Reviewed
Regulation (EU) 2024/1689
The Act reaches British practice through the market, not the border.
The EU AI Act (Regulation (EU) 2024/1689) applies according to where a system lands, not where its maker is registered. Enforcement began on 2 August 2026. This page sets out what is live, what is deferred, and the dates as they stand after the Digital Omnibus.
- Instrument
- Regulation (EU) 2024/1689
- In force
- 1 August 2024
- Enforcement from
- 2 August 2026
- Annex III high-risk
- 2 December 2027
- Annex I embedded
- 2 August 2028
- Maximum penalty
- €35M / 7%
Section I Scope
Establishment outside the Union is not an exemption.
Article 2 of the Regulation sets its territorial reach on two limbs. The first covers providers who place an artificial intelligence system on the Union market or put it into service in the Union, irrespective of where those providers are established. The second covers providers and deployers established in a third country where the output produced by the system is used in the Union.
A British consultancy building a screening tool for a client in Dublin engages the first limb. A British firm running a model in London whose scores are acted on in Frankfurt engages the second. Neither is a marginal case, and neither depends on having a European establishment.
Leaving the European Union ended the United Kingdom’s vote on this Regulation. It did not end the Regulation’s reach over British work sold into the single market.
The practical consequence is that the standard applied to a large part of British artificial intelligence practice is written and enforced elsewhere, and British professional bodies are not organised around it.
Where a high-risk system processes personal data, the General Data Protection Regulation continues to apply to the data-protection aspects, and the Act adds system-level requirements on top. The two are cumulative, not alternative.
Section II Timeline
The dates, as they stand.
The last two entries moved. The Digital Omnibus on artificial intelligence was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026, deferring the high-risk obligations.
-
Entry into force.
-
General provisions, the artificial intelligence literacy duty and the prohibitions apply.
-
Rules for general-purpose artificial intelligence apply. Governance structures and national penalty frameworks in place.
-
The majority of the rules are in force and enforcement starts. Article 50 transparency obligations apply.
Enforceable now
-
Further prohibitions apply, covering non-consensual sexual deepfakes and child sexual abuse material. Transitional deadline under Article 50(2) for synthetic-content systems already on the market.
-
Each Member State should have at least one artificial intelligence regulatory sandbox operational.
-
Obligations for high-risk systems listed in Annex III apply.
-
Obligations for high-risk systems embedded in regulated products under Annex I apply.
Section III What applies now
Article 50, in four duties.
The transparency obligations are the part of the Regulation most British practitioners will touch first, because they attach to ordinary generative and conversational systems rather than to a narrow high-risk list.
- Art. 50(1)
People are told they are dealing with a machine
A provider of a system intended to interact directly with natural persons must design it so those persons are informed they are interacting with an artificial intelligence system, unless that is obvious to a reasonably well-informed person in the circumstances.
- Art. 50(2)
Synthetic output is marked in machine-readable form
A provider of a system generating synthetic audio, image, video or text must mark the output so it is detectable as artificially generated or manipulated. Systems already on the market before 2 August 2026 have until 2 December 2026.
- Art. 50(3)
Emotion recognition and biometric categorisation are disclosed
A deployer of an emotion recognition system or a biometric categorisation system must inform the people exposed to it, and process personal data in accordance with data-protection law.
- Art. 50(4)
Deep fakes and published synthetic text are disclosed
A deployer generating or manipulating content that constitutes a deep fake must disclose that the content has been artificially generated or manipulated. Where artificially generated text is published to inform the public on matters of public interest, the same disclosure applies.
- Prohibited practices
- €35M / 7%
- High-risk breaches
- €15M / 3%
- Misleading authorities
- €7.5M / 1%
Or the stated percentage of worldwide annual turnover, whichever is higher. Penalties scale with severity, intent and the size of the undertaking.
Section IV Risk tiers
Four tiers, four sets of obligations.
The Regulation classifies every system by the risk it poses to health, safety and fundamental rights, and attaches obligations to the classification rather than to the technology.
- Unacceptable risk
- Practices prohibited outright. In force since 2 February 2025, with further prohibitions from 2 December 2026.
- High risk
- Systems listed in Annex III, and systems embedded as safety components in products regulated under Annex I. Conformity assessment, risk management, data governance, logging, human oversight and post-market monitoring.
- Transparency risk
- Systems that interact with people, generate synthetic content, recognise emotions or categorise biometrically. Governed by Article 50, enforceable now.
- Minimal risk
- Everything else. No obligations under the Regulation beyond the artificial intelligence literacy duty on providers and deployers.
Section V The United Kingdom position
Domestic rules moved the other way, which widens rather than closes the gap.
Section 80 of the Data (Use and Access) Act 2025 came into force on 5 February 2026, replacing Article 22 of the UK GDPR. The general prohibition on solely automated decision-making now applies only where the processing relies on special category data. Elsewhere, controllers may rely on legitimate interests, subject to safeguards.
So a practitioner selling into both markets is working to a domestic regime that has loosened and a European regime that has begun enforcing. The two now diverge on the exact point where artificial intelligence and personal data meet.
- ICO
- Information Commissioner’s Office
- FCA
- Financial Conduct Authority
- PRA
- Prudential Regulation Authority
- MHRA
- Medicines and Healthcare products Regulatory Agency
Section VI What membership adds
A professional affiliation inside the framework that governs the work.
AIPIA is an accredited member of the European AI Alliance and an accredited issuer of European Digital Credentials, the European Commission’s official credential format. Membership gives a practitioner in the United Kingdom guidance written for the European framework, a credential the Union verifies through its own infrastructure, and representation in the Commission’s stakeholder forum.
Membership of a professional association is not a compliance certification. It does not discharge an obligation under the Regulation, and no page on this site suggests otherwise. What it provides is standing, guidance and a verifiable record of competence.