5 things UK businesses still get wrong about the EU AI Act
The July 2026 omnibus moved the EU AI Act timeline. Five assumptions UK organisations still make, and what the amended Regulation actually says.
If you run a UK organisation and someone has asked whether the EU AI Act is your problem, you have probably already met some confident, wrong answers. The Digital Omnibus that came into force on 27 July 2026 changed enough of the detail that a lot of the advice written before it is now out of date. Here are five things UK businesses still get wrong, and what the amended Regulation says instead.
1. “We’re in the UK, so it doesn’t apply to us”
Whether the Act binds you does not turn on where you are based. It turns on where your AI activity reaches. Article 2 pulls in providers and deployers outside the EU when the output of their AI system is used in the EU, or when they put a system on the EU market. A UK company with EU customers, EU users, or work that feeds into an EU business can be inside its scope while a UK company that never touches the EU is not.
The practical answer is rarely “obviously yes” or “obviously no”. It depends on your role and your reach, which is exactly what an applicability check works out.
2. “There’s nothing to do until 2027”
The headline dates people repeat, December 2027 and August 2028, are real, but they cover the heaviest high-risk obligations: stand-alone high-risk systems under Annex III apply from 2 December 2027, and AI built into regulated products under Annex I from 2 August 2028. Plenty is already in force before then. The ban on prohibited practices and the AI literacy duty have applied since February 2025, obligations for general-purpose AI models since August 2025, and the transparency duties in Article 50 since August 2026.
So “nothing until 2027” is only true if none of those earlier obligations reaches you, and for most organisations at least one does.
3. “A certificate or a tool makes us compliant”
Buying a platform or holding a certificate is not the same as complying with a law. The Act asks you to know which of your systems it covers, meet the obligations that attach to them, and keep the records that show it. Governance is the set of decisions you have made and the evidence behind them. A tool can help you get there, but it is not the decision, and no certificate substitutes for the underlying work.
4. “The deadlines are whatever the article says”
This is the one the omnibus created. The Act is Regulation (EU) 2024/1689, and it was amended by Regulation (EU) 2026/1744. A large amount of published guidance still quotes the pre-omnibus timeline, so if you are reading a checklist or a summary, the first question is whether it was written against the amended text. If it does not say, treat its dates as suspect. Accuracy against the current wording is the whole game here, because the penalty for acting on a stale deadline is planning around the wrong date.
5. “High-risk is the only part that matters”
High-risk classification gets the attention because the obligations are the most demanding, but it is not where most organisations first meet the Act. The transparency duties in Article 50 reach far more businesses: telling people when they are talking to a chatbot, labelling synthetic or manipulated media, and disclosing emotion recognition or biometric categorisation where you use it. The AI literacy duty applies broadly too. Both are live now, and neither depends on your systems being high-risk.
Where to start
None of this needs a lawyer on day one. It needs a plain answer to which parts of the Act reach your organisation and which apply today. The free EU AI Act check works that out for your systems against the amended Regulation, and the EU AI Act overview sets out the full post-omnibus timeline. When you reach a point that needs a legal conclusion, take what you have found to your own adviser. This is general guidance, not legal advice.