Most people arrive at this question sideways. A client's procurement form asks whether your AI systems are AI Act compliant, or somebody on LinkedIn posts a screenshot of a €35m fine, and you go looking for the answer at half past ten on a Tuesday night.
The honest version is that the Act probably touches you, that what it asks of a small B2B firm is much shorter than the internet suggests, and that a fair amount of what you'll read about it describes a version of the law that changed in July 2026.
We're a growth consultancy, not a law firm. Nothing here is legal advice. It's written to help you work out whether you need to pay for some.
The short answer
If your business has EU customers, EU-based staff, EU prospects sitting in an outbound sequence, or an EU visitor who can open a chat widget on your website, you are probably in scope of Regulation (EU) 2024/1689. No EU entity is required. No office in Dublin, no VAT number, nothing.
What that scope means in practice, for a firm under about fifty people running ordinary commercial software, is a handful of transparency duties and a requirement to help your staff understand the tools you've given them. It is not the certification-and-conformity machinery you may have read about. That machinery is aimed at high-risk systems, which is a defined category, and a website chatbot is not in it.
Why Brexit doesn't settle this
Article 2(1) sets the territorial scope, and point (c) is the one that catches UK companies. It applies the Regulation to:
providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union
Read that twice, because the trigger is where the output lands, not where you are or where your server is. A UK consultancy running an AI tool that drafts personalised outbound emails, sent to a list that includes forty prospects in Amsterdam and Munich, is producing output used in the Union. The people receiving it are also "affected persons located within the Union" under Article 2(1)(g).
There's no de minimis threshold written into that test. Whether it bites on a handful of EU contacts is exactly the sort of question a qualified adviser should answer for your specific setup, and it's the first thing we'd send to one if you sell into Europe at all. What you shouldn't do is assume the answer is no because you left the single market.
The dates that matter
| Date | What applied | Status |
|---|---|---|
| 1 Aug 2024 | Regulation (EU) 2024/1689 entered into force | Done |
| 2 Feb 2025 | Prohibited practices (Article 5), AI literacy duty (Article 4) | In effect |
| 2 Aug 2025 | General-purpose AI model rules, governance, penalties | In effect |
| 2 Aug 2026 | Transparency obligations (Article 50), general applicability | In effect |
| 2 Dec 2026 | Grace period ends for machine-readable marking of generative systems already on the market before 2 Aug 2026 | Coming |
| 2 Dec 2027 | Standalone high-risk systems (Annex III) | Deferred |
| 2 Aug 2028 | High-risk AI embedded in regulated products (Annex I) | Deferred |
The last two rows moved. Both sets of high-risk obligations were originally due on 2 August 2026. They were pushed back by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Standalone high-risk systems listed in Annex III now have until 2 December 2027; AI built into products already covered by EU product safety law has until 2 August 2028.
Anything you read that was written before the summer will describe 2 August 2026 as the high-risk deadline. It was, and then it wasn't. Check the date on the article before you act on it.
Deployer vs provider: which one are you?
The Act splits duties between the person who builds and markets an AI system and the person who uses one. Most of the weight sits on the provider.
- A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.
- A deployer uses an AI system under its own authority, in the course of its own business.
Buy Intercom, switch on the AI agent, put it on your site: you're a deployer. Take a white-label conversational AI product, brand it as YourFirm Assist, and sell it on to your own clients as part of a retainer: you may have become a provider, with a materially heavier set of obligations, including the design duties in Article 50(1) and (2).
That second scenario is more common than it sounds among agencies and consultancies, because putting your name on somebody else's model is the standard way of packaging AI as a service right now. If any part of your offer involves reselling or rebranding an AI tool, get this classified properly rather than assuming you're on the light side of the line.
What Article 50 actually asks for
Article 50 has applied since 2 August 2026 and it's the part most small businesses are exposed to. Four obligations, and they don't all land on the same party:
| Provision | Applies to | What it requires |
|---|---|---|
| 50(1) | Provider | An AI system that interacts directly with people must be designed so those people are informed they're dealing with an AI system, unless that's obvious to a reasonably well-informed, observant and circumspect person |
| 50(2) | Provider | Outputs of generative systems, including synthetic audio, image, video and text, marked in a machine-readable format and detectable as artificially generated |
| 50(3) | Deployer | People exposed to emotion recognition or biometric categorisation must be told the system is operating |
| 50(4) | Deployer | Disclose deep fakes, and disclose AI-generated text published to inform the public on matters of public interest |
Two things worth pulling out of that table.
The first is the "unless this is obvious" carve-out in 50(1). It is not a loophole you can argue your way into after the fact. A widget in the corner of your site called Ava, which opens with "hi, what brings you here today", is not obviously software to a normal buyer, which is the entire reason it was named Ava. A line at the top of the chat costs you nothing and settles it.
The second is the editorial exemption in 50(4). The text disclosure duty is aimed at AI-generated text published to inform the public on matters of public interest, and it does not apply where the text has gone through human review and a person or company holds editorial responsibility for it. Your blog post, drafted by a model and edited by you before it went out, is not what that provision is chasing. If you publish machine-generated commentary on public affairs with nobody reading it first, it is.
Note also the four-month grace running to 2 December 2026, which covers only the machine-readable marking requirement, and only for generative systems that were already on the market before 2 August 2026. It is not a general extension.
The AI literacy duty got easier in July
This one is worth knowing because almost nothing written about it is current.
Article 4 has applied since February 2025. The original wording required providers and deployers to "ensure, to their best extent, a sufficient level of AI literacy" among staff and anybody operating the systems on their behalf. That is an obligation of result: you had to reach a level.
The Digital Omnibus rewrote it, with effect from 27 July 2026. Providers and deployers now "take measures to support the development of AI literacy", and the amended article says explicitly that this does not require anyone to guarantee any specific level of AI literacy of any individual. It became an obligation of effort.
It did not disappear. Every deployer still owes it, which includes you if there is a single AI tool in the business that a member of staff touches. What changed is that a documented hour of training plus a one-page policy on what may and may not be pasted into a model is now much closer to the shape of what the law asks for. Date it, minute it, keep it. For a team of eight, that is proportionate.