Does the EU AI Act apply to the UK?
Where you are registered doesn't settle it. What counts is where your AI systems are used and where their results end up.
A UK organisation with no EU customers, no EU users and no AI system outputs used in the EU is not bound by the EU AI Act today.
You can still be caught from the UK. The Act reaches past the EU's borders and follows the system and its results, so a UK organisation comes within scope when it provides an AI system in the EU, deploys one there, or produces output that is used there (Article 2).
That makes the first question a practical one: where does each system operate, and where do its results end up? Take your AI systems one at a time, work out what role you play with each, and follow the route by which the system or its output reaches people or operations in the EU. The EU AI Act overview has the scope routes and the roles in one place.
Three questions that decide it
For most UK organisations the whole of Article 2 comes down to these:
- Do you offer an AI system, or a product with AI in it, to customers or users in the EU, paid or free?
- Does any part of your organisation established in the EU use AI systems in its work?
- Does the output of an AI system you run get used in the EU, in a report for an EU client, a decision about an EU candidate, or content published there?
Three noes and the Act does not bind you today. One yes and it does, and the next question is which duties. The EU AI Act check asks these and seven more, system by system, and names the article behind each answer.
How can a UK organisation come within scope?
The Act applies to providers that place AI systems on the EU market or put them into service in the EU, wherever the provider is established. If you develop an AI system in the UK and offer it to EU customers under your own name, being outside the EU doesn't by itself take that system out of scope (Articles 2 and 3).
It also applies to deployers that are established or located in the EU, so a UK parent with an EU operation has to look at how that operation uses AI systems under its authority. You can hold more than one role at once, because the Act separately recognises providers, deployers, importers, distributors and product manufacturers (Articles 2 and 3).
The third route reaches furthest: the Act applies where the output of an AI system is used in the EU, even if the organisation operating the system is elsewhere (Article 2). So follow your outputs into the decisions and workflows they feed, because where the server or the supplier sits doesn't answer the question.
Which common UK setups are in scope?
The routes are abstract until you put a real setup through them. These four come up most for UK organisations, and each verdict names the article that decides it, so you can check the wording against your own case.
Is a UK SaaS product with EU customers in scope?
Yes. Offering an AI system to customers in the EU is placing it on the market or putting it into service there, and the Act applies to providers doing that wherever they are established (Article 2). A free tier changes nothing, because supply in the course of a commercial activity counts whether or not anyone pays (Article 3).
Which duties follow depends on what the system does. A customer-facing chatbot or a feature that generates synthetic content carries the Article 50 transparency duties now, and a system in an Annex III area works to the deferred December 2027 date.
Does using ChatGPT internally put us in scope?
Not by itself. A UK organisation using ChatGPT or a similar tool for internal work, with no EU customers, no EU users and no outputs used in the EU, is not bound by the Act today (Article 2).
The thing to watch is output. Internal use makes you a deployer, and the Act reaches a deployer outside the EU once the system's output is used in the EU, so a report drafted for an EU client or screening applied to candidates in the EU can open that route (Article 2). Follow each use through to where its results land before calling it internal.
Does selling through an EU distributor keep us out of scope?
No. The Act applies to providers placing AI systems on the EU market wherever they are established, and separately to the importers and distributors handling them, so routing sales through an EU intermediary adds regulated parties to the chain rather than taking you out of it (Article 2).
High-risk systems add a duty on this route: a provider outside the EU has to appoint an authorised representative established in the EU before making the system available there (Article 22). That obligation arrives with the deferred high-risk dates, 2 December 2027 for Annex III systems and 2 August 2028 for product-embedded ones.
What if our product is built on a general-purpose AI model?
The product still carries its own duties. Obligations for the model itself sit with the model provider (Chapter V), and an organisation that places a system built on that model on the EU market is the system's provider, wherever it is established (Article 2).
The roles are separate and one organisation can hold both. Calling a model through an API does not by itself make you the model's provider (Article 3), and what you owe follows the system you offer: Article 50 transparency where it applies now, and the high-risk duties on the deferred dates if the system sits in a listed area.
Most of the trouble UK organisations get into here comes from a small number of repeated assumptions, and the mistakes UK businesses make about the EU AI Act works through the ones that come up most.
What already applies if there is EU exposure?
Four sets of obligations are already in force. Prohibited AI practices have applied since 2 February 2025, including the specific practices listed in Article 5, and the AI literacy duty has applied from the same date, requiring providers and deployers to ensure that staff dealing with AI have a sufficient level of AI literacy (Articles 4 and 5).
General-purpose AI model obligations have applied since 2 August 2025 (Chapter V). Transparency obligations have applied since 2 August 2026, covering matters such as telling people when they interact with an AI system, machine-readable marking of synthetic outputs, notices for people exposed to emotion recognition or biometric categorisation, and disclosure of deepfakes (Article 50).
So you can have work to do now with nothing in a deferred high-risk category. Our guide to the transparency requirements in force now explains the Article 50 duties, the AI literacy guide covers the live staff duty, and the prohibited practices guide sets out what Article 5 bans, including the two prohibitions the omnibus added for 2 December 2026.
Which high-risk dates were deferred?
The omnibus changed the timetable for high-risk obligations. Duties for Annex III stand-alone high-risk systems are deferred to 2 December 2027 under Regulation (EU) 2026/1744. The listed areas include biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration and border control, and the administration of justice and democratic processes.
Obligations for Annex I product-embedded high-risk AI are deferred to 2 August 2028 under Regulation (EU) 2026/1744. This category concerns AI used as a safety component of products covered by EU harmonisation law, including machinery, medical devices, toys, lifts, radio equipment and in-vitro diagnostics. Both sets of duties still arrive on those later dates. The high-risk and Annex III guide covers the classification, the post-omnibus timeline has all the dates, and you can download it as a one-page PDF.
What are the penalties for non-compliance?
Fines under Article 99 reach €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices. Most other obligations, transparency included, carry up to €15 million or 3%, and supplying incorrect, incomplete or misleading information to authorities carries up to €7.5 million or 1%.
Member states set the penalty rules and their courts or authorities impose the fines, and the omnibus left every ceiling in place. It did adjust how fines fall on smaller companies: a fine on an SME, including a start-up, is capped at whichever of the pair is lower, and Regulation (EU) 2026/1744 extended that lower cap to small mid-caps for most breaches. When imposing a penalty, member states now also have to take account of the economic viability of SMEs and small mid-caps (Article 99).
What does UK law require instead?
There is no UK equivalent of the EU AI Act. Obligations for AI in the UK sit across existing law applied by existing regulators, and for most organisations the live one is data protection: the ICO's guidance on AI and data protection sets out how UK GDPR applies when AI systems process personal data.
The two regimes run separately, so a UK organisation within the Act's scope answers to both, and meeting one does not discharge the other. ISO 42001 is often offered as the bridge across them; it is a voluntary standard and certifying to it is not compliance with the Act, which our guide to ISO 42001 vs the EU AI Act covers in full.
What if the Act does not bind us today?
If you have no EU customers, no EU users and no outputs used in the EU, the Act does not bind you today (Article 2). Base that on where your customers, users and outputs actually are, and look at it again if you enter the EU or an AI output starts being used there.
UK-facing rules may still emerge domestically, and governance work you do now carries across to that position. While Article 2 leaves you outside scope, though, don't put that work to your board as a current EU legal obligation. It is a choice you are making.