AI Governance

The EU AI Act Is Now Being Enforced — Does Your Business Know What AI It Is Using?

IT Club9 minutes read21 August 2026
WhatsAppEmail
The EU AI Act Is Now Being Enforced — Does Your Business Know What AI It Is Using?

A plain-English, vendor-neutral guide to the EU AI Act for UK SMEs. It explains the August 2026 changes, possible UK business connections to the Act, AI literacy, Article 50 transparency, unmanaged AI, risk and waste, and sensible governance steps without presenting legal advice.

AI regulation is no longer something sitting several years in the future. The EU AI Act became broadly applicable on 2 August 2026, enforcement powers became active and new transparency requirements started applying to certain AI systems and uses.

But this does not mean every UK SME suddenly needs an “EU AI Act compliance project”. The Act has a defined scope, different duties for different roles and some requirements that apply on later dates.

The more useful question is this:

IF SOMEBODY ASKED TOMORROW:

Which AI systems do you use?
Who uses them, and for what?
What data goes into them?
Which tools are approved?
What are you paying for?
How do you govern the use?

COULD YOU ANSWER?

For many businesses, the answer will be no. That is an AI visibility problem before it is an EU legal problem.

Important context

This article is general technology information for UK businesses. It is not legal advice, an EU AI Act compliance assessment or a statement that the Act applies to every UK company. If your organisation's activities, customers or supply chain create a material EU connection, seek advice from a suitably qualified legal or compliance professional.

What changed in August 2026?

The EU AI Act entered into force on 1 August 2024. It was designed as a risk-based regulation: different requirements apply depending on the AI system, its role in the value chain and how it is used.

DateWhat happened
1 August 2024The Regulation entered into force. The transition towards the new AI framework began.
2 February 2025The rules on prohibited AI practices began applying, along with the AI literacy obligation.
2 August 2025Governance rules and obligations for providers of general-purpose AI models began applying.
2 August 2026The Act became broadly applicable, enforcement powers became active and Article 50 transparency obligations began applying.
Later datesSome high-risk AI requirements and rules for certain systems embedded in regulated products have later implementation dates, including dates in 2027 and 2028.

“Broadly applicable” is not the same as “every provision applies to every system today”. The Act contains exceptions, role-based duties, later dates and detailed definitions. A headline about enforcement should prompt an inventory and scope review, not an assumption that every AI use is now subject to the same checklist.

European Commission: AI Act regulatory framework and timeline

European Commission: enforcement and new transparency requirements from 2 August 2026

Does the EU AI Act apply to UK businesses?

Not automatically. A business being based in the United Kingdom is not, by itself, an answer to the scope question.

The Act can matter to an organisation outside the EU where its role or activity has an EU connection described by the Regulation. For example, a UK organisation may need to investigate its position if it:

  • operates in the EU;
  • provides or deploys an AI system in the EU;
  • supplies EU customers with a product or service involving AI;
  • places an AI system or AI-enabled product on the EU market;
  • produces AI-generated outputs that are used in the EU;
  • forms part of an EU customer's AI-related supply chain; or
  • has agreed through a customer or supplier contract to demonstrate particular AI governance controls.

The exact position depends on the facts: what the organisation does, where the system is placed or used, whether it is a provider or deployer, what the output is used for and which contractual relationships exist. “We are a UK company” is not a complete scope analysis, but neither is “we use an AI tool, so the whole Act applies”.

A sensible scope question

If an EU customer, regulator or procurement team asked how your AI use is governed, could you show the relevant tools, owners, data boundaries, review steps and supplier information?

This is a practical governance question, not a substitute for legal advice. Where the EU AI Act may materially affect your organisation, get the scope checked rather than relying on a generic online summary.

AI literacy: already relevant

The AI literacy obligation began applying in February 2025. It is easy to overstate this as “every employee must now complete certified AI training”. That is not a safe summary.

In practical terms, a business using AI should consider whether the people operating it understand enough about the systems they use and the risks of that use. The right level of knowledge depends on the person's role, the system and the risk.

People should understandPractical example
Appropriate useWhat the approved tool is for, and which decisions must stay with a person
LimitationsThat a fluent answer can still be inaccurate, incomplete or invented
Data and privacy risksWhat personal, confidential, client or commercially sensitive information must not be pasted into a tool
VerificationHow to check facts, figures, sources, calculations and customer-facing output
EscalationWho to ask when a prompt, output, data use or AI decision is unclear
Company policyWhich accounts and tools are approved, and how to report a mistake

A short briefing, a plain-English policy, examples relevant to the job and a clear reporting route may be more useful than a generic course certificate. Keep a record of what guidance was provided and review it as tools and use cases change.

IT Club AI Policy Starter Guide

IT Club: Safe Use of Generative AI at Work

What is Article 50 transparency?

Article 50 contains transparency obligations for providers and deployers of certain AI systems. They are not a requirement to put an “AI generated” label on every internal draft or to announce every routine use of ChatGPT or Copilot.

In broad terms, the obligations cover situations such as:

  • informing people when they are interacting directly with certain AI systems, such as an interactive system that could otherwise be mistaken for a human;
  • designing systems so AI-generated or manipulated content can be detected through machine-readable marking where the relevant obligation applies;
  • informing people when they are exposed to certain emotion-recognition or biometric-categorisation systems;
  • labelling or disclosing deepfake image, audio or video content; and
  • disclosing certain AI-generated or manipulated text published on matters of public interest where the relevant conditions apply.

The details matter. Article 50 contains different duties, exemptions and conditions, and the European Commission's guidance explains concepts such as direct interaction, synthetic content, deepfakes, public-interest text and standard editing.

What this does not mean

It does not mean that every routine use of ChatGPT, Copilot, Gemini or an AI writing feature automatically needs a public label. First identify the system, the role, the content, the audience and the specific obligation that could apply.

European Commission: Quick facts on AI transparency rules

European Commission: Guidelines on AI transparency obligations

The much bigger SME problem: unmanaged AI

Most businesses do not have an EU AI Act problem first. They have an AI visibility problem.

Staff may already be using ChatGPT, Microsoft Copilot, Gemini, Claude, meeting transcription tools, AI design software, AI features built into SaaS applications and personal AI subscriptions. They may be using them in entirely sensible ways to save time.

Management may not know:

  • which tools are in use;
  • which accounts people are using;
  • what company or customer data goes into them;
  • which tools are approved;
  • what is being paid for;
  • which AI features were switched on by a software update;
  • what business value is being obtained; or
  • who would answer a customer, insurer or supplier asking about AI governance.

That is the practical connection between the EU AI Act and ordinary SME management. You cannot decide whether a system is in scope, suitable, transparent or worth its cost if you do not know it exists.

Shadow AI: The Tools Your Team Isn't Telling You About

The six questions every business should answer

Do we know?

  1. 1What AI systems are being used?
  2. 2Who is using them and for what?
  3. 3What business or customer data goes into them?
  4. 4Which tools are approved?
  5. 5What are we paying for?
  6. 6Could we demonstrate how AI is governed if asked?

These six questions are useful whether or not the EU AI Act applies directly to your business. They also reveal duplicated subscriptions, unsafe data handling, unclear ownership, training gaps and promising use cases that no one has properly supported.

AI risk and AI waste

AI governance is not purely a cyber security story. The same lack of visibility can create both risk and waste.

AI riskAI waste
Customer or employee data entering an unsuitable accountSeveral teams paying for overlapping tools
Inaccurate outputs used without verificationUnused Copilot or other AI licences
Shadow AI outside company policyAI functionality already included in software the business owns
No clear owner for a tool or use caseIndividual departments buying separate solutions for the same problem
Unclear supplier retention, training or sharing settingsNo measurable benefit from the subscription
AI being used for a high-impact decision without proper oversightGood use cases being missed because no one owns experimentation

A tool register, a short acceptable-use policy and a recurring review can therefore do double duty: reduce the chance of harmful use and identify where the business is paying for more technology than it needs.

What should a sensible SME do now?

Do not begin with a huge policy copied from a multinational. Begin with a reliable picture of your own business.

  1. 1Create an AI inventory. Include standalone tools, AI features inside existing software, personal accounts used for work and AI services used by suppliers.
  2. 2Identify approved and unapproved tools. Treat the first list as a starting point, not a punishment exercise.
  3. 3Assign ownership. Each important tool or use case needs a person who can explain its purpose, data and settings.
  4. 4Review data handling. Check what information goes into the system, where it is processed, who can access it, how long it is retained and what the supplier terms say.
  5. 5Put a proportionate AI acceptable-use policy in place. Say what is allowed, what needs a check, what must not be entered and how to report mistakes.
  6. 6Provide appropriate AI literacy. Match guidance to people's roles and the systems they actually use; do not assume a certificate is the objective.
  7. 7Review subscriptions and costs. Find duplicated tools, unused seats and features the business already owns.
  8. 8Identify worthwhile use cases. Governance should help the business use AI well, not only create prohibitions.
  9. 9Review governance periodically. Tools, staff, settings, suppliers and uses change quickly.
  10. 10Seek specialist legal or compliance advice where EU AI Act scope is material. Do not rely on this article to decide a legal obligation.

A practical first week

Ask every team member to name the AI tools they use for work, what job each tool does and what kind of information goes into it. Compare that list with company card payments, software renewals, identity-provider applications and the AI settings inside Microsoft 365 or other major platforms.

You will not have a perfect register after one week. You will have something more useful: a list of what you did not know before.

What should an AI policy cover?

A small-business AI policy can be short. It should make the safe and useful route obvious rather than bury staff under legal language.

SectionQuestion to answer
Purpose and scopeWhy does the policy exist, and who does it apply to?
Approved toolsWhich tools and account types may staff use?
Data boundariesWhat personal, confidential, client or security information must not go into prompts?
Acceptable useWhat is encouraged, what needs care and what is not acceptable?
CheckingWhich facts, outputs and customer-facing material must a person verify?
DisclosureWhen should customers, colleagues or audiences be told that AI was involved?
OwnershipWho maintains the tool register and answers questions?
Mistakes and escalationHow does someone report an error, data disclosure or uncertain use?
ReviewWhen will the policy and approved-tool list be revisited?

The policy should work alongside your existing UK GDPR, confidentiality, information security, employment and customer-contract processes. It should not pretend to replace them.

AI Policy Starter Guide

AI Governance hub

Microsoft 365, Copilot and the EU AI Act

Microsoft 365 customers may already have several AI features and access paths to review. Copilot may be used inside Word, Outlook, Teams and other applications; Copilot Chat may be available under a business account; and other Microsoft or third-party services may connect to the tenant.

That does not mean Microsoft 365 automatically makes a business compliant with the EU AI Act. It also does not mean every Copilot prompt requires a public AI disclosure. The useful questions are which feature is being used, by whom, for what task, with what data, under which account, with what human review and whether an EU-connected use case changes the scope analysis.

Copilot or ChatGPT: What Should a Business Use?

Microsoft 365 Security Baseline Checklist

Business accounts, sensible tenant controls and clear data boundaries can reduce operational risk. They do not answer every legal, procurement or transparency question on their own.

Related frameworks

A business wanting a more structured approach to AI governance may encounter several related frameworks. They serve different purposes and none should be treated as mandatory for every SME simply because it appears in a supplier questionnaire.

Framework or lawWhat it helps with
EU AI ActRisk-based legal requirements for certain AI providers, deployers and uses with an EU connection
UK GDPR and Data Protection Act 2018Personal-data processing, transparency, security, rights and accountability in the UK
ISO/IEC 42001A certifiable management-system approach for organisations establishing an AI management system
Information security frameworksControls for protecting systems, identities, devices, data and business operations
Company AI policyPlain-English working rules for the tools, data, review and escalation routes in that business

ISO/IEC 42001 can be useful for a business with significant AI governance needs, customer requirements or a desire for a formal management system. Certification is not necessary for every small business, and buying a certificate without changing how AI is used will not create meaningful governance.

ICO guidance on AI and data protection

The Operational Heartbeat

AI governance is not a document you write once and put in a drawer. Staff change, tools add features, supplier terms change, licences renew, data flows move and a useful experiment can become a customer-facing process.

Review it regularly

At a regular Operational Heartbeat review, check the tool register, owners, account types, data handling, supplier terms, AI literacy, incidents, costs, useful outcomes and any new AI features inside existing software.

IT Club Operational Heartbeat checklist

What the EU AI Act does not change

  • AI output still needs checking before it influences an important business decision.
  • A supplier's “AI-powered” label does not tell you what data the tool handles.
  • A personal AI account is not automatically suitable for customer or confidential data.
  • A policy does not replace sensible access controls, backups, incident response or data protection work.
  • A UK business does not become directly subject to every EU AI Act provision merely because someone opened ChatGPT.
  • ISO/IEC 42001 certification is not a universal requirement for every SME.

IT Club view

The useful response to the EU AI Act is neither panic nor dismissal. The Act matters directly to some organisations and indirectly to many more through customers, procurement, supply chains and expectations about trustworthy AI.

For most UK SMEs, the first sensible move is not to commission a grand compliance programme. It is to make AI use visible, assign ownership, set proportionate data and review rules, and understand which parts of the business actually depend on AI.

The practical conclusion

You do not need to know every AI regulation before you can take the first useful step. You need to know what AI your business is using.

Ask the IT Club Advisor

Not sure whether your current AI use creates a governance, security or cost problem? Ask the IT Club Advisor. You can describe the situation in plain English and use the response as a starting point for your own internal review or for a conversation with a qualified adviser.

Ask the IT Club Advisor

Sources and further reading

The following official sources were reviewed on 21 August 2026. EU AI Act requirements, guidance and implementation dates can develop over time. This article is general technology information and not legal advice.

European Commission: AI Act regulatory framework

European Commission: enforcement and transparency requirements from 2 August 2026

European Commission: Quick facts on transparency rules for AI systems

European Commission: Guidelines on transparency obligations

EU AI Act Service Desk: Article 50

Regulation (EU) 2024/1689 on EUR-Lex

ICO: AI and data protection guidance

Frequently asked questions

Does the EU AI Act apply to UK companies?

Not automatically. It may matter where a UK organisation operates in the EU, provides or deploys an AI system into the EU, supplies EU customers, produces outputs used in the EU or has a relevant role in an EU customer's supply chain. The exact scope depends on the facts and may need specialist legal advice.

When did the EU AI Act start applying?

The Act entered into force on 1 August 2024. Prohibited AI practices and AI literacy obligations began applying on 2 February 2025; governance and general-purpose AI model obligations followed on 2 August 2025; and the Act became broadly applicable, with enforcement powers and Article 50 transparency obligations, on 2 August 2026. Some high-risk requirements have later dates.

Do employees need formal AI training?

Do not assume that every employee needs a certified course. AI literacy should be proportionate to the person's role, the system and the risk. People using AI should understand appropriate use, limitations, data risks, verification, escalation and the company's policy.

Does using ChatGPT mean my company must comply with the EU AI Act?

Not by itself. Using ChatGPT does not automatically make every UK company subject to every EU AI Act provision. Scope depends on the organisation's location, role, customers, deployment, outputs and use case. Regardless of scope, the business should govern what data enters the tool and how outputs are checked.

What is shadow AI?

Shadow AI is the use of AI tools for work without the business knowing, approving or recording them. It can include free personal accounts, browser extensions, AI features inside existing software and departmental subscriptions.

What should an SME AI policy cover?

A proportionate policy should cover approved tools and accounts, data boundaries, acceptable use, human checking, disclosure where relevant, ownership, mistake reporting and a review date. It should use plain English and work alongside existing data protection, confidentiality and security processes.

What is Article 50 of the EU AI Act?

Article 50 sets transparency obligations for providers and deployers of certain AI systems. Depending on the system and use, these can concern direct interaction with AI, marking AI-generated or manipulated content, deepfakes, emotion recognition, biometric categorisation and certain public-interest text.

Does Article 50 mean every AI-written email needs a label?

No. The obligations are not a blanket labelling rule for every internal draft or routine business use. The relevant system, content, audience, role and conditions need to be considered, including the guidance and any applicable exceptions.

What does AI literacy mean in practice?

It means people have enough understanding to use the AI system appropriately for their role, recognise limitations, protect data, verify output, escalate uncertainty and follow company rules. The depth of knowledge should match the risk and the use.

Should a small business get ISO/IEC 42001 certified?

Not necessarily. ISO/IEC 42001 can provide a structured AI management-system approach and may be useful where customers or risk justify it. Certification is not automatically necessary for every SME, and it should not replace practical ownership, data boundaries and review.

How can a UK SME start an AI inventory?

Ask staff what AI tools and features they use, compare the answers with company-card payments, software renewals and identity-provider application records, and check AI controls in major platforms. Record the tool, owner, purpose, account type, data, approval status and review date.

Is AI governance mainly a cyber security issue?

No. AI governance also covers accuracy, confidentiality, privacy, contracts, customer communication, human oversight, cost, value and accountability. Cyber security is one important part of the wider picture.

What should a business do if an EU customer asks about AI governance?

Start by understanding what the customer is asking for and which service or supply-chain relationship it concerns. Provide an accurate description of the AI tools, data boundaries, ownership, review and supplier information you actually have. If the request may create a legal obligation, seek specialist advice rather than guessing.

Plain-English Takeaway

The EU AI Act does not automatically turn every UK SME into an EU-regulated AI provider. But every business using AI should be able to explain what it uses, who uses it, what data goes into it, which tools are approved, what it pays for and how it governs the use.

Follow The IT Club Briefing on WhatsApp

Tap to follow The IT Club Briefing on WhatsApp.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor