The EU AI Act in plain English

The world’s first comprehensive AI law. It is already in force and its obligations are arriving in stages.

The Act regulates AI according to risk.

A small number of practices are banned outright. Systems used in sensitive areas such as recruitment, credit decisions, education and critical infrastructure are classed as high-risk and carry the heaviest obligations. Chatbots and AI-generated content carry transparency duties.

Most mid-market organisations are not building AI.

They are deployers, using AI supplied by others. Deployers still have real obligations, and the first step for every one of them is knowing what AI they are using.

It isn’t only for EU companies.

A UK business is in scope if it places AI systems on the EU market, or if the output of its AI is used in the EU.

Key Dates

High-risk dates reflect the Digital Omnibus amendments agreed in 2026.

DateWhat appliesStatus
2 Feb 2025Prohibited AI practices banned. AI literacy duty for staff using AI.In force
2 Aug 2025Rules for general-purpose AI models. Penalty regime and national authorities in place.In force
2 Aug 2026Transparency obligations: telling people when they are dealing with AI, and labelling deepfakes and AI-generated content.In force
2 Dec 2027High-risk obligations for Annex III systems, such as AI used in recruitment, credit scoring, education and essential services.Upcoming
2 Aug 2028High-risk obligations for AI built into regulated products (Annex I), such as medical devices and machinery.Upcoming

What you’ll need to show

An inventory of the AI systems your organisation uses

A risk classification for each, and a named owner