← Writing

EU AI Act 2026: Practical Checklist for UK SMEs

The EU AI Act is already binding. For many UK businesses, the next hard deadline is 2 August 2026, when transparency obligations under Article 50 start to bite for deployers, not just providers.

If you are a UK SME with customers or operations in the EU, or AI outputs that reach EU residents, the Act applies with extraterritorial reach: the same logic as GDPR. You do not need to be headquartered in Brussels to be in scope.

This checklist is a practical readiness pass for businesses up to £20M revenue that are already using AI (ChatGPT, Copilot, Claude, hiring tools, chatbots) but do not have a CISO or dedicated governance team.

Not legal advice. Use this to structure a conversation with qualified counsel and to decide what evidence you need before August.


Step 1: Inventory every AI use case (not every tool)

A spreadsheet of SaaS subscriptions is not governance. For each use case, capture:

If you cannot list ten use cases in thirty minutes, adoption width has outrun visibility. That is the primary risk.

See also: Compliance & governance focus


Step 2: Classify risk tier per use case

Map each use case to the EU AI Act risk framework:

TierExamples for SMEs
ProhibitedSocial scoring, manipulative practices: stop and get advice
High-riskHiring/screening, credit, essential services: full documentation path
LimitedChatbots, emotion recognition (where permitted): transparency duties
MinimalInternal spam filters, simple automation: lighter touch

Recruitment agencies and professional services firms often discover high-risk uses they treated as "just ChatGPT."


Step 3: Check transparency obligations (August 2026)

For limited-risk systems (many customer-facing chatbots), deployers must ensure users know they are interacting with AI. That is operational: website copy, call scripts, email footers, not a legal memo in a drawer.


Step 4: GDPR overlap: do not silo

Almost every AI use case touching personal data needs a UK GDPR lens:

ISO 42001 and commercial "AI quality marks" can help structure your programme, but they are not substitutes for EU AI Act conformity on their own.


Step 5: Evidence pack minimum

Before August, aim to hold:

  1. AI use-case register with owners and review dates
  2. Risk classification memo per material use case
  3. Human oversight record: who signs off what
  4. Vendor due diligence for third-party AI tools
  5. Incident / escalation path if AI output causes harm

Competitors sell scoping reviews for around £500 and sprints from £2,500–£10,000. The economics favour fixing governance before retrofit pressure; retrofit commonly runs 3–5× the cost of design-in.


Step 6: Decide your path

SituationSensible next step
Few tools, low riskRegister + quarterly review
Active AI in hiring, credit, or customer decisionsReadiness sprint + legal review
Board asking before AugustFixed-price sprint with 30-day action plan
Ongoing shadow AI growthMonthly governance monitoring

For software delivery under real operational constraints, Localhost Ltd runs Build, Managed Service, and Rescue engagements. For a practical readiness pass, keep this checklist and take the evidence pack to qualified counsel.


Related reading