Back to Blog
Data & Governance

Does the EU AI Act Apply to My UK Business? A Five-Question Test

A
Arun Godwin Patel
August 5, 20267 min read

Most UK SMEs are out of scope. Some are in it without realising. Five questions that settle the matter in about ten minutes, with what to do next in either case.

Five questions in sequence that settle whether the EU AI Act reaches a UK business, ending with most UK SMEs being out of scope.

Most UK small and medium businesses are out of scope of the EU AI Act. A minority are in it without realising, and a smaller minority have convinced themselves they are in it when they are not, usually after a conversation with someone selling compliance services.

This test settles which group you are in. It takes about ten minutes and you should write down the answers, because the value is partly in being able to show your reasoning later.

This article is part of our guide to the EU AI Act for UK businesses.

This is a practical scoping exercise, not legal advice. If questions four or five put you in the high-risk category, take proper counsel.

Question 1: Do you use anything that counts as an AI system?

Wider than people expect. It is not limited to chatbots and large language models. The Act defines an AI system broadly enough to catch machine learning models, and in some readings rule-based systems that infer outputs from inputs with a degree of autonomy.

In practice, list anything that:

  • generates text, images, audio or video
  • scores, ranks, sorts or matches people or applications
  • makes or recommends a decision that used to be made by a person
  • predicts something from historical data

Include tools you did not buy as AI. Your applicant tracking system may have added AI ranking. Your accounting package may categorise transactions with a model. Your marketing platform almost certainly scores leads. See AI and machine learning marketing terms explained.

If the answer is genuinely nothing, stop. You are out of scope. It is rarer than you would think.

Question 2: Does any EU connection exist?

Three routes into scope, and only three.

Do you place an AI system on the EU market? Sell, license, or otherwise make available a product or service containing AI, to customers in the EU. Distributing free of charge counts.

Is the output of your AI system used in the EU? You run it from the UK, and the result is used inside the Union. This is the one people miss. A UK firm using AI to sift candidates for an EU employer is caught by this, even with no EU entity and no EU sales.

Do you have an EU establishment? A subsidiary, branch or office.

If all three are no, stop. The EU AI Act does not apply to you. Write down the date and the reasoning. Move on to AI regulation in the UK, which does apply and which most businesses in this position have not thought about.

For a typical UK SME trading domestically, this is where the test ends.

Question 3: Are you a provider or a deployer?

If you are still going, this determines the weight of what follows.

You are a deployer if you use AI systems built by someone else, under their name, for their stated purpose. This is nearly everybody.

You are a provider if you develop an AI system and place it on the market under your own name or trademark. You also become one if you substantially modify a high-risk system, rebrand somebody else's as your own, or repurpose a system so that it becomes high risk.

The white-label trap is the common one. If you sell a chatbot to your customers as your product, built on somebody else's model, you are a provider. Provider duties are considerably heavier.

Question 4: Is any of it prohibited?

Short list, and worth checking because the penalties reach EUR 35 million or 7 per cent of global turnover.

Banned since February 2025: social scoring by public authorities, exploiting vulnerabilities of specific groups, untargeted scraping of facial images to build recognition databases, emotion recognition in the workplace or in education outside narrow medical and safety exceptions, and certain biometric categorisation.

The workplace emotion recognition point catches more businesses than expected. Software that scores sales calls or interviews on enthusiasm, sentiment or engagement is worth a careful look.

If anything here applies, stop and take advice this week.

Question 5: Is any of it high risk?

Two lists.

Annex III, standalone systems. AI used for:

  • recruitment, selection, promotion, termination, task allocation, or monitoring and evaluating workers
  • access to education or vocational training, and assessment within it
  • creditworthiness and credit scoring, and risk assessment and pricing in life and health insurance
  • eligibility for essential public benefits and services
  • emergency call triage and dispatch
  • law enforcement, migration, border control and the administration of justice

Annex I, AI embedded in regulated products. Medical devices, machinery, lifts, toys, vehicles and other categories already covered by EU product safety legislation.

Deadlines: 2 December 2027 for Annex III, 2 August 2028 for Annex I. Both were deferred from August 2026 by the Digital Omnibus, as covered in the EU AI Act deadline moved.

For ordinary businesses the realistic entry point is recruitment. Using AI to rank or sift job applicants for roles in the EU puts you here.

Reading your result

Out at question 2. The great majority. No AI Act obligations. Focus on UK GDPR and sector regulation instead, and do the staff literacy work anyway because it is cheap and useful.

In scope, nothing above minimal risk. Article 4 literacy applies. Nothing else does. A morning's work.

In scope with a chatbot or published AI content. Article 50 applies now. Add disclosure to the bot, review your content labelling. A few hours.

In scope and high risk. A real programme, with time to plan it. Start with the human oversight arrangement and the logging, because those take organisational change rather than purchasing.

Anything prohibited. Act now, independent of every other answer here.

The mistake both ways

The expensive mistake is assuming you are out because you are British. Scope follows the market. A forty-person UK consultancy with three Dublin clients and an AI tool in its hiring process is in scope and usually has no idea.

The other expensive mistake is assuming you are in because AI is involved and regulation exists. Most AI in normal business use is minimal risk and attracts no obligations at all. If someone has quoted you for a compliance programme without first establishing scope, they have skipped the only question that matters.

Key Takeaways

  • Only three routes into scope: placing AI on the EU market, output used in the EU, or an EU establishment. No route means no obligation.
  • Question two ends the test for most UK SMEs trading domestically. Write down the answer and the date.
  • Nearly all UK businesses are deployers. White-labelling somebody else's AI as your own product makes you a provider, with much heavier duties.
  • Recruitment is the realistic way an ordinary business lands in the high-risk category. Check that before anything else.
  • Out of scope of the AI Act is not out of scope of regulation. UK GDPR and sector rules apply now.

Frequently Asked Questions

Our software supplier is based in the EU. Does that put us in scope?

No. Buying from an EU supplier does not create scope. Your supplier has provider obligations. You are a UK deployer, and your position depends on whether your own activity has one of the three EU connections.

We sell to a UK business that we know resells into the EU. Where does that leave us?

Possibly in scope, and this is a genuinely grey area worth taking advice on. If the output of your AI system is knowingly used in the EU, the extraterritorial provision can bite even at one remove. Ask your customer what they do with it, in writing.

How often should we redo this test?

Twice a year, and whenever you sign a significant EU customer, acquire a business, or adopt a notable new tool. Scope changes through commercial decisions far more often than through regulatory ones.

What evidence should we keep?

The answers, the date, who decided, and a list of the AI systems you considered. One page. If a customer or regulator ever asks, being able to show that you assessed the question deliberately is most of the value.


Want the scope question settled properly rather than guessed at? Talk to Halo Technology Lab. Our strategy and scoping service includes an AI inventory and a written scope assessment.

Share this article

Enjoyed this? Get the next one by email

Practical AI playbooks, build logs and tool teardowns. One email a week, free, unsubscribe in one click.

See what’s in it first

Have a project in mind?

Let's discuss how we can help bring your ideas to life.

Get in Touch