Back to all articles
Compliance

What the EU AI Act and UK GDPR Mean for Small Businesses Using AI

Toi 'n' Moi® Team
9 September 2026

For years, "AI regulation" was something small businesses could file under not yet, not us. That has changed. The EU's Artificial Intelligence Act is now in force and applying in stages, its reach extends beyond the EU's borders, and the UK's own approach — while different in shape — already places real duties on any business using AI with personal data. Here is what actually applies, without the hype.

The EU AI Act: in force, and it may reach you even outside the EU

The AI Act is a full EU Regulation — Regulation (EU) 2024/1689 — that entered into force on 1 August 2024 and, per its Article 113, generally applies from 2 August 2026, with some parts phased differently:

  • 2 February 2025 — the bans on unacceptable-risk AI practices took effect.
  • 2 August 2025 — obligations for general-purpose AI models and the governance/penalty provisions began.
  • 2 August 2026 — the general application date for the bulk of the Regulation.
  • 2 August 2027 — obligations for certain high-risk systems that are, or are in, regulated products.

It works on four risk tiers: unacceptable (banned outright), high-risk (strict obligations), limited/transparency risk (you must tell people they are dealing with AI), and minimal risk (the vast majority of everyday tools, with no specific new rules).

The part UK businesses most often miss is reach. The Act is deliberately extraterritorial. Article 2 applies it to providers placing AI on the EU market "irrespective of whether those providers are established or located within the Union or in a third country," and to providers and deployers in a third country "where the output produced by the AI system is used in the Union." A UK business whose AI-driven output reaches customers in the EU cannot assume the Act is someone else's problem.

The UK's approach: principles, not a single Act — yet

The UK has deliberately not passed an equivalent single statute. Its pro-innovation approach to AI regulation sets out five cross-sector principles — safety, security and robustness; appropriate transparency and explainability; fairness; accountability and governance; and contestability and redress — to be applied by existing regulators rather than put on a statutory footing initially.

That does not mean AI is unregulated in the UK. It means the rules come through bodies that already govern you — above all the ICO, through UK GDPR. If your AI use touches personal data, the existing duties apply in full: a lawful basis, transparency, and a Data Protection Impact Assessment where the processing — including "innovative technology, including AI" — is likely to be high-risk. Solely-automated significant decisions carry their own rules under UK GDPR Articles 22A–22D, reformed by the Data (Use and Access) Act 2025. We cover the day-to-day version of this in shadow AI: where your business data goes.

What a small business should actually do

You do not need a compliance department. You need to know three things:

  1. Which category you are in. Most SMB AI use is minimal- or limited-risk, but you should confirm that rather than assume it — and know whether your output reaches the EU.
  2. Where personal data is involved, and whether a DPIA is required before you go further.
  3. Whether you have the basics of governance — a written acceptable-use position, a record of which tools you use and why, and a named person accountable for it.

A recognised, voluntary starting point for the governance itself is the NIST AI Risk Management Framework, which organises the job into four plain functions: govern, map, measure and manage. It is not a law, but it is a sensible spine to hang your own approach on.

Getting a clear read

Our AI Readiness Audit does this assessment for you: it establishes which duties apply to your business, maps your AI and data use against the NIST framework, flags where a DPIA is needed, and hands you a costed plan and an Acceptable AI Use policy. It records the evidence you would need to demonstrate good governance — it does not, and cannot, "make you compliant," and we never claim it does; that responsibility stays yours.

To get a clear read on where your business stands, book a free scoping call.

This article is general information about regulation as we understand it, not legal advice, and the regulatory position continues to change. Take your own professional advice on your specific obligations.

Start Your Digital Journey.

From polished brand websites to private AI-powered business platforms, we build digital systems that look premium, perform reliably, and scale with your business.

Start Your Project

Stay in the loop

Occasional updates on new features and what we're building — no spam, unsubscribe anytime.