There is no “UK AI Act.” If you run a small business in the UK, the law you’re actually exposed to depends on two separate things: which existing UK regulator covers your sector, and whether the EU AI Act reaches you because of who your customers are. Most of the anxiety around “AI law” comes from conflating the two. This guide separates them, and gives you the current deadlines — including a major EU change that landed just days ago.
The Core Question: Is There a “UK AI Act”?
No. The UK regulates artificial intelligence through existing sector regulators and general data protection law, not through a single AI statute. A House of Commons Library briefing published in June 2026 confirmed there is no standalone UK AI Act and no AI bill currently before Parliament.
The UK’s Principles-Based, Sector-Led Approach
The UK government set out its position in the 2023 white paper, A pro-innovation approach to AI regulation, and has stuck with it since. Rather than writing new AI-specific law, it asks existing regulators to apply five cross-sector principles — safety, transparency, fairness, accountability, and contestability — within their own remits. A Private Members’ AI Regulation Bill was introduced to the House of Lords in March 2025 but never progressed past its first reading, and ministers confirmed in early 2025 that most AI systems will continue to be regulated at the point of use, not through a dedicated AI authority.
The Role of Existing Regulators (ICO, FCA, Ofcom)
For a small business, this means your AI obligations sit with whichever regulator already governs your sector:
- ICO (Information Commissioner’s Office) — covers any AI system that processes personal data, which is most of them.
- FCA (Financial Conduct Authority) — following its January 2026 Mills Review, the FCA has signalled it will apply Consumer Duty and senior manager accountability rules more directly to AI-driven decisions in financial services.
- Ofcom — regulates AI chatbots and other AI features on online platforms under the Online Safety Act 2023.
- CMA (Competition and Markets Authority) — watches AI’s effect on competition and consumer markets.
These regulators coordinate through the Digital Regulation Cooperation Forum (DRCF), but there’s no single portal or checklist. If you’re not sure which regulator applies, start with the ICO — data protection touches almost every AI use case, from a chatbot on your customer service line to a CV-screening tool in your hiring process.
What the Data (Use and Access) Act 2025 Means for Automated Decision-Making
The Data (Use and Access) Act 2025 (DUAA) is the single most important piece of UK legislation for AI-using small businesses right now, and it’s genuinely new — most of its data protection provisions only came into force on 5 February 2026.
Direct answer: The DUAA rewrote how UK GDPR treats automated decision-making. It replaced the old Article 22, which banned solely automated decisions with legal or similarly significant effects by default, with a new permission-plus-safeguards model (Articles 22A–22D). For decisions that don’t involve special category data, you can now make significant automated decisions without needing a specific legal exception — but only if you provide:
- Clear information to the person about the decision
- A way for them to make representations
- A route to obtain human intervention
- A way to contest the decision
The DUAA also introduced a “recognised legitimate interests” lawful basis, which removes the need for a formal balancing test in certain circumstances. If you use any tool that scores, ranks, or filters people — job applicants, loan enquiries, customer complaints — you’re likely doing automated decision-making under this framework, whether you’ve labelled it that way or not. The ICO published a recruitment-specific report in March 2026 finding that many employers didn’t realise their HR software was making automated decisions at all, and that “a human nominally in the loop” isn’t enough — the reviewer needs real authority to change the outcome, not just rubber-stamp it. The ICO’s fuller guidance on this, following a consultation that closed in May 2026, is expected in summer 2026.

Why the EU AI Act Demands Attention from UK SMEs
Direct answer: The EU AI Act applies to your UK business if your AI systems’ outputs are used in the EU — for example, if you sell into the EU, serve EU customers, or your software touches EU users — regardless of where your company is registered.
The Extraterritorial Trap: Does the Act Apply to Your UK Business?
The EU AI Act works like GDPR did: it follows the data and the market, not the company’s home address. You’re potentially in scope if any of the following apply:
- You sell products or services into the EU that use AI features
- An AI system you built or deployed produces output used by people in the EU
- You act as a “provider” (you build or sell an AI system) or a “deployer” (you use one in your operations) that touches EU users
A UK boutique marketing agency running a basic AI chatbot for its own UK clients is a different risk profile from a UK recruiter using AI candidate-sorting tools for roles that include EU-based applicants. The second scenario pulls in EU high-risk obligations; the first largely doesn’t.
Key Deadlines: What’s Actually Live Now (Updated Following the July 2026 Omnibus)
This is where a lot of published advice is now out of date. Here’s the accurate picture as of late July 2026:
| Date | What happened / happens |
|---|---|
| 2 February 2025 | Bans on “unacceptable risk” practices took effect. The Article 4 AI literacy duty also began. |
| 2 August 2025 | Rules for general-purpose AI (GPAI) models and the AI Office governance structure became applicable. |
| 27 July 2026 | The EU’s Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force, formally postponing the high-risk system deadlines. |
| 2 December 2027 | New deadline for high-risk obligations on standalone Annex III systems (employment, credit scoring, education, essential services). Previously 2 August 2026. |
| 2 August 2028 | New deadline for AI embedded in regulated products (Annex I — medical devices, machinery, toys, etc.). |
| 2 December 2026 | Deadline for AI-generated content transparency/watermarking obligations. |
In plain terms: the widely reported “2 August 2026” deadline for high-risk AI systems has been pushed back, formally and finally, to December 2027 for most SME-relevant use cases. If you’ve seen guidance warning you to be compliant by this August, it’s describing a deadline that no longer applies to high-risk systems — though the GPAI rules, the Article 5 bans, and the Article 4 literacy duty are all still very much live. This is a genuine reprieve, not an excuse to stop preparing: the underlying obligations haven’t gone away, and the standards bodies still haven’t finished the technical guidance you’ll need.
Assessing Your Risk: The Four-Tier Classification
The EU AI Act sorts every AI system into one of four risk tiers. Where your tool lands determines what you must do.
| Tier | What it covers | What it means for you |
|---|---|---|
| Unacceptable risk | Social scoring, manipulative or exploitative systems, untargeted facial scraping, real-time public biometric surveillance by law enforcement | Banned outright since February 2025 |
| High risk | Systems used in employment, credit scoring, education, essential services, critical infrastructure | Conformity assessments, technical documentation, human oversight — deadline now December 2027 |
| Limited risk | Chatbots, generative AI tools, deepfake generators | Transparency duty: users must be told they’re interacting with AI |
| Minimal risk | Spam filters, AI-powered scheduling, inventory forecasting | No specific AI Act obligations, though UK GDPR and DUAA rules still apply if personal data is involved |
Most everyday small business tools — an AI writing assistant, a basic chatbot widget, scheduling automation — sit in the limited or minimal risk tiers. The tools that need real scrutiny are the ones making decisions about people: recruitment screening, credit or pricing decisions, and anything touching vulnerable groups.
The Hidden Mandate: Article 4 and the AI Literacy Requirement
Direct answer: If your business uses any AI tool and any part of your operation touches the EU, you likely have a live legal duty — active since February 2025 — to make sure staff using that tool understand it.
Article 4 of the EU AI Act requires providers and deployers to take measures ensuring “a sufficient level of AI literacy” among anyone operating an AI system on their behalf — employees, contractors, anyone. Following the July 2026 Omnibus, this has been softened from an obligation to ensure literacy to an obligation to support its development — an obligation of effort, not a guaranteed outcome, which lowers the compliance bar for small teams. National authorities began actively supervising and enforcing Article 4 from 2 August 2026 onward. For SMEs, penalty caps are set at the lower end of the scale under Article 99(6).
This obligation is broader than it sounds. It covers anyone using AI writing tools, Copilot-style assistants, or AI features baked into your CRM — not just people building AI systems from scratch.
4 Practical Steps to Make Your Small Business Compliant Today
Step 1: Map Your AI Use and Audit “Shadow AI”
Most small businesses use more AI than they realise. Free AI features get switched on inside existing software — Microsoft 365 Copilot, design tools like Canva’s AI features, CRM scoring, email spam filters — often without anyone formally approving it. Start with a simple register: list every tool, who uses it, what data it touches, and whether it makes or influences decisions about people.
Step 2: Implement an AI Acceptable Use Policy
A short, plain-language policy covering what tools staff can use, what data they can put into them, and who to ask before adopting a new one closes most of your immediate risk. Pair it with your existing data security and two-factor authentication practices, since most AI risk is really a data-handling risk in disguise.
Step 3: Train Your Staff (Solving the AI Literacy Obligation)
You don’t need a formal course. A recorded 30-minute session covering what your AI tools do, their limitations, and when a human must review the output — logged with date, attendees, and content — is a reasonable, low-cost way to demonstrate good-faith compliance with Article 4.
Step 4: Align with Standards (ISO/IEC 42001)
ISO/IEC 42001 is the international standard for AI management systems — the AI equivalent of ISO 27001 for information security. It’s voluntary, but adopting even its basic structure (governance, risk assessment, documented oversight) gives you a defensible paper trail if the ICO, FCA, or an EU regulator ever asks how you manage AI risk. It’s not mandatory for most small businesses, but it’s a useful shortcut to organising the DUAA and AI Act requirements you’re already on the hook for.

Frequently Asked Questions
Is there a UK AI Act?
No. The UK regulates AI through existing regulators and general law — principally UK GDPR, the Data (Use and Access) Act 2025, and sector rules from the ICO, FCA, and Ofcom — rather than a single AI statute.
Does the EU AI Act apply to UK small businesses?
Yes, if your AI system’s output is used by people in the EU — for example, through EU sales, EU customers, or downstream integrations — regardless of where your business is registered.
Is the EU AI Act’s high-risk deadline still 2 August 2026?
No. The Digital Omnibus on AI, in force since 27 July 2026, pushed high-risk obligations to 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in regulated products.
Do I need to train staff on AI under EU law?
If your business is in scope of the EU AI Act, yes — Article 4’s AI literacy duty has applied since February 2025, though it was softened by the July 2026 Omnibus to an obligation of reasonable effort rather than a guaranteed result.

