Does the EU AI Act apply to UK companies?
Does the EU AI Act apply to your UK business? You don't need to be an AI expert or understand hundreds of pages of legislation. But if your business uses AI, there are a few things you should know.
Does your business use ChatGPT or any AI model?
What about an AI chatbot on your website?
Does your recruitment software help screen applicants? Does your CRM score leads? Does software recommend what a customer should see next? Does your team use AI to write content, create images, summarise meetings or answer customer questions?
If you're thinking, "I'm actually not sure," you're not alone.
Someone starts using an AI tool because it saves them an hour. A software provider adds an AI feature to a product the company already uses. Marketing tries one tool. Sales tries another. Customer service introduces a chatbot.
Before long, the business is using AI in several places but nobody has a complete picture of where it is being used, what information is going into it or what decisions it is influencing.
This is more important because the EU AI Act is already partly in force.
And you don't need to be an EU company for it to apply to you.
What is the EU AI Act?
In very simple terms, the European Union has introduced rules around how artificial intelligence can be built and used.
Think of it like food safety rules. Nobody bans restaurants from serving food. But the riskier the dish, the more checks apply before it reaches a customer. The EU AI Act works the same way: the more an AI system could hurt someone physically, financially, or by treating them unfairly, the more checks it has to pass.
So this isn't a law saying: "Businesses can't use AI."
It's much closer to: "If you're going to use AI, understand what you're using it for, know who it could affect, and put reasonable safeguards around it."
The law was finalised in 2024 and is being rolled out in stages rather than all at once, and it’s still being actively amended. An update called the Digital Omnibus on AI changed some of the details as recently as July 2026, so this isn’t a read it once and forget it law. It’s one to keep an eye on.
That means this isn't something businesses should put on a list marked "deal with this in a few years." Some of it already applies to you, right now as of August 2026.
“We Are a UK Business, Does It Really Apply to Us?”
Possibly.
Since Brexit, it is easy to note the “EU AI Act” and assume it’s only for businesses based in the EU. But being UK-based doesn’t automatically put you outside it. The law follows the AIs connection to the EU, not where your company’s front door is. It can apply to you if:
You sell or offer an AI product or AI-powered service to people who are in the EU; or
Your AI’s output (a decision, a recommendation, a generated image or piece of text) ends up being used in the EU, even if your business itself never sets foot there.
So, the important question to think about and ask is “Does anything our AI produces reach someone in the EU?”, and “What if we just have customers in the EU?” This is where people mix up two separate things: the EU AI Act, and a different, older law called EU GDPR (the EU’s data privacy law).
Here is the difference in one sentence to help you understand - GDPR is about what you do with people’s personal information. The AI Act is about what your AI system does and who it could affect. You can trigger one without triggering the other.
If your UK business has EU customers, employees, or users, ask these two separate questions:
What are we doing with people’s personal information? (this is a GDPR question)
What are we doing with AI, and where does it end up? (this is a AI Act question)
Sometimes the answer to both is “yes, this applies to us”. Sometimes only one does. They need to be checked separately.
"But We Are Not an AI Company"
You don't have to be. This is the biggest misconception around. A business doesn't have to build artificial intelligence to have responsibilities around how it uses it. And AI isn't limited to the obvious tools with "AI" written across the homepage, it often quietly be built into software you’ve used for years.
AI here just means software that looks at information and produces a prediction, a piece of content, a recommendation, or a decision rather than following a fixed, hand-written set of rules.
In ordinary business terms:
Your recruitment system might help decide which applicants get shortlisted.
Your sales platform might score which leads your team should pursue.
A system might detect potentially fraudulent transactions.
A chatbot might answer questions on behalf of your business.
Software might recommend products to customers.
An AI assistant might draft reports or emails that employees then rely upon.
The question isn't simply - "Do we have ChatGPT?"
It's: "Where is AI being used in our business, what is it doing and who could be affected by it?" This is the starting point for any AI governance support that will actually hold up under scrutiny.
Not Every Use of AI Carries the Same Risk
This is one of the central ideas behind the EU AI Act. The Act sorts AI into a few risk tiers, think of them less as strict legal boxes and more as sliding scales from “harmless” to “seriously consequential for a real person”. A few practices are banned outright as highlighted in the next section. Some uses count as “high-risk” and come with much heavier obligations. AI that talks to or affects people directly has its own separate transparency rules. A single AI tool can sometimes land in more than one tier depending on how you use it. For a business owner,the easiest starting question is:
What could happen to a person if this AI gets it wrong?
Some Uses of AI Are Banned Outright
A small, specific list of AI uses is banned everywhere in the EU because they are considered too harmful to allow at all. This includes things like scoring or ranking people’s character or trustworthiness known as social scoring, manipulating people’s behaviour in harmful ways, exploiting children’s or vulnerable people's vulnerabilities, scraping the internet for faces to build facial-recognition databases, and certain uses of biometric identification.
For most ordinary businesses, this list isn’t where you would most like to spend much time as you would be unlikely to be doing any of this. The more relevant question is often whether AI is influencing important decisions about people.
High-Risk AI, Where It Actually Gets Practical
Imagine two businesses.
Business A uses AI to help write the first draft of its weekly newsletter.
Business B uses AI to assess people applying for jobs.
Both of these uses of AI aren't the same level of risk.
If the newsletter tool produces a terrible paragraph, somebody can delete it.
If the recruitment system incorrectly rejects a highly qualified candidate, the consequences for that person can be much greater.
That's why certain categories of use get much closer attention under the EU AI Act such as hiring and job-screening tools, credit and insurance-pricing decisions, medical devices, systems used in vehicles, law-enforcement systems and anything used to profile people (build a picture of their habits, preferences or likely behaviour).
If your AI use falls into one of those categories mentioned above, the law expects you to be able to show your homework, in everyday terms, that means being able to answer and show documented proof:
Who checks what the AI is doing?
Can a person challenge its recommendation?
Can someone override it?
Do we understand what information it is using?
Would we know if it started producing poor results?
Could we explain to somebody how we use it?
That is where governance starts becoming important.
Human Oversight Does Not Mean Someone Clicking “Approve”
I've seen businesses introduce AI fully intending to keep a human involved. Good instinct, but there’s an important trap. Having a human somewhere in the process isn't the same as that human actually providing meaningful oversight.
Imagine an AI system recommends rejecting a job applicant. The employee reviewing the recommendation automatically clicks Accept because they assume the system knows better. Technically, yes a human was involved. But did they really provide oversight?
Meaningful oversight is really a short checklist, not a single moment of review. Ask whether the person involved can:
Understand it: do they actually know what the system does and where its limitations are, rather than just knowing which button to click?
Spot a problem: would they notice if it started behaving oddly, producing biased results or getting things wrong?
Question or override it? Do they have enough information, and the actual authority, to disagree with it?
Switch it off: If something is clearly going wrong, can they actually stop the system being used, rather than just flagging it and hoping someone else deals with it?
That last point catches people out most often. Businesses often build in a way to override a single decision, reject this one output without ever asking who can pause or stop the system entirely if a pattern of problems emerges. Those are in essence two different powers.
A much better test than “was a human involved” is does the person understand what they are looking at, do they have enough information to question it, do they have the authority to override it, and if the AI tool is clearly broken, can someone actually turn it off?
AI should not become the person in the room nobody’s allowed to question. If this is a conversation you need to have inside your own business and are not sure how to start, book a call.
Your Website Chatbot Is a Good Example
You land on a company's website. A chat window pops up:
"Hi! How can I help you today?"
Are you talking to a real person? A scripted bot? An AI?
Under the EU AI Act's, the law says if people are interacting directly with AI, they need to be told it’s AI clearly enough that a reasonable person wouldn't be confused. It doesn’t have to be a giant disclaimer. It just can’t be hidden or misleading.
Don't make your customers guess whether they're dealing with a person or a machine.
What About AI-Generated Content?
You may have heard: “Everything made with AI has to have an AI label.” That is an oversimplification.
It means if your AI tool generates audio, images, video or text, the tool itself generally needs to mark that output in a way computers can detect (this is a background technical marker, not something a human necessarily sees). Separately, there are extra disclosure duties in specific situations such as deepfakes and AI-generated content published to inform the public on matters of public interest.
So no, an employee using AI to tidy up an email doesn’t need to write “This email was written by AI” underneath it. What is important is understanding what your AI produces, how you use that output, and whether one of the specific disclosure situations applies to you.
One of the Biggest Risks Is Not Knowing What Your Business Is Using
This is the issue I would encourage businesses to tackle first and it has nothing to do with reading legislation or running to a solicitor.
AI often sits quietly inside software a business has used for years. Individual teams adopt their own tools. Vendors add an AI feature. Someone signs up for a tool with a work email without anyone thinking twice about what customer information is going into it.
Nobody did anything malicious. It was just the technology simply moved faster than anyone’s awareness of it. That's why I wouldn't start with a 70-page policy. I would recommend starting with a spreadsheet and document the answers to the questions noted in the next section.
What Should You Do Now?
1. Find out where AI is being used
Ask every part of your business the following questions:
What AI tools do you use?
What existing software has AI features switched on?
What information goes into those tools?
What comes out?
What decisions or recommendations do they make?
Who relies on the output?
That's your starting AI inventory, just a list, nothing more technical than that.
2. Work out what each AI system actually does
Don't assume something as low-risk simply because it comes from a well-known software company. Look at your use of it.
AI drafting for example an internal meeting agenda is very different from AI ranking people applying for employment or using AI for employee performance appraisals.
3. Work out your role
In plain terms, are you using someone else’s AI as-is, or have you built or meaningfully customised one yourself, or are you selling an AI-powered product to someone else?
Give you a heads up, the law treats these roles differently, the person building the tools carries way more responsibilities than the person simply using it off the shelf, also known as the deployer, but users still have obligations too.
4. Check your EU connection
Don't assume you're outside the Act because your head office is in the UK. Ask:
Do we offer an AI product or AI-enabled service to people in the EU?
Is an AI system we use or provide actually being used by people in the EU?
Does anything our AI produces end up being used in the EU?
And separately: if you are offering goods or services in the EU and handling their personal information, check your GDPR obligations too as a completely separate exercise.
5. Look at decisions affecting people
Pay particular attention to AI involved in things such as recruitment, credit, insurance, healthcare and other decisions that could materially affect a real person’s life. If AI gets something wrong, ask yourself or the person who is responsible for the managing the tool:
“Who could be harmed and how serious could that harm be?”
6. Check your transparency
If customers are interacting directly with AI, do they know? If you're producing AI-generated content, does one of the disclosure situations apply to you?
7. Check your vendors
This one is important. Using somebody else's AI tool doesn't necessarily mean somebody else has taken care of every compliance issue for you.
Ask vendors:
What does the system actually do?
What information does it process?
Where does that information go?
What controls do we have over it?
What documentation can you give us?
What are you doing to meet your own obligations under this law?
Document the answer.
Check the vendor’s website to see if there are details that can answer the above questions as this is a good starting point
8. Start documenting your decisions
You don't need an enormous governance department to start doing this. Just document, in plain language:
what AI you're using and why
who is responsible for it internally
what information it processes
what could go wrong, and what you are doing about it (risk you are identifying and think beyond security, think bias and ethics)
whether humans review important outputs
what your vendor has told you
when you'll check it again
A simple record implemented today is way better than trying to reconstruct two years of decisions when somebody asks questions later. If the exercise starts to feel bigger than you can handle in-house, that is where an AI governance consultancy can step in.
And Yes, the Fines Can Be Significant
This is usually the part that gets a company name permanently recorded on government registers like UK ICO and in headlines.
Depending on the type of infringement, maximum penalties under the Act can reach:
Banned practices are up to €35 million or 7% of global annual turnover, whichever is higher
Most other breaches are up to €15 million or 3% of global annual turnover, whichever is higher
Giving regulators false information is up to €7.5 million or 1% of global annual turnover, whichever is higher
Those figures deserve yours and every business owner’s attention. But I don't think fear of a fine should be the only reason a business gets its AI governance in order, and the next section will explain.
You Should Be Able to Explain How Your Business Uses AI
Imagine a customer asks: "Did AI make that decision about me?" Could you answer?
Imagine your board asks: "What AI systems are currently being used across the company?" Could you produce the list?
Imagine an employee says: "This AI recommendation doesn't look right." Do they know who to tell?
Imagine an investor asks: "What controls and documentation do you have around AI?" Could you show them?
Imagine if a regulator asks: “Show us how you assessed this.” Could you produce proof?
If the answer to those questions is "I'm not sure," that is where I would start. You don't need to become an expert in European legislation and you don't need to stop using AI. You need to understand:
what you're using;
why you're using it;
what could go wrong;
who's responsible for it;
what safeguards make sense; and
What is being documented if we are asked to show proof?
The EU AI Act is making those questions harder for businesses to dismiss, but they're questions responsible businesses should probably have been asking anyway especially before deploying into business operations or accepting vendors automatically switching on AI into existing software tools.
If you would like to talk it through, book a call. No slides, no jargon. Just a plain conversation about what you are using and what to do next
FAQ’s:
Does the EU AI Act apply to UK businesses?
Potentially. You don’t need to be based in the EU. It depends on what AI your business is using or providing, and whether it, or its output, connects to the EU.
If we have EU customers, does the EU AI Act automatically apply?
No. that may trigger separate GDPR duties around personal information, a different law entirely. The two need checking separately.
Does using ChatGPT mean my business has to comply with the EU AI Act?
Not by itself. What matters is what you are using it for, who it affects, and whether that connects to the EU.
Do I have to tell customers when they're talking to an AI chatbot?
If it interacts directly with people like your customers, then yes, clearly enough so they aren’t left guessing.
Does all AI-generated content have to be labelled?
No, the rules depend on what kind of content it is, how it is being used, and your role. Most everyday internal AI use such as drafting an email, summarising notes isn’t covered by the public-facing disclosure rules.
What should a UK small business do first?
Find out what AI your business is using including existing software that has been used for years as the vendor may have added an AI feature that has been switched on automatically. At the end of the day you can’t govern what you don’t know exists.

