What is the EU AI Act and does it apply to UK businesses?
+
The EU AI Act is the first comprehensive law governing artificial intelligence. Although the UK has left the EU, the Act applies extraterritorially to any UK business whose AI outputs are used inside the EU, or who places AI systems on the EU market. In practice, this captures most UK SMEs with EU customers, users, or staff.
When do the EU AI Act obligations apply?
+
Full enforcement of the AI Act begins. Provisions covering general-purpose AI, high-risk systems, governance, and penalties become enforceable. Fines can reach €35 million or 7% of global turnover, whichever is higher.
Are these documents actually legally valid?
+
Our packs are drafted to the structure required by the relevant UK and EU regulations and are tailored to your declared business circumstances. They are designed to evidence your compliance obligations, not to constitute legal advice. We recommend any business with complex circumstances has its pack reviewed by a solicitor.
How is this different from a free template?
+
Templates are generic. Our packs are generated from your declared sector, headcount, AI tools, and high-risk use cases, then assembled with the correct policy clauses, register entries, and signatures already populated. A regulator or auditor expects a document that reflects your actual operations — not a placeholder PDF.
What does the Annual Update Subscription cover?
+
Whenever the ICO, EHRC, or EU AI Office publishes new guidance that affects your pack, we re-issue an updated version automatically. Your first year is included in the price of your pack. Your first renewal is half price at £74.50, and renewals after that are £149 per year.
Can I get a refund?
+
If document generation fails on our side and we cannot deliver your pack, you will receive a full refund automatically. If generation succeeds and your documents are delivered, the service has been performed and we do not offer refunds as standard — however if something is genuinely wrong with your documents, contact us at support@clausely.co.uk and we will regenerate or correct them at no charge. See our full Refund Policy for details.
What did the Digital Omnibus political agreement (May 2026) actually change?
+
The Digital Omnibus political agreement narrowed and clarified scope in several places, eased some technical compliance burdens for general-purpose AI providers, and pushed the substantive obligations for most Annex III high-risk AI systems to December 2027. What it did not change: the Article 4 AI literacy obligations, the Article 50 transparency obligations, the prohibited-use rules, and the governance and documentation expectations placed on deployers. For UK businesses deploying AI tools, the baseline policy framework you need is essentially unchanged, and only the timetable for high-risk system technical conformity has moved.
Has the high-risk AI deadline really moved to December 2027? What still applies now?
+
Yes. The agreement pushes the substantive technical and conformity obligations for most Annex III high-risk AI systems to December 2027, giving providers more time to complete conformity assessments and CE marking. Transparency obligations (Article 50), AI literacy obligations (Article 4), prohibited-use rules, governance structures, and the documentation expected of deployers sit outside that extension and already apply. In practice the policy framework, Acceptable Use, AI Literacy, Article 50 disclosures, oversight SOPs and vendor registers, needs to be in place now, even if you are also a high-risk system provider working to a 2027 conformity deadline.
Does the Digital Omnibus mean we can wait until 2027 to act?
+
No. The Omnibus extended one specific timetable, substantive conformity for most Annex III high-risk systems, to December 2027. It did not defer the transparency, literacy, governance, or deployer documentation obligations. If your business uses AI tools (ChatGPT, Copilot, an internal copilot, an AI chatbot, AI-assisted recruitment or marketing), those obligations already apply to you rather than waiting until 2027. Waiting risks both regulatory exposure and PI questionnaire failure at renewal.
What actually counts as a “high-risk” AI system under Annex III?
+
Annex III lists categories of AI systems treated as high-risk because of where they are used, not because of the underlying technology. These include AI used in: biometric identification and categorisation; critical infrastructure (water, gas, electricity, transport); education and vocational training (admissions, grading, proctoring); employment (recruitment, CV screening, performance evaluation, task allocation, termination); access to essential private and public services (credit scoring, insurance pricing, benefits eligibility, emergency dispatch); law enforcement, migration and border control; and administration of justice and democratic processes. If your AI sits in any of these workflows — even if it only assists a human decision — you are likely a high-risk deployer.
Does the EU AI Act still apply to UK businesses post-Brexit?
+
Yes. The Act applies extraterritorially. A UK business is in scope if it places an AI system on the EU market, if the output of its AI system is used in the EU, or if it employs or serves people in the EU or EEA. Brexit did not remove EU regulatory reach over UK businesses whose AI touches EU users, staff, or customers — much as UK GDPR continues to interact with EU data protection law for cross-border processing.
What happens if our business is not compliant?
+
Enforcement of the EU AI Act is phased and already under way, and there is no grace period once an obligation applies to you. National regulators (in the UK, the ICO and sector regulators acting in cooperation with EU authorities) can investigate, request your documentation, and refer matters for fines. Penalties reach €15 million or 3% of global annual turnover (whichever is higher) for breaches of deployer and transparency obligations, and €35 million or 7% of global turnover for the most serious prohibited-use breaches. PI insurers are already asking for documented AI policies at renewal, so undocumented AI use can affect cover as well as expose you to enforcement.
What does the Worker Protection Act 2024 actually require from employers?
+
It places a positive preventative duty on every UK employer to take reasonable steps to prevent sexual harassment of their workers, including harassment by third parties such as customers, contractors, and suppliers. In practice that means a documented risk assessment, an anti-harassment policy, a third-party harassment policy, a clear reporting route, and evidence that staff have been trained. The duty applies whether or not a complaint has ever been raised.
Does the Worker Protection Act apply to small employers with only a handful of staff?
+
Yes. There is no headcount threshold. A five-person business carries the same preventative duty as a five-hundred-person business, though what counts as reasonable steps is judged proportionately against your size, sector, and the risks your people actually face. Our Worker Protection Pack is generated against your declared working patterns and risk profile rather than a generic template.
What happens if we cannot evidence reasonable steps on harassment?
+
In a successful sexual harassment claim, an employment tribunal can uplift compensation by up to 25% where the employer has failed the preventative duty, and the EHRC has standalone enforcement powers it can use without any individual claim being brought. The practical test is documentary: a dated risk assessment, current policies, and training records.
When does UK GDPR require a DPIA, and do we need one?
+
A Data Protection Impact Assessment is required before processing that is likely to result in a high risk to individuals, which includes large-scale processing of special category data, systematic monitoring, profiling with significant effects, and in most cases feeding personal data into AI tools. If you are unsure, the ICO's position is that carrying out a DPIA is the safer course, and our UK GDPR and DPIA Pack produces one tailored to your declared processing.
What UK GDPR documentation should a small business already hold?
+
At minimum: a privacy notice that reflects what you actually do with personal data, a Record of Processing Activities covering your processing purposes, lawful bases, retention periods, and recipients, and a DPIA where your processing is high risk. Those are the first documents an ICO caseworker asks for, and the ones most small businesses either lack or have never updated.
Does putting client or customer data into an AI tool create UK GDPR obligations?
+
Yes. Personal data entered into an AI tool is still being processed, so you need a lawful basis, a privacy notice that reflects it, an entry in your Record of Processing Activities, and usually a DPIA. This is where UK GDPR and the EU AI Act overlap in practice, which is why our packs are designed to be held together rather than in isolation.