EU AI Act 2026: The Compliance Checklist Every UK SMB Should Fix Before August
If you're running AI tools in a UK small business, the EU AI Act just got real. On 18 July 2025, the European Commission published draft guidelines for General Purpose AI (GPAI) models, and the first compliance obligations are now flowing into enforcement windows. August 2026 is the hard deadline most UK SMBs need to worry about. The bad news: most are completely unprepared. The good news: the checklist is shorter than you think if you focus on what actually matters for your size.
What the 18 July 2025 GPAI Guidelines Actually Change
These draft guidelines clarify how the EU AI Act applies to general-purpose AI models—not bespoke internal tools, but the foundation models most businesses plug into: ChatGPT, Claude, Gemini, and the open-weights models running locally. The key shift is transparency obligations for downstream deployers. If your business uses AI in customer-facing or decision-making workflows, you now have a clearer path to accountability, even if you're not the original model provider.
For UK businesses exporting to EU markets or serving EU customers, this matters immediately. Even purely domestic UK operations should watch this carefully—UK regulators are aligning much of their AI governance framework with EU standards to preserve data and market access post-Brexit.
The 5-Step Compliance Checklist for UK SMBs
1. Map your AI systems in 30 minutes. List every tool your team uses that touches foundation models. Customer chatbots, email triage, document review, lead scoring—all of it. You can't comply with what you haven't inventoried.
2. Identify high-risk uses fast. The AI Act bans social scoring and puts strict requirements on employment screening, credit decisions, and biometric identification. If your AI touches any of these, you need documentation and human oversight requirements—not optional extras.
3. Document your provider chain. Record which models you're using, which vendor contracts cover them, and what data you're sending to them. If you're using an API, look for the provider's AI Act transparency disclosures. If they don't have them yet, that's a risk you're carrying.
4. Run a gap analysis before August 2026. The fixed-fee compliance assessment is usually the fastest way to get an honest view of your exposure. You want this done before the deadline, not after enforcement notices start landing.
5. Train one person to own AI governance. Regulation doesn't require a compliance team—it requires accountability. Appointing someone internally, even part-time, satisfies the governance expectation and stops AI risk sitting in a blind spot.
Why UK Small Businesses are Getting This Wrong Right Now
The biggest mistake is treating AI Act compliance like GDPR—something to solve with expensive external legal counsel over six months. For most SMBs, the obligations are narrower. The regulations target model providers and high-risk deployers first. If you're running a basic AI chatbot or internal automation, you likely fall into the lighter-touch category—but only if you can prove you assessed and documented that.
The second mistake is ignoring shadow AI. Teams adopt tools fast—AI copilots in browsers, summarisation tools, automated email responders—and finance never sees the invoices, let alone the compliance picture. An AI inventory isn't just a regulatory box-tick; it's a cost-control tool.
The third mistake is waiting. The August 2026 deadline sounds distant, but the work—documentation, provider review, training—takes longer than most expect when spread across busy teams.
What to Do This Week
Start with the EU AI Act compliance checker to understand your risk tier in under ten minutes. Then prioritise the inventory and gap analysis. If you'd rather outsource it, a fixed-fee compliance assessment removes the timeline ambiguity and gives you a documented baseline you can defend.
You can also audit your automation stack for AI costs and configuration drift—many businesses discover they're running more AI tools than they realised, often with overlapping functionality and zero oversight. See our EU AI Act Compliance service for a structured fixed-fee pathway, or run the free compliance check now if you want the instant baseline.
Every paid AI Suite service ships with a concrete deliverable and fixed fee—no open-ended engagements. If this sounds faster than hiring a law firm for six months, it is.