Data & Economics
What does EU AI Act compliance actually cost a UK business?
The headline penalties are large and the deadline has moved twice. What a UK business actually needs to budget for, and whether the Act applies to it at all.
The short answer
The EU AI Act sets penalties up to 35 million euros or 7% of global annual turnover for the most serious violations, and up to 15 million euros or 3% for most other breaches of the Act, whichever figure is higher. Those penalty tiers have not changed. What has changed twice is the timeline: the original 2 August 2026 date for high-risk system obligations has been deferred by the EU's Digital Omnibus, with standalone high-risk systems now due 2 December 2027 and high-risk AI embedded in regulated products due 2 August 2028. Transparency obligations under Article 50 largely keep their original schedule. Whether any of this applies to a UK business at all depends on where the AI system is placed on the market or whose data it processes, not on where the company is based, the same extraterritorial logic as GDPR. A UK-only business with no EU market exposure may fall outside scope entirely; one that sells into the EU, or processes EU residents' data, likely does not.
Two numbers get repeated about the EU AI Act: a large penalty figure, and a deadline that has already moved once. Neither tells a UK business what to actually budget for, or whether the Act reaches it at all.
Does it apply to you
The Act's reach is not about where a company is registered. It applies based on where an AI system is placed on the EU market, or where its output is used, the same extraterritorial logic that made GDPR apply well beyond the EU's own borders. A UK business with an AI feature sold into the EU, or an AI system that processes EU residents' data, can find itself inside scope with no EU office and no EU staff. A UK business trading only with UK customers, on UK infrastructure, is the case most likely to sit outside it, but that conclusion is worth reaching deliberately, with an actual review of where the business's customers, data and AI outputs actually go, not assumed because the letterhead says London.
The deadline that moved, twice
The Act's high-risk system obligations were originally due to take full effect on 2 August 2026. That date has been superseded. The EU's Digital Omnibus on AI deferred the high-risk timeline: standalone high-risk systems under Annex III are now due 2 December 2027, and high-risk AI embedded in regulated products under Annex I is due 2 August 2028. The process ran through a provisional political agreement on 7 May 2026, European Parliament endorsement on 16 June 2026, and Council's final green light on 29 June 2026.
Not everything moved. Article 50's transparency obligations, disclosing that content is AI-generated or that a person is interacting with an AI system rather than a human, largely kept their original schedule. Treating the whole Act as pushed back is a common and costly misreading of what actually happened.
The deferral changed when the obligations start, not what they cost once they apply, and not the transparency rules that were never deferred.
What the penalties actually are
Article 99 of the Act sets three tiers, and in each case the fine is whichever figure is higher, the flat amount or the percentage of global turnover:
| Violation type | Maximum penalty |
|---|---|
| Prohibited AI practices (Article 5) | 35 million euros or 7% of total worldwide annual turnover |
| Most other obligations, including high-risk system requirements | 15 million euros or 3% of total worldwide annual turnover |
| Incorrect, incomplete or misleading information to regulators | 7.5 million euros or 1% of total worldwide annual turnover |
These figures were fixed when the Act was adopted and the Digital Omnibus deferral did not change them. What changed is the date the obligations that carry the 15 million euro or 3% tier actually start applying.
The cost that is not a fine
The penalty tiers get the attention, but for most businesses in scope, the real budget line is not a hypothetical fine, it is the cost of building the compliance work itself: a technical documentation package that actually describes what the system does and how, a risk management process that runs across the system's life rather than once at launch, human oversight that is a real function with the authority to intervene rather than a named person on an org chart, and record-keeping that can reconstruct a consequential decision after the fact rather than a log file nobody has read. None of that is free, and none of it is optional once a system is classified as high-risk. Building it once, correctly, before a deadline is not the same cost as building it in a rush after one has already passed.
What this means in practice
A UK business genuinely outside the Act's scope has no obligation to build any of this. A business inside scope has real time before the high-risk obligations bind, December 2027 for standalone systems, August 2028 for systems embedded in regulated products, but the transparency obligations that were not deferred may already apply now. The honest budgeting exercise has three steps: establish scope properly rather than assuming it, separate the transparency obligations that are live from the high-risk obligations that are not yet due, and treat the deferred window as time to build the documentation and oversight processes correctly rather than a reason to postpone the decision entirely.
Questions readers ask
- Does the EU AI Act apply to a business with no EU office?
- Possibly, yes. The Act applies based on where an AI system is placed on the EU market or where its output is used, not on where the provider is headquartered, the same extraterritorial reach as GDPR. A UK business selling software with an AI feature into the EU, or processing EU residents' data through an AI system, can fall inside scope even with no EU legal entity. A UK business trading only domestically, with no EU customers or EU data subjects, is the case most likely to fall outside it, but that is a judgement to make deliberately, not an assumption to skip.
- Has the 2 August 2026 deadline actually moved?
- Yes. That date was the original deadline for high-risk AI system obligations. The EU's Digital Omnibus on AI deferred it: standalone high-risk systems under Annex III are now due 2 December 2027, and high-risk AI embedded in regulated products under Annex I is due 2 August 2028. This followed a provisional political agreement on 7 May 2026, European Parliament endorsement on 16 June 2026, and final Council sign-off on 29 June 2026. Article 50's transparency obligations, such as disclosing that content is AI-generated, largely kept their original schedule and were not part of the deferral.
- What are the actual penalty amounts?
- Three tiers, set out in Article 99 of the Act, whichever figure is higher in each case: up to 35 million euros or 7% of total worldwide annual turnover for violations involving prohibited AI practices; up to 15 million euros or 3% for violations of most other obligations, including the high-risk system requirements; and up to 7.5 million euros or 1% for supplying incorrect, incomplete or misleading information to regulators. These figures were set when the Act was adopted and were not changed by the Digital Omnibus deferral. The deferral moved when the high-risk obligations start applying, not what the penalty is once they do.
Published by Mickai LTD. Written by Micky Irons.
Common Fortune covers the economics of the whole category and treats Mickai as one option among serious alternatives. About the journal and the team.
Mickarle Wagstaff-Irons - Micky Irons, full name Mickarle Sean Junior Wagstaff-Irons. Founder and CEO of Mickai. Biography and related work.