INTELLIGENCE

The EU AI Act Is Now an Enforcement Problem for UK Firms.

The EU AI Act is already affecting UK companies that sell AI products or services into Europe. The key issue is not simply when each rule takes effect, but what those dates mean for product design, market access, contracts and responsibility. Organisatins that wait for the final deadlines may find that the important decisions have already been made for them.


AI governance / Regulatory intelligence 


9 September 2026 


Signal 


On 2 August 2026, the EU AI Act moved from implementation programme to enforcement regime. The European Commission's AI Office and national competent authorities now have enforcement powers, while the Act's transparency requirements under Article 50 also began to apply. The important change for UK businesses is not simply that another compliance date has passed. It is that the EU now has an operational mechanism for challenging AI systems supplied into its market — including certain systems supplied by organisations with no establishment in the EU.


Terrain 


The AI Act does not stop at the EU's physical border. 


Article 2 captures providers placing AI systems or GPAI models on the Union market regardless of where they are established. It also reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union.


That matters for UK firms whose commercial model is described internally as simply "selling into Europe." The relevant question is more granular: what is the firm supplying, to whom, in what role, and where is the resulting AI output used? 


The answer can move an organisation into a very different regulatory position. 


A UK software company supplying an AI-enabled product to an EU customer may be a provider. A UK group using an AI system on behalf of its EU operation may be a deployer. A UK business supplying a general-purpose AI model into the EU faces a different supervisory architecture again, with the AI Office directly responsible for GPAI providers.


And the dates are no longer one deadline. 


The prohibitions and AI-literacy requirements are already in force. GPAI obligations are already applicable, with Commission enforcement now active. Article 50 transparency requirements apply from 2 August 2026, subject to a limited 2 December 2026 transition for certain AI-generated-content marking obligations relating to systems already on the market. The principal high-risk regime has moved further out: Annex III high-risk systems are scheduled for 2 December 2027, while high-risk AI embedded in regulated products under Annex I is scheduled for 2 August 2028.


That creates a regulatory sequence, not a single compliance date. 


Judgment 


The mistake is treating the AI Act timeline as a calendar. It is a decision tree. 


A UK firm does not need to wait for the date on which a particular obligation becomes enforceable to decide what it is going to sell, where it is going to sell it, or which entity in its group will carry the regulatory burden. 


That decision has commercial consequences now. 


For a business selling AI-enabled products into the EU, the critical question is not "When do we need to comply?" It is "Which regulatory state are we building the business into?" 


That distinction matters because product architecture, contractual allocation of responsibility and market-entry strategy can become much harder to change after deployment. 


Take transparency. From 2 August 2026, Article 50 requires providers and deployers of certain AI systems to meet specific transparency obligations, including informing individuals when they are directly interacting with AI and applying machine-readable marking to certain AI-generated or manipulated content.


For a UK firm launching an AI product into the EU, this is not merely a compliance team's documentation exercise. It can affect product design, user journeys, content pipelines and customer contracts


The same logic applies further down the timeline. If the product could fall within the Annex III high-risk regime, waiting until late 2027 to discover that the product's governance architecture cannot support the required controls is not regulatory prudence. It is an avoidable product decision made too late. 


The AI Act therefore creates commercial decision points before it creates enforcement deadlines


That is the part of the timeline UK firms should be managing. 


Course of action 


1. Decide whether the EU is a market, a deployment environment, or both. 


Map each AI product against the Act's territorial triggers and identify the entity, customer and use case that bring it within scope. Do not use "UK company selling into Europe" as the compliance classification. Determine whether the organisation is acting as provider, deployer, importer, distributor or another actor in the AI value chain. The result should be a product-level scope determination, not a generic corporate position. 


2. Freeze the regulatory classification before the next product release. 


For each AI product entering the EU market, determine whether the relevant obligations are already live, arrive on 2 December 2026, or sit on the 2027–28 high-risk timetable. Where classification is uncertain, treat that uncertainty as a product and market-access issue rather than leaving it as an unresolved legal footnote. The Commission's own guidance makes clear that the high-risk timetable now extends to December 2027 and August 2028 depending on the legal basis for classification.


3. Put regulatory ownership into the commercial architecture. 


For UK-EU contracts, decide now who is responsible for the obligations created by the AI Act: the UK provider, the EU customer, an importer or another actor in the chain. Contractual language cannot change the statutory classification where the Act assigns obligations to a particular actor, but it can determine who carries operational responsibility, information duties, remediation costs and escalation rights between the parties. 


4. Treat 2027–28 products as today's governance decisions. 


If an AI product is likely to enter a high-risk category, build the required governance capability into its development and procurement cycle now. Waiting for the enforcement date confuses legal applicability with implementation lead time. By the time an obligation becomes enforceable, the expensive decisions — architecture, data practices, documentation, human oversight and supplier dependencies — may already have been made.

Beyond advice. Into action.

Beyond advice. Into action.

MERIOL. INTELLIGENCE.

© 2026 Meriol Intelligence. All rights reserved.