EU AI Act High-Risk Rules Are Now Law: What UK Businesses Must Do to Avoid a Fine
EU AI Act Articles 9-17 became enforceable on 2 August 2026. UK businesses aren’t exempt. Here’s what high-risk AI means, who’s in scope, and what the penalties
On 2 August 2026, the EU AI Act crossed its most significant milestone yet. The core provisions that actually govern how businesses must handle AI — Articles 9 through 17, covering high-risk AI systems — became legally enforceable. Penalties can reach 3% of global annual turnover. And UK businesses are not exempt, regardless of Brexit.
This is the moment the EU AI Act stopped being something compliance teams tracked from a safe distance and became something with real teeth. If your business deploys AI in recruitment, credit decisions, insurance underwriting, healthcare triage, or education assessment — and if any of your customers or users are based in the EU — those rules now apply to you.
When I first started tracking the EU AI Act back in 2023, the enforcement date felt comfortably abstract. Now it’s here. The businesses that spent the last 18 months preparing are in reasonable shape. The ones that assumed it wouldn’t apply to them, or that Brexit insulated UK companies, are in trouble.
What Actually Became Enforceable on 2 August 2026?
The EU AI Act is phased legislation. Not all of it kicked in at once. The first provisions — banning outright prohibited AI practices like real-time biometric surveillance in public spaces — became applicable in February 2025. General-purpose AI (GPAI) model obligations began applying from August 2025.
2 August 2026 is the main application date. Articles 9–17 (provider obligations for high-risk AI systems) and Article 26 (deployer obligations) are now fully in force. These cover:
- Risk management systems that must be established, documented, and maintained
- Technical documentation requirements, including data governance records
- Logging and audit trail requirements for high-risk AI outputs
- Transparency obligations — users must know when they’re interacting with high-risk AI
- Human oversight requirements — a person must be able to override, stop, or query AI decisions
- Accuracy, robustness, and cybersecurity standards
- Conformity assessments, CE marking, and EU AI database registration
That last point is worth dwelling on. CE marking for AI systems. It’s the same concept as CE marking on a physical product — proof that it meets EU safety standards. Except in this case, it’s your recruitment algorithm or your credit scoring model that needs to be certified.
What Counts as a High-Risk AI System?
The EU AI Act defines “high-risk” precisely in Annex III. The list is longer than most people expect.
High-risk AI systems include:
- Biometric identification — facial recognition, fingerprint matching, voice recognition used to identify people
- Critical infrastructure — AI managing electricity grids, water systems, transport networks
- Education and training — AI that determines admissions, grades students, or assesses qualifications
- Employment and HR — recruitment tools, CV screening, performance monitoring, promotion decisions
- Access to essential services — credit scoring, insurance underwriting, benefit assessments
- Law enforcement — AI used to assess criminal risk or investigate individuals
- Migration and border control — visa processing, fraud detection at borders
- Justice and democracy — AI used in judicial decisions or electoral systems
UK investors keep asking me which of these actually matter for ordinary businesses. The answer: employment AI and financial services AI are the two categories that hit the most companies.
If you use a tool like HireVue, Pymetrics, or any AI-based CV shortlister — even a third-party plugin bolted onto your applicant tracking system — you may be deploying a high-risk AI system. Same goes for lenders using automated creditworthiness assessments, or insurers using ML-based underwriting models.
What the Law Now Requires You to Have in Place
For providers (companies that build high-risk AI systems): the obligations are extensive. You need a documented quality management system, a technical file proving conformity, a risk management process that runs throughout the product lifecycle, and registration in the EU’s AI database.
For deployers (companies that use high-risk AI systems bought from someone else): your obligations are lighter but still real. You must:
- Ensure the system is used according to the provider’s instructions
- Assign human oversight to a named, qualified individual
- Log inputs and monitor outputs
- Inform employees that they’re subject to AI monitoring where applicable
- Conduct a Fundamental Rights Impact Assessment for public sector use
The practical reality: most UK businesses using AI tools are deployers, not providers. They didn’t build the model — they bought a SaaS platform that includes it. The good news is that deployer obligations are lighter. The bad news is that “we bought it from a vendor” is not a defence if you can’t demonstrate the oversight, logging, and transparency requirements are met.
The Penalties: Not Just for Big Players
Fines under the EU AI Act are calculated as a percentage of global annual turnover — not just EU revenue. For non-compliance with high-risk system obligations, that’s up to 3% of global annual turnover.
The numbers get serious fast. A UK business turning over £50 million globally faces potential fines of up to £1.5 million. A £5 million SME faces up to £150,000 — which can be business-ending if it follows a public enforcement action.
For prohibited AI practices (the most serious violations — things like social scoring systems or covert manipulation), the penalty climbs to 6% of global turnover. General-purpose AI model obligations carry up to €15 million or 3% of turnover, whichever is higher.
The enforcement architecture works through national market surveillance authorities. In France, that’s CNIL. In Germany, the relevant authorities vary by sector. There’s also the EU AI Office for GPAI model oversight. Each can investigate, and member states can bring cases independently.
I’ve seen UK businesses assume they’re too small to be worth pursuing. That’s a mistake. Early enforcement tends to target high-visibility violations, not necessarily large companies. A high-profile HR tool discriminating in hiring decisions makes for a better enforcement story than a quietly non-compliant £10 billion bank.
Why UK Companies Are Not Off the Hook Post-Brexit
This is the question I get asked most by UK founders and compliance managers. Brexit didn’t exempt you. Here’s why.
The EU AI Act has explicit extraterritorial scope. Article 2 states that it applies to providers placing AI systems on the EU market — wherever those providers are located. It also applies to deployers established in the EU, and to providers and deployers located outside the EU when the outputs of their AI systems are used in the EU.
That last phrase is the one that catches UK companies out. If your AI system’s outputs — your credit decisions, your hiring recommendations, your insurance quotes — affect people in EU member states, you’re in scope. It doesn’t matter that your servers are in London and your company is incorporated in England.
The practical trigger is whether you have EU customers or users. A UK fintech lending to French consumers? In scope. A UK HR software vendor selling to German companies? In scope. A UK healthtech tool used by Belgian hospitals? In scope.
What Brexit did change: the UK is not required to designate a UK Authorised Representative the way non-EU, non-UK companies must. UK businesses can deal with EU regulators directly. That’s a minor administrative saving, not a substantive exemption.
How the UK’s Own Approach Differs
The contrast between the EU’s and the UK’s approach to AI regulation is stark — and it’s worth understanding if you’re trying to navigate both.
The EU went big: a single, binding horizontal law with hard categories, mandatory conformity assessments, and substantial penalties. The UK went principles-based: the FCA, ICO, CMA, and Ofcom each apply sector-specific guidance under existing frameworks. There is no UK AI Act. There may never be one in this Parliamentary term.
That creates a real compliance asymmetry. UK businesses operating only in the UK face lighter, more flexible oversight. UK businesses operating in the EU face the full weight of the EU AI Act on top of any UK obligations.
The UK government hasn’t ignored this. The AI Safety Institute has been doing model evaluations. The ICO has published guidance on AI and data protection. The FCA’s position paper on AI in financial services sets clear expectations. But none of it has the teeth of the EU Act’s enforcement architecture — yet.
Some UK businesses are treating EU compliance as the de facto standard for their entire operations. That’s not a bad approach. Meeting the EU requirements often satisfies UK regulatory expectations too, and it keeps the door open to EU market access.
Who’s Most at Risk: Fintechs, HR Tools, and Lenders
Three UK sectors face the most immediate exposure.
Fintechs and lenders: Automated credit decisioning is squarely in Annex III. If your platform makes or significantly influences lending decisions for EU customers, you’re deploying a high-risk AI system. The obligation to explain decisions — why someone was declined — is now legally enforceable, not just a best practice.
HR software vendors: CV screening, candidate ranking, video interview analysis — all in scope if used for employment decisions. UK vendors selling into EU markets need to ensure their models have proper documentation, bias auditing, and override mechanisms.
Insurance: Underwriting models that use ML to set premiums or assess risk for EU policyholders are high-risk AI under Annex III. Insurers using any form of automated risk assessment need to have their conformity assessments ready.
The sector that’s probably most exposed but least prepared: recruitment software. The market is full of CV screeners, video analysis tools, and psychometric platforms, many of which are built on top of proprietary models with limited documentation. Vendors who haven’t audited their tools for EU AI Act compliance are exposed — and so are the UK businesses that bought their product.
What This Means for UK Businesses Using AI
If you’re a UK business with any EU-facing AI deployment, the time for monitoring is over. The law is in force.
Four things to do before the end of August:
- Map your AI systems. List every tool that makes or assists in decisions about EU users or customers. Be honest about what’s in scope under Annex III.
- Check your vendor obligations. For every AI tool you bought, request documentation of their EU AI Act compliance status. Providers should have technical files and conformity assessments prepared.
- Assign human oversight. For high-risk deployments, you need a named person responsible for monitoring, override, and audit. This can’t be a shared responsibility that nobody owns.
- Start logging. If you’re not already keeping records of AI inputs and outputs for high-risk decisions, start now. That trail is what protects you in an investigation.
The EU AI Act won’t be enforced uniformly from day one. Regulators are building capacity, and the first major enforcement actions will likely focus on high-profile or high-harm cases. But the law is live. The exposure is real. And “we didn’t realise it applied to us” won’t carry much weight in front of a market surveillance authority.
This article is for educational purposes only and does not constitute legal or professional advice. EU AI Act compliance requirements are complex and depend on your specific use cases and markets. Consult a qualified legal adviser for guidance specific to your business.
Stay ahead of the market
Join our community of nearly 5,000 across YouTube, LinkedIn, X, and Facebook — weekly crypto, AI, and digital lifestyle insights every Thursday. No spam. Unsubscribe any time.
Partner picks
Build a smarter digital stack
Explore curated AI, automation, wealth, and creator tools selected for practical value, transparent pricing, and clear use cases.
Disclosure: some links may be affiliate links. DigitechLifestyle may earn a commission at no additional cost to you.



