EU AI Act — what it means for UK financial services

EU AI Act.
UK obligations explained.
Practical. Plain English.

The EU AI Act is in force. UK firms with EU clients, EU operations, or EU-made AI systems face real obligations now.

In force
Since August 2024
High risk
Article 9 applies
Beyond EU
Extra-territorial reach — UK firms affected
5 dates
Phased in over three years — see the timeline

The essentials

The EU AI Act classifies AI systems into four tiers: Unacceptable Risk (prohibited), High Risk, Limited Risk, and Minimal Risk. For UK financial services, the most consequential obligations apply to High Risk systems — which include AI used in credit scoring, insurance underwriting, employment decisions, and financial market operations.

UK organisations are not automatically exempt. If you deploy AI systems to EU-based clients, operate EU subsidiaries, or use AI systems developed by EU providers, you are likely within scope.

The timeline

The Regulation phases in over three years. Five dates matter, and the last two are the ones a UK firm with EU exposure should be planning against.

  • 1 August 2024 — the Act entered into force.
  • 2 February 2025 — prohibited practices banned; the AI-literacy duty on providers and deployers applies.
  • 2 August 2025 — obligations for general-purpose AI models; the governance bodies and most penalty provisions apply.
  • 2 August 2026 — the Act applies in general, including the high-risk obligations for the Annex III use cases in the table below and the transparency duties.
  • 2 August 2027 — high-risk obligations for AI embedded in products already covered by EU product-safety law (Annex I).

One caution. In November 2025 the European Commission proposed, in its Digital Omnibus package, to postpone the high-risk obligations — Annex III to as late as December 2027 and Annex I to August 2028 — until harmonised standards are available. That is a proposal until Parliament and Council adopt it; check its status before relying on either date.

High-risk classifications relevant to financial services

AI applicationClassification
Credit scoring and creditworthiness assessmentHigh Risk
AI in access to essential private and public servicesHigh Risk
Employment, worker management and access to self-employmentHigh Risk
AI systems used in financial market operationsUnder review
Customer service chatbots with limited outputLimited Risk
AI-generated marketing contentMinimal Risk

What high-risk obligations require

For each system classified as High Risk, organisations must maintain: a risk management system, technical documentation, data governance procedures, transparency documentation for users, human oversight measures, and accuracy and robustness testing.

Most organisations cannot currently demonstrate compliance with these requirements because they do not have a complete inventory of which systems they operate — let alone which are in scope for High Risk classification.

The EAIC approach

The Sentinel engagement classifies every AI system in your estate against EU AI Act risk tiers, quantifies the monetary exposure of non-compliance, and builds the documentation and governance controls required for compliance — with a fixed-fee engagement.

Where you want the answer as a document rather than a live platform, the review runs on paper. Sentinel is for when you want the picture to stay live — the two front doors to the same estate review.

Find out what AI is really costing you.

A Sentinel Diagnostic takes one day.

Price agreed before we start · No commitment beyond the Diagnostic