Keep up to date with the trending topics
from our industry experts

EU AI Act – What financial services firms need to know!

Written by Dan O’Hara

Tuesday, 4 August, 2026

Webinar:

The true cost of AI: A reality check for fund managers

23rd September 2026

AI now comes with a meter running. Join our expert panel to explore how consumption-based pricing is reshaping AI adoption and how to prove it’s delivering measurable value.

The EU AI Act is the world's first comprehensive law governing artificial intelligence, and some of its most significant compliance deadlines are now landing. If you have seen headlines suggesting the Act has been delayed, that is only half of the story. While some obligations have been pushed back, others will take effect in August 2026 exactly as planned.

For UK financial services firms, the obvious question is whether any of this applies to you at all. The short answer: probably not directly if you have no EU footprint. However, there are several reasons why the Act should be on your radar. Here’s what you need to know.

What is the Act trying to achieve?

In plain English, the EU AI Act regulates AI based on the risk it poses to people, rather than the technology itself. It categorises AI systems into four buckets:

  1. Prohibited risk: Practices the EU considers unacceptable, such as social scoring and certain forms of manipulative AI. These have been prohibited since February 2025.
  2. High risk: AI used in areas such as recruitment, creditworthiness assessments and access to essential services. These systems face the most extensive obligations, including risk management, documentation, human oversight and registration requirements.
  3. Limited risk: AI systems that interact with people, such as chatbots, or generate content. These are subject to transparency obligations. For example, users may need to be told when they are interacting with AI, and certain AI-generated content must be identifiable (a trickier aspect the AI industry is still grappling with).
  4. Minimal risk: Most other AI applications, including spam filters, have no additional regulatory burden under the Act.

The Act also contains separate rules for general-purpose AI models. These obligations generally apply to the providers of the underlying models (i.e. OpenAI, Microsoft, Anthropic and Google) rather than the firms that use them.

The dates that matter

The timeline has shifted recently. In May this year, the EU agreed the "Digital Omnibus", which pushed back the high-risk AI rules because the technical standards firms needed for compliance were simply not ready. The revised timeline looks like this:

  • Already in force - prohibited AI practices and AI literacy requirements (February 2025), along with rules for general-purpose AI models (August 2025).
  • August 2026 - transparency obligations take effect. Chatbots must disclose they are AI systems, and certain AI-generated content must be labelled accordingly. Regulators also gain full enforcement and penalty powers from this date.
  • December 2026 – additional controls added by the Omnibus take effect.
  • December 2027 - high-risk AI obligations apply, having been postponed from August 2026.
  • August 2028 - high-risk rules apply to AI embedded within regulated products.

The EU has been clear that, despite the revised deadlines, organisations should already be preparing for compliance.

Does it apply to UK firms?

For a typical UK financial services firm with no EU offices and no EU clients, the Act may not directly apply.

So far, the UK government has opted for a lighter-touch, principles-based approach, relying on existing regulators such as the FCA rather than introducing an equivalent AI law.

However, if:

  • You have an EU branch, office or management company
  • You market funds to EU investors or serve EU clients
  • You use AI in a way that results in outputs being relied upon within the EU

Then it’s worth carrying out a proper assessment to check whether the Act applies to your organisation.

Even if it doesn't apply, is there anything firms should look out for?

There are three main ways the AI Act reaches UK firms indirectly.

1. Through your vendors

Many of the AI tools firms use today, such as Microsoft 365 Copilot and Anthropic Claude, are built by providers who are firmly within the scope of the Act. As a result, you are likely to see changes flow through to your existing tools, including content labelling and updated contractual terms, whether you asked for them or not.

2. Through your counterparties

EU investors, clients and partners are increasingly asking about AI governance as part of their due diligence processes. Being able to show what AI you use, how it is controlled, and who is accountable for its oversight is quickly becoming a standard part of due diligence questionnaires.

3. Through the direction of travel.

The FCA has been clear that existing frameworks, including the Senior Managers Certification Regime, Consumer Duty and operational resilience requirements, already apply to how firms use AI. The EU AI Act is helping to shape global expectations of what "good" looks like, and UK regulatory expectations are unlikely to diverge significantly from that direction of travel.

What practical things can firms do now?

The sensible steps are largely the same as those we would recommend as part of good AI governance, regardless of regulation:

  1. Build an AI inventory. You cannot govern what you cannot see. Identify the AI tools being used across the business, including those embedded within software you already own, such as Microsoft Copilot.
  2. Put an AI usage policy in place. Create a short, practical document that sets out what staff can and cannot use AI for, as well as what data may be entered into AI tools. You can download our AI Acceptable Use Policy template here: Download your own Acceptable Use Policy for AI template.
  3. Train your people. The Act's AI literacy requirement provides a useful benchmark, even for UK firms. Employees who use AI should understand both its capabilities and its limitations, along with the associated risks.
  4. Check your data governance. AI is only as safe as the data it can access. Sensitivity labels, access controls and data classification policies do the heavy lifting here.
  5. Review vendor AI features. Understand which of your suppliers are switching on AI capabilities within their products and what controls your organisation has over their use.
  6. Keep humans in the loop. Any AI output that feeds a material business decision should be subject to appropriate human oversight.

How can Lanware help?

We work with financial services firms on exactly these challenges every day. That includes AI training, building AI usage policies and governance frameworks aligned with FCA expectations, configuring AI and security controls so tools such as Microsoft Copilot only access the data they should, and deploying compliant, private AI solutions where your data never leaves your environment.

If you are unsure where your financial services firm stands, a good first step is a conversation to understand what AI is already being used across your business. The answer usually surprises people.

Useful further reading

If you are interested in learning more, then please speak to one of our experts.

Our services

Our 4 pillars for a complete choice of managed IT services - all tailored to the needs of financial services firms in London and the UK.

Finance Forward 365

Microsoft modern workplace & cloud technology for digital transformation.

Compliant Teams

Increased productivity & collaboration with call recording whilst reducing costs.

Cyber Security

Keep your data secured against rapidly changing threats within Financial Services.

Power BI

Business Intelligence transformation and support tailored for Financial Services.

The LanWIRE

Join the community for financial services businesses

  • Stay updated with technology and cyber security trends
  • Network with your industry peers
  • Get invites to webinars and exclusive events
  • Gain access to useful tools and templates

The LanWIRE

Join the community for financial services businesses moving to the Microsoft Cloud

Q