Does the EU AI Act Apply to UK Companies?

Yes. The EU AI Act applies to UK companies in three main situations: where they place an AI system or general-purpose AI model on the EU market, where they put a system into service in the EU, and — the one that catches most UK businesses out — where they are established outside the EU but the output produced by their AI system is used in the EU. That last ground, in Article 2(1)(c) of Regulation (EU) 2024/1689, means Brexit did not take UK organisations out of scope. It only changed the route by which they get caught.

For UK SMEs, this is not a theoretical point. A Cardiff software company selling into Dublin, a London recruiter screening candidates for a client’s Paris office, or a Manchester SaaS provider whose EU customers rely on AI-generated scores are all potentially within the Act’s reach — without ever opening an EU entity.

The three grounds that catch UK organisations

The first ground is the most intuitive. If a UK company acts as a provider — developing an AI system or having one developed and supplying it under its own name — and places that system on the market in the EU, the Act applies exactly as it would to a French or German provider. Selling a subscription to an EU customer is placing on the market. There is no de minimis carve-out for company size, although the Act does contain some proportionality measures for SMEs.

The second ground covers putting a system into service in the EU. A UK company that deploys an AI system for use by its own EU branch, subsidiary or operations can trigger obligations in the deployer role even where no product is being sold.

The third ground is the extraterritorial catch. Under Article 2(1)(c), the Act applies to providers and deployers of AI systems established in a third country — which the UK now is — where the output produced by the system is used in the Union. The classic example is a UK business running an AI analysis whose results are relied upon by, or applied to, people or organisations in the EU. The system never leaves a UK server. The company has no EU presence. The output crossing into EU use is enough.

Why “we’re a UK company” is not a defence

The pattern here is deliberate and familiar. The GDPR’s Article 3 taught EU legislators that territorial rules based on where a company is incorporated simply invite structuring around the rules. The AI Act follows the same logic as the GDPR’s extraterritorial reach: what matters is where the effects land, not where the server sits or where the company is registered.

The practical consequence is that a UK organisation cannot answer the scoping question by looking at its own corporate structure. It has to look at its AI systems one by one and ask where each system’s outputs are actually used. That is an inventory and classification exercise, not a legal opinion about the company as a whole. If your organisation has never mapped which of its AI systems produce output consumed in the EU, the honest answer to “does the Act apply to us?” is “we do not yet know” — which is a worse position than either yes or no.

Which obligations bite, and when

Being in scope does not mean every duty in the Act applies. Obligations depend on two variables: the organisation’s role for each system (provider, deployer, importer, distributor or authorised representative) and the system’s risk classification.

The prohibitions in Article 5 — covering practices such as harmful manipulation, social scoring and untargeted facial-image scraping — have applied since 2 February 2025, alongside AI literacy duties. Obligations for general-purpose AI models took effect on 2 August 2025. The main high-risk framework applies from 2 August 2026, with a longer runway for certain high-risk systems embedded in regulated products. A UK company that discovers in a procurement questionnaire that one of its systems is high-risk has, in other words, already missed the preparation window the staged timetable was designed to provide.

One duty deserves specific attention from UK providers: a third-country provider of a high-risk AI system must appoint an authorised representative established in the EU before making the system available there. That is a concrete, contractual step — not a policy statement — and it is one of the first things an EU customer’s due diligence process will check.

What a proportionate UK response looks like

For most UK SMEs, the correct response is not to commission a firm-wide legal opinion or to assume the Act is someone else’s problem. It is to build the operating basics that make the scoping question answerable and the answer defensible.

That starts with an AI inventory: every AI system in use or on the roadmap, its purpose, its owner, and — critically for the UK analysis — where its outputs are used. From there, each system needs a documented role determination and a classification against the Act’s categories, recorded with the rationale. Systems that turn out to be in scope then need obligation mapping, assigned controls and evidence. Systems that turn out to be out of scope need the analysis retained, because “we assessed it and here is why it falls outside Article 2” is a defensible position; “we never looked” is not.

This is the same discipline that AI governance under the Act requires of EU organisations, applied through a UK lens. It is also the evidence base that increasingly determines whether a UK supplier passes EU customer procurement — often a more immediate commercial pressure than regulatory enforcement itself.

The question UK boards should be asking is therefore not “does the EU AI Act apply to us?” in the abstract. It is “which of our systems produce output used in the EU, what category does each fall into, and can we show our working?” A UK company that can answer those three questions is ahead of most of its competitors — on either side of the Channel.