AI Governance

The EU AI Act Is Now Being Enforced — Does Your Business Know What AI It Is Using?

IT Club9 minutes read21 August 2026Updated 21 September 2026
WhatsAppEmail

IT Club — Powered by Altitude AI (opens in a new tab)

The EU AI Act Is Now Being Enforced — Does Your Business Know What AI It Is Using?

Keep up with IT Club

Add IT Club as a preferred source in Google Search.

A plain-English, vendor-neutral guide to the EU AI Act for UK SMEs. It explains the 2026 AI Omnibus timetable, revised AI-literacy wording, possible UK business connections to the Act, Article 50 transparency, unmanaged AI, risk and waste, and sensible governance steps without presenting legal advice.

AI regulation is no longer something sitting several years in the future. The EU AI Act became broadly applicable on 2 August 2026, enforcement powers became active and new transparency requirements started applying to certain AI systems and uses.

Updated September 2026

This article has been updated to reflect the EU AI Omnibus timetable changes and revised AI literacy wording. Dates and guidance can change, so check the current official sources before making a material business or legal decision.

But this does not mean every UK SME suddenly needs an “EU AI Act compliance project”. The Act has a defined scope, different duties for different roles and some requirements that apply on later dates.

The more useful question is this:

IF SOMEBODY ASKED TOMORROW:

Which AI systems do you use?
Who uses them, and for what?
What data goes into them?
Which tools are approved?
What are you paying for?
How do you govern the use?

COULD YOU ANSWER?

For many businesses, the answer will be no. That is an AI visibility problem before it is an EU legal problem.

Important context

This article is general technology information for UK businesses. It is not legal advice, an EU AI Act compliance assessment or a statement that the Act applies to every UK company. If your organisation's activities, customers or supply chain create a material EU connection, seek advice from a suitably qualified legal or compliance professional.

What changed in August 2026?

The EU AI Act entered into force on 1 August 2024. It was designed as a risk-based regulation: different requirements apply depending on the AI system, its role in the value chain and how it is used.

DateWhat happened
1 August 2024The Regulation entered into force. The transition towards the new AI framework began.
2 February 2025The rules on prohibited AI practices began applying. Article 4 AI literacy duties also applied, with the current wording focused on taking measures to support AI-literacy development rather than guaranteeing a specific level.
2 August 2025Governance rules and obligations for providers of general-purpose AI models began applying.
2 August 2026The Act became broadly applicable, enforcement powers became active and Article 50 transparency obligations began applying.
2 December 2027High-risk AI systems under Article 6(2) and Annex III: the relevant rules apply from this date under the AI Omnibus timetable.
2 August 2028High-risk AI systems embedded in regulated products under Article 6(1) and Annex I: the relevant rules apply from this date under the AI Omnibus timetable.

“Broadly applicable” is not the same as “every provision applies to every system today”. The 2026 AI Omnibus changed the timetable for high-risk AI, so older summaries suggesting that these obligations generally started in August 2026 are now out of date. The Act still contains exceptions, role-based duties, later dates and detailed definitions. A headline about enforcement should prompt an inventory and scope review, not an assumption that every AI use is now subject to the same checklist.

European Commission: AI Act regulatory framework and timeline →

European Commission: enforcement and new transparency requirements from 2 August 2026 →

European Commission: AI Omnibus enters into force →

European Commission: guidelines for providers and deployers of high-risk AI systems →

EUR-Lex: consolidated EU AI Act text →

Does the EU AI Act apply to UK businesses?

Not automatically. A business being based in the United Kingdom is not, by itself, an answer to the scope question.

The Act can matter to an organisation outside the EU where its role or activity has an EU connection described by the Regulation. For example, a UK organisation may need to investigate its position if it:

  • operates in the EU;
  • provides or deploys an AI system in the EU;
  • supplies EU customers with a product or service involving AI;
  • places an AI system or AI-enabled product on the EU market;
  • produces AI-generated outputs that are used in the EU;
  • forms part of an EU customer's AI-related supply chain; or
  • has agreed through a customer or supplier contract to demonstrate particular AI governance controls.

The exact position depends on the facts: what the organisation does, where the system is placed or used, whether it is a provider or deployer, what the output is used for and which contractual relationships exist. “We are a UK company” is not a complete scope analysis, but neither is “we use an AI tool, so the whole Act applies”.

A sensible scope question

If an EU customer, regulator or procurement team asked how your AI use is governed, could you show the relevant tools, owners, data boundaries, review steps and supplier information?

This is a practical governance question, not a substitute for legal advice. Where the EU AI Act may materially affect your organisation, get the scope checked rather than relying on a generic online summary.

AI literacy: already relevant

Article 4 now says that providers and deployers must take measures to support the development of AI literacy for the people who operate or use AI systems on their behalf. The consolidated wording also says that this obligation does not require providers or deployers to guarantee any specific level of AI literacy for an individual.

That does not mean every employee needs a formal qualification, exam, badge or certificate. In practical terms, a business using AI should consider whether the people operating it understand enough about the systems they use and the risks of that use. The right level of knowledge depends on the person's role, the system and the risk.

A proportionate approach may include:

  • a basic AI policy and approved-tools guidance;
  • role-appropriate training and examples of safe and unsafe use;
  • clear data-handling guidance;
  • human-review expectations for important outputs;
  • an escalation route for uncertainty or mistakes; and
  • evidence that relevant guidance or training was provided.

These are practical governance examples, not a prescribed package or proof of formal legal compliance.

People should understandPractical example
Appropriate useWhat the approved tool is for, and which decisions must stay with a person
LimitationsThat a fluent answer can still be inaccurate, incomplete or invented
Data and privacy risksWhat personal, confidential, client or commercially sensitive information must not be pasted into a tool
VerificationHow to check facts, figures, sources, calculations and customer-facing output
EscalationWho to ask when a prompt, output, data use or AI decision is unclear
Company policyWhich accounts and tools are approved, and how to report a mistake

A short briefing, a plain-English policy, examples relevant to the job and a clear reporting route may be more useful than a generic course certificate. Keep a record of what guidance was provided and review it as tools and use cases change.

IT Club AI Policy Starter Guide →

IT Club: Safe Use of Generative AI at Work →

What is Article 50 transparency?

Article 50 contains transparency obligations for providers and deployers of certain AI systems. They are not a requirement to put an “AI generated” label on every internal draft or to announce every routine use of ChatGPT or Copilot.

In broad terms, the obligations cover situations such as:

  • informing people when they are interacting directly with certain AI systems, such as an interactive system that could otherwise be mistaken for a human;
  • designing systems so AI-generated or manipulated content can be detected through machine-readable marking where the relevant obligation applies;
  • informing people when they are exposed to certain emotion-recognition or biometric-categorisation systems;
  • labelling or disclosing deepfake image, audio or video content; and
  • disclosing certain AI-generated or manipulated text published on matters of public interest where the relevant conditions apply.

The details matter. Article 50 contains different duties, exemptions and conditions, and the European Commission's guidance explains concepts such as direct interaction, synthetic content, deepfakes, public-interest text and standard editing.

What this does not mean

It does not mean that every routine use of ChatGPT, Copilot, Gemini or an AI writing feature automatically needs a public label. First identify the system, the role, the content, the audience and the specific obligation that could apply.

European Commission: Quick facts on AI transparency rules →

European Commission: Guidelines on AI transparency obligations →

The much bigger SME problem: unmanaged AI

Most businesses do not have an EU AI Act problem first. They have an AI visibility problem.

Staff may already be using ChatGPT, Microsoft Copilot, Gemini, Claude, meeting transcription tools, AI design software, AI features built into SaaS applications and personal AI subscriptions. They may be using them in entirely sensible ways to save time.

Management may not know:

  • which tools are in use;
  • which accounts people are using;
  • what company or customer data goes into them;
  • which tools are approved;
  • what is being paid for;
  • which AI features were switched on by a software update;
  • what business value is being obtained; or
  • who would answer a customer, insurer or supplier asking about AI governance.

That is the practical connection between the EU AI Act and ordinary SME management. You cannot decide whether a system is in scope, suitable, transparent or worth its cost if you do not know it exists.

Shadow AI: The Tools Your Team Isn't Telling You About →

Business AI Readiness: Find Out What You Already Have →

The six questions every business should answer

Do we know?

  1. 1What AI systems are being used?
  2. 2Who is using them and for what?
  3. 3What business or customer data goes into them?
  4. 4Which tools are approved?
  5. 5What are we paying for?
  6. 6Could we demonstrate how AI is governed if asked?

These six questions are useful whether or not the EU AI Act applies directly to your business. They also reveal duplicated subscriptions, unsafe data handling, unclear ownership, training gaps and promising use cases that no one has properly supported.

AI risk and AI waste

AI governance is not purely a cyber security story. The same lack of visibility can create both risk and waste.

AI riskAI waste
Customer or employee data entering an unsuitable accountSeveral teams paying for overlapping tools
Inaccurate outputs used without verificationUnused Copilot or other AI licences
Shadow AI outside company policyAI functionality already included in software the business owns
No clear owner for a tool or use caseIndividual departments buying separate solutions for the same problem
Unclear supplier retention, training or sharing settingsNo measurable benefit from the subscription
AI being used for a high-impact decision without proper oversightGood use cases being missed because no one owns experimentation

A tool register, a short acceptable-use policy and a recurring review can therefore do double duty: reduce the chance of harmful use and identify where the business is paying for more technology than it needs.

What should a sensible SME do now?

Do not begin with a huge policy copied from a multinational. Begin with a reliable picture of your own business.

  1. 1Create an AI inventory. Include standalone tools, AI features inside existing software, personal accounts used for work and AI services used by suppliers.
  2. 2Identify approved and unapproved tools. Treat the first list as a starting point, not a punishment exercise.
  3. 3Assign ownership. Each important tool or use case needs a person who can explain its purpose, data and settings.
  4. 4Review data handling. Check what information goes into the system, where it is processed, who can access it, how long it is retained and what the supplier terms say.
  5. 5Put a proportionate AI acceptable-use policy in place. Say what is allowed, what needs a check, what must not be entered and how to report mistakes.
  6. 6Provide appropriate AI literacy. Match guidance to people's roles and the systems they actually use; do not assume a certificate is the objective.
  7. 7Review subscriptions and costs. Find duplicated tools, unused seats and features the business already owns.
  8. 8Identify worthwhile use cases. Governance should help the business use AI well, not only create prohibitions.
  9. 9Review governance periodically. Tools, staff, settings, suppliers and uses change quickly.
  10. 10Seek specialist legal or compliance advice where EU AI Act scope is material. Do not rely on this article to decide a legal obligation.

A practical first week

Ask every team member to name the AI tools they use for work, what job each tool does and what kind of information goes into it. Compare that list with company card payments, software renewals, identity-provider applications and the AI settings inside Microsoft 365 or other major platforms.

You will not have a perfect register after one week. You will have something more useful: a list of what you did not know before.

What should an AI policy cover?

A small-business AI policy can be short. It should make the safe and useful route obvious rather than bury staff under legal language.

SectionQuestion to answer
Purpose and scopeWhy does the policy exist, and who does it apply to?
Approved toolsWhich tools and account types may staff use?
Data boundariesWhat personal, confidential, client or security information must not go into prompts?
Acceptable useWhat is encouraged, what needs care and what is not acceptable?
CheckingWhich facts, outputs and customer-facing material must a person verify?
DisclosureWhen should customers, colleagues or audiences be told that AI was involved?
OwnershipWho maintains the tool register and answers questions?
Mistakes and escalationHow does someone report an error, data disclosure or uncertain use?
ReviewWhen will the policy and approved-tool list be revisited?

The policy should work alongside your existing UK GDPR, confidentiality, information security, employment and customer-contract processes. It should not pretend to replace them.

AI Policy Starter Guide →

AI Governance hub →

Microsoft 365, Copilot and the EU AI Act

Microsoft 365 customers may already have several AI features and access paths to review. Copilot may be used inside Word, Outlook, Teams and other applications; Copilot Chat may be available under a business account; and other Microsoft or third-party services may connect to the tenant.

That does not mean Microsoft 365 automatically makes a business compliant with the EU AI Act. It also does not mean every Copilot prompt requires a public AI disclosure. The useful questions are which feature is being used, by whom, for what task, with what data, under which account, with what human review and whether an EU-connected use case changes the scope analysis.

Copilot or ChatGPT: What Should a Business Use? →

Microsoft 365 Security Baseline Checklist →

Business accounts, sensible tenant controls and clear data boundaries can reduce operational risk. They do not answer every legal, procurement or transparency question on their own.

Microsoft agent governance is becoming more important

Businesses are starting to create AI agents inside Microsoft 365 and Power Platform. The governance question is no longer only “Who can use Copilot?” It is also: what agents exist, who created them, what can they access, who can use them, whether anonymous users can reach them, which data or connectors they use, who owns them and whether they are still needed.

Microsoft's 2026 Power Platform release plan describes planned enhanced admin controls for agent security. The listed capabilities include requiring Microsoft Entra ID authentication, allowing only approved external identity providers, prohibiting anonymous access, controlling agent sharing and enforcing policies at deployment and runtime. Microsoft currently lists general availability as September 2026, but it also says release dates can change and planned functionality may not be released. Check the customer's tenant before treating these controls as deployed.

Agent inventory fieldWhat to record
AI or agent nameThe name people see and any internal identifier
PlatformMicrosoft 365, Power Platform or another connected service
OwnerThe person or team responsible for purpose, access and review
PurposeThe business process and intended outcome
AuthenticationHow users and connected services authenticate
Users or audienceWho can use it and whether access is internal or external
Data and connectorsInformation, systems and actions the agent can reach
Sharing statusWho it is shared with and whether anonymous access is possible
Risk level and review dateWhat could go wrong, the response and when to review it

Microsoft Learn: Manage agent security with enhanced admin controls →

A business wanting a more structured approach to AI governance may encounter several related frameworks. They serve different purposes and none should be treated as mandatory for every SME simply because it appears in a supplier questionnaire.

Framework or lawWhat it helps with
EU AI ActRisk-based legal requirements for certain AI providers, deployers and uses with an EU connection
UK GDPR and Data Protection Act 2018Personal-data processing, transparency, security, rights and accountability in the UK
ISO/IEC 42001A certifiable management-system approach for organisations establishing an AI management system
Information security frameworksControls for protecting systems, identities, devices, data and business operations
Company AI policyPlain-English working rules for the tools, data, review and escalation routes in that business

ISO/IEC 42001 can be useful for a business with significant AI governance needs, customer requirements or a desire for a formal management system. Certification is not necessary for every small business, and buying a certificate without changing how AI is used will not create meaningful governance.

ICO guidance on AI and data protection →

The Operational Heartbeat

AI governance is not a document you write once and put in a drawer. Staff change, tools add features, supplier terms change, licences renew, data flows move and a useful experiment can become a customer-facing process.

Review it regularly

At a regular Operational Heartbeat review, check the tool register, owners, account types, data handling, supplier terms, AI literacy, incidents, costs, useful outcomes and any new AI features inside existing software.

IT Club Operational Heartbeat checklist →

What the EU AI Act does not change

  • AI output still needs checking before it influences an important business decision.
  • A supplier's “AI-powered” label does not tell you what data the tool handles.
  • A personal AI account is not automatically suitable for customer or confidential data.
  • A policy does not replace sensible access controls, backups, incident response or data protection work.
  • A UK business does not become directly subject to every EU AI Act provision merely because someone opened ChatGPT.
  • ISO/IEC 42001 certification is not a universal requirement for every SME.

IT Club view

The useful response to the EU AI Act is neither panic nor dismissal. The Act matters directly to some organisations and indirectly to many more through customers, procurement, supply chains and expectations about trustworthy AI.

For most UK SMEs, the first sensible move is not to commission a grand compliance programme. It is to make AI use visible, assign ownership, set proportionate data and review rules, and understand which parts of the business actually depend on AI.

The practical conclusion

You do not need to know every AI regulation before you can take the first useful step. You need to know what AI your business is using.

Ask the IT Club Advisor

Not sure whether your current AI use creates a governance, security or cost problem? Ask the IT Club Advisor. You can describe the situation in plain English and use the response as a starting point for your own internal review or for a conversation with a qualified adviser.

Ask the IT Club Advisor →

Sources and further reading

The following official sources were reviewed for this update on 22 September 2026. EU AI Act requirements, guidance and implementation dates can develop over time. This article is general technology information and not legal advice.

European Commission: AI Act regulatory framework →

European Commission: AI literacy questions and answers →

European Commission: enforcement and transparency requirements from 2 August 2026 →

European Commission: Quick facts on transparency rules for AI systems →

European Commission: Guidelines on transparency obligations →

EU AI Act Service Desk: Article 50 →

Regulation (EU) 2024/1689 on EUR-Lex →

European Commission: AI Omnibus enters into force →

European Commission: guidelines for providers and deployers of high-risk AI systems →

Microsoft Learn: Manage agent security with enhanced admin controls →

ICO: AI and data protection guidance →

Frequently asked questions

Does the EU AI Act apply to UK companies?

Not automatically. It may matter where a UK organisation operates in the EU, provides or deploys an AI system into the EU, supplies EU customers, produces outputs used in the EU or has a relevant role in an EU customer's supply chain. The exact scope depends on the facts and may need specialist legal advice.

When did the EU AI Act start applying?

The Act entered into force on 1 August 2024. Prohibited AI practices began applying on 2 February 2025; governance and general-purpose AI model obligations followed on 2 August 2025; and the Act became broadly applicable, with enforcement powers and applicable Article 50 transparency obligations, on 2 August 2026. Under the AI Omnibus timetable, high-risk AI under Article 6(2) and Annex III applies from 2 December 2027, while high-risk AI embedded in regulated products under Article 6(1) and Annex I applies from 2 August 2028.

Do employees need formal AI training?

No formal qualification, exam, badge or certificate is required by this wording. Article 4 requires providers and deployers to take measures to support the development of AI literacy, taking account of role, system and risk; it does not require a guaranteed level for every individual. Practical measures may include policy, approved-tools guidance, role-appropriate training, safe-use examples, data guidance, human review and escalation.

Does using ChatGPT mean my company must comply with the EU AI Act?

Not by itself. Using ChatGPT does not automatically make every UK company subject to every EU AI Act provision. Scope depends on the organisation's location, role, customers, deployment, outputs and use case. Regardless of scope, the business should govern what data enters the tool and how outputs are checked.

What is shadow AI?

Shadow AI is the use of AI tools for work without the business knowing, approving or recording them. It can include free personal accounts, browser extensions, AI features inside existing software and departmental subscriptions.

What should an SME AI policy cover?

A proportionate policy should cover approved tools and accounts, data boundaries, acceptable use, human checking, disclosure where relevant, ownership, mistake reporting and a review date. It should use plain English and work alongside existing data protection, confidentiality and security processes.

What is Article 50 of the EU AI Act?

Article 50 sets transparency obligations for providers and deployers of certain AI systems. Depending on the system and use, these can concern direct interaction with AI, marking AI-generated or manipulated content, deepfakes, emotion recognition, biometric categorisation and certain public-interest text.

Does Article 50 mean every AI-written email needs a label?

No. The obligations are not a blanket labelling rule for every internal draft or routine business use. The relevant system, content, audience, role and conditions need to be considered, including the guidance and any applicable exceptions.

What does AI literacy mean in practice?

It means people have enough understanding to use the AI system appropriately for their role, recognise limitations, protect data, verify output, escalate uncertainty and follow company rules. The depth of knowledge should match the risk and the use.

Should a small business get ISO/IEC 42001 certified?

Not necessarily. ISO/IEC 42001 can provide a structured AI management-system approach and may be useful where customers or risk justify it. Certification is not automatically necessary for every SME, and it should not replace practical ownership, data boundaries and review.

How can a UK SME start an AI inventory?

Ask staff what AI tools and features they use, compare the answers with company-card payments, software renewals and identity-provider application records, and check AI controls in major platforms. Record the tool, owner, purpose, account type, data, approval status and review date.

Is AI governance mainly a cyber security issue?

No. AI governance also covers accuracy, confidentiality, privacy, contracts, customer communication, human oversight, cost, value and accountability. Cyber security is one important part of the wider picture.

What should a business do if an EU customer asks about AI governance?

Start by understanding what the customer is asking for and which service or supply-chain relationship it concerns. Provide an accurate description of the AI tools, data boundaries, ownership, review and supplier information you actually have. If the request may create a legal obligation, seek specialist advice rather than guessing.

Plain-English Takeaway

The EU AI Act does not automatically turn every UK SME into an EU-regulated AI provider. But every business using AI should be able to explain what it uses, who uses it, what data goes into it, which tools are approved, what it pays for and how it governs the use.

Follow The IT Club Briefing on WhatsApp

Tap to follow The IT Club Briefing on WhatsApp.

Need help putting this into practice?

IT Club helps you understand the technology. If you need implementation, support or consultancy, the teams behind IT Club can help.

Altitude IT (opens in a new tab) — IT support, cyber security, Microsoft 365 and technology operations.

Altitude AI (opens in a new tab) — AI discovery, automation, governance and implementation.

Enjoyed this article?

Follow The IT Club Briefing on WhatsApp for short daily technology updates and practical business insights.

Have a question we should answer?

Ask the IT Club Advisor