Sometimes. The EU AI Act reaches UK firms that supply AI in the EU or whose AI output is used there. Here is when it applies, the risk tiers, the current timeline and how the UK regulates AI.
Yes, in some cases. The EU AI Act applies to a UK business that places an AI system on the EU market, or whose AI system produces output that is used in the EU, even though the business is based outside the EU. If you only use AI inside the UK, for UK customers, it is unlikely to apply to you directly, but UK law still does. This is practical guidance, not legal advice; check your own position with a qualified adviser.
When the EU AI Act reaches a UK business
The Act follows AI into the EU, wherever the business behind it is based. In plain terms, a UK firm is likely to be in scope if any of these is true:
- You supply an AI system in the EU. That includes software with AI features that EU customers use, and AI models offered to EU businesses. The Act calls you a provider, and it applies wherever you are established.
- Your AI output is used in the EU. If you run an AI system in the UK and its output, such as a screening result, a credit decision or generated content, is used in the EU, the Act can apply even though the system never leaves the UK.
- You have an EU office or subsidiary that uses AI. That business is a deployer established in the EU, with its own obligations.
- You import or distribute AI systems into the EU. Importers and distributors have duties of their own.
The Act does not cover AI used purely for personal, non-professional purposes, or AI developed only for scientific research. Most UK firms that use AI tools only for their own UK operations will not be directly in scope. Your EU clients may still ask you about it, because they may be.
The risk tiers in plain words
The Act sorts AI by what it is used for, not by the technology behind it. The more harm a use could do, the tighter the rules.
- Banned. A short list of practices the EU treats as unacceptable, such as social scoring, manipulating people in harmful ways, exploiting vulnerable people, scraping facial images from the internet or CCTV to build recognition databases, and recognising emotions at work or in education other than for medical or safety reasons. AI that generates non-consensual intimate images or child sexual abuse material is being added to the list.
- High risk. Uses that can seriously affect people’s health, safety or rights, such as recruitment and decisions about workers, education, critical infrastructure and access to essential services. For financial firms, that includes judging the creditworthiness of individuals (but not fraud detection) and setting risk and prices for individuals in life and health insurance. Before they reach the market, high-risk systems need risk management, good-quality data, activity logs, detailed documentation, human oversight, and strong accuracy, robustness and cybersecurity.
- Transparency. People must be told when they are talking to a chatbot, and deepfakes and certain AI-generated content must be labelled.
- Minimal risk. Everything else, such as spam filters or AI in video games. No new obligations.
There are separate rules for the providers of general-purpose AI models, the large models behind tools such as ChatGPT. Those fall on the model developers, not on the firms that use the tools. Firms in scope also have a duty to support AI literacy among the staff who use AI systems.
Fines for using a banned practice can reach €35 million or 7% of worldwide annual turnover, whichever is higher, while smaller businesses are capped at the lower of the two.
The timeline, including the 2026 changes
The Act came into force on 1 August 2024 and applies in stages. In 2026 the dates for high-risk systems were pushed back by an amending regulation known as the AI Omnibus. The European Commission proposed it in November 2025, and it came into force on 27 July 2026, a few days before the original high-risk deadline.
- 2 February 2025. The bans on prohibited practices and the AI literacy duty began to apply.
- 2 August 2025. The rules for providers of general-purpose AI models began to apply.
- 2 August 2026. The Act became generally applicable, apart from the dates below. That includes the transparency duties for chatbots and AI-generated content. Generative AI systems already on the market before that date have until 2 December 2026 to add machine-readable marking to their output.
- 2 December 2026. The new ban on AI that generates non-consensual intimate images or child sexual abuse material applies.
- 2 December 2027. High-risk rules apply to stand-alone systems, such as those used for recruitment, credit scoring and education. This was originally 2 August 2026.
- 2 August 2028. High-risk rules apply to AI built into products already covered by EU safety law, such as medical devices and machinery. This was originally 2 August 2027.
The timetable has already moved once, and more guidance is still to come, so check the European Commission’s AI Act page for the current position before you rely on any date, including these.
How AI regulation works in the UK
The UK has taken a different route. As of October 2026 there is no AI-specific Act and no government AI bill before Parliament. Private members’ bills on AI have been put forward, but none has become law, and the King’s Speech in May 2026 did not include an AI bill. Instead, the government’s principles-based approach asks existing regulators to apply principles such as safety, transparency, fairness, accountability and the right to challenge a decision within their own sectors.
In practice, the law you already follow applies to AI too:
- Data protection. UK GDPR applies whenever AI processes personal data. The ICO’s guidance on AI and data protection explains what it expects, including when a data protection impact assessment is likely to be needed.
- Automated decisions. The Data (Use and Access) Act 2025, whose data protection changes are now largely in force, widened the situations in which a firm can make significant decisions about people by solely automated means, as long as safeguards are in place: telling people, letting them challenge the decision and giving them access to a person. Special category data stays more tightly protected.
- Financial services. The FCA’s statement on its approach to AI says it does not plan to introduce extra rules for AI. It expects firms to apply the rules they already have, in particular the Consumer Duty and the Senior Managers and Certification Regime, which holds named senior managers accountable.
- Other sectors. Other regulators apply their existing rules to AI in the same way, within their own areas.
A short checklist for UK firms
- List the AI you use and supply. Include AI features inside software you already pay for. You can’t judge scope without the list.
- Mark anything that touches the EU. EU customers, EU staff, an EU office, or AI output that is used in the EU.
- Check for banned and high-risk uses. Look hardest at recruitment, credit decisions and insurance pricing for individuals.
- Label chatbots and AI-generated content wherever EU users will see them.
- Ask your suppliers how they meet the Act, if you use their AI in the EU.
- Cover UK law as well. Data protection, the rules on automated decisions and, for regulated firms, the FCA’s existing rules apply now, whatever happens in the EU.
- Put governance around it. A use policy, a register and named owners make all of this easier to show. The guide to building an AI governance framework sets out the order.
- Check the dates again regularly. The EU timetable has already changed once.
Getting help
If you want help working out where your firm stands, AI governance consulting covers the register, the risk sorting and the evidence, or you can book a free 30-minute AI consultation.
