Skip to main content
ISO 42001

EU AI Act enforcement timeline for UK organisations

By Goldline Consultancy

11 min read

Contents

    UK organisations are not exempt from the EU AI Act. If you develop, deploy, or use AI systems that affect individuals in the European Union, regardless of where your organisation is based, the Act applies. This includes UK organisations selling SaaS into the EU, UK consultancies supplying AI-driven services to EU clients, UK manufacturers placing AI-enabled products in the EU market, and UK platforms whose users include EU citizens.

    This article sets out the enforcement timeline as amended by the Digital Omnibus on AI, and what UK organisations should be doing now.

    The published timeline

    The EU AI Act entered into force on 1 August 2024. The Act applies on a phased schedule with key milestones spread across three years.

    2 February 2025: The prohibitions of Article 5 and AI literacy obligations of Article 4 became applicable. Eight categories of AI use are now banned in the EU, including social scoring, predictive policing based solely on profiling, emotion recognition in workplaces and education, and certain real-time biometric identification practices. AI literacy requirements apply to providers and deployers of AI systems; staff using AI in operational contexts must have appropriate training.

    2 August 2025: Rules for general-purpose AI models took effect and EU-level governance structures, including the AI Office, AI Board, Scientific Panel, and Advisory Forum, became operational. Member States designated national competent authorities. Penalties for prohibited practices started applying.

    2 August 2026: The transparency obligations of Article 50 apply, except Article 50(2), which does not apply to systems already on the market at that date.

    2 December 2026: The Article 50(2) transparency requirements apply to legacy systems already on the market, and the new prohibited practices apply.

    2 August 2027: Member states must have established at least one national AI regulatory sandbox.

    2 December 2027: Obligations for high-risk AI systems apply to Annex III standalone systems, covering employment and worker management, creditworthiness, education, access to essential services, law enforcement, migration, and administration of justice.

    2 August 2028: Obligations for high-risk AI systems apply to Annex I systems, being AI embedded in products already regulated under EU product safety legislation, including medical devices.

    The Digital Omnibus amendment

    The original timetable set 2 August 2026 as the application date for high-risk obligations. The Digital Omnibus on AI, proposed by the European Commission in November 2025, amended this. Political agreement was reached on 7 May 2026, the European Parliament endorsed it on 16 June, and the Council gave final approval on 29 June 2026.

    The effect is a sixteen-month deferral for Annex III standalone systems and a two-year deferral for Annex I embedded systems. The transparency obligations under Article 50 were not deferred and apply from 2 August 2026 as originally scheduled. The prohibitions from February 2025 and the AI literacy obligations are unchanged.

    The obligations themselves are unchanged in substance. A provider or deployer still needs a risk management system, data governance documentation, technical documentation, human oversight procedures, and a fundamental rights impact assessment where required. Building that retrospectively under deadline pressure inside a system already running in production is materially harder than building it in from the start. Organisations treating the deferral as a reason to start now rather than to wait will spend less overall.

    What counts as high-risk AI under Annex III

    Annex III lists eight areas where the use of AI is considered particularly sensitive and where AI systems are classified as high-risk by default. The areas include biometrics, critical infrastructure, education and vocational training, employment and workforce management, access to essential services, law enforcement, migration and asylum, and administration of justice and democratic processes.

    For UK organisations, employment and workforce management is the area where high-risk classification arrives most often without warning. AI systems used to recruit or select individuals, place targeted job advertisements, analyse and filter applications, or evaluate candidates are classified as high-risk by default. Organisations using applicant tracking systems with AI features, AI-driven CV screening tools, or AI-augmented performance management platforms need to assess whether they fall within this scope.

    Critical infrastructure is the second area where UK organisations may be in scope without realising. AI systems used as safety components in road traffic, water supply, gas, heating, or electricity infrastructure are high-risk. UK organisations supplying technology to EU critical infrastructure operators are captured.

    What high-risk classification requires

    If an AI system is classified as high-risk under Annex III, the obligations are substantial. The provider must implement a risk management system covering the full lifecycle of the AI system. Data and data governance requirements apply, including bias detection and mitigation in training data. Technical documentation must be produced and maintained. Record-keeping obligations require automatically generated logs of system operation. Transparency requirements ensure deployers receive sufficient information to use the system safely. Human oversight must be designed in. Accuracy, robustness, and cybersecurity standards must be met. A quality management system must be in place.

    Penalties for non-compliance reach up to €35 million or 7% of global turnover for violations of prohibited practices, up to €15 million or 3% for high-risk violations, and lower amounts for other violations.

    Where ISO 42001 fits

    ISO 42001, published in December 2023, is the world's first AI management system standard. It is not the same as the EU AI Act, and certification does not equate to AI Act compliance. But the structural overlap is significant.

    ISO 42001 requires organisations to establish, implement, maintain, and continually improve an AI management system covering AI policy, AI risk management, AI lifecycle governance, supplier AI governance, and human oversight. These domains map directly onto the obligations the AI Act places on providers and deployers of high-risk systems.

    Organisations pursuing ISO 42001 certification will satisfy most of the documentation, governance, risk management, and oversight requirements the Act imposes. The remaining work is specific to the AI Act, including Annex III risk classification, Article 9 risk management system specifics, Article 10 data governance specifics, Article 11 technical documentation specifics, Article 13 transparency obligations, and the EU declaration of conformity for high-risk systems.

    UK regulators including the ICO and the FCA are signalling alignment with ISO 42001 as a credible governance approach. Procurement frameworks in regulated UK sectors are starting to ask suppliers about their AI governance posture.

    What UK organisations should be doing now

    Regardless of how the Omnibus question resolves, four pieces of work are usefully done now.

    AI inventory and use case classification. You cannot govern what you have not inventoried. Most organisations underestimate their AI footprint, particularly embedded AI in SaaS products and copilot tools.

    EU AI Act risk classification per AI use case. Identify which of your AI systems fall under Annex III, which are limited risk, which are minimal risk, and which would be prohibited. This is the foundation for everything else.

    AI governance framework establishment. Acceptable use policies, model selection criteria, data handling procedures, human oversight protocols, incident response procedures. This is the substantive work that ISO 42001 implementation produces.

    Supplier AI governance review. Most organisations have AI exposure they do not own. Microsoft Copilot, Salesforce Einstein, Google Workspace AI features, embedded AI in dozens of SaaS tools. The AI Act and ISO 42001 both treat embedded AI as in scope of your AI governance.

    Closing thought

    The EU AI Act applies to UK organisations regardless of Brexit. The high-risk deadlines have moved, but the preparation should not. The window between now and 2 December 2027 is the window in which organisations who get governance right will have a procurement advantage over those who do not.

    Goldline Consultancy is led by a senior practitioner ISO 27001 Lead Implementer (PECB) with deep ISO 42001 implementation and AI governance practice, SC-cleared, and supports UK and EU organisations on EU AI Act readiness, ISO 42001 alignment, and AI governance maturity. Take our free ISMS maturity self-assessment or book an AI governance diagnostic call.

    Alfred Obeng

    Founder of Goldline Consultancy. ISO 42001 Lead Implementer (PECB), ISO 42001 Lead Auditor (PECB), ISO 27001 Senior Lead Implementer (PECB), ISO 27001 Lead Auditor (PECB), CISSP, PMP.

    We use cookies and similar technologies to measure how this site is used, to see which organisations visit, and to measure our advertising. If you accept, we load Plausible, Google Analytics and Google Ads, Microsoft Clarity, which records session replays, and Apollo. Nothing loads until you accept. Read our Cookies policy.