
veritas_fox
Frequently asked Questions
Veritas Fox is a UK-based AI Governance and Compliance consultancy specialising in EU AI Act readiness and ISO/IEC 42001:2023 (AI management systems).
EU AI Act
Does the EU AI Act apply to UK companies?
Yes, it can apply to a UK company with no EU office. Under Article 2 of the EU AI Act (Regulation (EU) 2024/1689), the Act reaches any provider that places an AI system on the EU market, and any provider or deployer based outside the EU where the output of their AI system is used in the EU. Since Brexit, the UK is a "third country," so EU membership no longer shields you: if you sell an AI-enabled product to EU customers, or your AI produces outputs used by people in the EU, you are likely in scope. A single EU user can be enough; scope does not depend on how many EU customers you have. What varies is your role and the system's risk level, not whether the Act applies. https://ai-act-service-desk.ec.europa.eu/en/ai-act/article-2
Does the EU AI Act apply to startups and small companies?
Yes, there is no exemption based on company size. Your obligations scale with the risk level of your AI use, not your headcount or turnover. Most small companies using AI for ordinary purposes fall under lighter transparency duties rather than the high-risk regime, but a startup building or deploying a higher-risk system, for example in hiring, credit scoring or biometrics, carries the full set of obligations. The Act does build in help for smaller players: priority access to regulatory sandboxes and proportionate treatment for SMEs. Since the 2026 Omnibus, the AI-literacy duty is also lighter: a duty to take measures to support AI literacy rather than strictly guarantee it.
Has the EU AI Act been delayed? What changed in 2026?
Partly. One track was delayed, not the whole Act. The Digital Omnibus on AI (Regulation (EU) 2026/1744) entered into force on 27 July 2026 and pushed back the high-risk deadlines: standalone high-risk systems (Annex III) now apply from 2 December 2027, and high-risk AI embedded in regulated products (Annex I) from 2 August 2028. But three things did not move: the Article 50 transparency obligations still applied from 2 August 2026, the existing prohibitions stayed in force, and the general-purpose AI rules (in force since August 2025) were untouched. The Omnibus also added two new prohibitions and softened the AI-literacy duty. Treating the whole Act as "postponed" is the most common and costly misreading.
What parts of the EU AI Act are already in force?
Most of the foundational obligations are already live. In force now: the Article 5 prohibitions and the AI-literacy duty (both since 2 February 2025), the general-purpose AI model obligations (since 2 August 2025), and the Article 50 transparency obligations (since 2 August 2026). The penalty regime has applied since 2 August 2025. Still to come: two new prohibitions on "nudifier" and CSAM-generating AI (2 December 2026), watermarking for synthetic-content systems already on the market (2 December 2026), and the high-risk obligations (2 December 2027 / 2 August 2028).
What AI is banned under the EU AI Act?
The Act bans a specific list of "unacceptable-risk" practices outright under Article 5. There is no compliance route for these; a system doing them must simply stop. The original eight, in force since 2 February 2025, include: harmful subliminal or manipulative techniques, exploiting vulnerabilities (such as age or disability), social scoring, certain biometric categorisation, emotion recognition in workplaces and schools, untargeted scraping of facial images, real-time remote biometric identification in public spaces by law enforcement (with narrow authorised exceptions), and predictive policing based solely on profiling. The 2026 Omnibus added two more, AI that generates non-consensual intimate imagery ("nudifiers") and AI that generates child sexual abuse material, which apply from 2 December 2026.
(Article 5 Article 5: Prohibited AI practices | AI Act Service Desk)
Am I a "provider" or a "deployer" under the EU AI Act?
If you only use an AI tool like ChatGPT in your business, you are almost always a "deployer," not a "provider." Under Article 3, a provider develops an AI system (or has one developed) and places it on the market or puts it into service under its own name or trademark; a deployer uses an AI system under its own authority in a professional context. Deployers carry lighter obligations than providers for most systems, but real duties still apply, especially for high-risk systems (human oversight, monitoring, record-keeping). The line can move: if you substantially modify a system, or put your own brand on it, you can become a provider and take on the heavier obligations.
When do the EU AI Act's transparency rules apply, and what do they require?
They already apply. The Article 50 transparency obligations took effect on 2 August 2026 and were not delayed by the 2026 Omnibus. They require you to tell people when they are interacting with an AI system (for example, a chatbot), and to label AI-generated or manipulated content, including deepfakes. Crucially, they apply based on what the system does, not its risk tier, so ordinary generative-AI use is in scope even though it is not "high-risk." A narrower watermarking requirement, for synthetic-content systems already on the market before August 2026, has until 2 December 2026. (Article 50, AI acts search | AI Act Service Desk)
How much can you be fined under the EU AI Act, and is it lower for startups?
Fines run in three tiers under Article 99. Breaching the prohibited-practice rules (Article 5) can reach €35 million or 7% of worldwide annual turnover, whichever is higher. Most other breaches, including high-risk requirements and the Article 50 transparency duties, sit at €15 million or 3%, and supplying incorrect information to authorities is capped at €7.5 million or 1%. A widely repeated error is applying the €35M/7% figure to a transparency or high-risk breach; it applies only to prohibited practices. For SMEs and start-ups the maths reverses: the cap is the lower of the fixed amount or the percentage, a genuine statutory reduction keyed to company size (Article 99(5)). (Article 99, Article 99: Penalties | AI Act Service Desk)
ISO/IEC 42001:2023
Does ISO/IEC 42001:2023 certification make me compliant with the EU AI Act?
No, ISO/IEC 42001:2023 certification is strong evidence of good AI governance, but it is not the same as legal compliance with the EU AI Act. As of 2026, ISO/IEC 42001:2023 is not a "harmonised standard" under the Act, so it confers no presumption of conformity and does not replace the conformity assessment the Act requires for high-risk systems. It does give you much of the operational scaffolding the Act expects (risk management, documentation, human oversight), which makes compliance considerably easier. One structural difference is worth knowing: ISO/IEC 42001:2023 is built around managing risk to your organisation, whereas the AI Act is concerned with risk to people. The Act's own harmonised standards are being developed separately by CEN-CENELEC (the first, prEN 18286, is still in progress).
What is ISO/IEC 42001:2023 and who needs it?
ISO/IEC 42001:2023 is the world's first certifiable standard for an AI management system (AIMS), a framework for governing how an organisation develops, deploys and oversees AI responsibly. Published in December 2023 by ISO and IEC, it uses the same management-system structure as standards like ISO 27001, with a set of controls (Annex A) you select via a Statement of Applicability. It is voluntary and certified by accredited third parties, on a three-year cycle with annual surveillance audits. It matters most when your customers, investors or partners want assurance that your AI is well-governed. Major AI providers including Microsoft, AWS, OpenAI and Anthropic have certified to it as a trust signal.
What's the difference between ISO 42001 and ISO 27001?
ISO 27001 governs information security; ISO 42001 governs AI-specific risks. They share the same underlying management-system structure, so if you already hold ISO 27001 you will recognise the format and can run the two together rather than build a second system from scratch. ISO 42001 adds controls specific to AI that ISO 27001 does not cover, such as training-data quality, transparency, human oversight, and the risks that come with automated decision-making.
Working with Veritas_fox
Where should a UK company start with EU AI Act compliance?
Start by building an inventory of your AI systems and classifying each one by risk. You cannot work out your obligations until you know what AI you use, what each system does, and whether you are a provider or a deployer for it. From there, a gap assessment shows where you stand against the Act, and a prioritised plan tackles the highest-exposure items first. Free Consultation - veritas_fox
What we offer:
AI Compliance Readiness Review
Using our smart questionnaire our experts can guide you through the requirements of ISO/IEC 42001 and the EU AI Act to determine where your organisation may need to introduce new steps.
What the review includes:
-
Discovery session
-
Document and process review
-
AI use-case mapping
-
Red/amber/green (RAG) gap assessment against EU AI Act and ISO/IEC 42001 readiness themes
-
Written findings report
-
30/60/90-day action roadmap
What you walk away with:
-
A readiness report you can take to your board
-
A prioritised, ranked gap list
-
A red/amber/green maturity snapshot
-
A 30/60/90-day roadmap
-
Clear options for what comes next.
Reviewed by Laura Pappi, CEO, Veritas_Fox, last reviewed September 2026. This page is general information about AI regulation and standards, not legal advice; obligations depend on your specific circumstances. Regulatory dates reflect the position as of the review date above and should be kept current.
