A risk-based structure, not a blanket ban

The EU AI Act classifies AI systems by risk: prohibited practices at one end, high-risk systems subject to detailed obligations, limited-risk systems with transparency requirements, and lower-risk systems with lighter expectations. Where a system sits depends on its use case, not on the technology alone.

Two dates worth knowing

The European Commission's current position gives an extended transition to 2 December 2027 for high-risk Annex III systems used in sensitive areas, and to 2 August 2028 for high-risk systems embedded in regulated products under Annex I. The proposed EU Omnibus wording refers to the same two dates. These are not abstract; they set the point by which provider and deployer obligations, including risk management, technical documentation, human oversight and post-market monitoring, need to be in place.

Why UK organisations still care

A UK company serving EU users, an AI product sold into multiple jurisdictions, or a general-purpose AI model used inside a UK business tool can all fall within scope depending on where the system is provided or deployed. Treating the EU AI Act as someone else's problem is a common and avoidable mistake.

It sits inside a wider global pattern

The EU AI Act is not developing in isolation. South Korea's AI Basic Act, growing US federal and state-level AI governance activity, and AI governance direction from Canada and China are all part of an international convergence around risk, transparency and accountability. Reading only one jurisdiction's rules leaves gaps for organisations operating internationally.

Provider or deployer: know which one you are

Provider obligations and deployer obligations are different, covering different evidence: technical documentation and conformity assessment sit mainly with providers, while deployer obligations focus more on use in context, human oversight and monitoring. Getting this distinction right early avoids collecting the wrong evidence later.

We cover EU AI Act classification, the global law landscape and the evidence each obligation needs in the AI Governance, Risk & Compliance Practitioner programme.