AI Strategy

The EU AI Act Just Got Teeth: Enforcement, Model Inspections And Fines Up To €15 Million Are Now Live - What Every UK Business Using AI Needs To Do

For two years the EU AI Act was a set of rules with a distant deadline. As of this month, it is a set of rules with real enforcement power behind it. The Act's enforcement provisions, activated on 2 August, now enable authorities to conduct model inspections, impose market restrictions, and levy fines of up to €15 million or 3% of global turnover - whichever is higher. This is no longer a compliance exercise businesses can defer; it is a live regulatory regime with serious teeth. And here is the part many UK businesses have not fully registered: this affects you even though Britain is outside the EU. If your AI touches EU users, customers or markets in the relevant ways, the EU AI Act can apply to you regardless of where your business is based - just as GDPR did. With enforcement now active and the fines substantial, UK businesses using AI need to understand where they stand and what they must do. This featured analysis explains, without the legal jargon, what the EU AI Act enforcement means, which UK businesses are affected, and the practical steps to get compliant - turning a source of anxiety into a manageable, and even advantageous, part of doing AI properly.

 ·  12 min read  ·  By BraivIQ Editorial

The EU AI Act Just Got Teeth: Enforcement, Model Inspections And Fines Up To €15 Million Are Now Live - What Every UK Business Using AI Needs To Do

2 August 2026 - The EU AI Act's enforcement provisions activated - moving from rules on paper to a live regime with real power  ·  €15m / 3% - Maximum fines under the Act - up to €15 million or 3% of global turnover, whichever is higher  ·  Inspections - Enforcement powers now enable model inspections and market restrictions, not just fines  ·  Applies to UK - If your AI touches EU users or markets in the relevant ways, the Act can apply regardless of where you are based

For two years the EU AI Act was a set of rules with a distant deadline. As of this month, it is a set of rules with real enforcement power behind it. The Act's enforcement provisions, activated on 2 August, now enable authorities to conduct model inspections, impose market restrictions, and levy fines of up to €15 million or 3% of global turnover - whichever is higher. This is no longer a compliance exercise businesses can defer to some future date; it is a live regulatory regime with serious teeth, and the shift from 'rules that will eventually be enforced' to 'rules being enforced now' changes the calculus for every business using AI in ways that touch Europe.

As an AI Agency London that helps UK businesses deploy AI properly - which increasingly includes deploying it compliantly - we think this deserves clear, calm attention, because there is both real risk in ignoring it and real reassurance in understanding it. And here is the part many UK businesses have not fully registered, and most need to: this affects you even though Britain is outside the EU. The EU AI Act, like GDPR before it, has extraterritorial reach - if your AI touches EU users, customers or markets in the relevant ways, the Act can apply to your business regardless of where it is based. UK businesses that assumed 'we're not in the EU, so this doesn't apply to us' may be mistaken, exactly as many were about GDPR, and the parallel is worth taking seriously because the consequences are now live.

This is not a reason to panic, and it is emphatically not a reason to avoid AI - it is a reason to understand where you stand and do the sensible, manageable work of compliance. With enforcement now active and the fines substantial, UK businesses using AI need to know whether and how the Act applies to them and what they must do about it. The good news is that for most businesses, the practical requirements are reasonable and align with good AI practice anyway - much of compliance is doing AI responsibly, which you should be doing regardless. This featured analysis explains, without the legal jargon, what the EU AI Act enforcement means, which UK businesses are affected, and the practical steps to get compliant - turning a source of anxiety into a manageable, and even advantageous, part of doing AI properly.

Does It Apply To Your UK Business? The GDPR Parallel

The most important question for a UK business is whether the Act applies to it at all, and the honest answer is 'it depends, and you should check' - but the GDPR parallel is the best guide to why you cannot simply assume it does not. When GDPR arrived, many UK and non-EU businesses assumed it was an EU-only concern, and many were wrong, because GDPR applied based on whether you handled EU residents' data, not on where your business sat. The EU AI Act follows the same logic: its reach is based substantially on whether your AI touches EU users, customers or markets in the ways the Act covers, not on your business's location. So a UK business whose AI serves EU customers, is used in the EU, or affects EU users in the relevant ways may well fall within scope, exactly as it did for GDPR - which is why 'we're outside the EU' is a starting question, not a conclusion.

This means the practical first step for a UK business is to honestly assess its EU exposure: does your AI touch EU users, customers or markets, and in what ways? For a purely domestic UK business with no EU dimension to its AI, the Act may not apply - though UK AI regulation is developing too, so responsible practice matters regardless. For a UK business with genuine EU exposure in its AI, the Act may apply, and the sensible response is to understand how and get proper guidance. The mistake to avoid is the GDPR mistake: assuming a foreign regulation cannot reach you because you are not based there, and being caught out. Check your exposure properly rather than assuming, because the cost of wrongly assuming you are exempt is now backed by real enforcement and substantial fines.

The Risk-Based Approach: Most AI Is Not High-Risk

The single most reassuring thing to understand about the EU AI Act is that it is risk-based, not one-size-fits-all - it imposes obligations in proportion to risk, so the burden on your business depends entirely on what kind of AI you use. A small set of AI uses are prohibited outright. A defined set of 'high-risk' uses - broadly, AI used in consequential decisions about people, such as in employment, credit, essential services, and similar significant contexts - carry substantial obligations around risk management, documentation, human oversight, transparency and more. Broader transparency rules apply to things like AI chatbots (which must disclose they are AI) and synthetic media (which must be labelled). And genuinely low-risk AI - which is most everyday business AI - carries light obligations. So the burden is concentrated on the high-risk uses, and most businesses will find much of their AI use is low-risk.

This is why the right first move is to categorise your AI use rather than assume the heaviest obligations apply to everything. Map what AI your business uses and where it falls: is any of it in the prohibited category (which you must stop), the high-risk category (which carries real requirements you must meet), or the transparency-obligation category (disclose chatbots, label synthetic media)? Most will likely be low-risk, with light requirements. This categorisation turns a daunting-sounding regime into a manageable set of specific obligations that actually apply to your specific AI - and usually reveals that the serious compliance work is needed only for a subset of high-risk uses, if any, while the rest requires little beyond the responsible-AI practices you should follow anyway. Knowing which category your AI falls into is the foundation of proportionate, manageable compliance.

What To Actually Do - And Why Much Of It You Should Do Anyway

The genuinely encouraging part is that much of EU AI Act compliance overlaps with responsible AI practice you should be doing regardless of any regulation. The Act's requirements for high-risk AI - proper governance, documentation of what your AI does and why, human oversight of consequential decisions, transparency, risk management, and the audit trails we have covered recently - are, in large part, simply what deploying AI responsibly looks like. A business that governs its AI well, documents it, keeps humans overseeing important decisions, is transparent about AI use, and can account for what its AI does is most of the way to compliance already, and is also just running its AI properly. So for many businesses, getting compliant is less about a special regulatory project and more about applying good AI governance - which protects the business and serves customers well independent of the regulation.

The practical path, then, is: assess your EU exposure and categorise your AI use to understand what actually applies; for any high-risk uses or significant EU exposure, get proper legal and compliance guidance, because the obligations there are real and the stakes are now live; and across the board, apply the responsible-AI practices - governance, documentation, human oversight, transparency, audit trails - that constitute most of compliance and that you should do anyway. Approached this way, the EU AI Act is manageable rather than overwhelming, and it can even be an advantage: as AI trust becomes a business issue, being able to demonstrate that your AI is governed, documented and compliant becomes a genuine selling point, especially with the customers and partners who care most about doing AI responsibly. The businesses that treat compliance as part of doing AI well, rather than as a grudging burden, turn a regulatory requirement into a mark of trustworthiness.

The 90-Day EU AI Act Readiness Plan For UK Businesses

  1. Days 1-20: Assess your EU exposure - does the AI in your business touch EU users, customers or markets in ways the Act covers? - to understand whether and how it applies to you.
  2. Days 21-40: Categorise your AI use by risk - prohibited, high-risk (consequential decisions about people), transparency-obligation (chatbots, synthetic media), or low-risk - to see what obligations actually apply.
  3. Days 41-60: For any high-risk uses or significant EU exposure, get proper legal and compliance guidance and address the specific obligations - the stakes there are real and now live.
  4. Days 61-80: Across all your AI, apply the responsible-AI practices that make up most of compliance - governance, documentation, human oversight, transparency, audit trails - which you should do regardless.
  5. Days 81-90: Establish ongoing AI compliance and governance as standard practice, so you stay compliant as your AI use and the rules evolve, and can demonstrate trustworthiness as an advantage.

Sources

  1. European Commission - EU AI Act enforcement provisions (activated 2 August 2026; model inspections, market restrictions, fines up to €15 million or 3% of global turnover)
  2. Mitchell Bryson - 'Today in AI, 22 August 2026' (EU AI Act enforcement powers activated on 2 August)
  3. Augusto Digital - 'Monthly LLM News August 2026'
  4. European Parliament - EU Artificial Intelligence Act risk-based framework and obligations
  5. UK ICO / DSIT-successor - guidance on AI regulation and responsible AI for UK businesses
  6. BraivIQ - Batch 28 EU AI Act August 2026 Enforcement, Batch 27 AI Governance and Batch 37 Shadow AI Agents & Audit Trails articles (internal reference)