increasingly can't.
