EU AI Act and UK Businesses: Frequently Asked Questions
Does the EU AI Act apply to your UK business? Extraterritorial scope, provider versus deployer, the four risk tiers and the deferred high-risk deadlines.
The EU AI Act applies to UK organisations that place AI systems on the EU market, or whose AI system outputs are used inside the EU. Establishment in the UK does not exempt you. Obligations depend on the risk tier of the system and on whether you act as provider or deployer.
This page answers the questions UK compliance leads, general counsel and technology directors ask once the headlines have passed and someone needs a defensible answer. It covers extraterritorial scope, obligation tiers, the phase-in timeline and how the Act interacts with existing UK compliance work. It is general information rather than legal advice.
Does the EU AI Act apply to my UK business?
The Act applies if you place an AI system on the EU market, put one into service in the EU or if the output produced by your AI system is used within the EU. That third condition is the one UK organisations underestimate: a UK company running a model in a UK data centre, for a UK team, can still fall in scope if the results drive decisions affecting people in the EU. Registration and server location are not determining factors, because the Act is written to prevent regulatory arbitrage by relocation; what matters is where the system, or its output, lands.
If you have no EU customers, no EU users, no EU subsidiaries and no outputs consumed in the EU, you are likely outside scope. Our AI Act Preparedness work starts with exactly that scoping question, and our FAQ on EU AI Act compliance for UK organisations covers the detail behind each scope test.
We only sell into the EU through a reseller. Are we still in scope?
Usually yes, and often with more obligations than expected. If your AI system reaches the EU market through a distributor, importer or reseller, you remain the provider of that system and the provider carries the heaviest obligations under the Act: technical documentation, conformity assessment for high-risk systems and post-market monitoring. The reseller relationship changes who else acquires duties, not whether yours disappear.
Importers and distributors have their own verification obligations and will look to you for the evidence they need to discharge them, which means documentation requests from EU channel partners tend to arrive well before any regulator does.
What is the difference between a provider and a deployer?
A provider develops an AI system, or has one developed and places it on the market under its own name or trade mark; a deployer uses an AI system under its own authority in the course of its activities. Providers carry documentation, risk management, data governance, transparency and conformity obligations, while deployers carry narrower duties: following the instructions for use, assigning human oversight, monitoring operation and, for certain high-risk uses, informing affected individuals.
The trap is substantial modification, because fine-tuning, retraining or repurposing a purchased system can make you its provider and hand you the heavier obligation set. Our AI Security Gap Analysis maps which role you hold for each system in the estate.
Which obligation tier applies to us?
The Act sorts systems into four tiers by risk, and prohibited practices such as certain social scoring and manipulative techniques are banned outright. High-risk systems, including many uses in employment, education, credit, essential services and biometrics, carry the full obligation set of risk management, data governance, technical documentation, logging, human oversight, accuracy and cybersecurity requirements. Limited-risk systems carry transparency duties, so users must know they are interacting with an AI system and synthetic content must be labelled.
Minimal-risk systems, which the European Commission has described as the large majority, carry no specific obligations beyond general law. General-purpose AI models sit in a parallel regime with their own documentation and copyright-policy requirements. Tier assignment is made per system and per use case, so the same model can be minimal-risk in one application and high-risk in another. Our AI risk assessment entry covers how to structure that judgement.
What are the compliance deadlines?
The Act entered into force on 1 August 2024 and its obligations phase in on a staged timeline. The Digital Omnibus on AI, Regulation (EU) 2026/1744, entered into force on 27 July 2026 and deferred the high-risk deadlines. The dates that matter now are:
- 2 February 2025: prohibitions on unacceptable practices and the AI literacy duty.
- 2 August 2025: obligations for general-purpose AI models.
- 2 December 2027: high-risk obligations for standalone systems in the Annex III use cases.
- 2 August 2028: high-risk obligations for systems embedded in products already regulated under other EU legislation, listed in Annex I.
The preparation work does not shift with the dates, because building a system inventory, assigning provider and deployer roles and producing technical documentation takes months in any organisation of scale. Our EU AI Act preparedness guide sets out the full timeline, and our AI governance entry covers how to sequence the work.
How does this interact with UK regulation?
The UK has taken a principles-based, regulator-led approach rather than passing a single AI statute, so existing regulators apply existing powers to AI within their sectors. A UK organisation in scope of the EU AI Act therefore manages two frameworks: the Act’s prescriptive requirements for its EU-facing systems, and UK sector regulation across everything else. Which UK rules apply to you is covered in our answer on UK AI regulation by sector.
Running two parallel programmes is wasteful, because most of the underlying evidence, including system inventory, risk assessment, data lineage, human oversight design and incident logging, satisfies both. Our ISO 42001 service covers how a certified management system provides that common evidence base, and our EU AI Act entry sets out the requirements in more detail.
Do we need to worry about AI tools staff adopted without approval?
Yes. You cannot classify systems you have not found, and unapproved tools introduced by teams directly, without procurement or security review, sit outside every inventory and every risk assessment while processing real data and shaping real decisions. If one of those tools handles EU personal data or produces output used in the EU, it falls in scope of the Act while remaining invisible to your compliance programme, so discovery has to precede classification. Our Shadow AI entry covers how unapproved adoption happens and how to surface it.
What should we do first?
Build the inventory. Identify every AI system in use, including embedded features inside software you already licence, and record for each one the use case, the data it processes, whether outputs reach the EU and whether you are provider or deployer. That single artefact answers the scope question, drives tier classification and becomes the foundation of your technical documentation. Classification depends on discovery, so the legal analysis cannot be completed until the inventory exists.
This page is general information about the EU AI Act and is not legal advice. Obligations turn on your specific systems, uses and markets, so take advice on your own position before acting.
For further reading, see our AI Behaviour Verification service and our Shadow AI Discovery service.
Settle the scope question first
AI Act Preparedness establishes whether the Act reaches your systems, which role you hold for each one and what evidence you need before the deferred deadlines.