Does the EU AI Act apply to UK businesses?

Yes, it can. The EU AI Act applies to UK businesses that place AI systems on the EU market or whose AI output is used in the EU.

Why Brexit does not take you out of scope

The EU AI Act, Regulation (EU) 2024/1689, follows the market rather than the company's address. It entered into force in August 2024. It can reach businesses outside the EU, including UK businesses, that place AI systems on the EU market or whose AI system output is used in the EU. If you sell into Europe, serve EU customers online or deliver work that EU clients rely on, you cannot assume the Act stops at the Channel.

That does not mean every UK firm with a French client faces heavy compliance work. Your exposure depends on what your AI does and who it affects, not just on whether you have EU customers.

Work out which camp you are in

Most SMEs fall into one of three positions.

  • Internal productivity use: You use general-purpose tools to draft, summarise and research, and a person reviews the output before it reaches anyone. Your obligations under the Act are likely to be light, although your normal data protection duties still apply.

  • Customer-facing AI: You run a chatbot, voice assistant or similar system that interacts directly with people in the EU. Transparency rules matter here, because people need to know they are dealing with an AI system.

  • AI in sensitive decisions: You build, sell or use AI that screens job applicants, assesses students or judges creditworthiness for people in the EU. This is where high-risk rules may apply, and where you need specialist advice early.

Key dates for UK businesses

The Act phases in over several years. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and changed parts of the timetable. The dates that matter now:

  • 2 February 2025: Rules on prohibited AI practices began to apply.

  • 2 August 2026: Transparency obligations under Article 50 began to apply, including telling people they are interacting with an AI system.

  • 2 December 2027: High-risk obligations apply to stand-alone systems listed in Annex III, which covers specified uses in areas including employment, education and credit assessment.

  • 2 August 2028: High-risk obligations apply to AI embedded in regulated products under Annex I.

Read the Annex III date carefully. Not every AI system used in hiring, education or lending is high-risk. Whether yours qualifies depends on exactly what it does and how its output is used, and that judgement needs advice rather than guesswork.

What to do now

  • Map your AI use: List the tools you use, what each one does and whether its output reaches anyone in the EU. A one-page inventory is enough to start.

  • Check customer-facing systems first: If a chatbot or automated assistant talks to EU users, make sure it clearly tells them it is an AI. This is the obligation most likely to affect an SME today.

  • Flag sensitive uses: Note any AI involved in recruitment, assessment or credit decisions affecting people in the EU. Review these well before December 2027.

  • Set internal rules: A clear AI acceptable use policy records which tools staff may use and for what. It also helps you show control if a client asks.

The UK position

The UK has no standalone AI law equivalent to the EU AI Act. UK businesses using AI must comply with existing law, such as data protection, and with guidance from sector regulators. For most SMEs, the bigger day-to-day risk is how staff handle information, so it is worth understanding what UK GDPR means for client data in AI tools.

The rules on scope and classification are detailed and their practical application is still developing. Take advice on your own situation before concluding you are in or out of scope.

Want to talk this through?