If you heard that the EU AI Act's deadline got pushed back and breathed a sigh of relief, hold that thought. The headline date for high-risk AI systems did move, from 2 August 2026 to 2 December 2027. But the rules that will touch the largest number of UK businesses, the transparency duties and general-purpose AI enforcement, still start on 2 August 2026 as originally planned. And yes, this reaches UK organisations even though we're outside the EU.

What is the EU AI Act Digital Omnibus?

The change comes from the Digital Omnibus on AI, formally Regulation (EU) 2026/1744, which amends the original EU AI Act (Regulation (EU) 2024/1689). It was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, six days before the original deadline would have landed. It is now settled law, not a proposal still in negotiation.

The Digital Omnibus on AI is the first substantive amendment to the EU AI Act since it took effect in 2024. It defers the compliance deadline for high-risk AI systems by roughly sixteen months, adds two new prohibited practices, and hands the EU AI Office wider supervisory powers, while leaving the Act's transparency rules and general-purpose AI provisions untouched.

What it delayed is the heaviest part of the Act: risk management systems, technical documentation, conformity assessment, human oversight and post-market monitoring for high-risk AI. What it left completely alone is everything to do with transparency and general-purpose AI models. That distinction matters more than the headline suggests, because most UK businesses using AI commercially will hit the second category long before they ever reach the first.

Does the EU AI Act even apply to UK businesses?

This is usually the first question in the room, and the answer catches people out. Brexit does not exempt UK organisations from the EU AI Act. The Act works on the same principle as GDPR: it follows the market and the data, not the address on your certificate of incorporation.

You are in scope if any of the following is true:

  • You place an AI system on the EU market, as a provider, regardless of where your company is based.
  • You use an AI system whose output affects people in the EU, which makes you a deployer even if you never touch EU soil.
  • Your AI-enabled software, chatbot, or SaaS product has EU customers, employees, or users.

A UK consultancy selling an AI-powered analytics tool to a client in Dublin is in scope. So is a UK retailer running a customer service chatbot that EU shoppers can use, or a UK recruitment platform processing applications from candidates in Germany. “We're a UK business, this is an EU problem” is the single most expensive misreading of this regulation, and it's the same misreading that caught plenty of UK businesses out with GDPR a decade ago.

What still applies from 2 August 2026?

Two things go live on schedule, and between them they reach far more organisations than the high-risk rules ever will.

Article 50 transparency obligations become enforceable. This is four separate duties, and they don't all fall on the same people:

  • Chatbot and assistant disclosure. If a system talks to people, they need to be told upfront that they're dealing with a machine, not buried in the terms and conditions. This extends to agentic AI acting on a user's behalf.
  • Synthetic content marking. AI-generated or AI-edited text, images, audio and video need a machine-readable marker so other platforms can detect they're synthetic.
  • Emotion recognition and biometric categorisation disclosure. Deploy either of these, and the people subject to it must be told.
  • Deepfake and public-interest content labelling. Content realistic enough to pass as genuine needs a label, even without intent to deceive. AI-written text on matters of public interest needs a flag too, unless a human has genuinely edited it and takes ownership of the result. A light touch-up does not clear that bar.

You carry these obligations whether you built the AI system yourself or bought it from a vendor. If the vendor's platform doesn't handle the disclosure for you, the legal responsibility still sits with you.

GPAI enforcement goes live. The EU AI Office gains active supervisory and fining powers over general-purpose AI models, and national market surveillance authorities across all 27 member states can begin investigating and issuing penalties.

Fines for breaching Article 50 or the high-risk rules run up to €15 million or 3% of global annual turnover, whichever is higher. Breach one of the prohibited practices, and the ceiling rises to €35 million or 7% of global turnover. Article 50 and high-risk breaches are enforced by the national market surveillance authority in whichever member state your customers or users are located. General-purpose AI models sit under a different regulator entirely: the EU AI Office holds exclusive supervisory authority there, at Commission level. Either way, a UK business can end up answering to a regulator it has never directly dealt with.

What moved to 2027 and 2028?

Does the delay mean UK businesses can slow down?

It's tempting to read a sixteen-month extension as permission to slow down. That reading misses two things.

First, the deferral exists because the infrastructure businesses need to comply, harmonised technical standards, notified-body capacity, detailed regulatory guidance, wasn't ready in time. That's a comment on how substantial this work is, not a reason to treat it as optional. A defensible risk management system, full technical documentation and post-market monitoring aren't things you build in a single sprint before a deadline.

Second, nothing about the underlying obligations has softened. The risk tiers and classification logic are unchanged. Systems already classified as not high-risk still carry a registration step, with lighter paperwork but the same underlying assessment behind it. “Not high-risk” was never the same as “nothing to do.”

This is the gap between design-time and runtime governance, a distinction that sits at the centre of any credible enterprise AI governance framework. A policy document or a risk register nobody's touched since Q1 ticks the design-time box. It says nothing about whether your organisation can produce audit-grade evidence when a regulator asks or catch a system drifting out of compliance once it's live. The Digital Omnibus has bought UK enterprises time. It hasn't bought the governance infrastructure to use that time well. That still must be built.

One more point worth being direct about: a management system standard like ISO/IEC 42001 is genuinely useful groundwork, and neither it nor the NIST AI RMF substitutes for the Act's per-system conformity assessment, CE marking, or EU database registration. These frameworks give you a running start on the parts of governance that transfer across regimes. They don't complete your regulatory obligations for you.

What should UK enterprise leaders do now?

  1. Establish your AI inventory now, not in 2027. You cannot classify what you haven't found. Shadow AI, tools adopted by teams without procurement or IT sign-off, is the most common blind spot.
  1. Map your Article 50 exposure this quarter. Any customer-facing chatbot, content-generation tool, or biometric feature needs a disclosure plan before August.
  1. Confirm your role under the Act for each system. Provider, deployer, importer or distributor. The obligations differ, and you can be more than one role across different systems.
  1. Use the extended high-risk timeline to build evidence infrastructure, not to wait. A governance programme that only exists as a policy document will not survive a conformity assessment or a regulator's questions.
  1. Treat ISO/IEC 42001 as your foundation, not your finish line. It gives you a structured, auditable management system that maps cleanly onto both EU AI Act evidence requirements and UK regulatory expectations from the ICO and FCA. It does not replace system-specific conformity assessment where that applies.

Frequently asked questions

Has the EU AI Act deadline been delayed?

Partly. The Digital Omnibus, in force since 27 July 2026, pushed the high-risk deadline back, standalone Annex III systems to 2 December 2027 and embedded Annex I systems to 2 August 2028. Article 50 transparency rules and general-purpose AI enforcement still start on 2 August 2026 as originally planned.

Does the EU AI Act apply to UK businesses after Brexit?

Yes. The Act has extraterritorial reach, similar to GDPR. If you place an AI system on the EU market, or its output is used by people in the EU, you're in scope regardless of where your company is registered.

What are the Article 50 transparency obligations?

Four disclosure duties: telling users when they're interacting with a chatbot, marking AI-generated content in machine-readable form, notifying people subject to emotion recognition or biometric categorisation, and labelling deepfakes and AI-written public-interest content. They apply to providers and deployers from 2 August 2026.

What happened to the high-risk AI system deadline?

It moved from 2 August 2026 to 2 December 2027 for standalone high-risk systems under Annex III, and to 2 August 2028 for AI embedded in already-regulated products under Annex I.

Is ISO 42001 enough for EU AI Act compliance?

No. ISO/IEC 42001 provides a strong, auditable governance foundation and maps well onto the Act's evidence requirements, but it doesn't replace the Act's per-system conformity assessment, CE marking or EU database registration where those apply.

What are the penalties for non-compliance?

Up to €35 million or 7% of global annual turnover for prohibited practices, whichever is higher. Up to €15 million or 3% of global turnover for high-risk and transparency breaches. National market surveillance authorities in any of the 27 member states can enforce, alongside the EU AI Office for general-purpose AI models.

Do UK-only businesses need to worry about this at all?

If you have no EU customers, users, or data subjects whose outcomes your AI affects, your primary obligations sit with the UK's own regulators (ICO, FCA and sector bodies) rather than the EU AI Act. Many UK enterprises assume this applies to them without checking, and it's worth confirming rather than assuming.

What should we do differently now that the deadline has moved?

Treat the extra time as room to build proper governance infrastructure, an AI inventory, role classification, and audit-ready evidence, rather than as a reason to delay. The businesses that use this window well will be ready ahead of December 2027. The ones that wait will be doing sixteen months of work in the final quarter.

This article reflects the regulatory position as of 14 August 2026 and will be reviewed quarterly. It is provided for general information and does not constitute legal advice. For your organisation's specific obligations under the EU AI Act, take advice from qualified counsel.

How Aligne helps: We work with UK enterprises to close the gap between AI governance on paper and AI governance that survives an audit, from ISO/IEC 42001 readiness through to design-time and runtime controls for systems already in production. If you're mapping your Article 50 exposure or building your AI inventory, we can help you get a defensible programme in place.

Blog

Our latest news

Stay Informed: Engage with our Blog for Expert Analysis, Industry Updates, and Insider Perspectives

All Posts
Services Image
EU AI Act Deadline 2026: What Changed for UK Businesses
If you heard that the EU AI Act’s deadline got pushed back and breathed a sigh of relief, hold that thought. The headline date for high-risk AI systems did move, from 2 August 2026 to 2 December 2027. But...
Read Details
Services Image
Enterprise AI Governance: The Complete Guide for UK Enterprise Leaders (2026)
This complete guide to Enterprise AI Governance covers why it matters now, what the regulatory landscape requires in the UK, EU and US, which frameworks to adopt, how to build an operating model that works in practice, and how ...
Read Details
Services Image
ISO 42001 and the Evidence Problem: Why Good Intentions Don't Survive an Audit
ISO/IEC 42001 is the first international standard for AI management systems, and its real value is that it forces an organisation to turn good intentions about AI governance into evidence that can survive an audit, a regulator's query, or an enterprise buyer's due diligence...
Read Details

Ready to Take the First Step?

let’s design the governance framework your AI strategy deserves

Thank you! Your submission has been received!
Oops! Something went wrong while submitting the form.
bg elementbg elementLet's Talk