Where are you operating from?
UK alone does not trigger EU AI Act duties.
Built for engineering, product, and risk teams: verified Regulation (EU) 2024/1689 timeline milestones, role-based obligation mapping, and explicit scope logic so UK organisations are not incorrectly flagged as EU-only unless EU market triggers apply.
Current date context: 2026-09-20. Main application date: 2 August 2026.
UK alone does not trigger EU AI Act duties.
If Yes, obligations apply under Article 2 extraterritoriality.
Role changes obligations and penalty liabilities.
When uncertain, start at limited and test scenarios.
A Yes here triggers mandatory Articles 9-15 high-risk controls.
Timeline-sensitive obligations are date-dependent.
Timeline stage: Phase 3 — main obligations apply (since 2 Aug 2026) · EU applicability: Unlikely (UK Domestic Only)
Calculate your legal maximum exposure based on global annual turnover and company type. Under Article 99(6), SMEs and startups benefit from the LOWER of the fixed Euro cap vs percentage rate.
Fixed Euro Cap: €15.0M
Turnover Rate (3%): €0.30M
Rule Applied: SME / Startup Rule (Art. 99(6)): Capped at whichever is LOWER (€15.0M vs 3% of turnover).
Search terms across the 8 banned practices and 8 Annex III high-risk domains.
Subliminal techniques or deceptive tactics distorting behavior and impairing informed decisions to cause significant harm (Art. 5(1)(a)).
Exploiting age, disability, or specific social/economic situation to distort behavior causing harm (Art. 5(1)(b)).
Evaluating or classifying natural persons over time based on social behavior or personal traits causing detrimental treatment (Art. 5(1)(c)).
Predicting an individual's risk of committing a crime based solely on profiling or personality traits (Art. 5(1)(d)).
Creating or expanding facial recognition databases via untargeted scraping of internet or CCTV footage (Art. 5(1)(e)).
Inferring emotions of natural persons in workplace and educational institutions, except for medical or safety reasons (Art. 5(1)(f)).
Categorising natural persons based on biometric data to deduce race, political opinions, trade union membership, religious/philosophical beliefs, or sexual orientation (Art. 5(1)(g)).
Live remote biometric identification in publicly accessible spaces for law enforcement, unless strictly necessary for narrow exceptions (Art. 5(1)(h)).
Digital or safety components in road traffic, water, gas, heating, electricity where failure endangers life and health.
AI determining access, admission, assignment, or evaluating learning outcomes and exam scoring.
CV-sorting, recruitment tooling, performance evaluation, task allocation, promotion, or termination decisions.
Credit scoring, risk assessment for life/health insurance, dispatching emergency first responders.
Post remote biometric identification systems and emotion recognition not banned under Art 5.
Assessing criminal risk, polygraphs/lie detectors, evidence reliability scoring, profiling during detection.
Polygraphs, risk assessment for border entry, visa application examination, asylum eligibility verification.
Assisting judicial authorities in researching and interpreting facts and law, or influencing election outcomes.
Continuous iterative risk assessment, testing, and mitigation across the entire lifecycle.
High-quality training, validation, and testing datasets with bias mitigation and representative sampling.
Detailed up-to-date documentation proving conformity before placement on the EU market.
Automatic logging of events enabling traceability, auditability, and monitoring across operation.
Clear instructions for use, capabilities, limitations, and operational specifications for deployers.
Built-in interface controls allowing human operators to oversee, override, or interrupt output.
Resilience against adversarial prompt injection, cyber threats, data poisoning, and performance drift.
Required from 2 August 2026: Implement user-facing disclaimers and machine-readable synthetic content watermarks.
<!-- Article 50(1) Interactive AI User Disclaimer -->
<div class="ai-disclosure-banner" role="status" aria-live="polite">
<span class="ai-icon">🤖</span>
<p><strong>Notice:</strong> You are interacting with an automated AI assistant powered by synthetic intelligence.</p>
</div>Not automatically — the UK is not in the EU. But the Act has extraterritorial reach (Article 2): it applies to any UK firm that places AI systems or GPAI models on the EU market, puts them into service in the EU, or where the system's output is used in the EU. UK-only operations follow domestic UK rules (UK GDPR, Equality Act 2010, ICO guidance, sector regulators).
Under Article 113, the main bulk of the AI Act became active and enforceable on 2 August 2026 — including Annex III high-risk system duties, Article 50 transparency obligations, deployer rules, and notified body workflows. The European AI Office also issued GPAI Codes of Practice, establishing operational compliance benchmarks for frontier model providers. Carve-outs remain: Article 6(1) product-safety classification applies from 2 August 2027.
Under Article 99(6), for SMEs and startups (defined under EU Recommendation 2003/361/EC), fine ceilings are capped at whichever of the two amounts (the fixed Euro cap vs the percentage of global annual turnover) is LOWER, rather than higher.
Eight practices have been prohibited since 2 February 2025 — including harmful manipulation, social scoring, untargeted facial scraping, workplace/school emotion recognition, and real-time remote biometric identification for law enforcement (narrow exceptions).
Yes. Obligations for general-purpose AI model providers (Chapter V) have applied since 2 August 2025 — transparency, technical documentation, EU copyright law compliance, and training content summaries, plus extra requirements for models with systemic risk (>10^25 FLOPs).
No. It is compliance intelligence for engineering, product, and legal triage. For binding conformity declarations, filings, and legal sign-off, consult qualified EU/UK legal counsel and verify against Regulation (EU) 2024/1689.