The EU AI Act and the UK

A practitioner's analysis of how Regulation (EU) 2024/1689 applies to UK companies after Brexit, scope, obligations, deadlines, and the UK's own regulatory trajectory.

Updated April 2026 · Reviewed against Regulation (EU) 2024/1689 & UK DSIT guidance

→ Not sure how this affects your AI system?

Take the free 5-minute Risk Classifier, article-grounded scoring against Article 5, 6, Annex III, and Article 50.

Run the classifier →
The short answer for UK businesses: Yes, the EU AI Act applies to you whenever your AI systems produce outputs used in the EU, regardless of where your company is registered. Brexit does not insulate UK companies from EU AI law.

1. Does the EU AI Act Apply to UK Companies After Brexit?

Yes. The EU AI Act (Regulation EU 2024/1689) has explicit extraterritorial scope defined in Article 2, and that scope captures a substantial portion of UK AI activity.

Under Article 2(1), the Act applies to:

  • Providers placing AI systems on the EU market or putting them into service in the EU, regardless of where the provider is established
  • Deployers of AI systems whose place of establishment or location is within the EU
  • Providers and deployers established outside the EU where the output produced by the AI system is used in the EU
  • Importers and distributors of AI systems within the EU market
  • Product manufacturers placing AI systems on the EU market together with their product and under their own name or trademark
  • Authorised representatives of providers established outside the EU

The third bullet, output used in the EU, is the one that captures most UK businesses. A UK-based SaaS platform using AI for credit scoring on EU customers, a UK HR-tech vendor with AI-assisted recruitment screening EU candidates, a UK marketing platform generating AI content for EU audiences, all in scope.

Practical test: If your AI system's output is read, viewed, or acted upon by a natural or legal person in the EU, you are in scope. The physical location of your servers, company registration, or data processing does not provide exemption.

2. Is There a UK AI Act Equivalent?

No, and that matters for compliance planning. The UK government has deliberately chosen not to adopt a comprehensive AI statute equivalent to the EU AI Act. Instead, the UK pursues a principles-based, sectoral approach set out in the March 2023 AI White Paper "A pro-innovation approach to AI regulation."

UK AI governance is currently delivered through existing regulators:

  • ICO, data protection aspects of AI (continuation of GDPR/UK GDPR)
  • FCA, AI in financial services and consumer credit
  • CMA, competition and consumer aspects of AI markets
  • Ofcom, AI in online safety and communications services
  • MHRA, AI as software-as-a-medical-device
  • HSE, AI in workplace safety
  • Equality and Human Rights Commission, AI bias and discrimination

The UK Artificial Intelligence (Regulation) Bill, reintroduced in the House of Lords by Lord Holmes of Richmond, is a private member's bill and is not government policy. Several iterations have lapsed at the end of parliamentary sessions. It should not be treated as likely law for compliance planning purposes.

The compliance trap: The absence of a UK AI Act leads some UK businesses to conclude "AI regulation doesn't apply to us." This is a dangerous misreading. UK businesses are subject to EU AI Act obligations when serving EU users, and separately to existing UK statutory regimes (UK GDPR, Equality Act 2010, consumer protection law) which already apply to AI-driven decisions.

3. Which UK Businesses Must Comply With the EU AI Act?

The following UK business profiles should assume EU AI Act scope until they can document a clear exception:

UK Business Profile Why In Scope Likely Priority Obligations
UK SaaS platform serving EU customers AI output used in EU (Art. 2(1)(c)) Art. 50 transparency, high-risk assessment per Annex III
UK financial services firm with EU clients Credit scoring / creditworthiness is Annex III point 5(b) Full high-risk obligations (Art. 9-15, 27 FRIA)
UK HR-tech / recruitment platform Employment AI is Annex III point 4 Full high-risk obligations, including FRIA for each deployment
UK medical device manufacturer (AI-enabled) MDR/IVDR products are Annex I safety components Art. 6(1) route, notified body required (Annex VII)
UK AI model provider (foundation / GPAI) GPAI obligations apply where model placed on EU market Articles 51-56, already active since 2 Aug 2025
UK edtech with EU users Education / vocational training is Annex III point 3 Full high-risk obligations
UK biometrics / identity verification vendor Annex III point 1 applies universally Full high-risk + Annex VII notified body assessment

4. The Enforcement Timeline for UK Businesses

The phased enforcement schedule applies to UK businesses identically to EU-established businesses. There is no Brexit-related grace period.

2 February 2025, ACTIVE
Article 5 prohibited practices
UK businesses cannot deploy prohibited AI practices for EU users. Penalties up to €35M or 7% global turnover.
2 August 2025, ACTIVE
GPAI obligations (Arts. 51-56)
UK providers of general-purpose AI models placing them on the EU market already subject to full transparency, documentation, and copyright obligations.
2 August 2026, STILL APPLIES
Article 50 transparency (most) + Article 49 registration + MSA powers
Chatbot disclosure, deepfake disclosure to users, emotional-recognition disclosure, EU database registration, and national market surveillance authority enforcement powers apply as enacted. Only Article 50(2) watermarking shifted under the Omnibus.
2 December 2026, NEW UNDER OMNIBUS
Article 50(2) watermarking + new Article 5 CSAM/NCII prohibition
Synthetic-content watermarking shifted from 2 Aug 2026 to 2 Dec 2026. New Article 5 prohibition on AI generating non-consensual intimate imagery or CSAM applies from this date. Affects every UK generative AI provider serving EU users.
2 December 2027, ANNEX III HIGH-RISK
High-risk AI systems (Annex III)
Full compliance burden applies: risk management, technical documentation, human oversight, conformity assessment, CE marking, EU database registration. UK providers need an authorised representative in the EU under Article 22. Moved from 2 August 2026 under the Digital Omnibus (adopted by Parliament 16 June 2026, Council adoption 29 June 2026), a 16-month deferral.
2 August 2028
Annex I embedded high-risk AI
AI embedded in medical devices, machinery, vehicles, and other regulated products must comply. Notified body route applies. Moved from 2 August 2027 under the Omnibus, a 12-month deferral.

5. The Authorised Representative Requirement (Article 22)

This is the most commonly missed obligation for UK businesses. Under Article 22, providers of high-risk AI systems established outside the EU must appoint an authorised representative established within the EU, by written mandate, before placing the system on the EU market.

The authorised representative's role is significant: they verify that the EU Declaration of Conformity and technical documentation have been drawn up, keep those documents available to national competent authorities, cooperate with authorities on request, and terminate the mandate if the provider acts contrary to obligations.

Practical implication: UK businesses placing high-risk AI on the EU market after 2 December 2027 without an appointed EU authorised representative are non-compliant from day one, regardless of whether the underlying AI system meets all other technical requirements. For UK generative AI providers, watermarking and the new Article 5 CSAM/NCII prohibition apply from 2 December 2026 regardless.

6. UK-EU Dual-Track Compliance: The Practical Framework

For UK businesses, the most efficient compliance posture is to treat EU AI Act obligations as the primary compliance framework, then verify UK regulatory overlay separately. This is because EU AI Act requirements are prescriptive; UK regulator expectations are currently principles-based and less specific.

Recommended approach:

  1. Complete EU AI Act scoping: inventory all AI systems, classify against Annex III, identify all deployments with EU output use
  2. For each in-scope system, build the Article 9-15 compliance stack (risk management, data governance, technical documentation, human oversight, accuracy/robustness/cybersecurity)
  3. Run EU AI Act FRIA (Article 27) and UK GDPR DPIA in parallel, they share most inputs
  4. Appoint EU authorised representative before 2 December 2027 if you are a provider of high-risk AI
  5. Cross-check against ICO guidance on AI and data protection, FCA Handbook (if applicable), CMA AI market study findings
  6. Document the UK-EU compliance architecture for board-level oversight

7. Frequently Asked Questions

Northern Ireland is part of the UK and is not an EU Member State. However, under the Windsor Framework, certain EU laws continue to apply in Northern Ireland where goods are concerned. The EU AI Act is a regulation of general application and currently applies in NI only to the extent AI outputs are used in the EU, the same test that applies to Great Britain. Consult qualified counsel for NI-specific questions.

No. The EU AI Act's extraterritorial trigger is the use of AI output in the EU, not the location of the underlying infrastructure. UK-hosted AI generating decisions, recommendations, or content for EU users remains in scope.

Article 99 penalties apply to UK companies identically to EU-established companies: up to €35M or 7% of global turnover for prohibited practice violations, €15M or 3% for high-risk AI non-compliance, €7.5M or 1% for information offences (misleading information to authorities). Enforcement of fines against non-EU entities depends on assets in the EU or cooperation between authorities, but market access restrictions are the more practically significant consequence.

No. The TCA does not contain provisions exempting UK businesses from EU regulations of general application such as the AI Act, GDPR, or Digital Services Act. UK businesses serving the EU market must comply with EU law on the same terms as any other third-country provider.

There is no confirmed government plan to introduce a comprehensive UK AI Act in the current parliamentary session as of April 2026. The Labour government's October 2024 consultation on "AI Action Plan" contemplated regulatory development but no statute has been introduced. UK businesses should not delay EU AI Act compliance in anticipation of UK-level harmonisation.

8. What to Do Next

For UK businesses approaching the 2 December 2027 deadline, the sequence matters:

  1. Inventory, identify every AI system you build, deploy, or integrate, including third-party AI features embedded in SaaS you use
  2. Classify, run each system through the Annex III domains. If it fits, the system is provisionally high-risk unless Article 6(3) exception applies
  3. Assess, for each high-risk system, complete a gap assessment against Articles 9-15
  4. Document, build the Annex IV technical documentation pack, the Article 27 FRIA (where applicable), and the quality management system under Article 17
  5. Appoint, engage an EU authorised representative before first EU market placement
  6. Register, submit Annex VIII information to the EU AI database
  7. Monitor, implement Article 72 post-market monitoring and Article 73 incident reporting
For UK Businesses

Get Audit-Ready Before 2 December 2027

Our EU AI Act Full Readiness Bundle contains the 11 documents a UK compliance team needs to build a defensible programme, from the Annex III classification matrix to the Article 27 FRIA template, Annex IV technical documentation checklist, and vendor AI readiness questionnaire.

View Full Bundle, $499 → Start with Checklist, $149 →

Instant download · Word (.docx) + PDF · 12-month update access · Use across your organisation