Skip to content
Get in touch 

EU AI Act for UK businesses: does it apply, and ISO 42001

Does the EU AI Act apply to UK businesses, what the December 2027 high-risk deferral changes, and how its duties map onto ISO 42001 controls.

Ibrahim Mizi Ibrahim Mizi  · 13 min read Updated
A pair of balance scales holding level

The EU AI Act applies to UK businesses more often than people expect. Article 2 sets the scope by the role you play rather than by where you are registered, so you are caught if you place an AI system on the EU market, if you deploy one and your place of establishment is in the EU, or if you sit outside the EU and the output your system produces is used inside it.[1] Brexit created no exemption, and the question to answer is which of those roles you occupy.

This guide is for the founder or operations lead who has to make an AI tool defensible without a legal department behind them. It covers when the Act applies, what the December 2027 high-risk deferral actually changes, how the duties map onto the ISO 42001 management standard, and how to run credible governance without a dedicated compliance team.

Last updated 10 August 2026.

One honesty note up front. OpenKit helps clients design systems and governance that align toward the EU AI Act and ISO 42001. We hold ISO 27001, ISO 9001 and Cyber Essentials, and we operate to UK GDPR. We are not certified to ISO 42001, and we are not a notified body or conformity assessor under the Act. Where formal certification or third-party assessment is needed, we point you to accredited bodies and help you arrive ready.

Does the EU AI Act apply to UK businesses?

Often, yes. Article 2 of the EU AI Act defines scope by role, and three of those roles pull a UK company in.[1] You do not need an EU office for any of them to bite.

You are a provider when you developed the AI system and it is placed on the EU market or put into service in the EU, which catches SaaS platforms that EU users can sign up to. You are a deployer in scope when you use an AI system under your own authority and your place of establishment is in the EU, which is what pulls in a UK group’s EU subsidiary. The role people miss is the third: where a provider or deployer sits outside the EU and the output the system produces is used inside it, so a model whose results inform decisions taken in the EU is caught even though you never targeted that market.

That makes the working test a question about roles, asked system by system rather than about the company as a whole. For each AI system you run, work out where it is placed on the market or put into service, where the organisation deploying it is established, and where its output actually gets used. Answering those at company level is how teams talk themselves out of an obligation one of their systems already carries, and finding out after enforcement starts is the expensive way to learn it.

If you would rather work that test question by question, there is a free EU AI Act applicability check at AI Governance Check that walks the Article 2 roles and returns which duties are already in force and which have been deferred.

What must be in place, and by when?

The Act rolls out in phases, and the phases moved in July 2026. Stand-alone Annex III high-risk obligations now apply from 2 December 2027 and high-risk systems embedded in regulated products from 2 August 2028, while the transparency duties have applied since 2 August 2026.[2] By the high-risk deadline a high-risk system needs a quality management system, technical documentation, a completed conformity assessment, EU database registration where required, and a working post-market monitoring plan. The earlier phases have already landed: prohibited practices since 2 February 2025, and general-purpose AI model duties since 2 August 2025.[2]

Those dates are enacted law rather than a proposal. Regulation (EU) 2026/1744, the Digital Omnibus on AI, was adopted by the European Parliament on 16 June 2026 and the Council on 29 June 2026, published in the Official Journal on 24 July and in force since 27 July 2026.[3]

Two things about the final text are worth knowing if you read the Commission’s proposal when it landed. The new dates are unconditional: the proposal would have tied the high-risk start to a decision confirming that harmonised standards and guidance were actually available, and the enacted text drops that trigger, so December 2027 holds even if the standards run late. The substance moved as well, with the AI literacy duty softened from ensuring a level of literacy to supporting its development, registration in the EU database simplified for systems claiming an exemption, and several accommodations built for SMEs extended to small mid-cap companies.[3] What did not move is the work itself: classification, documentation, human oversight and monitoring still land on the same systems, so the responsible plan is to build the infrastructure now and treat December 2027 as breathing room rather than a reprieve.

How does the EU AI Act map to ISO 42001?

ISO/IEC 42001 is the international management system standard for artificial intelligence, published in December 2023.[4] It is not the same thing as the EU AI Act: the Act is law with conformity assessments and penalties, while ISO 42001 is a voluntary standard you can be certified against by an accredited body. They fit together well, though. An AI management system built to ISO 42001 produces most of the operational evidence the Act asks for, so you are documenting once and using it twice.

The table below maps the Act’s main high-risk duties onto the ISO 42001 clauses and Annex A controls that do similar work. It is a planning aid, not a legal equivalence; ISO 42001 certification does not satisfy the Act’s conformity assessment, and the Act reaches obligations ISO 42001 does not, such as EU database registration.

EU AI Act duty (high-risk)ISO 42001 area that supports itGap the standard does not close
Risk management system (Art. 9)AI risk assessment and treatment, plus the AI policy and objectives in the management system clauses.Mapping each risk to the Act’s specific high-risk requirements is still your legal interpretation.
Quality management system (Art. 17)The management system itself: documented policy, roles, lifecycle procedures, and continual improvement.The Act prescribes specific QMS contents for high-risk systems beyond the generic structure.
Technical documentation (Art. 11)AI system lifecycle, data management, and documented information controls in Annex A.Article 11 lists mandatory contents; you must check your documentation covers each one.
Data and data governance (Art. 10)Data management controls covering provenance, quality, and preparation across the lifecycle.Specific training, validation, and test-data quality criteria sit in the Act, not the standard.
Human oversight (Art. 14)Operational controls and impact assessment that require oversight to be designed in.The Act specifies override and intervention capabilities you must build and evidence.
Post-market monitoring (Art. 72)Performance monitoring, internal audit, and management review of the AI system over time.The Act adds incident reporting to market surveillance authorities on top of monitoring.
Conformity assessment and registrationCertification readiness: the standard gets your evidence into auditable shape.The legal conformity assessment, CE marking, and EU database entry are separate and mandatory.

The honest read of that table: an ISO 42001 management system carries most of the operational weight, but it does not make you EU AI Act compliant on its own. You still owe the legal conformity assessment and registration, and you still have to check your evidence against the Act’s article-by-article contents.

A UK-operator action checklist

If you are a UK business that may be in scope, the work breaks into seven concrete steps. None of them require a deadline panic if you start now, and the early ones cost time rather than money.

  • Build an AI system inventory. List every AI system you build, deploy, or use, with what it does, what data it touches, who uses the output, and which jurisdictions that output reaches.
  • Classify each system by risk tier. Prohibited, high-risk, limited, or minimal. Pay particular attention to hiring, credit, insurance, education, and access-to-essential-services use cases, which are where Annex III bites for most companies.[1]
  • Map data flows end to end for anything high-risk. Collection, preparation, training, inference, output, and retention. This doubles as GDPR data-mapping evidence the ICO already expects.[5]
  • Design human oversight that works. Operators who understand the system, can evaluate its output, and have real authority to override or stop it. A confirm button nobody questions does not count.
  • Start the technical documentation now. System purpose, model and design rationale, training-data characteristics and limitations, test results, and a change log. Retrofitting this six weeks before a deadline does not work.
  • Name one governance owner. A single accountable person who maintains the inventory and classifications, coordinates documentation, and tracks regulatory change. It is the cheapest step here and the one that stops the rest from drifting.
  • Confirm transparency duties for limited-risk systems. Chatbots, AI-generated content, and similar tools mainly owe disclosure to users, which is lighter but still mandatory.

Governance without a dedicated compliance team

Most UK SMEs reading this do not have a compliance department, and they do not need one to be defensible. AI governance at this size is mostly engineering discipline written down: a current inventory, an honest risk classification, documented oversight for anything that affects people, and one named owner who keeps it true. You can run all of that on existing tools without hiring a single specialist.

What a small team usually lacks is not capability but pattern recognition. The conformity assessment process borrows from EU product safety frameworks used for medical devices and machinery, so teams that have never touched that world spend longer than they should working out what assessors actually look for. That is the part where an outside perspective earns its keep, and it is bounded work rather than an open-ended retainer.

OpenKit works with UK businesses on AI governance and compliance, including risk classification, documentation frameworks, and the oversight architecture that makes a system defensible rather than performative. We hold ISO 27001, ISO 9001 and Cyber Essentials, and we operate to UK GDPR, which gives us a working foundation in governance, and we are direct about what those certifications cover and what they do not. We help clients design toward the EU AI Act and ISO 42001; we do not hold ISO 42001 and we are not a conformity assessor, so for formal certification we get you ready and hand you to an accredited body.

If you are earlier in your AI journey and still working out where AI fits, our AI consulting work starts with the strategic questions before implementation, and for organisations weighing data sovereignty as part of compliance, our private AI deployment work covers the infrastructure side.

References

  1. European Union. (2024). Regulation (EU) 2024/1689 laying down harmonised rules on artificial intelligence (Artificial Intelligence Act), as amended, accessed on 10 August 2026, https://eur-lex.europa.eu/eli/reg/2024/1689/oj
  2. European Commission. AI Act implementation timeline, accessed on 10 August 2026, https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  3. European Union. (2026). Regulation (EU) 2026/1744 of 8 July 2026 amending Regulations (EU) 2024/1689, (EU) 2018/1139 and (EU) 2023/1230 as regards the simplification of the implementation of harmonised rules on artificial intelligence (Digital Omnibus on AI), accessed on 10 August 2026, https://eur-lex.europa.eu/eli/reg/2026/1744/oj
  4. International Organization for Standardization. (2023). ISO/IEC 42001:2023 Artificial intelligence management system, accessed on 29 May 2026, https://www.iso.org/standard/42001
  5. Information Commissioner’s Office. Guidance on AI and data protection, accessed on 29 May 2026, https://ico.org.uk/for-organisations/uk-gdpr-guidance-and-resources/artificial-intelligence/guidance-on-ai-and-data-protection/

Updated 10 August 2026 to reflect changes in the law.

Ibrahim Mizi

Ibrahim Mizi

Co-founder & CEO · Full-Stack AI Engineer · OpenKit

Co-founded OpenKit in 2020 and runs the consultancy side end to end. Eight years of full-stack development, then production AI for SMEs and the public sector.

Does the EU AI Act apply to UK businesses?

Often, yes. Article 2 sets the scope by the role you play rather than by where you are registered. You are in scope if you place an AI system on the EU market or put one into service there, if you deploy an AI system and your place of establishment is in the EU, or if you sit outside the EU and the output your system produces is used inside it. Brexit created no exemption, and a UK registered address takes you out of none of those roles.

What do UK businesses need to do, and by when?

Inventory your AI systems, classify each by risk tier, and start the documentation, human oversight, and monitoring work for anything high-risk. Regulation (EU) 2026/1744, the Digital Omnibus on AI, has been in force since 27 July 2026 and moved stand-alone Annex III high-risk obligations to 2 December 2027 and high-risk systems embedded in regulated products to 2 August 2028. Those dates are fixed rather than conditional on harmonised standards arriving, and the transparency duties still apply from 2 August 2026.

How does the EU AI Act map to ISO 42001?

ISO 42001 is the AI management system standard. Its clauses on AI policy, risk assessment, impact assessment, lifecycle controls, and monitoring line up closely with the Act's quality management, risk management, and post-market monitoring duties. Building an ISO 42001 system gives you most of the operational evidence the Act asks for, though not the legal conformity assessment itself.

Can you do AI governance without a dedicated compliance team?

Yes. A small business does not need a compliance department to be defensible. It needs one named owner, a current AI system inventory, a risk classification for each system, and documented human oversight for anything that affects people. Most of this is engineering discipline written down, not legal headcount.

Is OpenKit certified to ISO 42001 or an EU AI Act certifier?

No. OpenKit holds ISO 27001, ISO 9001 and Cyber Essentials, and operates to UK GDPR. OpenKit is not certified to ISO 42001 and is not a notified body or conformity assessor under the EU AI Act. We help clients design systems and governance that align toward those standards, then point you to accredited bodies for formal certification or assessment.

Does ISO 27001 cover the EU AI Act?

Partly. ISO 27001 governs information security and overlaps with the Act on risk management, documented procedures, and monitoring. It does not address AI-specific duties such as conformity assessment, model and training-data documentation, human oversight design, or bias testing. Treat it as a foundation, not a full answer.

What are the penalties under the EU AI Act?

Up to 35 million euros or 7% of global annual turnover, whichever is higher, for the most serious breaches such as prohibited practices, with lower bands for other infringements. The figures track the EU AI Act text and apply to providers and deployers in scope.

Settle the rules before you buy.

If this raised a question about what your own team is allowed to do, the answer is an AI Charter. It is four decisions with names against them, short enough that people actually read it. One Charter, agreed once, governs every system we build with you and every one your team runs after we have gone.

Find your first workflow.

We start with a conversation, audit where AI actually pays back, and build the first automation into how your team already works. We reply within one working day.