UK / EU · GLACIS guides · EU timeline checked August 2026

UK vs EU AI Act: which rules apply to which AI

A working guide for organizations operating in both markets, updated for the EU AI Omnibus now in force. Relevant Annex III high-risk duties apply from December 2027 and relevant Annex I product-embedded duties from August 2028; the UK continues to use a sector-led framework.

By Joe Braidwood Reviewed 26 August 2026
Nov 2025
EU Digital Omnibus on AI tabled by Commission
27 Jul 2026
AI Omnibus (Regulation (EU) 2026/1744) enters into force
2 Dec 2027
Relevant EU Annex III high-risk duties apply
2 Aug 2028
Relevant EU Annex I product-embedded duties apply
What changed since January 2026
The bottom line

The UK and EU have taken different approaches to AI regulation. The EU AI Act is horizontal regulation with duties that vary by role and classification. The UK framework relies heavily on existing sectoral regulators and non-statutory principles. As of August 26, 2026, the AI Growth Lab offers joined-up guidance within existing rules; government has said legislation for additional testing powers will be brought forward, so the Lab should not be described as a current legislative vehicle or a license to relax regulation.

Critical point: UK companies can fall within the EU AI Act when they place systems on the EU market or when outputs produced by a system are used in the EU, subject to Article 2’s conditions and exceptions. UK compliance does not itself establish EU compliance. The AI Omnibus changes when specified high-risk duties apply, not the Act’s territorial test.

UK

UK approach

  • · Principles-based, sectoral regulation
  • · Five non-statutory principles
  • · No central AI authority — DRCF coordinates
  • · Outcome-focused, flexible
  • · Prioritises innovation and growth (DSIT Blueprint, AI Growth Lab)
EU

EU AI Act

  • · Horizontal, prescriptive regulation
  • · Four risk tiers with specific requirements
  • · European AI Office + national authorities
  • · Process-focused, compliance-driven
  • · Prioritises safety and rights — Omnibus delay reshapes timing

Detailed comparison

Aspect UK EU AI Act
Regulatory structure Principles-based and sectoral. Existing regulators (FCA, MHRA, ICO, Ofcom, CMA) apply existing law within their domains. The AI Growth Lab offers coordinated regulatory advice within current rules; broader waivers or new powers would require legislation. Horizontal regulation. Single legal framework applies across all sectors with uniform requirements.
Central authority None. AI Security Institute evaluates frontier AI but does not regulate. DRCF coordinates regulators. European AI Office at EU level. Each member state designates national competent authorities.
Risk classification No formal tiers. Risk assessment left to individual regulators and organizations. Four tiers: unacceptable (banned), high-risk (strict requirements), limited risk (transparency), minimal (no requirements).
Prohibited practices No AI-specific prohibitions in law. Existing laws (Equality Act, UK GDPR) apply. Explicit bans: social scoring, real-time remote biometric ID (exceptions), manipulation, emotion recognition in workplaces and schools.
High-risk requirements Depends on sector. FCA: Consumer Duty and SM&CR. MHRA: current medical-device rules. No unified AI-specific requirements or single horizontal commencement date. Conformity assessment, risk management, data governance, logging, human oversight, transparency, accuracy / robustness testing, registration.
Documentation Existing sectoral requirements apply. No AI-specific documentation mandates. Extensive: technical documentation, quality management system, instructions for use, conformity declaration, EU registration.
Penalties Vary by regulator. FCA can impose unlimited fines. ICO up to £17.5M / 4% turnover. Up to €35M or 7% global turnover (prohibited practices), €15M or 3% (listed operator and Article 50 transparency obligations), and €7.5M or 1% (incorrect, incomplete, or misleading information supplied on request).
Timeline Ongoing. No comprehensive horizontal AI Act. Existing law and sector regulators remain central; the AI Growth Lab operates as an advisory route within current rules, while any broader statutory powers require legislation. Prohibitions in force Feb 2025; GPAI model duties from Aug 2025. Under the AI Omnibus now in force, relevant Annex III high-risk duties apply from 2 Dec 2027 and relevant Annex I product-embedded duties from 2 Aug 2028.
Legal basis Non-statutory principles. Relies on existing legislation (UK GDPR, DUAA 2025, sectoral statute). Directly applicable EU regulation with legal force in all member states.

Extraterritorial impact: when EU rules apply to UK companies

Critical for UK organizations

The EU AI Act can apply to UK companies when they place AI systems on the EU market or when a system’s outputs are used in the EU, subject to Article 2’s conditions and exceptions. The AI Omnibus now sets the relevant high-risk dates; it does not change the need for a system-specific territorial-scope analysis.

The EU AI Act has broad extraterritorial reach. Article 2 specifies it applies to:

  • Providers placing AI systems on the EU market — regardless of where they are established
  • Deployers of AI systems located within the EU
  • Providers and deployers in third countries where AI output is used in the EU
  • Importers and distributors of AI systems in the EU

Practical implications

  • Selling AI software into the EU can bring a provider within scope when the Act’s territorial and material conditions are met
  • EU subsidiaries using UK-developed AI should assess their role and obligations system by system
  • For third-country providers or deployers, output used in the Union can trigger scope under Article 2(1)(c), subject to the Act’s conditions and exceptions
  • Products containing AI sold in the EU may face AI Act duties alongside applicable product-safety law
  • The AI Omnibus is in force: relevant Annex III high-risk duties apply from 2 December 2027; technical standards and system-specific conformity planning still require advance work

Dual compliance strategy

Organizations operating in both markets can use a shared controls-and-evidence baseline, then map distinct EU legal duties and UK sector expectations. The AI Omnibus changes specified EU high-risk dates; it does not make the two regimes interchangeable.

Recommended approach

1

Classify AI systems under EU AI Act

Determine the applicable EU risk category and the UK sector rules for each system. For EU high-risk systems, map the enacted 2 December 2027 or 2 August 2028 date to the correct pathway.

2

Map the EU duties precisely

Identify the documentation, risk-management, data, oversight and monitoring duties that apply to each EU role and system. Do not assume that meeting them resolves UK sector requirements or future UK policy.

3

Layer UK sectoral requirements

Add UK-specific obligations from relevant regulators (FCA Consumer Duty, PRA SS1/23, MHRA medical device rules, ICO ADM requirements, and DUAA section 103, which commenced 19 June 2026) on top of EU compliance.

4

Maintain dual documentation

Keep separate obligation maps and submission artefacts while reusing defensible source records where appropriate. Reuse reduces duplication; it does not make the regimes or review processes equivalent.

Key differences in practice

Risk assessment

UK

No prescribed methodology. Organisations determine approach. Regulators expect “proportionate” risk consideration aligned with the five principles.

EU

Article 9 mandates risk management systems for high-risk AI: identification, analysis, evaluation and mitigation throughout the lifecycle.

Human oversight

UK

For relevant solely automated significant decisions, the DUAA safeguards include telling the person, allowing representations, and enabling them to obtain human intervention. The ICO consultation on draft ADM and profiling guidance closed on 29 May 2026; final guidance had not been published on the consultation page as of 26 August. Sectoral requirements may apply on top.

EU

Article 14 mandates human oversight for high-risk AI with specific capabilities: understanding, monitoring, interpreting, deciding to override, and stopping the system.

Transparency

UK

“Appropriate transparency” principle. ICO guidance on explaining AI decisions. No mandatory disclosures for AI interaction (unlike EU chatbot rules).

EU

Article 50 imposes defined transparency duties for certain direct AI interactions, synthetic or manipulated content, emotion recognition and biometric categorization, subject to the provision’s obviousness, law-enforcement, editorial, artistic and other context-specific conditions and exceptions.

Timeline comparison

Date UK development EU AI Act milestone
Feb 2025 AI Safety → AI Security Institute rename Prohibited AI practices banned
Jun 2025 DUAA Royal Assent —
Aug 2025 DUAA stage 1 effective GPAI model obligations apply
Sep 2025 PRA SS1/23 model-risk principles (current version 23 Apr 2026) —
Oct 2025 DSIT Blueprint for AI regulation; AI Growth Lab call for evidence opens —
Nov 2025 — EU Commission tables Digital Omnibus on AI (19 Nov 2025)
Dec 2025 AISI Frontier AI Trends Report —
27 Jan 2026 FCA Mills Review launched —
5 Feb 2026 DUAA bulk data-protection provisions in force —
Mar 2026 ICO AI & biometrics strategy update —
Apr–May 2026 FCA AI Live Testing cohort 2; AI Airlock phase 2 completes in May —
6–7 May 2026 — Omnibus provisional agreement (historical milestone)
19 Jun 2026 DUAA section 80 ADM safeguards and separate section 103 complaints duty in force —
27 Jul 2026 — AI Omnibus enters into force as Regulation (EU) 2026/1744
6 Jul 2026 FCA publishes Mills Review and seven recommendations for its Board and Executive to consider —
Next MHRA AI Airlock phase 3 design in progress; follow official MHRA updates for timing and eligibility —
No later than 2 Dec 2027 — Relevant Annex III high-risk duties apply
No later than 2 Aug 2028 — Relevant Annex I product-embedded high-risk duties apply

Sector-specific considerations

Financial services

UK (FCA / PRA)
  • · Consumer Duty applies to relevant AI-enabled retail outcomes; Mills Review published 6 July 2026
  • · SM&CR accountability for AI decisions
  • · SS1/23 Model Risk Management — automated monitoring expected
  • · Principles-based, outcomes-focused approach remains the FCA baseline
  • · AI Live Testing cohort 2 running through end-2026
  • · BoE FPC priority: agentic AI in payments and markets
EU AI Act
  • · Creditworthiness evaluation or credit scoring for natural persons is listed, except fraud detection
  • · Life-and-health risk assessment or pricing for natural persons is listed; insurance generally is not
  • · Apply Article 6 classification and the applicable conformity pathway
  • · Registration duties and Article 6(3) documentation depend on the classification result
  • · Relevant Annex III high-risk duties apply from 2 Dec 2027

Healthcare

UK (MHRA)
  • · AI Airlock phase 2 completed May 2026
  • · Phase 2 reports are not formal MHRA guidance
  • · AI Airlock phase 3 design is in progress
  • · Conformity and transition rules depend on device and certificate
  • · Post-market surveillance in force since June 2025
  • · NHS AI & Digital Regulations Service consolidates guidance
EU AI Act + MDR
  • · Article 6(1) requires both Annex I product-law coverage and a required third-party conformity assessment
  • · Where that trigger is met, AI Act and MDR / IVDR duties can apply together
  • · The product’s actual classification determines whether a notified body is required
  • · Relevant Annex I product-embedded duties apply from 2 Aug 2028

How GLACIS can support dual-market evidence preparation

Operating in both markets means mapping the EU’s legal requirements and the UK’s sector-based expectations separately. The AI Omnibus sets the EU high-risk dates now in force; UK sector timelines continue independently. A shared evidence infrastructure can support both mappings without implying that one regime’s requirements satisfy the other.

Reuse evidence without equating regimes

For an instrumented workflow, GLACIS can preserve selected control-execution records that teams may reuse when preparing UK and EU materials. Each regime still requires its own legal, technical and sector-specific assessment.

EU AI Act technical documentation

Covered high-risk AI systems need technical documentation under the EU AI Act. GLACIS can capture operational evidence relevant to risk management, data governance, human oversight, and performance; legal sufficiency remains system- and pathway-specific.

UK principles evidence

Signed records of selected runtime events and control decisions may help a team prepare evidence for internal review or a regulator-facing process. GLACIS is not integrated with the FCA, PRA, MHRA, ICO or Bank of England, and no regulator acceptance or legal sufficiency is implied.

Potential evidence contributions across both regimes

Requirement EU AI Act UK approach Potential GLACIS contribution
Risk management Article 9 RMS Sectoral guidance Timestamped records of selected configured controls and review events; not a complete risk-management system
Human oversight Article 14 DUAA meaningful intervention (5 Feb 2026) Captured override and escalation events with available operator context
Transparency Article 13 / Article 50 Principle 2 Export of the events and fields actually captured; completeness must be assessed separately
Accuracy and robustness Article 15 Principle 1 Binding of supplied performance metrics and configured guardrail events to versioned context
Post-market monitoring Article 72 Sectoral post-market surveillance under current MHRA requirements Configured production records may support incident correlation; reporting sufficiency remains pathway-specific
Individual rights / contestation Article 86 right to explanation DUAA section 80 / new UK GDPR Articles 22A–22D Retrieval of captured decision and review events may support investigation and response preparation

Map one evidence boundary across both markets

The AI Omnibus now sets the EU high-risk dates; UK sector timelines continue independently. A dual-framework assessment can map gaps without treating either regime as a substitute for the other.

Talk to us

Related guides