Key takeaway

The EU AI Act applies to UK businesses in three situations: you sell an AI system or AI-enabled product into the EU, you have an EU establishment that uses AI, or the output of your AI system is used in the EU. UK-only businesses with no EU customers are outside its scope. Since 2 August 2026 the Article 50 transparency obligations are live law: chatbots must disclose they are AI and AI-generated content must be machine-readable marked. The high-risk obligations were delayed to December 2027 and August 2028.

It depends on your connection to the EU market, not your country of registration. The EU AI Act applies to UK businesses in three situations defined by Article 2: you place an AI system or general-purpose AI model on the EU market, you have an EU establishment that uses AI, or the output produced by your AI system is used in the EU. A UK company with purely domestic customers and no EU-bound output is outside the scope of the Act, although even then EU clients may impose AI Act requirements contractually.

What Is the EU AI Act?

The EU AI Act (Regulation (EU) 2024/1689) is the first wide-ranging AI law in the world. It sorts AI systems into risk tiers and attaches obligations to each tier. Prohibited practices, such as social scoring and emotion recognition in workplaces, are banned outright. High-risk systems, such as AI used in recruitment screening or credit decisions, carry conformity assessment and documentation duties. Limited-risk systems, which is where most SME AI use sits, carry transparency duties only. The Act is a horizontal, product-safety-style law rather than a set of principles, which is why it applies regardless of company size.

There is no equivalent wide-ranging AI statute in the UK. The UK approach relies on existing regulators, such as the ICO for data protection, applying five cross-cutting principles. This means the EU Act is usually the higher bar for UK firms, and complying with UK guidance alone does not achieve EU conformity.

When Did the EU AI Act Take Effect?

The timeline is staggered, and the June 2026 Digital Omnibus amendments changed it. The prohibited practices have been enforceable since February 2025. The obligations for general-purpose AI model providers have been binding since August 2025, although the Commission only gained enforcement powers, including investigation and fining authority, on 2 August 2026. The Article 50 transparency obligations became directly applicable on 2 August 2026, with a grace period to 2 December 2026 for marking systems that were already on the market. The high-risk regime for standalone systems was delayed from August 2026 to 2 December 2027, and for AI embedded in regulated products to 2 August 2028.

The practical consequence: a UK business with EU exposure has live transparency obligations now, and a build window of roughly 15 months before the high-risk regime arrives.

What Does Article 50 Require UK Businesses to Do?

Article 50 sets out four transparency duties. First, providers must ensure people interacting with AI systems, such as chatbots and virtual assistants, are informed of that fact. Second, providers of generative AI systems must mark synthetic output, including images, video and text, in machine-readable form so it can be detected as AI-generated. Third, deployers using emotion recognition or biometric categorisation must inform the people exposed to it. Fourth, deployers publishing deepfakes must disclose that the content is artificially generated or manipulated, and AI-generated text published to inform the public on matters of public interest must be disclosed.

For a typical UK SME, the first two duties are the relevant ones. If you operate a customer-facing chatbot, it must disclose. If you publish AI-generated content that could be mistaken for authentic, it must be marked. Where you use third-party AI platforms, the marking duty generally sits with the platform provider, but you should confirm your vendor position in writing because your customers will ask.

How Does the Act Reach UK Companies With No EU Office?

Article 2(1)(c) applies the Act to providers and deployers established outside the EU where the output produced by their AI system is used in the EU. A UK company serving an AI-powered analytics feature to a customer in Germany is in scope, even though the company has no EU presence and the system runs entirely on UK infrastructure. Incidental access by someone who happens to be in the EU does not trigger scope, but where EU use is a real part of how your product is consumed, assume it applies.

There is also a contractual route. EU companies buying from UK suppliers need to understand the AI in their own supply chain to meet their own obligations, and they do this through procurement and security questionnaires. UK firms increasingly encounter the Act through these questionnaires before they ever encounter it through its legal scope.

What Are the Penalties?

Under Article 99, fines reach 35 million euros or 7% of worldwide annual turnover for prohibited practices, 15 million euros or 3% for most other breaches, including the transparency duties and deployer obligations, and 7.5 million euros or 1% for providing misleading information to authorities. The higher of the two figures applies, except that SMEs pay the lower figure. The fines are calculated on global turnover, not EU revenue, which is why the exposure is taken seriously by companies of all sizes.

What Should a UK SME Do Now?

Four practical steps cover the current obligations. One: inventory every AI tool in use, noting which ones touch EU customers or produce EU-bound output. Two: check every customer-facing AI touchpoint against Article 50, particularly chatbot disclosure and content marking. Three: ask your AI vendors for their EU AI Act compliance position and keep it on file. Four: prepare a short evidence summary so an EU procurement questionnaire can be answered in days rather than weeks. None of this requires enterprise budgets, and the high-risk obligations now arriving in December 2027 give UK firms a defined window to build documentation habits early.

To check your position in two minutes, use our free EU AI Act Readiness Checker. For the commercial view of what this means for UK SMEs selling into Europe, see our blog analysis of the EU AI Act coming into force. If you want help putting the governance in place, book a free discovery call or read about our AI governance service.

Frequently Asked Questions

Common questions about this topic, answered directly.

Does the EU AI Act apply to UK companies after Brexit? +

Yes, where there is an EU connection. The Act is extraterritorial under Article 2. It applies to UK companies that place AI systems on the EU market, operate through an EU establishment, or whose AI output is used in the EU. A UK company with no EU customers and no EU-bound output is outside its scope, but EU clients frequently pass AI Act requirements down through contracts and procurement questionnaires regardless.

What applied on 2 August 2026? +

The Article 50 transparency obligations became directly applicable: AI chatbots must inform users they are interacting with AI, synthetic content must be marked in machine-readable form, deepfakes must be labelled, and emotion recognition or biometric categorisation must be disclosed to the people exposed to it. The European Commission also gained enforcement powers over general-purpose AI providers, including fines up to 3% of global turnover or 15 million euros.

Was the EU AI Act delayed? +

Only partly. In June 2026 the European Parliament approved the Digital Omnibus amendments, which pushed the high-risk obligations out: standalone high-risk systems (Annex III) move from August 2026 to 2 December 2027, and AI embedded in regulated products (Annex I) moves to 2 August 2028. The transparency obligations and prohibited practices were not delayed and are live law now.

What are the fines for breaking the EU AI Act? +

Up to 35 million euros or 7% of global annual turnover for prohibited practices, up to 15 million euros or 3% for most other breaches including the transparency duties, and up to 7.5 million euros or 1% for supplying misleading information to authorities. Fines are calculated on worldwide turnover, not EU revenue only. For SMEs, the lower of the two figures applies.

Do I need an EU authorised representative? +

If you are a UK provider placing a high-risk AI system on the EU market, yes. Article 22 requires a written mandate with an authorised representative established in the EU before the system is made available there. The same applies to UK providers of general-purpose AI models under Article 54. Businesses whose AI is limited-risk (chatbots, generative content tools) do not need a representative.

How do I check if my business is ready? +

Start with an inventory of every AI tool in use and identify which ones reach EU customers or produce output used in the EU. Check chatbot disclosure and AI content labelling against Article 50. Ask your AI vendors for their compliance position. Our free EU AI Act readiness checker walks through this in ten questions and gives a prioritised action plan.

Written by ajairu. Our practical guides help UK SMEs assess AI opportunities, plan implementation, and measure results. Learn more about ajairu.

Want help appearing in AI search results?

We help UK businesses optimise for AI Overviews, ChatGPT citations, and generative search visibility. Book a free discovery call to see where you stand.