DEWOLF.CO / TIMELINE
AI regulation timeline for UK businesses
Last checked against primary and law-firm sources on 9 September 2026. Revised quarterly, or sooner when something moves. Operational guidance, not legal advice.
The EU AI Act
In force now
Prohibited practices and the AI literacy obligation (Article 4): since 2 February 2025.
General-purpose AI model obligations: since 2 August 2025.
Transparency obligations (Article 50), including disclosure and machine-readable marking of AI-generated content and labelling of deepfakes: since 2 August 2026. Systems generating synthetic content that were already on the market before that date have until 2 December 2026 to comply with the marking requirement; new systems comply from the start.
What the omnibus changed
Regulation (EU) 2026/1744, the "digital omnibus on AI", was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. It deferred the high-risk obligations: stand-alone high-risk systems (Annex III: employment, credit, education, essential services, law enforcement, and others) now apply from 2 December 2027; high-risk AI used as a safety component in regulated products (Annex I) from 2 August 2028. The transparency obligations were not deferred. The literacy obligation was reworded from ensuring a sufficient level of AI literacy to taking measures to support its development: an obligation of means that has to be documented, not a level to be certified. SME relief was extended.
What did not move
Everything under "in force now". The penalty structure. The fact that a UK business selling to EU clients, serving UK clients who operate in the EU, or running EU operations is in scope for the work that touches the EU.
The United Kingdom
There is no UK equivalent of the EU AI Act and none is planned. AI is regulated through existing law and existing regulators.
For financial services, the FCA has said it does not plan to introduce extra regulations for AI and will rely on existing frameworks, principally the Consumer Duty and the Senior Managers and Certification Regime. In practice that means the board is accountable for AI-driven decisions about customers regardless of who or what made them, and the test is the outcome for the customer.
For everyone else, the relevant law is UK GDPR and the Data (Use and Access) Act for personal data and automated decisions, the Equality Act for discrimination, and sector regulators. The ICO and the CMA have published AI guidance under existing powers.
UK firms with EU exposure comply with the EU rules for that work. The UK position does not switch them off.
The United States
There is no federal AI law. A December 2025 executive order directed the Attorney General to establish a task force to challenge state AI laws deemed inconsistent with federal policy and asked Commerce to identify burdensome state laws. State laws continue to be enacted and to take effect.
Illinois: the amendment to the Human Rights Act (HB 3773) prohibiting discriminatory use of AI in employment decisions, and requiring notice, in effect since 1 January 2026.
Texas: the Responsible Artificial Intelligence Governance Act, prohibiting AI developed or deployed for specified harmful purposes, in effect since 1 January 2026.
California: a package of AI laws in effect from 1 January 2026, including frontier-model transparency (TFAIA), generative-AI training-data disclosure (AB 2013), and companion-chatbot rules (SB 243); the AI Transparency Act (SB 942, detection tools and watermarks) delayed to 2 August 2026.
Colorado: the 2024 Colorado AI Act was repealed before it took effect and replaced on 14 May 2026 by the Automated Decision-Making Technology Act, which drops the discrimination and impact-assessment duties in favour of documentation, notice before consequential decisions, adverse-outcome disclosure, three-year records, and trained personnel for meaningful human review. Effective 1 January 2027, contingent on the Attorney General completing rulemaking.
The pattern: US state law is converging on notice, human review, and record-keeping for automated decisions about people, which is the same ground as EU high-risk obligations and UK Consumer Duty, reached by a different route.
What this means for a UK business, in three lines
If you publish or deliver AI-generated content, the disclosure and marking rules apply now, and your clients are already asking.
If you use AI in decisions about people, the obligations arrive in late 2027 in the EU, are already in force in several US states, and are already expected by the FCA for customers. The common requirement across all three is a named human who reviews, with a record.
If your policy exists on paper and not in behaviour, none of the dates above help you. The work is the same whichever deadline you pick.
Sources
EU: White & Case, "EU AI Omnibus enters into force, amending the AI Act" (https://www.whitecase.com/insight-alert/eu-ai-omnibus-enters-force-amending-ai-act); Gibson Dunn, "EU AI Act Omnibus Agreement" (https://www.gibsondunn.com/eu-ai-act-omnibus-agreement-postponed-high-risk-deadlines-and-other-key-changes/); lawandtechnology.eu on Article 4 (https://lawandtechnology.eu/en/ai-literacy-digital-omnibus-article-4-ai-act/). UK: FCA, "AI and the FCA: our approach" (https://www.fca.org.uk/firms/innovation/ai-approach). US: King & Spalding, "New State AI Laws are Effective on January 1, 2026" (https://www.kslaw.com/news-and-insights/new-state-ai-laws-are-effective-on-january-1-2026-but-a-new-executive-order-signals-disruption); Skadden, "Colorado Repeals and Replaces Its AI Act" (https://www.skadden.com/insights/publications/2026/06/colorado-repeals-and-replaces-its-ai-act).
Daniel de Wolf · [email protected] · dewolf.co
Not sure where your business sits? Take the five-minute check.