Does the EU AI Act apply to UK companies?
A UK AI vendor pitching into the European market, or a UK SaaS company that quietly bolted an AI feature onto a product already sold to clients in Germany and the Netherlands, tends to ask the same question once someone finally raises it: does the EU AI Act even apply to us? We're not an EU company. The instinct is reasonable and, on its own, wrong. Where your AI system's output ends up matters more than where your company is registered, and that's the part most UK teams haven't priced in yet.
What's actually in force in the UK right now: not much, on paper
It's worth being precise here, because it's easy to overstate. The UK currently has no binding AI-specific statute of its own. The Department for Science, Innovation and Technology (DSIT) published its "Blueprint for AI regulation" in October 2025, setting out pro-innovation principles, things like safety, transparency, fairness, and accountability, for regulators to apply within their existing sectoral remits. Those principles are guidance, not law: there is no standalone UK AI Act, no UK equivalent of Annex III high-risk categories, and no UK body currently empowered to fine a company for an AI-specific breach the way the ICO can fine for a data protection breach. A statutory code from the ICO covering AI and automated decision-making is expected by around August 2027, but it doesn't exist yet, and treating it as though it were already in force would be a genuine mistake, not a rounding error.
That light-touch domestic position is a deliberate policy choice, not an oversight, and it's been the UK's stated approach for several years now: regulate AI through existing sectoral regulators and general law, rather than a single cross-cutting statute on the EU model. Whatever the merits of that approach, it means a UK company checking "are we AI Act compliant" against UK law alone will, correctly, find very little to comply with. The mistake is stopping there.
Why the EU AI Act reaches you anyway
The EU AI Act, formally Regulation (EU) 2024/1689, sets its own scope in Article 2, and that scope explicitly extends beyond companies established in the EU. Article 2(1)(c) is the provision that catches UK companies: the Act applies to providers and deployers of AI systems located outside the EU where the output produced by the AI system is used in the EU. That's an output-based test, not an establishment-based one. It doesn't ask whether you have an EU office, an EU subsidiary, or an EU-registered entity. It asks whether what your AI system produces, a score, a recommendation, a generated document, a decision, ends up being used by someone in the EU. The Act's Article 2 also separately catches a UK provider that places an AI system on the EU market or puts it into service there, even before anyone gets to the output question.
For a UK AI vendor, that means clients using your model's output to make hiring, credit, or eligibility decisions in the EU can bring you inside scope even if you never opened an EU office or signed an EU-specific contract. For a UK SaaS company with an AI feature, the same logic applies if EU-based users are the ones acting on what that feature generates. The UK's own light-touch stance on AI doesn't insulate you from this. The EU AI Act doesn't care what the UK has or hasn't legislated domestically; it cares where the output lands.
What it costs to get this wrong
The EU AI Act's fine structure, under Article 99, is tiered by severity. Prohibited practices, the short list of banned uses such as certain social-scoring or manipulative systems, carry fines of up to €35 million or 7% of global annual turnover, whichever is higher. Most other breaches, including failures tied to high-risk system obligations, top out at €15 million or 3% of global turnover. Article 99(6) provides for proportionately lower caps for SMEs and startups, which matters for a lot of UK AI vendors reading this, but it reduces the ceiling, it doesn't remove the underlying obligation or the fact that a UK company with no EU establishment can still be pursued for it.
Who this actually affects
Two UK profiles are worth a closer look. First, UK AI vendors and model providers whose customers or downstream users are in the EU, where the question isn't "do we sell into the EU" but "is our output used by someone in the EU", a test that can be met through a single EU-based customer's usage pattern rather than a formal market entry. Second, UK SaaS and tech companies who didn't set out to be AI companies at all, but who've had AI features added to an existing product that already has EU users, where the AI Act question sits quietly inside a product that was already assessed for GDPR years ago and never revisited for this.
What to check in your own business
- Does any AI system you build or use produce output, a score, a decision, a recommendation, a generated document, that's used by someone based in the EU, regardless of whether you have an EU office?
- Have you separately checked whether you're placing an AI system on the EU market or putting it into service there, which is a distinct trigger from the output-based test?
- If your product falls into an Annex III high-risk category, such as employment screening or creditworthiness assessment, does that hold true for your EU-facing use case specifically, not just your UK use case?
- Are you treating DSIT's pro-innovation principles as if they were binding law, when they're currently guidance rather than a statute?
- Do you know who in your business is tracking the EU AI Act's staged obligations timeline, separate from whoever tracks UK regulatory developments?
- If a client procurement questionnaire asked for your EU AI Act risk classification tomorrow, could you answer it, or would you be starting from a blank page?
General information, not legal advice: the boundary between UK guidance and EU AI Act obligations depends on the specific facts of what your AI system does and who uses its output, which this article can't resolve for your particular business. Where Komplya publishes guidance like this, we're clear about which layers have been legally reviewed and which remain draft material, so you can weigh it accordingly.
Rather than trying to read Regulation (EU) 2024/1689 cold against a UK business that was never built with it in mind, the more useful step is to walk through your actual AI systems and where their output ends up. Answer a short questionnaire on how your business builds or uses AI and get a plain-language read on whether the EU AI Act applies to you, and if so, where.