← All articles EU AI Act

Does the EU AI Act Apply to UK Companies? Yes — Here Is When and How

Brexit did not put UK businesses beyond the reach of EU law, and the AI Act is a clear example. Like GDPR before it, the Act has extraterritorial reach: it can apply to a UK company with no EU office at all, purely because of where its AI system's output is used. If you serve EU clients, users or markets in any way that involves AI, you need to know when you are in scope — and this guide explains exactly that.

Does the EU AI Act apply to UK companies after Brexit?

Yes, it can. The EU AI Act applies to UK companies when they place AI systems on the EU market, or when the output of their AI system is used within the EU — regardless of whether they have any establishment in the EU. Being outside the EU is not, by itself, an exemption.

The Act was written to prevent businesses from side-stepping it simply by locating outside the EU. So it reaches non-EU providers and deployers in defined circumstances. For a UK SME, the key trigger is usually the second one: if the output produced by your AI system is used inside the EU, the Act can apply to you even though your company, your servers and your staff are all in the UK.

When is a UK business actually in scope?

A UK business is typically in scope if it sells or supplies an AI system into the EU market, or if the results its AI system produces are used by people or businesses in the EU. Common triggers are EU clients, EU users of your product, or AI-generated outputs delivered into the EU.

Common ways UK SMEs get caught

  • You supply an AI-enabled product or service to customers in the EU.
  • Your software has EU users, and it includes AI features.
  • You produce AI-generated outputs — screening results, analyses, content — that are then used by a client in the EU.
  • You provide AI-driven services (recruitment, credit assessment, analysis) to EU-based clients.

The common thread is EU use of AI output, not EU location of your business. A UK recruitment agency screening candidates for a German client, or a UK SaaS firm whose AI feature serves French users, can both be in scope.

Does the AI Act apply if I only have a few EU customers?

Potentially yes. The Act does not set a minimum number of EU customers before it applies. Even limited EU-facing AI use can bring you within scope, though the practical extent of your obligations depends on what the AI does and its risk level, not on how many EU customers you have.

There is no de minimis customer threshold that switches the Act off. That said, scope is not the same as burden. Being in scope with a low-risk AI tool means light obligations — chiefly literacy and transparency. Being in scope with a high-risk system means much more. So the practical question is not only "am I in scope?" but "what is my AI doing, and at what risk level?" — which our EU AI Act Compliance for SMEs guide breaks down.

How is this similar to GDPR for UK companies?

Very similar. Like GDPR, the AI Act reaches beyond EU borders based on the effect of your activity within the EU, not your location. UK firms that already navigated GDPR's extraterritorial scope will recognise the pattern — and can reuse much of that compliance thinking for the AI Act.

UK businesses spent years adapting to GDPR's reach, and the AI Act follows the same logic: if your activity touches people in the EU, EU rules can apply. The upside is that your GDPR groundwork transfers. Your data governance, records and accountability structures all have AI-Act analogues, so you are not starting from zero. We map that overlap in GDPR vs EU AI Act.

What should a UK company do to check and comply?

Confirm whether your AI output reaches the EU, establish your role (deployer or provider) and your systems' risk level, then meet the applicable obligations — starting with AI literacy and transparency. A short self-assessment settles scope and role quickly; heavier steps follow only if you operate high-risk systems.

The sensible approach for a UK SME is to assume potential scope wherever you have an EU footprint, then confirm rather than assume exemption. Run the free EU AI Act self-assessment to establish whether you are caught and in what role. If you are in scope with low-risk AI, the path is short — literacy, transparency, documentation. If a system is high-risk, plan that work toward the 2027–2028 deadlines. Either way, knowing your position beats guessing at it, especially when an EU client asks.

Three UK scenarios: in scope or not?

A UK recruitment agency screening EU candidates with AI is in scope. A UK SaaS firm whose AI feature serves EU users is in scope. A UK bakery using an AI tool purely for its UK-only marketing is generally not — because none of its AI output reaches the EU. The test is always EU use of the output.

Applying the rule to concrete cases makes it clearer:

  • In scope — a UK recruitment agency uses an AI tool to screen and rank candidates for a client based in Germany. The AI output is used in the EU, so the Act reaches the agency as a deployer of a high-risk system.
  • In scope — a UK software company sells a SaaS product with an AI feature to customers across the EU. Its AI output serves EU users, bringing it within scope.
  • Generally out of scope — a UK bakery uses an AI writing tool for social posts aimed only at its local UK customers. No AI output is used in the EU, so the Act does not apply on that basis.

The dividing line is not the tool or the sector; it is whether the AI's output lands in the EU. Businesses with any EU-facing activity should assume they may be caught and confirm, rather than reasoning from their UK location.

What happens if a UK company ignores the AI Act?

A UK company in scope that ignores the Act faces the same enforcement exposure as an EU one, including significant fines for serious breaches, plus the practical risk of losing EU business when clients require compliance. For most UK SMEs the commercial risk arrives before any regulator does.

Enforcement of an extraterritorial regime is harder in practice, but that is thin comfort. The more immediate consequence for a UK SME is commercial: EU clients increasingly ask suppliers to demonstrate AI Act compliance as a condition of doing business, so a UK firm that ignores the Act risks being screened out of EU deals long before an authority takes an interest. Compliance, in other words, is as much about protecting revenue as avoiding penalties — the theme of our EU AI Act Compliance for SMEs guide.

Frequently asked questions

Do UK businesses have to comply with the EU AI Act?

They do when they place AI systems on the EU market or when their AI system's output is used in the EU. A UK company can be in scope with no EU establishment, purely because of where its AI output is used — much like GDPR.

Does the AI Act have extraterritorial scope like GDPR?

Yes. The Act deliberately reaches non-EU providers and deployers whose AI activity affects the EU, to prevent businesses avoiding it by locating outside the EU. UK firms familiar with GDPR's reach will recognise the same approach.

Is a UK company in scope if its AI output is used in the EU?

Generally yes. Where the output produced by your AI system is used within the EU, the Act can apply even though your business is entirely UK-based. This is the most common trigger for UK SMEs.

What is the first step for a UK business unsure about AI Act scope?

Run a short self-assessment to confirm whether your AI output reaches the EU and to establish your role and risk level. That settles scope quickly and tells you whether you face only light obligations or heavier high-risk duties.

See where your business stands

The free EU AI Act self-assessment gives you a plain-English read on your position in five minutes.