Skip to main content
ExplainerEU AI Act5 min read

Does the EU AI Act Apply to UK Businesses?

Find out when the EU AI Act can apply to a UK business, how to check your role and what the July 2026 changes mean for the timetable.

AI-assisted guidance from RightCyber. Sources checked on 16 September 2026.

BylineWritten by RightCyber · Published by RightCyber

PublicationPublished · Updated

Source statusReviewed 16 September 2026 · Review due 16 October 2026

At a glance

Follow what each AI tool does, what role your business has and where the results are used to work out which EU AI Act duties apply.

On this pageArticle contents

Share this article

LinkedInEmail

Being based in the UK doesn't, by itself, put your business outside the EU AI Act. You need to look at what the AI does, who supplies it and where people use its outputs.

A recruitment agency, developer or consultancy might encounter the Act through an ordinary customer project. Using an AI writing tool doesn't automatically bring every UK business under every part of the law, either.

This guide draws on official sources checked on 16 September 2026. For a complicated cross-border service, get advice on the details of your arrangement.

Follow the work from start to finish

Article 2 covers providers offering AI systems in the EU, wherever the provider is based. It also covers deployers established or located in the EU, plus providers or deployers outside the EU when their system's output is used there. Other roles, including importers and distributors, are covered too.

There isn't a blanket exemption for small UK businesses. Any exclusion or exception needs to fit what your business actually does.

Start with a sketch of how the work happens. Where does the AI run? Who receives its recommendations or generated content? Where does someone act on the result? Which business signs the customer contract?

Take a hypothetical British consultancy that uses AI to rank candidates for an employer in France. Its staff and computers stay in the UK, but the rankings will be used in France. It needs to check scope, its role and the recruitment classification.

For a UK-only task, a supplier that also trades in Europe doesn't settle the question. Write down the EU connection your own work has, if any.

Work out your role for each system

Two terms come up often: provider and deployer. Under the Article 3 definitions, a provider develops an AI system, or has one developed, and puts it on the market or into service under its own name or trademark. A deployer uses an AI system under its authority in a professional context.

If you subscribe to an existing tool for work, you'll often be a deployer. If you commission a system and supply it under your own brand, you may be its provider. The invoice alone won't tell you which role you have.

Imagine an agency that uses a writing assistant for internal drafts and also sells a customer-service assistant built for clients. It needs to look at those two activities separately. Saying “we only use someone else's model” leaves an important question unanswered: who is responsible for the finished service?

Ask the supplier which business provides the system, what the system is intended to do and which responsibilities sit with you. Keep the reply with the contract and technical documents. If you and the supplier disagree, sort that out before making compliance promises to a customer.

Check what the tool actually does

A system can fall within the Act without being high-risk. Your obligations depend on your role, the system and its use. The Commission's AI Act overview sets out prohibited practices, high-risk uses, transparency duties and other applications.

Describe the task in a sentence someone outside your team could understand. “AI in HR” tells them very little. “Ranks applicants and recommends who gets an interview” is much clearer. So is “corrects spelling in a job advert”. Those tasks deserve different levels of scrutiny.

Look closely at tools involved in employment decisions, access to important services, biometric uses or safety-related work. If an error could seriously affect someone, or the intended purpose is unclear, ask someone with the right expertise to review the classification. A supplier's generic “low risk” badge isn't enough to resolve it.

Check the dates against the current rules

Older summaries may give you the wrong timetable. The AI Omnibus entered into force on 27 July 2026. It extended the main Annex III high-risk timetable to 2 December 2027 and the relevant Annex I product timetable to 2 August 2028. It didn't postpone the whole Act.

Transparency obligations started applying on 2 August 2026, subject to specific provisions and transitions. The Commission's transparency guidance explains the rules for systems that interact with people and certain generated content.

Write down each obligation beside its applicable date. One deadline won't necessarily cover everything. If an older page conflicts with current guidance, check the adopted amending regulation.

Keep a record you can use

One page per use is a reasonable starting point. Include:

  • The system, supplier, person responsible and purpose.
  • Your likely role and why you think it fits.
  • The EU connection, including where outputs are used.
  • Who could be affected by a wrong output, and how.
  • Any questions about prohibited uses, high-risk classification or transparency.
  • The evidence you've checked, decisions still needed and next review date.

This is a practical way to organise your assessment. It isn't a prescribed legal form. It's fine to mark a question as unresolved, provided you also say what evidence is missing and who will find it.

Come back to the record when you change the task, take on an EU customer or start using a new feature. A tool that once helped draft text needs another look if you begin using it to recommend decisions about people.

Pick one tool your team already uses and follow a piece of work from its first input to the final decision. That gives you something concrete to discuss with the supplier or an adviser.

Provenance

Sources reviewed

Reviewed 16 September 2026

Sources reviewed by RightCyber on 16 September 2026. A source’s classification describes where it came from; it is not a blanket claim about every source.

Disclaimer

RightCyber is independent and is not affiliated with or endorsed by the European Commission or any source linked here. This article gives general information. It isn't legal advice and doesn't establish whether your organisation complies. Check how the rules apply to your work and get advice where you need it.

Clarifications

Frequently asked questions

Can the EU AI Act apply to a business based in the UK?
Yes. It can apply when you supply AI systems into the EU, and in certain situations where a system's outputs are used there. Check what your business does, your role and the rules that cover the activity. Your registered address doesn't decide the answer.
Does buying an AI tool make us its provider?
Not automatically. If you use an existing system for work, you'll often be a deployer. If you have a system developed and supply it under your own name, you may be its provider. Look at each use separately, including the contract and how the service works.
Did the July 2026 changes postpone the entire AI Act?
No. The adopted AI Omnibus changed specific provisions and extended the main high-risk timetables. Other duties, including relevant transparency obligations, already apply. Check the date for each duty that affects your business.

Continue reading

Continue with a related article

The AI tools your team uses also need secure accounts and devices. Our guide explains the everyday weaknesses that can give attackers a way in.

Keep exploring

Browse the RightCyber Blog
  • People and account security

    How Cyber Attacks Often Start

    Many incidents begin with an ordinary request to click, reset, scan, or pay. Verify money movements, bank-detail changes, and account recovery through a separate trusted channel every time.

  • People and account security

    Why MFA Isn't Enough on Its Own

    MFA still blocks a huge amount of password abuse, but phishable prompts and stolen sessions remain. Move important accounts towards passkeys or FIDO2, then review recovery, session controls, and monitoring.

  • Cyber Essentials

    Cyber Essentials Tender Requirements: What PPN 014 Means for Your Bid

    PPN 014 tells named central-government and NHS bodies to require proportionate cyber controls on relevant procurements. Cyber Essentials or Plus is a standard route, but equivalent controls must be accepted; this article explains the rule, certificate checks, and evidence-before-award timing.