In May 2026, the EU Parliament and Council agreed a significant set of changes to the EU AI Act through what is being called the Omnibus amendment. The most immediately relevant change for UK businesses: the compliance deadline for high-risk AI systems has been pushed back from August 2026 to 2 December 2027. For any organisation that was sweating an imminent deadline, this is a meaningful reprieve — but the preparation window is not an excuse to park it.

If your business sells software, services, or AI-powered products into European markets, or if your AI outputs affect EU customers, you remain in scope regardless of where you are based. Brexit did not remove UK companies from the reach of the EU AI Act.

What actually changed in the Omnibus

The amended Act reorganises the compliance timeline into three distinct tracks:

Already enforceable (no extension): Prohibitions on unacceptable-risk AI practices — social scoring by governments, real-time biometric surveillance in public spaces, subliminal manipulation — have been in force since February 2025. If your business touches any of these areas, you have been non-compliant for over a year.

August 2026 (unchanged): General-purpose AI model obligations and transparency requirements for AI systems that interact with humans — disclosures that a user is talking to an AI, for instance — still arrive in August. Chatbots, AI customer service tools, and AI-generated content tools need to be compliant by then.

December 2027 (extended from August 2026): High-risk AI systems as defined in Annex III — tools used in recruitment, credit scoring, education assessment, and similar high-stakes decisions — now have until December 2027. Embedded high-risk AI in regulated products (Annex I) moves to August 2028.

The SME definition for penalty purposes has also been expanded to include companies with up to 750 employees and €150 million in annual revenue, which means lower maximum fines for qualifying businesses. But lower fines are not no fines, and the underlying compliance obligations are the same.

Why UK businesses cannot treat this as someone else’s problem

The EU AI Act follows the data. If your AI system makes decisions about EU residents — employment screening, loan applications, customer risk scoring — you are in scope even if your servers are in Manchester and your company is registered in London. The watermarking and transparency obligations due in August 2026 apply to AI systems used in the EU, not AI systems built there.

For UK SMEs using AI tools purchased from third-party vendors, the compliance burden partly shifts to those vendors, but your procurement decisions still matter. If you are using an AI tool for hiring decisions, performance management, or financial risk assessment and you have EU staff or EU customers, you need to understand whether that tool meets the Act’s requirements.

Asking vendors a simple question now — “Is your product compliant with the EU AI Act for high-risk use cases?” — costs nothing and puts the obligation clearly in their court. Contracts without this clause leave the risk with you.

The four things to do before December 2027

1. Inventory your AI systems. List every AI tool your business uses and categorise what decisions it supports. Misclassifying a high-risk system as low-risk is itself a violation of the Act — and “we didn’t think it counted” is not a defence.

2. Classify against the four risk tiers. Most tools used by SMEs will be in the minimal or limited risk category. But if you use AI in hiring, credit assessment, or personalised pricing, you need proper classification documented.

3. Review vendor contracts. Any contract for an AI tool used in EU-facing contexts should include representations about Act compliance. Renewals are the natural moment to raise this.

4. Build AI governance now. A simple AI register, a data governance policy, and a named person responsible for AI compliance positions your business ahead of most SMEs and ahead of the enforcement wave that will follow the December 2027 deadline.

ApplyAI helps UK businesses map their current AI tool use and understand where compliance obligations sit. The EU AI Act is not a barrier to using AI — it is a framework for using it responsibly, and the December 2027 deadline is now realistic enough to build a proper preparation plan against.

The one date that isn’t moving

August 2026 is still live. If you have any AI system that interacts with EU users — including chatbots, AI-generated marketing, automated customer support — the transparency requirements that take effect then are not subject to the Omnibus extension. Check those obligations now, not in the autumn.