Contents
- What the AI Act regulates (and what it does not)
- The risk pyramid: four levels, four sets of obligations
- Unacceptable risk — prohibited
- High risk — strict requirements
- Limited risk — transparency obligations
- Minimal risk — no additional obligations
- Who the AI Act applies to
- Key deadlines: what is already in force
- Fines: three tiers depending on the infringement
- Practical first step: classify your AI systems
- How Yeeply can help
The EU Artificial Intelligence Act came into force in August 2024. It is binding law across all 27 EU member states — and its first deadlines have already passed. For UK companies that develop or use AI systems reaching European users, it applies regardless of where the company is registered.
This guide covers what the AI Act actually regulates, who it applies to, how it classifies risk, and what the fines look like.
What the AI Act regulates (and what it does not)
The AI Act regulates artificial intelligence systems based on the risk they pose to people — not based on the technology they use. Whether your product uses neural networks, large language models or computer vision does not matter: what matters is what it does and in what context.
Outside scope: systems used exclusively for military or national security purposes, R&D systems without commercial deployment, and purely personal systems with no impact on third parties.
The risk pyramid: four levels, four sets of obligations
Unacceptable risk — prohibited
The AI Act bans outright: subliminal manipulation causing harm, exploitation of vulnerabilities based on age, disability or socioeconomic situation, social scoring by public authorities, real-time biometric identification in public spaces (with very narrow law enforcement exceptions), emotion recognition in workplaces and educational settings, and inferring sensitive attributes from biometric data.
These prohibitions have been in force since February 2025.
High risk — strict requirements
The most relevant category for technology companies. Systems fall here if they make or assist decisions in: hiring and HR management, access to education, credit and financial services, healthcare and diagnosis, critical infrastructure (energy, water, transport), law enforcement, and migration management.
Requirements: documented risk management system, data governance (quality and representativeness of training data), technical documentation, active human oversight, robustness and cybersecurity certification, and automatic activity logging.
Limited risk — transparency obligations
Systems interacting with people must identify themselves as AI. If your app has a chatbot, users must be told they are talking to an automated system. Deepfakes and realistic synthetic content have specific labelling requirements.
Minimal risk — no additional obligations
Most AI systems fall here: spam filters, content recommendation engines, text correction tools, generative AI for internal use without impact on decisions about people. No AI Act-specific requirements beyond existing law.
Who the AI Act applies to
- Providers: companies that develop AI systems and place them on the EU market, including via API or as a component of another product
- Deployers: companies that use third-party AI systems in professional contexts with impact on people
- Importers and distributors: companies bringing to the EU market AI systems developed outside it
- Companies outside the EU: if your system affects EU users, the AI Act applies regardless of where your company is incorporated
Key deadlines: what is already in force
| Date | Milestone |
|---|---|
| August 2024 | AI Act enters into force |
| February 2025 | Prohibited AI systems — already applicable |
| August 2025 | Obligations for general-purpose AI models (GPAI) such as GPT-4 or Gemini |
| August 2026 | Requirements for high-risk AI systems (most tech companies) |
| August 2027 | Additional deadlines for systems already in use before the regulation |
Fines: three tiers depending on the infringement
| Infringement | Maximum penalty |
|---|---|
| Using prohibited AI systems | €35M or 7% of global annual turnover (whichever is higher) |
| Non-compliance with high-risk system requirements | €15M or 3% of global turnover |
| Providing incorrect information to authorities | €7.5M or 1.5% of global turnover |
For SMEs, the fixed amounts are proportionally reduced: the lower of the fixed cap and the turnover percentage always applies.
Practical first step: classify your AI systems
Before investing in compliance, the most useful exercise is an inventory of all AI systems your company develops or uses — including those contracted from third parties — and classifying each one according to the AI Act risk pyramid.
If any falls into high risk, the specific requirements kick in: risk management system, technical documentation, activity logging and human oversight. If limited risk, the main obligation is informing users. If minimal risk, nothing AI Act-specific is required.
How Yeeply can help
At Yeeply we work with certified software development companies that are already adapting their processes and architectures to the AI Act. Whether you are building an AI system from scratch or need to audit an existing one, we can connect you with the right technical team for your sector and risk level.
For budget-conscious projects, we also work with specialist teams offering the same technical guarantees at 30 to 40% lower cost. Use the Request a quote button at the top of yeeply.com/en or write to sales@yeeply.com.
Tags
Related posts
AI Governance in Software: What UK Enterprises Are Getting Right (and Wrong) in 2026
What good AI governance looks like in practice for UK enterprises: what companies are getting right, what they miss, and the regulatory landscape for 2026.
Custom Software vs Off-the-Shelf ESG Platform: A Cost Comparison for UK SMEs
Build vs buy for ESG reporting software: licence costs, integration reality, and when custom development makes more sense than an off-the-shelf platform.
AI Integration Costs for Enterprise Apps: What UK Businesses Actually Pay
Real figures for AI integration in UK enterprise apps: chatbots, document processing, fine-tuning. Plus the hidden costs nobody quotes upfront.
ESG Software Requirements: What UK Companies Need to Build Before the UK SRS Deadline
What software UK companies need to build or buy before the UK SRS deadline: data integration, reporting, audit trails and realistic timelines.
How Much Does a Penetration Test Cost in the UK? (2026 Prices)
Real penetration testing prices in the UK for 2026: from £3,000 for a basic web pentest to £80,000 for red team. What's included, what drives costs, and how to hire without overpaying.
How Much Does Enterprise App Development Cost in 2026? Real Prices by Project Type
Enterprise app development costs in 2026 vary widely by project type, technology, and team location. Here are real price ranges and what drives them up or down.
MVP in 6 Weeks: A Step-by-Step Guide for Companies That Want to Test Before Investing
An MVP in 6 weeks is achievable — if you know what to put in it. This guide covers the phases, what to cut, realistic costs, and how to measure whether it worked.
What AI Agents Actually Do in a Software Project (And What They Still Can’t)
AI agents in software development do real, concrete things — and have real, concrete limits. Here's an honest breakdown of what they handle today and what still needs a human developer.
A Practical Guide to Building an Enterprise App in 2026 Without Burning Your Budget
Building an enterprise app without burning your budget starts long before the first line of code. A step-by-step guide to phases, common mistakes, and managing the project without technical expertise.
What Is AI-Native Software and Why Companies That Build It Win in 2026
What AI-native software is, how it differs from adding AI to an existing app, and why companies that build it from day one gain a competitive edge in 2026.
