The regulation, decoded

Does the EU AI Act apply to your UK business?

The short answer: the UK sits outside the EU AI Act, but the Act reaches beyond EU borders. It applies to UK companies that place AI systems on the EU market, and to UK firms whose AI outputs are used inside the EU. Plenty of UK businesses are in scope without knowing it.

First, the basics

What the EU AI Act actually is

The EU AI Act, formally Regulation (EU) 2024/1689, is the world's first comprehensive law regulating artificial intelligence. It treats AI the way the EU treats other products: the riskier the use, the heavier the obligations, from an outright ban at the top to nothing at all for everyday tools at the bottom.

It is a regulation rather than a directive, so it applies directly across every EU member state without national implementing laws. And like the GDPR before it, it is written to follow the market rather than the map, which is exactly why a UK business cannot dismiss it just because the UK left the EU.

The tests that matter

When the Act catches a UK company

Three routes bring a business established outside the EU into scope: placing an AI system on the EU market, putting one into service in the EU, or operating a system whose outputs are used in the EU. Here is how those tests play out for three familiar kinds of UK firm.

A UK SaaS firm with EU customers

You sell software with AI features to businesses in Ireland, Germany or anywhere else in the EU. You are placing an AI system on the EU market, so the Act applies to you as a provider. If the feature does something in a high-risk area, sifting job applications for an EU employer for instance, the full high-risk regime attaches to it.

A UK manufacturer selling into the EU

Your product ships with an AI safety component, a vision system on machinery, say. It follows the Act's product-regulation route: conformity assessment alongside your existing CE obligations, on the extended timeline for regulated products.

A UK-only firm with UK-only clients

No EU sales, no EU users. You sit outside the Act, with one caveat: if the output of an AI system you run is used inside the EU, perhaps analysis produced for an EU client, that use can pull you into scope. Genuinely domestic operations answer instead to UK regulators and their expectations.

The four tiers

The EU AI Act risk categories, explained

Everything in the Act flows from which tier a system falls into, so classification is the first real piece of compliance work. An AI risk assessment that inventories your systems is where that starts.

Tier What falls into it What the Act demands
Prohibited Practices the EU has banned outright: social scoring, manipulative techniques that cause harm, untargeted scraping of facial images, emotion recognition in workplaces and schools, and real-time remote biometric identification in public spaces (with narrow law-enforcement exceptions). Banned. These practices have been unlawful in the EU since 2 February 2025.
High-risk AI used in areas the Act lists as consequential: biometrics, critical infrastructure, education, employment and worker management, access to essential services such as credit and insurance, law enforcement, migration and justice. Also AI safety components of products already regulated by EU law. The heavy regime: risk management, data governance, technical documentation, logging, human oversight, accuracy and cyber security requirements, conformity assessment and registration.
Limited risk Systems that interact with people or generate content: chatbots, AI-generated media, deepfakes. Transparency: people must be told they are dealing with AI, and synthetic content must be identifiable as such.
Minimal risk Everything else, which is most AI in commercial use: spam filters, recommendation engines, internal productivity tools. No new obligations. Voluntary codes of conduct are encouraged.

The deadlines

When the EU AI Act comes into force

The Act is already law. Its obligations arrive in waves, and the biggest one, the high-risk regime, lands on 2 August 2026.

  1. 1 August 2024

    The Act entered into force. The clock started on every deadline below.

  2. 2 February 2025

    The prohibitions took effect, along with the AI literacy duty on providers and deployers.

  3. 2 August 2025

    Obligations for general-purpose AI models began, alongside the Act's governance and penalty provisions.

  4. 2 August 2026

    The Act's main application date. Most obligations, including the bulk of the high-risk regime, now apply.

  5. 2 August 2027

    The extended deadline for high-risk AI embedded in products covered by existing EU product legislation.

The enforcement teeth

What the fines look like

Penalties are tiered to match the breach. Using a prohibited practice carries fines of up to EUR 35 million or 7% of worldwide annual turnover, whichever is higher. Breaching most other obligations, including the high-risk requirements, carries up to EUR 15 million or 3%. Supplying incorrect or misleading information to authorities carries up to EUR 7.5 million or 1%.

For SMEs the same tiers apply but capped at whichever figure is lower, a deliberate softening for smaller firms. Even so, these are GDPR-scale numbers, and they apply to non-EU companies in scope just as they do to European ones.

Meanwhile, at home

What UK regulation does instead

The UK has so far declined to pass a single AI statute. Its approach is principles-based: existing regulators such as the ICO, FCA and Ofcom apply cross-sector principles to AI within their own remits, supported by government guidance rather than a new rulebook. That means a UK firm can face EU product regulation abroad and expectation-setting guidance at home for the same system.

The most concrete piece of that UK guidance for security teams is the government's voluntary AI Cyber Security Code of Practice, which we cover in full on its own page. For structuring the whole picture, our AI governance framework shows how the EU and UK regimes fit into one operating model.

If you would rather be certain

The fixed-price applicability assessment

As part of the AI Readiness Assessment (£8,500 to £16,700 by scope) we inventory the AI systems your business builds, buys and runs, test each one against the Act's applicability rules and risk tiers, and give you a written determination: which systems are in scope, under which tier, which obligations attach and by which date. You also get the prioritised next steps, so the finding turns into a plan rather than a worry.

If you already know you are in scope, ISO 42001 certification is one of the strongest ways to evidence a serious compliance posture. Every price we charge is published on our pricing page.

Quick answers

EU AI Act questions, answered

Does the EU AI Act apply to UK companies?

Not automatically, because the UK is not an EU member. But the Act is extraterritorial: it catches UK companies that place AI systems on the EU market or put them into service there, and UK firms whose AI systems produce outputs used in the EU. If you sell AI-enabled products or services to EU customers, assume you need to check.

When does the EU AI Act come into force?

It is already in force, since 1 August 2024, and its obligations arrive in stages: prohibitions from 2 February 2025, general-purpose AI obligations from 2 August 2025, most high-risk obligations from 2 August 2026, and the final tranche for AI embedded in regulated products by 2 August 2027.

Who does the EU AI Act apply to?

Providers who develop or supply AI systems, deployers who use them in a professional context, and importers and distributors in the EU supply chain. Crucially, providers and deployers established outside the EU, including in the UK, are covered where their systems or their systems' outputs reach the EU.

How do you comply with the EU AI Act?

In order: establish whether you are in scope at all, classify each AI system against the four risk tiers, then meet the obligations for the tier. For high-risk systems that means risk management, data governance, documentation, human oversight and conformity assessment; for limited-risk systems it is mostly transparency. An applicability assessment and an AI risk assessment are the natural first two steps.

What are the EU AI Act risk categories?

Four tiers. Prohibited practices are banned outright. High-risk systems carry the full compliance regime. Limited-risk systems carry transparency duties, such as telling people they are talking to a chatbot. Minimal-risk systems, the majority, carry no new obligations.

Rocket launching above the AI Governance UK call to action

Scope first, panic never

Settle your applicability question in one call

Forty-five free minutes with a consultant is usually enough to tell whether the EU AI Act is likely to touch your business, and what an applicability assessment would cover if it does.