
The deadline moved. The other one didn't.
In the space of a week the EU deferred the AI Act's heaviest obligations to December 2027 — and brought its transparency rules into force. Most coverage reported the first half. Here's where the Act actually stands, and the short list of things a UK organisation should check now.
What applies, and when.
The AI Omnibus — Regulation (EU) 2026/1744, in force 27 July 2026 — deferred the high-risk regime. It did not touch the transparency obligations, which have applied since 2 August 2026 and are being enforced by national authorities.
Penalties for breaching the transparency obligations run to €15 million or 3% of worldwide annual turnover, whichever is higher.
If a person meets your AI, tell them.
The transparency obligations are far more widely applicable than the high-risk rules ever were. Annex III catches recruitment, credit scoring, education and essential services. Article 50 catches anyone who put a chatbot on their website.
If it generates content, mark it
If it reads emotion or biometrics, disclose it
Published text has an editorial carve-out
Two questions, honestly answered.
Post-Brexit the UK is a third country. That doesn't exempt you, but the test is narrower and more mechanical than the headlines suggest.
Do you place an AI system on the EU market?
Selling it, licensing it, or otherwise making it available to users in the EU makes you a provider, whatever your postcode.
Are the outputs used in the Union?
The Act reaches third countries — which the UK now is — where the output produced by the system is used in the EU. This is the limb that catches people: it asks where the answers land, not where the company is registered.
If both are no, you're out
A genuinely UK-only, internal-only deployment is not the regulator's problem. Plenty of the firms who ask us this question get exactly that answer, and we'd rather say so than sell you a programme.
Worth knowing what is not caught: a system has to be an AI system. Our own schools assessment scores against a fixed rubric with no model involved anywhere — it is software, not AI, and the Act has nothing to say about it. Plenty of what gets called AI internally is the same. The inventory is worth doing precisely because it shrinks the problem.
An afternoon, not a programme.
For the transparency obligations specifically, the work is small and the main risk is not knowing where your AI surfaces are.
Inventory the places a person meets AI
Website chat, phone triage, in-app assistants, automated replies. Usually shorter than feared and longer than expected.
Check each one discloses, before first contact
In the interface, in plain words — not in a privacy policy nobody opens.
Mark what you generate
Metadata on generated documents, images and audio where it's technically feasible. Proportionate, not gold-plated.
Name an owner and a review date
Models change, vendors change, and settings get flipped back. This is the step people skip.
We ran exactly this over our own estate and found a gap in our own chatbot. That's the honest argument for doing it: it catches ordinary, well-meaning setups, not just careless ones. If it's useful, the wider regime work sits in compliance and regulatory alignment, and stays current through Continuous Compliance.
This page is a plain-English summary written by a technology firm, not legal advice. Whether the Act applies to a particular workload is a question for your own advisers — we’re happy to do the technical groundwork that makes their answer a short one.
Not sure whether any of this reaches you?
A short scoping conversation usually settles it — including, often enough, telling you it doesn't apply and you can stop worrying about it.