Responsible AI

The EU AI Act: what it means if you sell into Europe

The EU AI Act bans almost nothing a mid-sized company actually does with AI. It asks you to know what you use, to say so, and to keep a record. Here is what applies, when — and why it reaches you from Leeds or Bristol.

8 September 20266 min readBy Sébastien Joumel
Deployer, not providerMost companies are « deployers » under the Act, not providers. The heaviest obligations are not aimed at them — but three of them are, and already.

The dates, without commentary

Regulation (EU) 2024/1689 entered into force on 1 August 2024 and applies in stages:

  • 2 February 2025 — prohibited practices (social scoring, exploiting vulnerabilities, emotion recognition at work…) and an AI literacy duty for staff who use these systems.
  • 2 August 2025 — obligations on providers of general-purpose models, and national authorities in place.
  • 2 August 2026 — general application, including Annex III high-risk systems (employment, education, access to essential services, credit…).
  • 2 August 2027 — high-risk systems embedded in already regulated products.

These dates are public and checkable. What needs an opinion is which box your use falls into — and that opinion comes from your counsel, not from us.

Why this reaches a UK business

The Act follows the market, not the postcode. If your system is used in the EU, or its output is used there, it is in scope — wherever your servers and your staff sit.

In practice, three situations bring it home: you sell software to EU customers; you run a service used by EU staff of a client; or you are in the supply chain of a company that must answer for its own compliance. The third arrives as a supplier questionnaire, usually with four weeks’ notice.

Most UK companies meet the AI Act not through a regulator, but through a customer’s procurement form.

Domestically the picture is different — the UK has taken a regulator-led approach rather than a single statute — but that does not remove the EU obligations when you serve EU users.

The three duties that touch almost everyone

Say it is a machine

A system that interacts with a person must make that clear, unless it is obvious. Generated content aimed at the public must be identifiable as such. That is a line in your interface and a mention on your pages — not an engineering project.

Train the people who use it

AI literacy has been required since February 2025. In practice: the people using the agent know what it does, what it does not do, and when they must check. Half a day done properly beats a ten-page policy.

Keep a record

Who triggered what, on which data, with which output. The log is not only a possible obligation: it is what lets you answer a customer, an employee or an auditor without reconstructing from memory.

What we do with it, concretely

Three questions are enough to frame a given system: does it decide something about a person? does it speak to a customer under your brand? does it touch a domain listed in Annex III?

If the answer is no to all three, the subject fits on one page. If it is yes to any of them, we do not start with that system — we open the one that raises no such question, and prepare the file for the other with your counsel.

It is also why three limits are written into every quote we issue: no automated rejection, no legal opinion, no publication without a named human review. They do not come from the Act — they simply make it easier to comply with.

Read on the site

Other notes

All notes →

First call — fifteen minutes

We will tell you which system to open first.

Describe the task that costs you the most. We will tell you what is feasible, how long it takes and what it costs. If the answer is no, you will leave with the two reasons why.