The EU AI Act and the UK
A practitioner's analysis of how Regulation (EU) 2024/1689 applies to UK companies after Brexit, scope, obligations, deadlines, and the UK's own regulatory trajectory.
Updated April 2026 · Reviewed against Regulation (EU) 2024/1689 & UK DSIT guidance
Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.
1. Does the EU AI Act Apply to UK Companies After Brexit?
Yes. The EU AI Act (Regulation EU 2024/1689) has explicit extraterritorial scope defined in Article 2, and that scope captures a substantial portion of UK AI activity.
Under Article 2(1), the Act applies to:
- Providers placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established
- Deployers of AI systems whose place of establishment or location is within the EU
- Providers and deployers established outside the EU where the output produced by the AI system is used in the EU
- Importers and distributors of AI systems within the EU market
- Product manufacturers placing AI systems on the EU market together with their product and under their own name or trademark
- Authorised representatives of providers established outside the EU
The third bullet, output used in the EU, is the one that captures most UK businesses. A UK-based SaaS platform using AI for credit scoring on EU customers, a UK HR-tech vendor with AI-assisted recruitment screening EU candidates, a UK marketing platform generating AI content for EU audiences, all in scope.
2. Is There a UK AI Act Equivalent?
No, and that matters for compliance planning. The UK government has deliberately chosen not to adopt a comprehensive AI statute equivalent to the EU AI Act. Instead, the UK pursues a principles-based, sectoral approach set out in the March 2023 AI White Paper "A pro-innovation approach to AI regulation."
UK AI governance is currently delivered through existing regulators:
- ICO, data protection aspects of AI (continuation of GDPR/UK GDPR)
- FCA, AI in financial services and consumer credit
- CMA, competition and consumer aspects of AI markets
- Ofcom, AI in online safety and communications services
- MHRA, AI as software-as-a-medical-device
- HSE, AI in workplace safety
- Equality and Human Rights Commission, AI bias and discrimination
The UK Artificial Intelligence (Regulation) Bill, reintroduced in the House of Lords by Lord Holmes of Richmond, is a private member's bill and is not government policy. Several iterations have lapsed at the end of parliamentary sessions. It should not be treated as likely law for compliance planning purposes.
3. Which UK Businesses Must Comply With the EU AI Act?
The following UK business profiles should assume EU AI Act scope until they can document a clear exception:
| UK Business Profile | Why In Scope | Likely Priority Obligations |
|---|---|---|
| UK SaaS platform serving EU customers | AI output used in EU (Art. 2(1)(c)) | Art. 50 transparency, high-risk assessment per Annex III |
| UK financial services firm with EU clients | Credit scoring / creditworthiness is Annex III point 5(b) | Full high-risk obligations (Art. 9-15, 27 FRIA) |
| UK HR-tech / recruitment platform | Employment AI is Annex III point 4 | Full high-risk obligations, including FRIA for each deployment |
| UK medical device manufacturer (AI-enabled) | MDR/IVDR products are Annex I safety components | Art. 6(1) route, notified body required (Annex VII) |
| UK AI model provider (foundation / GPAI) | GPAI obligations apply where model placed on EU market | Articles 51-56, already active since 2 Aug 2025 |
| UK edtech with EU users | Education / vocational training is Annex III point 3 | Full high-risk obligations |
| UK biometrics / identity verification vendor | Annex III point 1 applies universally | Full high-risk + Annex VII notified body assessment |
4. The Enforcement Timeline for UK Businesses
The phased enforcement schedule applies to UK businesses identically to EU-established businesses. There is no Brexit-related grace period.
5. The Authorised Representative Requirement (Article 22)
This is the most commonly missed obligation for UK businesses. Under Article 22, providers of high-risk AI systems established outside the EU must appoint an authorised representative established within the EU, by written mandate, before placing the system on the EU market.
The authorised representative's role is significant: they verify that the EU Declaration of Conformity and technical documentation have been drawn up, keep those documents available to national competent authorities, cooperate with authorities on request, and terminate the mandate if the provider acts contrary to obligations.
6. UK-EU Dual-Track Compliance: The Practical Framework
For UK businesses, the most efficient compliance posture is to treat EU AI Act obligations as the primary compliance framework, then verify UK regulatory overlay separately. This is because EU AI Act requirements are prescriptive; UK regulator expectations are currently principles-based and less specific.
Recommended approach:
- Complete EU AI Act scoping: inventory all AI systems, classify against Annex III, identify all deployments with EU output use
- For each in-scope system, build the Article 9-15 compliance stack (risk management, data governance, technical documentation, human oversight, accuracy/robustness/cybersecurity)
- Run EU AI Act FRIA (Article 27) and UK GDPR DPIA in parallel, they share most inputs
- Appoint EU authorised representative before 2 December 2027 if you are a provider of high-risk AI
- Cross-check against ICO guidance on AI and data protection, FCA Handbook (if applicable), CMA AI market study findings
- Document the UK-EU compliance architecture for board-level oversight
7. Frequently Asked Questions
Northern Ireland is part of the UK and is not an EU Member State. However, under the Windsor Framework, certain EU laws continue to apply in Northern Ireland where goods are concerned. The EU AI Act is a regulation of general application and currently applies in NI only to the extent AI outputs are used in the EU, the same test that applies to Great Britain. Consult qualified counsel for NI-specific questions.
No. The EU AI Act's extraterritorial trigger is the use of AI output in the EU, not the location of the underlying infrastructure. UK-hosted AI generating decisions, recommendations, or content for EU users remains in scope.
Article 99 penalties apply to UK companies identically to EU-established companies: up to €35M or 7% of global turnover for prohibited practice violations, €15M or 3% for high-risk AI non-compliance, €7.5M or 1% for information offences (misleading information to authorities). Enforcement of fines against non-EU entities depends on assets in the EU or cooperation between authorities, but market access restrictions are the more practically significant consequence.
No. The TCA does not contain provisions exempting UK businesses from EU regulations of general application such as the AI Act, GDPR, or Digital Services Act. UK businesses serving the EU market must comply with EU law on the same terms as any other third-country provider.
There is no confirmed government plan to introduce a comprehensive UK AI Act in the current parliamentary session as of April 2026. The Labour government's October 2024 consultation on "AI Action Plan" contemplated regulatory development but no statute has been introduced. UK businesses should not delay EU AI Act compliance in anticipation of UK-level harmonisation.
8. What to Do Next
For UK businesses approaching the 2 December 2027 deadline, the sequence matters:
- Inventory, identify every AI system you build, deploy, or integrate, including third-party AI features embedded in SaaS you use
- Classify, run each system through the Annex III domains. If it fits, the system is provisionally high-risk unless Article 6(3) exception applies
- Assess, for each high-risk system, complete a gap assessment against Articles 9-15
- Document, build the Annex IV technical documentation pack, the Article 27 FRIA (where applicable), and the quality management system under Article 17
- Appoint, engage an EU authorised representative before first EU market placement
- Register, submit Annex VIII information to the EU AI database
- Monitor, implement Article 72 post-market monitoring and Article 73 incident reporting
Get Audit-Ready Before 2 December 2027
Our EU AI Act Full Readiness Bundle contains the 11 documents a UK compliance team needs to build a defensible programme, from the Annex III classification matrix to the Article 27 FRIA template, Annex IV technical documentation checklist, and vendor AI readiness questionnaire.
Instant download · Word (.docx) + PDF · 12-month update access · Use across your organisation
Continue Reading
Annex III High-Risk AI Systems
The 8 domains that trigger high-risk classification, with detailed use case mapping.
Fines & Penalties
Full penalty structure under Article 99, who can be fined, how much, and what defends against enforcement.
EU AI Act vs GDPR
How the AI Act and GDPR interact for UK businesses, FRIA vs DPIA, authority overlap, and joint compliance.