The EU AI Act: what it means if you sell into Europe
The EU AI Act bans almost nothing a mid-sized company actually does with AI. It asks you to know what you use, to say so, and to keep a record. Here is what applies, when — and why it reaches you from Leeds or Bristol.
The dates, without commentary
Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages:
- 2 February 2025 — prohibited practices (social scoring, exploiting vulnerabilities, emotion recognition at work…) and an AI literacy duty for staff who use these systems.
- 2 August 2025 — obligations on providers of general-purpose models, and national authorities in place.
- 2 August 2026 — general application, including Annex III high-risk systems (employment, education, access to essential services, credit…).
- 2 August 2027 — high-risk systems embedded in already regulated products.
These dates are public and checkable. What needs an opinion is which box your use falls into — and that opinion comes from your counsel, not from us.
Why this reaches a UK business
The Act follows the market, not the postcode. If your system is used in the EU, or its output is used there, it is in scope — wherever your servers and your staff sit.
In practice, three situations bring it home: you sell software to EU customers; you run a service used by EU staff of a client; or you are in the supply chain of a company that must answer for its own compliance. The third arrives as a supplier questionnaire, usually with four weeks’ notice.
Most UK companies meet the AI Act not through a regulator, but through a customer’s procurement form.
Domestically the picture is different — the UK has taken a regulator-led approach rather than a single statute — but that does not remove the EU obligations when you serve EU users.
The three duties that touch almost everyone
Say it is a machine
A system that interacts with a person must make that clear, unless it is obvious. Generated content aimed at the public must be identifiable as such. That is a line in your interface and a mention on your pages — not an engineering project.
Train the people who use it
AI literacy has been required since February 2025. In practice: the people using the agent know what it does, what it does not do, and when they must check. Half a day done properly beats a ten-page policy.
Keep a record
Who triggered what, on which data, with which output. The log is not only a possible obligation: it is what lets you answer a customer, an employee or an auditor without reconstructing from memory.
What we do with it, concretely
Three questions are enough to frame a given system: does it decide something about a person? does it speak to a customer under your brand? does it touch a domain listed in Annex III?
If the answer is no to all three, the subject fits on one page. If it is yes to any of them, we do not start with that system — we open the one that raises no such question, and prepare the file for the other with your counsel.
It is also why three limits are written into every quote we issue: no automated rejection, no legal opinion, no publication without a named human review. They do not come from the Act — they simply make it easier to comply with.
- AI for legal teams — the limit we set on advice
- AI for healthcare — a sector where scope is decided first
- AI for manufacturing — the supplier questionnaire, where this usually lands
- The survey of your ten systems — free, delivered within 72 hours
Other notes
« What if it makes things up? » — getting an agent to cite its sources
A model produces a plausible sentence, not a true one. The four designs that make invention visible, and the single rule that matters: every claim points to its source.
Systems · 4 September 2026AI agent or plain automation: the £20,000 question
A third of the use cases brought to us need no model at all. How to tell a workflow from an agent, and why getting it wrong is expensive in both directions.
Systems · 2 September 2026Your document base, or why the agent answers beside the point
An agent is only worth what it can read. The four defects that produce answers beside the point — duplicates, undated versions, scanned PDFs, implicit context — and the preparation that fixes them.