The EU AI Act and UK Businesses: What Actually Applies to You
The UK has not adopted the EU AI Act, and it can still reach your business. A complete guide to which duties apply, when, what the penalties are, and what a sensible response looks like.

The UK did not adopt the EU AI Act. It voted to leave the European Union, it has published its own, considerably lighter, approach to AI regulation, and there is no UK AI Act on the statute book.
None of which means the EU AI Act cannot reach your business. Scope follows the market, not the registered office, which is the single most misunderstood thing about it.
This guide sets out what the Act is, which parts apply to whom, what changed in July 2026, what the penalties are, and what a proportionate response looks like for a business of twenty to five hundred people. It is written for owners and managers rather than lawyers, and it is a plain-English summary rather than legal advice.
The shape of the Act in one page
The AI Act sorts AI systems into four tiers by risk, and attaches different duties to each.
Unacceptable risk: banned. Social scoring by public authorities, exploiting vulnerabilities, untargeted scraping of facial images, emotion recognition in workplaces and schools with narrow exceptions. In force since 2 February 2025. Penalties here are the heaviest in the Act.
High risk: heavily regulated. Two lists. Annex III covers standalone systems in recruitment and worker management, education access, credit and insurance scoring, essential public services, law enforcement, migration and justice. Annex I covers AI embedded in products already regulated for safety, such as medical devices and machinery. Duties include risk management, data governance, technical documentation, human oversight, accuracy and robustness standards, conformity assessment and registration.
Limited risk: transparency only. Chatbots, emotion recognition outside the banned contexts, deepfakes and AI-generated content. The duty is disclosure, not approval. This is Article 50 and it is where most ordinary businesses land.
Minimal risk: nothing. Spam filters, recommendation engines, most productivity tooling. The overwhelming majority of AI in normal business use sits here and attracts no obligations at all.
Running underneath all four tiers is Article 4, the AI literacy duty, which applies to providers and deployers regardless of risk tier.
The dates that matter
| Duty | Applies from |
|---|---|
| Prohibited practices (Article 5) | 2 February 2025 |
| AI literacy (Article 4) | 2 February 2025, supervised from 2 August 2026 |
| General-purpose AI provider obligations | 2 August 2025 |
| Transparency (Article 50) | 2 August 2026 |
| High risk, Annex III standalone | 2 December 2027 |
| High risk, Annex I embedded in products | 2 August 2028 |
The last two rows moved. They were both 2 August 2026 until the Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026. The rows above them did not move, which is covered in the EU AI Act deadline moved.
Are you a provider or a deployer?
This distinction determines almost everything, and it is frequently got wrong.
A provider develops an AI system and places it on the market under its own name. A deployer uses an AI system in the course of its activity.
Nearly every UK SME is a deployer. Using ChatGPT, running a chatbot built on somebody else's model, using an applicant tracking system with AI sifting: all deployment. Deployer duties are much lighter than provider duties.
The trap is that you can become a provider without intending to. Put your own name on an AI system, substantially modify a high-risk one, or change the purpose of one so that it becomes high risk, and you take on provider obligations. A business that white-labels a chatbot as its own product is a provider, not a deployer.
How a UK business ends up in scope
Three routes, and only three.
You place an AI system on the EU market. You sell, license or otherwise make available a product with AI in it, to customers in the EU.
The output is used in the EU. You operate the system from the UK, and the result is used inside the Union. A UK recruitment firm sifting candidates for an EU-based employer is the standard example.
You have an EU establishment. A subsidiary, a branch, an office.
If none of the three apply, the AI Act does not apply to you. That is the position for most domestically-trading UK SMEs, and it is worth establishing definitively rather than assuming. The five-question test takes about ten minutes.
Being out of scope of the AI Act does not mean being unregulated. UK GDPR, the ICO, the FCA, the EHRC and employment law all constrain how you use AI, and they apply to you today. See AI regulation in the UK.
What you actually have to do
Assuming you are in scope and a deployer, which is the common case.
If your systems are minimal risk
Nothing under the risk tiers. Article 4 literacy still applies.
If you are in limited risk territory (Article 50)
Three concrete things.
Disclose AI interaction. If a person is dealing with an AI system, they must be told, unless it is obvious. In practice: a line on the chatbot before it starts.
Label synthetic content. AI-generated or manipulated audio, image, video and text published to inform the public on matters of public interest must be marked as artificial. Machine-readable marking where feasible.
Disclose deepfakes. Content that appreciably resembles real people, places or events must be disclosed as generated.
Cost to comply: a few hours of someone's time. Detail in Article 50.
If you are a deployer of high-risk AI
Heavier, and deferred to December 2027 for Annex III. Use the system according to instructions, assign human oversight to someone competent and empowered to intervene, monitor operation and report serious incidents, keep logs for at least six months, ensure input data is relevant and representative, and inform workers before deploying a high-risk system in the workplace.
If you sift job applications with AI and sell into the EU, this is you. The recruitment case is the most common way an ordinary business finds itself in the high-risk category, which is why we wrote AI CV screening for small employers.
Everyone in scope: Article 4
Ensure a sufficient level of AI literacy among staff and others operating AI on your behalf, taking account of their technical knowledge, experience and training, the context of use, and who is affected.
There is no prescribed curriculum and no certificate. That is deliberate, and it also means "we did nothing" is not defensible. Around 22 per cent of UK businesses have trained the staff deploying AI. See Article 4 and AI literacy and the AI training guide.
Four worked examples
Abstract rules are hard to apply to your own business. Here are four real shapes of UK company and where each actually lands.
A 40-person accountancy practice in Leeds, UK clients only, uses an AI tool to draft client emails and summarise meetings. Out of scope. No EU market activity, no EU-used output, no establishment. The AI Act imposes nothing. UK GDPR very much does, because client information is going into a third-party tool, and that is the question worth spending the afternoon on rather than this one.
A 120-person recruitment firm in London placing candidates with employers in Dublin and Amsterdam, using AI to rank applicants. In scope, and in the high-risk category. Employment and worker management is Annex III, and the output is used in the EU. Deployer duties apply from 2 December 2027: human oversight by someone competent to overrule the ranking, logging kept at least six months, monitoring, incident reporting, and informing workers. Article 4 literacy applies now. This is the case where proper advice is worth paying for.
An 18-person e-commerce brand in Bristol shipping to EU consumers, running a customer service chatbot and publishing AI-assisted product descriptions. In scope, limited risk. Article 50 applies now: the chatbot must say it is a chatbot, and generated content published to the public needs marking where the rules bite. Total remediation is a few hours. No high-risk exposure, no conformity assessment, nothing to register.
A 300-person UK manufacturer selling machinery into Germany with an AI-driven safety cut-out embedded in the product. In scope, Annex I high risk, and a provider rather than a deployer because the AI ships inside a product sold under their name. This is the heaviest position in the four and the deadline is 2 August 2028. It also sits alongside existing machinery safety law rather than replacing it. Specialist advice, not a blog article.
The pattern across all four: the risk tier is driven by what the AI decides about people, not by how advanced it is. A sophisticated model writing marketing copy is minimal risk. A simple rules-based tool ranking job applicants is high risk.
Penalties
Three tiers.
- Prohibited practices: up to EUR 35 million or 7 per cent of global annual turnover, whichever is higher.
- Most other breaches, including high-risk and transparency duties: up to EUR 7.5 million or 1.5 per cent of global annual turnover, whichever is higher.
- Supplying incorrect or misleading information to authorities: lower tier again.
Enforcement is by national market surveillance authorities in member states. A UK business is reached through its EU activity.
Proportionality applies, and the framework directs authorities to take the size of the business into account. Nobody sensible expects a forty-person UK firm to be the first enforcement target. Nobody sensible builds a plan on that either.
A proportionate response
For a business under a few hundred people, this is a morning and a page.
Step one: establish scope. Run the five-question test. Write down the answer and the date. If you are out of scope, you are done with the Act and should move to the UK regulations that do apply.
Step two: inventory your AI. List every AI system in use, what it does, what data goes into it, and who is accountable for it. Most businesses find between five and fifteen, including several nobody had registered as AI.
Step three: classify each one. Minimal, limited or high risk. Most will be minimal. If any looks high risk, that is the point to take proper advice.
Step four: fix the Article 50 items. Chatbot disclosure and content labelling. Hours, not weeks.
Step five: do something real about literacy. The only item on this list with a return independent of regulation.
Step six: write a one-page risk register and review it twice a year. Format in how to build an AI risk register.
What we would not do: buy a governance platform, commission an external audit, or create a role. For businesses of this size those are answers to a problem you do not have, sold by people who benefit from you believing you do.
Key Takeaways
- The UK has no AI Act, and the EU AI Act can still apply to you through EU customers, EU-used outputs, or an EU establishment.
- Nearly every UK SME is a deployer rather than a provider, and deployer duties are much lighter. You can become a provider accidentally by white-labelling.
- Most business AI is minimal risk and attracts no obligations. Article 50 transparency and Article 4 literacy are what actually catch ordinary businesses.
- High-risk deadlines moved to December 2027 and August 2028. Article 50 and Article 4 did not move and are live now.
- A proportionate response is scope check, AI inventory, classification, chatbot and content labelling, staff literacy, and a one-page register reviewed twice a year.
Frequently Asked Questions
We are a UK business with no EU customers. Can we ignore all of this?
You can set the AI Act aside, and it is worth writing down your reasoning and the date so the question does not keep reopening. You cannot ignore AI regulation generally, because UK GDPR and sector rules already govern how you use AI and are enforced by regulators who are active today.
What if we are not sure whether our supplier's tool is high risk?
Ask them in writing. Providers are obliged to classify their own systems and to supply instructions for use. A supplier who cannot tell you the risk classification of their own product has told you something useful about the supplier.
Does using ChatGPT make us a provider of AI?
No. Using a general-purpose model in your business makes you a deployer. You would become a provider if you built the model's capability into a product you offer under your own name, which is a meaningfully different activity.
How does this interact with UK GDPR?
They overlap and neither replaces the other. GDPR governs personal data: lawful basis, transparency, automated decision-making rights. The AI Act governs the system itself: safety, oversight, documentation. An AI recruitment tool can comfortably engage both at once.
Is there any advantage in complying if we do not have to?
Some, and it is worth being honest that it is modest. The inventory and classification work is genuinely useful management information regardless of regulation, the literacy work pays for itself, and larger customers increasingly ask AI governance questions in procurement. Doing the rest of it voluntarily is not a good use of money.
Want a straight answer on whether the EU AI Act applies to your business? Talk to Halo Technology Lab. Our strategy and scoping service includes an AI inventory and scope assessment, and in most cases the answer is that you have less to do than you feared.
Enjoyed this? Get the next one by email
Practical AI playbooks, build logs and tool teardowns. One email a week, free, unsubscribe in one click.
Related Articles
The Data You Already Own: How UK SMEs Turn Decades of Records into Revenue
Your archive is not just history, it is the raw material for products you could sell. A complete guide to finding, valuing, cleaning and commercialising the data your business already holds.
AI Training for UK Businesses: What Your Team Actually Needs to Learn
Most AI training teaches tools. Tools change every six months. A complete guide to what to teach, who to teach it to, which format suits which team, and how to tell whether it worked.
Modernising a Legacy Business: A UK Owner's Guide to Technology That Actually Sticks
A complete guide for owners of established UK businesses. What to modernise first, what to leave alone, what it costs, and how to avoid the failed project that puts everyone off trying again.