UK firms hear "EU AI Act deadline" and picture one cliff-edge date. There are two separate deadlines, for two different reasons, and conflating them means either scrambling for something you have until December 2027 to fix, or missing something that's due in three weeks.

2 August 2026 is real, and it's about transparency, not risk classification. If your firm uses AI to generate content, or deploys any system that interacts directly with clients, Article 50 requires you to disclose that. This applies regardless of sector or use case — a client-facing chatbot, AI-drafted correspondence, synthetic voice or image tools all fall under it. This date was not moved by the Digital Omnibus, now formally adopted as of 29 June 2026.

2 December 2027 is the one that moved — the "high-risk" regime under Annex III. This is the heavier obligation set: documented risk management, technical documentation, human oversight design, conformity assessment, registration. It only applies if your AI system falls into one of Annex III's listed domains — most relevantly for regulated professional services, credit and creditworthiness assessment and employment decisions (recruitment, performance management, termination). A general-purpose drafting tool or research assistant doesn't trigger this regime. An AI system that scores a client's creditworthiness or screens job candidates does.

The practical read for UK regulated firms: don't let the December 2027 extension become a reason to stop working — inventory and classification take as long whenever you start them, and the underlying obligation to know what your AI systems do and where they sit doesn't change. But do stop telling clients or your own board that "the AI Act deadline" is one date in August. It isn't.

Date What happens
2 August 2026 Article 50 transparency obligations apply — labelling AI-generated content, disclosing AI interaction. Untouched by the Omnibus.
2 December 2026 Article 50(2) extends to legacy systems already on the market before August 2026. New Article 5 prohibition on AI-generated non-consensual intimate imagery and CSAM takes effect the same date.
2 August 2027 Member states must have an AI regulatory sandbox running. Not a compliance deadline for firms.
2 December 2027 Annex III high-risk obligations apply — risk management systems, technical documentation, human oversight architecture, conformity assessment, registration. Deferred from 2 August 2026 by 16 months.
2 August 2028 High-risk obligations for AI embedded in already-regulated products (Annex I — medical devices, machinery, vehicles) apply.

This is a plain-English checklist of what the Act requires in practice — written for the people who will have to deliver it, not the lawyers who will advise on it.

Who this applies to

One thing worth checking before any of this applies to you at all: the EU AI Act's reach depends on where your AI system's output is used or placed on the market, not simply on being a UK regulated firm. A solicitor or IFA serving only UK clients, with no EU-facing operations, may not be in scope at all. If you're unsure, that's worth resolving before the checklist below, not after.

Where the Act does apply, the relevant question for most firms is not whether it applies. It is which of your AI systems fall into the high-risk category under Annex III — and whether you can evidence compliance for those systems before the 2 December 2027 high-risk deadline. The transparency obligations under Article 50, by contrast, apply from 2 August 2026 and are not limited to high-risk systems.

High-risk AI systems under Annex III of the Act include systems used in:

Two sectors deserve particular attention because they are both explicitly named in Annex III and significantly underserved on governance guidance:

Recruitment and HR firms — if you use AI in any part of the hiring process, from CV screening to candidate ranking to interview scheduling, you are operating a high-risk AI system under the Act. This is one of the most clearly named categories in Annex III. It is also the sector with the least practical compliance guidance available in plain English right now.

Education providers — AI used in student assessment, admissions decisions, or learning personalisation falls within scope. Many EdTech platforms and further education providers are not yet aware of their exposure.

For financial services firms, solicitors, accountants and IFAs — the high-risk classification may or may not apply depending on what your AI is doing. The key question is whether your AI is making or materially influencing a decision that affects a person's access to services, employment, or legal rights. If the answer is yes or possibly yes, treat it as high-risk until you can evidence otherwise.

If you are not sure where your organisation stands, the TrustProof free AI accountability check identifies your specific governance gaps in five questions — no email required.

The checklist — what you need to have in place

The Act's requirements for high-risk AI systems are grouped below into five practical areas. This is not legal advice — it is a practitioner's summary of what compliance looks like in an organisation that has to deliver it.

Not every item below has the same deadline. AI inventory and accountability aren't EU AI Act line items at all — they're the foundation every other obligation depends on, and worth having regardless of which regime applies to you. Human oversight design matters for both Article 50 transparency contexts and Annex III high-risk contexts, though the bar is considerably higher for the latter. Technical documentation and conformity assessment are specifically Annex III obligations — they apply from 2 December 2027, only if you have a system that falls into one of Annex III's listed domains.

1. Know Your AI (KYAI) — understand what you are running

In financial services we talk about KYC — Know Your Customer. The equivalent for AI governance is more urgent right now: Know Your AI. Before anything else, you need a documented inventory of every AI system in use across the organisation.

This sounds straightforward. It is not. Most organisations have AI embedded in tools they did not deploy as AI — Microsoft Copilot, automated decisioning in CRM systems, AI-assisted underwriting tools, chatbots with escalation logic. Staff are also using AI tools individually that the organisation has no visibility of.

What you need:

The Act refers to this obligation under Article 49 — the requirement to register high-risk AI systems. But the practical starting point is the inventory, not the registration. You cannot register what you have not found.

Under GDPR Article 30, you are also required to maintain a record of processing activities. If AI tools are processing personal data — and most are — this obligation already exists and the AI inventory should sit alongside it.

2. Assign accountability

For every AI system classified as high-risk, the Act requires a named individual who is accountable for its deployment, operation, and outcomes.

In financial services, this maps directly onto SM&CR. The FCA has confirmed that existing frameworks apply to AI — "the model decided" is not a governance position. A Senior Manager decided. The model was the mechanism.

For solicitors, the named accountable individual maps to the Compliance Officer for Legal Practice (COLP) — the SRA-designated role responsible for ensuring the firm complies with regulatory arrangements, now explicitly extended to AI use. For all UK firms, the Data Use and Access Act 2025 already requires that a named individual can account for any AI-assisted decision that materially affects a person — regardless of whether EU AI Act obligations have yet taken effect. The ICO is required by SI 2026/425 (in force 12 May 2026) to publish a statutory Automated Decision-Making Code, expected summer 2026, which will set out the detail of that accountability.

For other regulated sectors, the accountability requirement is the same even if the framework has a different name. Someone in the organisation needs to be able to answer, under regulatory scrutiny, for every material decision the AI system influenced.

What you need:

The accountability gap is the most common gap we see in practice. Organisations have deployed the AI. They have no clear answer to the question: if this produces an outcome that harms someone, who is responsible?

3. Document your human oversight arrangements

One of the Act's central requirements for high-risk systems is meaningful human oversight — not just a human in the loop, but a human who is genuinely able to understand, monitor, and where necessary override the AI's outputs.

What you need:

The Act uses the phrase "appropriate human oversight measures" — the standard is not just that someone clicked approve. In practice, this means your oversight process needs to be documented, followed, and evidenced. A quarterly review meeting is not meaningful human oversight of a system making daily decisions.

The ICO has been explicit on this point: a review that amounts to rubber-stamping AI output does not satisfy the meaningful human involvement test under UK data protection law. The standard is not whether a human was present — it is whether that human was genuinely able to understand, challenge, and override the AI's output. Documenting that standard is being met is the compliance requirement.

4. Build your technical documentation

For high-risk AI systems, the Act requires technical documentation that describes what the system does, how it was developed, what it was tested on, and how its performance is monitored.

If you bought the AI from a third-party vendor, some of this documentation should come from the vendor. Many UK organisations are discovering that their vendors cannot provide it — either because the vendor is outside the EU and did not anticipate the requirement, or because the documentation does not exist in the required form.

What you need:

Organisations using large language models face particular uncertainty here. LLMs do not come with clean documentation of training data or performance characteristics in the way a traditional model does. If you are using an LLM in a high-risk context, the documentation challenge is significant and worth addressing now.

5. Complete your conformity assessment

Before a high-risk AI system can be put into service under the Act, it requires a conformity assessment — a formal evaluation that the system meets the Act's requirements.

For most systems, this is a self-assessment. It does not require a third party. But it does require documentation, and for high-risk systems already in operation it needs to be complete by the 2 December 2027 deadline. That is over a year away, but the inventory and classification work that tells you whether a system needs a conformity assessment at all takes just as long whenever you start it.

What you need:

The penalty for non-compliance with the high-risk system requirements is up to €35 million or 7% of global annual turnover — whichever is higher. For a small professional services firm, the absolute figure is lower, but the proportional impact is the same.

The governance gap most organisations have right now

Research from Cambridge University's Centre for Alternative Finance, published April 2026 across 628 firms, found that 52% of organisations are already piloting or deploying autonomous AI agents — but accountability frameworks are absent or fragmented. 65% do not monitor their AI systems for bias or discrimination despite it being a regulatory priority.

These are organisations that deployed AI faster than governance could follow. The Act is, in effect, a forcing function — a set of fixed deadlines that require the accountability architecture to catch up with the deployment reality.

The organisations that will navigate both deadlines well are not the ones with the most sophisticated AI. They are the ones that treated this as a delivery programme — assigned an owner, scoped the work, documented the outputs, and got sign-off ahead of the date that actually applies to each obligation.

Where to start if you have not started

If your organisation has not yet begun this work, the practical starting point is the inventory. Not the legal framework, not the conformity assessment — the inventory.

List every AI tool in use. Classify each one against Annex III. Identify which trigger Article 50 transparency obligations from August 2026, and which fall into the high-risk regime that applies from December 2027. Then work backwards from whichever date applies, with a realistic delivery plan.

That exercise alone — done honestly — will surface the gaps that matter. It is, in effect, your Know Your AI audit. It will also tell you whether you can close them internally in time, or whether you need external support to get there.

Free diagnostic tool

Not sure which of these gaps apply to your firm?

Run the free AI Accountability Check — five questions, instant gap map, no email required to see your results.

Check your firm's exposure →

There is enough time if you start now — the 2 August 2026 Article 50 transparency deadline is weeks away, and the 2 December 2027 high-risk deadline rewards early inventory work rather than a late scramble. There is not enough time if you wait until the guidance feels complete.