Does the EU AI Act Apply to My UK Business?

Being UK-based does not automatically exempt you. Here is how to work out whether the EU AI Act actually applies to your business, in plain English.

By Clausely Team

Brexit did not put you out of scope

The most common assumption we hear is that a UK company cannot be caught by an EU law. It is an understandable reading, and it is wrong.

The EU AI Act is written around where an AI system’s output lands, not where the company sits on a map. If the output of your AI system is used in the EU, or the system itself is placed on the EU market, the Act can reach you regardless of where you are registered or where your servers are.

In practice that means a UK business with EU customers, EU employees or contractors, or EU users of its product can fall in scope, exactly as it could before Brexit. The question is not your address. It is who is on the receiving end.

The three triggers to check

There are three main ways a UK business is pulled into scope. You only need one of them to apply.

  1. You provide an AI system to users in the EU. If you sell, license, or make available a product with AI in it, and EU users can access it, you are placing that system on the EU market as a provider.
  2. The output of your AI system is used in the EU. Even where the system runs entirely in the UK, if what it produces is used in the EU, the Act can apply. Content, scores, rankings, recommendations and generated documents all count as output.
  3. You deploy an AI system and the output affects people in the EU. If you use an AI tool internally and its results affect EU-based staff, candidates, or customers, you are a deployer with obligations of your own.

What counts as an AI system is broader than you think

Many businesses read the coverage of the Act, picture large generative models, and conclude that none of it applies to them. The definition is considerably wider than that.

The Act covers software that infers from inputs how to generate outputs such as predictions, recommendations, content, or decisions that influence people. That takes in a lot of ordinary business tooling.

Common examples already in use across UK businesses include:

  • CV screening, candidate ranking and shortlisting tools built into applicant tracking systems.
  • Customer service chatbots and automated reply assistants on your website or inbox.
  • Automated content generation for marketing copy, product descriptions, images or video.
  • Scoring and risk models used in credit checks, fraud detection or pricing.
  • Meeting transcription and summarisation tools that produce records people rely on.

The timeline as it now stands

The Digital Omnibus package changed the sequencing, so it is worth being precise about the dates that actually apply.

Article 50 transparency obligations apply from 2 November 2026. These are the duties to tell people when they are interacting with an AI system, and to disclose AI generated or manipulated content. If you run a chatbot or publish AI generated material, this is the date that matters to you.

Annex III high-risk obligations apply from 2 December 2027. These cover the heavier requirements for systems used in areas such as recruitment, credit, essential services and education, including risk management, human oversight and conformity work.

The earlier August 2026 date that circulated widely no longer applies. Separately, the Article 4 AI literacy duty has already been in force since February 2025, so staff understanding of the tools they use is not a future problem.

What to do about it

Guessing your way through scope is the expensive option. Businesses tend to err in both directions: some assume they are exempt and do nothing, others assume the worst and buy documentation they will never need.

The sensible first step is a proper risk check. Work out which of the three triggers you meet, list the AI tools actually in use across your business, and identify whether any of that use falls into an Annex III high-risk category.

Clausely’s free compliance checker does exactly that. It takes about two minutes, asks about your sector, headcount, AI tools and EU exposure, and tells you which obligations are likely to apply under the EU AI Act, the Worker Protection Act 2024 and UK GDPR. You can run it at /compliance-checker.

If it turns out you are in scope, the documentation you need is generated from your own declared operations rather than pulled off a shelf. If it turns out you are not, you will have a written record of why, which is worth having on file.

Recommended next step

Find out in two minutes.

Rather than guessing, run the free compliance risk check. It asks about your sector, your AI tools and your EU exposure, then shows which obligations are likely to apply to you.

Run the free compliance checkerSee pack pricing

Prefer to see what is included first? The EU AI Act Essentials brochure is a one-page summary of the documents in the pack.

This article was written with AI assistance and reviewed for accuracy against current UK and EU regulatory guidance. It does not constitute legal advice. If you require specific legal guidance, please consult a qualified solicitor.