EU AI Act: Does It Apply to a UK Business?
The Act follows the market, not the company registration. What went live on 2 August 2026, what moved to December 2027, and how to work out which half reaches you.
Short answer: Brexit did not put you outside it. The EU AI Act follows the market, not the company registration — so the question is not where your business is based, but where your AI's output ends up.
Here is how to work out whether it reaches you, what actually applies today, and what has been pushed to 2027.
Corrected 9 August 2026. An earlier version of this article said the high-risk obligations began on 2 August 2026. They did not: the Digital Omnibus on AI pushed them back to 2 December 2027, and to 2 August 2028 for AI embedded in regulated products. The transparency duties did start on 2 August 2026. The article below reflects the current dates.
The dates that matter
The Act has been law since August 2024, but it applies in stages, and the stages have moved. Two things are true as of August 2026.
Live now. On 2 August 2026 the transparency duties in Article 50 switched on, and the Commission gained real enforcement powers. If an AI system interacts with people, they have to be told they are dealing with a machine. Deepfakes have to be labelled, and AI-generated or altered content has to carry machine-readable marks so it can be detected. These apply to in-scope systems regardless of when they were put on the market — though the marking and detection duties on generative systems that already existed have a transitional run to 2 December 2026.
Pushed back. The obligations most people were bracing for — the "high-risk" regime — did not start this August. The Digital Omnibus on AI moved them to 2 December 2027 for standalone high-risk systems, and 2 August 2028 for AI built into regulated products, to give the EU's standardisation bodies time to publish the technical standards that make compliance demonstrable.
So the practical position is the reverse of what a lot of firms prepared for. If you run a customer-facing chatbot, your duty is live today. If you use AI in hiring or credit decisions, you have until the end of 2027 — and that is time to use, not time to ignore.
How a UK business ends up in scope
The Act uses two roles. A provider builds or sells an AI system. A deployer uses one in the course of business. Most SMEs are deployers.
A UK business is in scope if either of these is true:
- You place an AI system or AI-powered product on the EU market — selling software with AI features to EU customers counts.
- You use an AI system whose output is used in the EU. A UK recruitment firm screening CVs with an AI tool for a Dublin client is the standard example. The firm is in Leeds; the output lands in the EU; the Act applies.
That second limb is the one that surprises people. It was written deliberately, to stop companies serving the EU from outside its borders while ignoring its rules.
If you sell only in the UK
Then the Act does not bind you directly. But two things still reach you.
First, contract flow-down. EU clients — and UK clients who themselves serve the EU — are already pushing AI Act compliance clauses into supplier contracts. You can be outside the law and still unable to win the work without meeting it.
Second, UK law hasn't gone quiet. UK GDPR still governs automated decisions about people, and the ICO has been explicit that AI tools do not suspend it. A UK-only firm using AI to make decisions about customers or staff has obligations today, with or without Brussels.
What being in scope actually requires
It depends on what the system does. The Act sorts AI into tiers, and most business uses sit in the lower ones.
A small set of practices is banned outright — social scoring, emotion recognition on staff in the workplace, and similar. If none of that sounds like your business, good; check anyway, because "emotion recognition" has been read broadly.
High-risk covers AI used for things like recruitment and employee management, credit decisions, and access to essential services. If you deploy AI there, you must use it according to the provider's instructions, keep a meaningful human in the loop, monitor how it performs, keep its logs, and tell affected staff it is in use. Not a transformation programme — but not nothing, and it needs an owner. These duties bite from 2 December 2027, so the work to do now is knowing whether you are in the category, not racing a deadline.
Limited-risk systems, like customer-facing chatbots, carry one duty: people must be told they are talking to a machine. This one is live now, and it is the obligation most likely to catch an ordinary SME, because a website chatbot is a far more common purchase than a CV-screening engine.
Penalties scale to the offence — up to €35m or 7% of worldwide turnover for banned practices, up to €15m or 3% for breaches on the general-purpose model and transparency side — with proportionality for SMEs built in. Nobody is fining a 20-person firm €35m. But the Commission's enforcement powers are no longer theoretical.
What to do this week
Four steps, none of which need a consultant on retainer:
- Inventory. List every AI tool in use — including the ones staff adopted without asking. You cannot classify what you have not found.
- Classify. For each: does it talk to customers (disclosure duty — live now, fix this month)? Does it touch hiring, credit, or access to services (high-risk territory — December 2027, plan for it)? Or is it drafting emails (minimal risk, carry on)?
- Check your EU exposure. Any EU customers, clients, or group companies whose work your AI output feeds into? That is the scope question answered.
- Name an owner. One person accountable for the list, the classifications, and the vendor questions. In a 30-person firm this is a responsibility, not a hire.
For the board-level view of why static policies struggle with systems that change under you, our briefing Static Controls, Live Models goes deeper on the governance problem behind all of this.
And if you want to know where you stand before you spend anything: our AI readiness scorecard takes a few minutes and tells you which of these gaps applies to you. Start there.
Ready to integrate AI into your business?
See how Model Context Protocol (MCP) can connect your AI assistant to all your business tools. Book a call with our team to discuss your specific needs.
Book a Call (opens in a new tab)