White Paper: What the EU AI Act Means for UK Technology Employers
Edited September 2026
The EU AI Act could affect more than how organisations use artificial intelligence. For UK technology employers working with European markets, it could also influence the capabilities they need and how they build their technology teams.
The key question for employers is not simply whether they need to comply with the legislation. It is whether their existing teams have the right skills to build, implement, secure and manage AI responsibly.
The EU AI Act is being introduced in stages. Some requirements already apply, while others take effect later. From 2 August 2026, the European Commission’s AI Office and national authorities began enforcing provisions that had reached their application date. The 2026 AI Omnibus also extended some later deadlines, including those covering certain high-risk AI systems.
This creates a workforce question: do you have the right capabilities in place as AI becomes part of your technology environment?
Does the EU AI Act Apply to UK Companies?
Being based in the UK does not automatically put an organisation outside the EU AI Act.
Certain obligations can apply to organisations outside the EU, depending on their role, the AI systems they place on the EU market or use within the EU, and whether the output of those systems is used in the EU.
For UK technology businesses operating across European markets, this means understanding which of their AI activities fall within the Act.
The requirements will vary between organisations. A company using a general-purpose AI tool internally will not necessarily face the same requirements as a technology business developing an AI system for use in a regulated environment.
That distinction matters when planning recruitment. Employers need to understand the capabilities their technology actually requires before adding AI or regulatory requirements to a role.
How Could AI Regulation Affect Technology Skills?
The AI Act takes a risk-based approach. The requirements placed on an AI system depend on how it is used and the risks associated with it.
For high-risk systems, requirements can include risk management, data governance, logging, documentation, human oversight, robustness, cybersecurity and accuracy.
This means AI projects can require a wider range of capabilities than software development alone.
A technology team may need expertise across engineering, data, cybersecurity, testing, governance and risk. In some organisations, these capabilities will already exist across different roles. In others, there may be genuine gaps.
The result will not necessarily be a new generation of AI-specific job titles. It may instead change what employers expect from existing technology roles.
AI Skills Are Not Just Technical Skills
AI capability extends beyond people who build machine-learning models.
Research from the Department for Work and Pensions and Skills England in 2026 identifies three broad areas of AI skills: technical, responsible and ethical, and non-technical capabilities. It also found that most roles require a combination of these skills rather than advanced technical expertise alone.
That changes how AI capability should be assessed.
A Software Engineer may need to verify AI-generated code and understand its limitations. A Data Engineer may need stronger data governance knowledge. A Cybersecurity professional may need to understand AI-specific risks. A Technology Manager may need enough understanding of AI and its risks to make informed decisions about technology projects.
These capabilities don’t necessarily require separate hires.
Employers should first establish what their existing teams can already do, where the gaps are and which capabilities genuinely need to be added.
AI Literacy Could Affect Existing Teams
The AI Act also includes an AI literacy obligation.
Article 4 requires providers and deployers of AI systems to take measures to support the AI literacy of staff and others working with AI systems on their behalf. The obligation has applied since February 2025, with supervision and enforcement beginning in August 2026. The European Commission says organisations should consider factors such as technical knowledge, experience, education, training and the context in which the AI system is used.
For employers, the practical implication is that AI capability may need to be developed across existing teams rather than concentrated in a single specialist role.
Some organisations may be able to close capability gaps through training and development. Others may need specialist expertise. Many will need both.
The important question is not whether an organisation has an “AI person”. It is whether the people responsible for its AI systems have the knowledge they need to do their jobs effectively.
Should Employers Hire AI Specialists?
Sometimes. But not automatically.
An organisation might assume that increasing use of AI means it needs to hire an AI specialist. In practice, the required capability may already sit across several technology disciplines.
A Software Engineer may provide the engineering expertise. A Data Engineer may manage data requirements. A Cybersecurity professional may address security risks. A Technology Architect may consider how the AI system fits into the wider technology environment.
Another organisation may genuinely need dedicated AI expertise.
The starting point should therefore be the business and technology problem, not the job title.
This is particularly important when defining specialist vacancies. Combining software engineering, machine learning, cybersecurity, data governance, regulatory compliance and transformation into one role may create a specification that very few candidates can realistically meet.
Hire for Capability, Not Buzzwords
AI experience is becoming an increasingly common requirement in technology vacancies. Adding it to a job description, however, does not necessarily tell employers what a candidate actually needs to do.
A Software Engineer working on an AI-enabled product may need experience with AI-assisted development, testing and verification. A Data Engineer may need experience with data quality and governance. A Cybersecurity specialist may need to understand AI-specific attack surfaces.
These are different capabilities.
Treating them all as “AI skills” can make a role harder to define and harder to recruit for.
A better approach is to identify the outcome the person needs to deliver, then determine which capabilities are essential to achieving it.
That also makes it easier to separate skills that are required on day one from those that can be developed after hiring.
What Does This Mean for Software Engineers?
AI will not affect every Software Engineering role in the same way.
For some engineers, AI may primarily be another tool within the development process. Others may build or maintain AI systems operating in environments with additional requirements around testing, documentation, data, security and human oversight.
This makes “AI experience” a poor standalone measure of suitability.
Someone who regularly uses AI coding tools is not automatically equipped to develop or maintain a regulated AI system.
Employers should instead assess whether candidates understand the technology they are building, can critically evaluate AI-generated output and can work within the technical requirements of the environment.
Data and Cybersecurity Skills Are Also Changing
AI increases the importance of understanding the data behind a system.
For higher-risk AI systems, data quality, governance and documentation can form part of the wider technology responsibility. Depending on the system, Data Engineers may therefore need to understand areas such as data provenance, quality and governance alongside their existing technical skills.
The same applies to cybersecurity.
Cybersecurity and robustness are among the requirements associated with high-risk AI systems. In July 2026, the European Commission also published an Action Plan on Cybersecurity and Artificial Intelligence, highlighting the growing connection between AI and cybersecurity.
For employers, this could increase the value of professionals who understand both areas.
It does not necessarily mean creating new “AI Data” or “AI Cybersecurity” roles. It may mean strengthening the capabilities of existing teams or bringing in specialist expertise where a genuine gap exists.
What About AI Used in Recruitment?
AI regulation is particularly relevant to employers because certain AI systems used in employment are classified as high risk.
The European Commission identifies examples including systems used to place targeted job advertisements, analyse and filter applications and evaluate candidates. However, the classification applies to specific use cases rather than automatically making every AI tool used by a recruitment team high risk.
Understanding the technology’s actual use is therefore important.
An AI tool used somewhere in the recruitment process does not automatically create the same regulatory requirements as an AI system used to evaluate candidates.
Where AI is used for screening, evaluation or other employment-related decisions, employers may need closer collaboration between Talent, HR, Technology, Data, Legal and Compliance teams.
When Do the High-Risk Employment Rules Apply?
The timing gives employers an opportunity to prepare.
Following the 2026 AI Omnibus changes, the rules for high-risk AI systems covered by Annex III are scheduled to apply from 2 December 2027. This includes the relevant employment-related use cases covered by the framework.
Employers can use the time before these requirements apply to understand which AI systems they use, what those systems do, who is responsible for them and whether the necessary capabilities exist within their teams.
That assessment can inform workforce planning before a skills gap becomes a recruitment problem.
Avoid Creating an Impossible Technology Role
AI can make job descriptions more complicated very quickly.
An employer may want someone who understands software engineering, machine learning, cybersecurity, data governance, regulatory requirements, risk management and business transformation.
That may sound comprehensive, but it can also describe an unrealistic candidate.
The more requirements a role combines, the smaller the pool of genuinely suitable candidates becomes. It can also become difficult to distinguish between capabilities that are essential and those that would simply be useful.
Employers should start with the outcome they need.
From there, they can identify the capabilities required, determine what already exists within the team and decide whether the remaining gap should be addressed through development, recruitment, contracting or specialist support.
What Should Technology Employers Do Now?
The EU AI Act does not mean every UK technology employer needs to restructure its workforce.
It does mean organisations should understand how AI is being used across their technology environment and consider whether their teams have the capabilities required to support it.
That means looking at the systems being developed or deployed, the markets they serve and the responsibilities attached to them.
Employers can then assess their existing capability and identify genuine gaps.
Some gaps may be addressed through upskilling. Others may require changes to existing responsibilities. Some may justify a permanent hire, while others may be better suited to contractors or specialist project support.
The important thing is to make that decision based on the capability the organisation actually needs.
Key Takeaways
- AI regulation is changing the capabilities technology employers need, not necessarily creating demand for entirely new roles.
- AI capability extends beyond technical expertise, with existing roles increasingly needing relevant data, cybersecurity, governance and AI knowledge.
- Employers should define the capability they need before defining the vacancy, particularly where several technology disciplines overlap.
- Not every capability gap requires recruitment; employers can consider upskilling, changing responsibilities, contractors or specialist support.
- Hiring should focus on genuine capability gaps, rather than adding broad AI requirements to existing technology roles.