It depends on your connection to the EU market, not your country of registration. The EU AI Act applies to UK businesses in three situations defined by Article 2: you place an AI system or general-purpose AI model on the EU market, you have an EU establishment that uses AI, or the output produced by your AI system is used in the EU. A UK company with purely domestic customers and no EU-bound output is outside the scope of the Act, although even then EU clients may impose AI Act requirements contractually.
What Is the EU AI Act?
The EU AI Act (Regulation (EU) 2024/1689) is the first wide-ranging AI law in the world. It sorts AI systems into risk tiers and attaches obligations to each tier. Prohibited practices, such as social scoring and emotion recognition in workplaces, are banned outright. High-risk systems, such as AI used in recruitment screening or credit decisions, carry conformity assessment and documentation duties. Limited-risk systems, which is where most SME AI use sits, carry transparency duties only. The Act is a horizontal, product-safety-style law rather than a set of principles, which is why it applies regardless of company size.
There is no equivalent wide-ranging AI statute in the UK. The UK approach relies on existing regulators, such as the ICO for data protection, applying five cross-cutting principles. This means the EU Act is usually the higher bar for UK firms, and complying with UK guidance alone does not achieve EU conformity.
When Did the EU AI Act Take Effect?
The timeline is staggered, and the June 2026 Digital Omnibus amendments changed it. The prohibited practices have been enforceable since February 2025. The obligations for general-purpose AI model providers have been binding since August 2025, although the Commission only gained enforcement powers, including investigation and fining authority, on 2 August 2026. The Article 50 transparency obligations became directly applicable on 2 August 2026, with a grace period to 2 December 2026 for marking systems that were already on the market. The high-risk regime for standalone systems was delayed from August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028.
The practical consequence: a UK business with EU exposure has live transparency obligations now, and a build window of roughly 15 months before the high-risk regime arrives.
What Does Article 50 Require UK Businesses to Do?
Article 50 sets out four transparency duties. First, providers must ensure people interacting with AI systems, such as chatbots and virtual assistants, are informed of that fact. Second, providers of generative AI systems must mark synthetic output, including images, video and text, in machine-readable form so it can be detected as AI-generated. Third, deployers using emotion recognition or biometric categorisation must inform the people exposed to it. Fourth, deployers publishing deepfakes must disclose that the content is artificially generated or manipulated, and AI-generated text published to inform the public on matters of public interest must be disclosed.
For a typical UK SME, the first two duties are the relevant ones. If you operate a customer-facing chatbot, it must disclose. If you publish AI-generated content that could be mistaken for authentic, it must be marked. Where you use third-party AI platforms, the marking duty generally sits with the platform provider, but you should confirm your vendor position in writing because your customers will ask.
How Does the Act Reach UK Companies With No EU Office?
Article 2(1)(c) applies the Act to providers and deployers established outside the EU where the output produced by their AI system is used in the EU. A UK company serving an AI-powered analytics feature to a customer in Germany is in scope, even though the company has no EU presence and the system runs entirely on UK infrastructure. Incidental access by someone who happens to be in the EU does not trigger scope, but where EU use is a real part of how your product is consumed, assume it applies.
There is also a contractual route. EU companies buying from UK suppliers need to understand the AI in their own supply chain to meet their own obligations, and they do this through procurement and security questionnaires. UK firms increasingly encounter the Act through these questionnaires before they ever encounter it through its legal scope.
What Are the Penalties?
Under Article 99, fines reach 35 million euros or 7% of worldwide annual turnover for prohibited practices, 15 million euros or 3% for most other breaches, including the transparency duties and deployer obligations, and 7.5 million euros or 1% for providing misleading information to authorities. The higher of the two figures applies, except that SMEs pay the lower figure. The fines are calculated on global turnover, not EU revenue, which is why the exposure is taken seriously by companies of all sizes.
What Should a UK SME Do Now?
Four practical steps cover the current obligations. One: inventory every AI tool in use, noting which ones touch EU customers or produce EU-bound output. Two: check every customer-facing AI touchpoint against Article 50, particularly chatbot disclosure and content marking. Three: ask your AI vendors for their EU AI Act compliance position and keep it on file. Four: prepare a short evidence summary so an EU procurement questionnaire can be answered in days rather than weeks. None of this requires enterprise budgets, and the high-risk obligations now arriving in December 2027 give UK firms a defined window to build documentation habits early.
To check your position in two minutes, use our free EU AI Act Readiness Checker. For the commercial view of what this means for UK SMEs selling into Europe, see our blog analysis of the EU AI Act coming into force. If you want help putting the governance in place, book a free discovery call or read about our AI governance service.