The short version
Three things are true at once, and conflating them is where most of the confusion comes from.
The transparency rules are live. Article 50 obligations applied from 2 August 2026 and were not postponed. If your product talks to people, generates content, or produces synthetic media, this affects you now.
The high-risk rules moved. Under the Digital Omnibus amendments, obligations for Annex III high-risk systems now apply from 2 December 2027, and for high-risk AI embedded in regulated products under Annex I from 2 August 2028. That is genuine breathing room, not a cancellation.
The UK has no AI Act. There is no UK equivalent in force and no AI Bill before Parliament. UK obligations come from existing law — principally UK GDPR as amended by the Data (Use and Access) Act 2025, enforced by the ICO — applied through sector regulators.
The timeline, as it now stands
| Date | What applies | Status |
|---|---|---|
| 2 February 2025 | Prohibited practices; AI literacy duties; definitions | In force |
| 2 August 2025 | General-purpose AI model obligations; national authorities and penalties | In force |
| 2 August 2026 | Article 50 transparency rules; enforcement begins for prohibitions, GPAI, transparency and AI literacy | In force |
| 2 December 2026 | Transitional deadline for certain systems already on the market, including machine-readable marking | Upcoming |
| 2 August 2027 | Full compliance deadline for GPAI models placed on the market before August 2025 | Upcoming |
| 2 December 2027 | Annex III high-risk system rules (amended by Digital Omnibus) | Delayed from Aug 2026 |
| 2 August 2028 | Annex I high-risk AI in regulated products (amended by Digital Omnibus) | Delayed |
Does it apply to a UK company?
The Act is extraterritorial, and the test is not where you're incorporated. You are in scope where there is an EU nexus — broadly, if you place an AI system on the EU market, if the output of your AI system is used in the EU, or if the system affects people located in the EU. Practically, that catches a lot of UK SaaS businesses:
You are likely in scope if:
Note the provider/deployer distinction, because it determines which obligations land on you. A provider develops an AI system and puts it on the market under its own name. A deployer uses an AI system under its own authority. Most UK SMEs are deployers of third-party AI, which carries a lighter but non-zero set of duties. UK SaaS companies shipping AI features to customers are usually providers, which is the heavier position — and one plenty of teams have not realised they occupy.
What Article 50 actually requires
This is the part that is live now, and it is more tractable than the compliance industry sometimes implies. Four duties matter for typical software products.
1. Tell people they're talking to AI
Where a system interacts directly with people, users must be informed that they are interacting with an AI system unless it is obvious from context. A small persistent label on a support chat widget usually satisfies this. A cheerful human-sounding name with no disclosure does not.
2. Disclose AI-generated or manipulated content
Content generated or materially altered by AI must be disclosed where it could mislead. This matters for AI-drafted customer communications, generated imagery in marketing, and synthetic audio in any customer-facing flow.
3. Mark synthetic content machine-readably
Providers of systems generating synthetic audio, image, video or text must mark outputs in a machine-readable format — watermarking, metadata, or similar — so the content can be detected as artificially generated downstream. Pre-existing systems have until 2 December 2026 on this point.
4. Label deepfakes and certain published text
Deepfake content must be labelled as artificially generated. Text published to inform the public on matters of public interest must be disclosed as AI-generated unless it went through human editorial review with someone holding editorial responsibility.
Alongside these, the AI literacy obligation from February 2025 remains in force: organisations must take measures to ensure staff dealing with AI systems have a sufficient level of understanding. For most SMEs that is a documented internal training session and a written acceptable-use policy, not a compliance programme.
The UK picture: no Act, more regulators
UK businesses sometimes read "no UK AI Act" as "no UK AI regulation." That is the wrong conclusion. The UK has chosen a principles-based, sector-led approach that spreads AI oversight across existing regulators rather than concentrating it in one statute.
The ICO is the closest thing to a general AI regulator, because most AI systems process personal data and therefore fall under UK GDPR and the Data Protection Act 2018 as amended by the Data (Use and Access) Act 2025. Its existing guidance on AI and data protection is the practical baseline for UK deployments. The FCA governs AI in financial services through the FSMA framework and Consumer Duty; Ofcom covers online safety and telecoms.
The awkward consequence for a UK business with EU customers is that you are mapping two regimes simultaneously: an EU framework organised by risk tier, and a UK framework organised by sector and by data protection law. The good news is the underlying engineering overlaps heavily — documentation, logging, human oversight, and the ability to explain a decision serve both.
What to actually build
Most of what these regimes ask for is engineering work you should probably be doing anyway. In rough order of value:
Practical priorities for the next two quarters:
If you have any system plausibly in Annex III territory — recruitment and worker management, access to essential services, creditworthiness, education assessment — the December 2027 date is far enough away to design properly and close enough that it belongs on the roadmap now. Risk management documentation, data governance, technical documentation, automatic logging, and accuracy and robustness measures are not things you retrofit in a quarter.
AyTech note: The delay to the high-risk deadlines is a genuine gift of time, and the worst possible response is to spend it. Teams that use the window to build the inventory, logging, and oversight layer will find the 2027 obligations mostly a documentation exercise. Teams that wait will be doing architecture under deadline.
This article is general technical guidance for engineering and product teams, not legal advice. Regulatory timelines have moved more than once; confirm the current position with a qualified adviser before making compliance decisions.
Need your AI features audited against this?
AyTech can inventory your AI systems, identify where you sit as provider or deployer, and turn the gaps into a scoped engineering plan.
Book a technical review