Skip to main content
Part of Applied AI Solutions Ltd

Compliance

The EU AI Act applies to you even though we left the EU

· 7 min read

The most common thing Midlands manufacturers say about the EU AI Act is that it does not apply to them. Most of them are wrong, for the same reason GDPR applied: the regulation follows the market, not the company's address.

If you place an AI-enabled product on the EU market, or the output of an AI system you use is used in the EU, you are in scope.

The dates

The Act phases in, and two milestones have already passed:

  • 2 February 2025 — prohibited practices took effect
  • 2 August 2025 — obligations on general-purpose AI model providers
  • 2 August 2026 — transparency requirements under Article 50, and the AI Office's enforcement powers. Systems already on the market before this date have until 2 December 2026 to comply
  • 2 December 2027 — the substantial high-risk obligations under Annex III
  • 2 August 2028 — high-risk obligations under Annex I, which is where products with safety components sit

Note where you are in that list. The transparency duties are live now, and the grace period for existing systems runs out in December.

Transparency, in practice

For most SMEs this is the obligation that bites first, and it is not onerous: people should know when they are dealing with an AI system rather than a person, and AI-generated content should be identifiable as such.

If you have a chatbot on your website, that is in scope. If you generate customer-facing content, that is in scope. The fix is usually a sentence of disclosure, not an engineering programme — but it has to actually be there.

Where manufacturers get caught

The high-risk category is the one that matters for product businesses, and it is broader than people expect. AI used as a safety component of a product — vision systems that make pass/fail decisions, predictive maintenance that determines whether a machine keeps running, control systems that adjust a process without human input — can fall into it.

The obligations then look familiar to anyone who has been through CE marking: risk management, data governance, technical documentation, logging, human oversight, accuracy and robustness standards, conformity assessment, registration.

That is a product development programme, not a compliance form. Which is why December 2027 is closer than it looks.

Provider or deployer?

The distinction decides how much lands on you. Broadly, if you build or badge the AI system, you are a provider and carry the heavier set. If you use someone else's system in your operations, you are a deployer and carry a lighter but real set.

The trap: if you put your name on a product containing someone else's AI, you may be the provider as far as the regulation is concerned — the same way you carry responsibility for a bought-in component under product safety law.

What to do now

Inventory first. You cannot classify what you have not listed. Write down every AI system you build into products, and every AI system you use in operations — including the ones your staff adopted without telling you.

Then classify each one: prohibited, high-risk, limited-risk with transparency duties, or minimal. Most SME uses land in the last two, and finding that out is reassuring rather than alarming.

Then, for anything plausibly high-risk, start the documentation now. Not because the deadline is imminent, but because retrofitting a risk management file to a product already in the field is far more expensive than building it alongside.

Worth noting if you make connected products: this sits alongside the Cyber Resilience Act, whose reporting duties went live on 11 September 2026. Different regulation, overlapping products, and both have documentation demands that are cheaper to meet together than separately.