Skip to content
Comonad

Home / Guides / Does the EU AI Act apply to UK companies?

Does the EU AI Act apply to UK companies?

Short answer: Yes, in many cases. The EU AI Act (Regulation (EU) 2024/1689) applies to UK organisations that place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, or use an AI system whose output is used in the EU. Scope follows the activity, wherever the organisation is established.

Last reviewed: 27 September 2026.

This guide explains the law in general terms. It is not legal advice. Take advice from your counsel on your own systems.

The short answer

The Act reaches organisations established outside the EU. Article 2(1) applies it to providers placing AI systems or general-purpose AI models on the EU market "irrespective of whether those providers are established or located within the Union or in a third country", and to providers and deployers in a third country "where the output produced by the AI system is used in the Union". For a UK organisation, three activities bring a system into scope:

  • Placing on the market: making an AI system or model available in the EU for the first time.
  • Putting into service: supplying an AI system for first use in the EU, including for your own use there.
  • Output used in the EU: the system runs in the UK, and its output is used in the EU.

The test applies system by system. One organisation can have some systems in scope and others outside it.

The three ways a UK organisation comes into scope

The examples below are generic illustrations. They describe patterns and make no claim about any particular organisation.

Selling an AI system or model into the EU

A UK software company sells a product with an AI feature to customers in France and Germany. The company is a provider placing an AI system on the EU market, and the Act applies to that system. The same holds for a UK developer that makes a general-purpose AI model available to EU users.

Putting an AI system into service in the EU

A UK group builds an AI tool and gives it to its EU subsidiary to use. The UK company that developed the tool and supplied it under its own name is likely to be the provider putting the system into service in the EU. The EU subsidiary using it is a deployer established in the EU, which Article 2(1)(b) covers directly.

Producing output that is used in the EU

A UK firm runs an AI model on its own infrastructure and sends the resulting scores or recommendations to an EU client under contract. The system never leaves the UK, and its output is used in the EU. Article 2(1)(c) brings third-country providers and deployers into scope in that situation.

Provider or deployer: which are you?

A provider develops an AI system or model, or has it developed, and places it on the market or puts it into service under its own name or trademark (Article 3(3)). A deployer uses an AI system under its own authority, other than for a personal non-professional activity (Article 3(4)). Most obligations fall on providers of high-risk systems, and deployers have their own duties, including human oversight and keeping logs.

RoleMain duties at a high level
Provider of a high-risk AI systemRisk management system, data governance, technical documentation, record-keeping, information for deployers, human oversight by design, accuracy, robustness and cybersecurity, quality management system, conformity assessment, registration, post-market monitoring and serious-incident reporting
Deployer of a high-risk AI systemUse the system in line with the provider's instructions, assign human oversight to people with the necessary competence and authority, monitor operation, and keep the logs under your control for at least six months (Article 26)
Provider or deployer of any AI systemAI literacy measures (Article 4), the prohibitions (Article 5), and the transparency duties in Article 50 where they apply
Provider of a general-purpose AI modelThe Chapter V obligations for general-purpose AI models, including an EU authorised representative for providers outside the EU

One organisation can hold both roles. A company that fine-tunes a model and ships it in its own product is typically a provider of that product, and a deployer of any third-party AI tools it uses internally.

What already applies (2025 to 2026)

Prohibited AI practices have applied since 2 February 2025 and general-purpose AI model duties since 2 August 2025. The Act's general application date was 2 August 2026, which brought in most transparency duties under Article 50, with a grace period to 2 December 2026 for some generative systems already on the market.

  • Prohibited practices (Article 5). Banned since 2 February 2025. They include, for example, social scoring, untargeted scraping of facial images to build facial recognition databases, and inferring emotions in workplaces and education institutions, with narrow exceptions. The Digital Omnibus on AI adds prohibitions covering AI that generates non-consensual intimate imagery and child sexual abuse material, which apply from 2 December 2026.
  • AI literacy (Article 4). Chapter I, which contains Article 4, has applied since 2 February 2025. The Digital Omnibus replaced its wording. It now says: "Providers and deployers of AI systems shall take measures to support the development of AI literacy of their staff and other persons dealing with the operation and use of AI systems on their behalf", taking into account their knowledge, experience and training and the context of use, and adds that this "does not require providers or deployers to guarantee any specific level of AI literacy of any individual."
  • General-purpose AI models (Chapter V). Obligations for providers of general-purpose AI models have applied since 2 August 2025.
  • Transparency (Article 50). From 2 August 2026: tell people when they are interacting with an AI system, mark synthetic audio, image, video and text in a machine-readable way, inform people exposed to emotion recognition or biometric categorisation, and disclose deepfakes. Generative systems placed on the market before 2 August 2026 have until 2 December 2026 to meet the marking duty in Article 50(2).

High-risk AI: what it is and when the rules apply

There are two routes to high risk under Article 6. The first is AI that is a safety component of a product, or is itself a product, covered by the EU harmonisation legislation listed in Annex I, such as machinery or medical devices. The second is AI used for the purposes listed in Annex III, which has eight areas:

  1. Biometrics.
  2. Critical infrastructure, including safety components in the supply of water, gas, heating or electricity.
  3. Education and vocational training.
  4. Employment and management of workers.
  5. Access to essential private and public services and benefits.
  6. Law enforcement.
  7. Migration, asylum and border control.
  8. Administration of justice and democratic processes.

Article 6(3) excludes some Annex III systems that pose no significant risk of harm, for example a system intended to perform a narrow procedural task. A provider relying on that derogation must document its assessment.

After the Digital Omnibus on AI (Regulation (EU) 2026/1744, in force since 27 July 2026), obligations for high-risk AI systems listed in Annex III apply from 2 December 2027, and for high-risk AI in products covered by Annex I from 2 August 2028. Earlier commentary giving 2 August 2026 as the high-risk date is out of date.

DateWhat applies
1 August 2024The Act enters into force
2 February 2025Prohibited practices, and Chapter I including AI literacy
2 August 2025General-purpose AI model obligations, the governance chapter and the penalty provisions (Commission fines for general-purpose AI model providers follow from 2 August 2026)
2 August 2026General application, including most Article 50 transparency duties
2 December 2026Article 50(2) marking for generative systems placed on the market before 2 August 2026; the prohibitions added by the Digital Omnibus
2 December 2027High-risk obligations for Annex III systems
2 August 2028High-risk obligations for Annex I systems (AI in regulated products)
2 August 2030Deadline for providers and deployers of existing high-risk systems intended to be used by public authorities

What high-risk obligations look like in a running system

The legal text describes outcomes. In a running system, each outcome needs evidence that someone can produce on request.

  • Risk management. A living register tied to the system: each identified risk, its owner, the control that treats it and the test that shows the control works. It is updated when the system, its data or its model changes.
  • Record-keeping and logs. Article 12 requires high-risk systems to allow automatic recording of events over their lifetime. In practice that means deciding what is logged (inputs, outputs, model version, the human decisions taken), where the logs live, and for how long. Deployers keep the logs under their control for at least six months under Article 26.
  • Human oversight. Article 14 expects the people assigned to oversight to be able to monitor the system, interpret its output, decide not to use it or override it, and interrupt it so that it comes to a halt in a safe state. That needs a named role, a documented way to intervene, and a stop mechanism that has been tested in a release.
  • Accuracy, robustness and cybersecurity. Article 15 expects an appropriate and consistent level of each. Evaluation before release and after every change, with a regression set of known cases, gives you measured evidence.
  • Technical documentation. Kept current with each release, so the document describes the system that is actually running.

These map closely to the controls we recommend for agents; see how to govern AI agents in production. For help turning obligations into controls and evidence, see our AI governance consultancy.

Authorised representatives and penalties

A provider established outside the EU must appoint, by written mandate, an authorised representative established in the EU before making a high-risk AI system available on the EU market (Article 22). Providers of general-purpose AI models established outside the EU have an equivalent duty (Article 54). The representative keeps documentation available and cooperates with the competent authorities.

Fines scale with the breach (Article 99): up to €35 million or 7% of total worldwide annual turnover, whichever is higher, for prohibited practices; up to €15 million or 3% for breaches of listed obligations, including those of providers, deployers and authorised representatives, and the Article 50 transparency duties; and up to €7.5 million or 1% for supplying incorrect or misleading information to authorities. For SMEs, including start-ups, each cap is whichever amount is lower. The Digital Omnibus left these amounts unchanged and extended the "whichever is lower" rule to small mid-cap enterprises for the two lower tiers. The Commission can separately fine providers of general-purpose AI models up to 3% or €15 million (Article 101).

How this fits with UK rules

There is no UK equivalent of the EU AI Act. As the House of Commons Library put it in June 2026, "The UK does not have any AI-specific regulation or legislation covering AI as a technology." AI is regulated through existing law and regulators: data protection through the Information Commissioner's Office (ICO), and sector regulators such as the FCA and Ofgem. In September 2026 the Department for Science, Innovation and Technology (DSIT) published an AI Risk Management Toolkit, written for government departments and useful to anyone running AI projects.

EU AI ActUK approach
Legal basisA single regulation that applies across sectorsExisting law, applied by existing regulators
StructureRisk tiers: prohibited, high-risk, transparency duties, general-purpose AI modelsSector guidance, for example the ICO's guidance on AI and data protection and Ofgem's guidance on ethical AI use in the energy sector
EnforcementNational market surveillance authorities, and the Commission for general-purpose AI modelsUK regulators within their existing powers

A UK organisation in scope of the EU Act still has its UK obligations. In practice, one set of controls and evidence can serve both, provided each control is mapped to the specific requirement it meets.

A first plan for UK organisations

Start with an inventory of AI systems, record where each is sold or where its output is used, decide your role for each, classify each system's risk, and check the duties that already apply. Then plan the high-risk evidence against the 2027 and 2028 dates.

  1. Inventory. List every AI system you build, buy or use, including AI features inside third-party products.
  2. Market and output mapping. For each system, record whether it is sold or supplied in the EU, used by an EU entity, or produces output used in the EU.
  3. Roles. Decide whether you are the provider, the deployer or both for each system in scope.
  4. Classification. Check each system against the prohibitions, Annex I, Annex III and the Article 6(3) derogation, and record the reasoning.
  5. Current duties. Confirm what applies now: AI literacy measures, the prohibitions, Article 50 transparency, and general-purpose AI model duties if you provide a model.
  6. High-risk evidence plan. For any high-risk system, plan the risk management, logging, human oversight, evaluation and technical documentation, working back from 2 December 2027 or 2 August 2028.
  7. Owner and review cadence. Name an owner for the inventory and review it when systems change and when the rules change.

How Comonad helps

Comonad Limited, a London applied-AI consultancy, helps UK organisations work out which systems the Act reaches, classify them, and build the control sets and evidence mapped to the Act: risk registers, logging, human oversight and evaluation that stand up to review. We work alongside your legal and risk teams. Legal sign-off stays with your counsel. See our AI governance consultancy.

Book an introductory call

Frequently asked questions

Does the EU AI Act apply to UK companies?

Yes, in many cases. The EU AI Act applies to UK organisations that place an AI system or general-purpose AI model on the EU market, put an AI system into service in the EU, or whose AI system produces output used in the EU. Scope depends on the activity and applies system by system, so one organisation can have some systems in scope and others outside it.

When do the EU AI Act high-risk rules apply?

After the Digital Omnibus on AI, Regulation (EU) 2026/1744, which entered into force on 27 July 2026, obligations for high-risk AI systems listed in Annex III apply from 2 December 2027. Obligations for high-risk AI in products covered by the EU product legislation in Annex I apply from 2 August 2028. Earlier guidance giving 2 August 2026 as the high-risk date is out of date.

Is there a UK equivalent of the EU AI Act?

No. The UK has no cross-sector AI Act. AI is regulated through existing law and regulators: data protection through the ICO, and sector regulators such as the FCA and Ofgem. The Department for Science, Innovation and Technology published an AI Risk Management Toolkit in September 2026. UK organisations selling into the EU can face both regimes at once.

Does the EU AI Act apply to AI we only use internally in the UK?

Often it will not, where the system is not placed on the EU market or put into service there and its output is not used in the EU. An EU subsidiary using the system, or output that reaches EU customers or staff, can bring it into scope. Check each system individually, treat this as a question for your counsel, and avoid assuming a blanket exemption.