EU AI Act: Does It Apply to a UK Business?
The Act follows the market, not the company registration. How to work out whether it reaches you before enforcement starts on 2 August 2026.
Short answer: Brexit did not put you outside it. The EU AI Act follows the market, not the company registration — so the question is not where your business is based, but where your AI's output ends up.
Here is how to work out whether it reaches you, and what to do about it either way.
The date that matters
The Act has been law since August 2024, but it applies in stages. On 2 August 2026 the bulk of it switches on: the obligations for "high-risk" systems, the transparency duties for everyday AI like chatbots, and the national enforcement regimes that make the penalties real. Up to now the Act has mostly been something to read about. From August it is something you can be fined under.
How a UK business ends up in scope
The Act uses two roles. A provider builds or sells an AI system. A deployer uses one in the course of business. Most SMEs are deployers.
A UK business is in scope if either of these is true:
- You place an AI system or AI-powered product on the EU market — selling software with AI features to EU customers counts.
- You use an AI system whose output is used in the EU. A UK recruitment firm screening CVs with an AI tool for a Dublin client is the standard example. The firm is in Leeds; the output lands in the EU; the Act applies.
That second limb is the one that surprises people. It was written deliberately, to stop companies serving the EU from outside its borders while ignoring its rules.
If you sell only in the UK
Then the Act does not bind you directly. But two things still reach you.
First, contract flow-down. EU clients — and UK clients who themselves serve the EU — are already pushing AI Act compliance clauses into supplier contracts. You can be outside the law and still unable to win the work without meeting it.
Second, UK law hasn't gone quiet. UK GDPR still governs automated decisions about people, and the ICO has been explicit that AI tools do not suspend it. A UK-only firm using AI to make decisions about customers or staff has obligations today, with or without Brussels.
What being in scope actually requires
It depends on what the system does. The Act sorts AI into tiers, and most business uses sit in the lower ones.
A small set of practices is banned outright — social scoring, emotion recognition on staff in the workplace, and similar. If none of that sounds like your business, good; check anyway, because "emotion recognition" has been read broadly.
High-risk covers AI used for things like recruitment and employee management, credit decisions, and access to essential services. If you deploy AI there, from August 2026 you must use it according to the provider's instructions, keep a meaningful human in the loop, monitor how it performs, keep its logs, and tell affected staff it is in use. Not a transformation programme — but not nothing, and it needs an owner.
Limited-risk systems, like customer-facing chatbots, carry one duty: people must be told they are talking to a machine.
Penalties scale to the offence — up to €35m or 7% of worldwide turnover for banned practices, up to €15m or 3% for breaking the high-risk rules — with proportionality for SMEs built in. Nobody is fining a 20-person firm €35m. But enforcement, like the rules, becomes real this August.
What to do this week
Four steps, none of which need a consultant on retainer:
- Inventory. List every AI tool in use — including the ones staff adopted without asking. You cannot classify what you have not found.
- Classify. For each: does it touch hiring, credit, or access to services (high-risk territory)? Does it talk to customers (disclosure duty)? Or is it drafting emails (minimal risk, carry on)?
- Check your EU exposure. Any EU customers, clients, or group companies whose work your AI output feeds into? That is the scope question answered.
- Name an owner. One person accountable for the list, the classifications, and the vendor questions. In a 30-person firm this is a responsibility, not a hire.
For the board-level view of why static policies struggle with systems that change under you, our briefing Static Controls, Live Models goes deeper on the governance problem behind all of this.
And if you want to know where you stand before you spend anything: our AI readiness scorecard takes a few minutes and tells you which of these gaps applies to you. Start there.
Ready to integrate AI into your business?
See how Model Context Protocol (MCP) can connect your AI assistant to all your business tools. Book a call with our team to discuss your specific needs.
Book a Call (opens in a new tab)