Since the UK left the European Union, a persistent myth has taken hold in British boardrooms: EU regulations are no longer our problem. For data protection, that myth was dispelled quickly — GDPR’s extraterritorial reach forced UK companies to comply regardless. The same pattern is now repeating with the EU AI Act.
The EU AI Act, which entered into force on 1 August 2024 and is rolling out obligations through 2027, does not stop at the Channel. Its extraterritorial scope means that thousands of UK businesses are already within its reach. Understanding exactly how, when, and why is no longer a nice-to-have — it is a compliance imperative.
À retenir
- The EU AI Act applies to UK businesses whose AI systems are placed on the EU market or whose AI outputs affect EU citizens
- Article 2 establishes extraterritorial jurisdiction — the provider's location is irrelevant if the EU market is affected
- The UK has no binding AI-specific legislation; its voluntary, sector-led approach leaves significant regulatory gaps
- Dual compliance with both the EU AI Act and UK sector regulators is the most pragmatic path for British firms
- Article 4 competency obligations have been in force since August 2025 — UK firms in scope should already be compliant
The extraterritorial scope: why Brexit does not shield you
The EU AI Act’s jurisdictional reach is defined in Article 2, and it is deliberately broad. The regulation applies to three categories of organisation, regardless of where they are established:
- Providers who place AI systems on the EU market or put them into service within the EU
- Deployers of AI systems who are located within the EU
- Providers and deployers located outside the EU, where the output produced by their AI system is used within the EU
That third category is the one that catches most UK businesses. You do not need to have an EU office, an EU subsidiary, or even a direct EU customer. If the output of your AI system — a recommendation, a classification, a generated document — ends up being used by someone in the EU, you are potentially in scope.
73%
of UK tech firms export digital services to EU member states, many involving AI-enabled products
Source : techUK Digital Economy Survey 2025
Consider some common scenarios for UK businesses:
- A London-based recruitment platform uses AI to screen CVs. A German employer subscribes to the service. The UK firm is a provider placing a high-risk AI system on the EU market.
- A Manchester fintech deploys an AI credit scoring model. It processes applications from customers across Europe. The AI output is used within the EU — the Act applies.
- A Scottish legal tech company offers AI contract analysis. A French law firm uses it. The output affects EU-based clients — the company is in scope.
- An employee at a UK consultancy uses an unsanctioned AI tool to draft reports for EU clients. Even this shadow AI usage can bring the organisation within the Act’s reach.
The principle mirrors GDPR, which UK businesses have been navigating since 2018. The difference is that the AI Act’s obligations go far beyond data protection — they cover system accuracy, transparency, human oversight, risk assessment, and workforce competency.
When the EU AI Act obligations apply: the timeline
The regulation’s phased implementation means different requirements activate at different points:
| Date | Obligation | UK impact |
|---|---|---|
| February 2025 | Prohibited AI practices banned (social scoring, manipulative AI, untargeted facial recognition) | UK firms selling these systems into the EU must stop |
| August 2025 | Article 4 competency obligations — all organisations must ensure adequate AI literacy | UK firms in scope need documented training programmes |
| August 2026 | High-risk AI system requirements (Annex III) and general-purpose AI transparency rules | UK providers of high-risk systems need conformity assessments |
| August 2027 | Full requirements for high-risk AI in EU-regulated products (Annex I) | UK firms in regulated sectors (medical devices, machinery) face the strictest obligations |
The Article 4 competency obligation is already in force. If your UK business serves EU clients using AI systems, your staff should already have documented AI literacy training proportionate to their roles. Non-compliance is not a future risk — it is a present one.
The UK approach compared: a regulatory gap
The UK government has deliberately chosen a different path from the EU. Rather than comprehensive AI legislation, DSIT published a framework in 2023 based on five voluntary principles — safety, transparency, fairness, accountability, and contestability — to be interpreted and enforced by existing sector regulators.
As of March 2026, the UK has passed no binding AI-specific legislation. The principles remain guidance. Enforcement depends entirely on which regulator oversees your sector:
- The FCA has issued the most detailed AI guidance, covering model governance, explainability, and consumer outcomes in financial services
- The ICO focuses on AI and data protection, particularly automated decision-making under UK GDPR Article 22
- The CMA has examined AI competition issues, particularly around foundation models
- Ofcom addresses AI in communications and media, including deepfakes and synthetic content
0
binding AI-specific laws enacted by the UK Parliament — the sector-led approach remains entirely voluntary
Source : DSIT AI Regulation Policy Paper, updated March 2026
This creates an asymmetry. UK businesses operating purely domestically face lighter, less prescriptive AI regulation. But those with EU exposure must meet the full force of the AI Act — while also satisfying their UK sector regulator. The result is not less regulation, but dual regulation.
For UK firms, the AI governance framework they build must therefore satisfy both environments. A solely UK-focused approach leaves them exposed on the EU side; a solely EU-focused approach may miss sector-specific UK requirements.
Building a dual compliance strategy: practical steps
1. Audit your EU exposure
Map every AI system your organisation develops, deploys, or uses. For each one, trace the output: does it reach an EU citizen, an EU-based client, or an EU-regulated process? If the answer is yes — even indirectly — the AI Act likely applies.
Do not overlook internal tools. An AI system used by your customer service team to handle queries from EU customers brings you within scope just as surely as a product sold directly into the EU market.
2. Classify your systems by risk tier
The AI Act uses a four-tier framework: unacceptable, high, limited, and minimal risk. Most enterprise AI falls into the limited or high-risk categories. High-risk systems include those used for:
- Recruitment, HR management, and worker evaluation
- Credit scoring and insurance underwriting
- Access to essential public and private services
- Education and vocational assessment
If your system falls into a high-risk category, you face the most demanding requirements: conformity assessments, risk management processes, technical documentation, data governance, human oversight mechanisms, and post-market monitoring.
3. Invest in AI competency training
Article 4’s competency obligation requires all organisations in scope to ensure their staff have “a sufficient level of AI literacy” proportionate to their role and the context of AI use. This is not optional and it is not satisfied by a single awareness session.
Effective compliance requires structured, role-specific AI training programmes with documented completion records that serve as evidence in regulatory inquiries. An AI readiness assessment is a practical first step to identify gaps.
4. Appoint an EU authorised representative
Article 22 of the AI Act requires providers established outside the EU to designate an authorised representative within the EU before placing their systems on the market. This representative serves as the regulatory point of contact and must have sufficient powers to cooperate with authorities.
For UK firms, this is a concrete post-Brexit compliance step that cannot be deferred.
5. Align governance with both frameworks
The most efficient approach is to build a single AI governance structure that satisfies both the EU AI Act and UK sector requirements. This means:
- An AI policy that addresses both EU risk classification and UK sector-specific guidance
- Training programmes covering EU Article 4 obligations and UK regulator expectations
- Documentation practices that serve EU conformity assessments and UK regulatory inquiries
- An ISO 42001-certified management system as a unified governance backbone
- Incident reporting processes aligned with the EU’s 72-hour serious incident notification requirement
Build your compliance programme to the higher EU standard, then layer on UK sector-specific elements. This approach is more efficient than maintaining two parallel governance systems, and it future-proofs you against potential UK legislation that may converge with the EU model — just as UK GDPR mirrored EU GDPR.
The cost of inaction
Fines under the EU AI Act are severe: up to 35 million euros or 7% of global annual turnover for prohibited AI practices, and up to 15 million euros or 3% of turnover for other violations, including failure to meet Article 4 competency requirements.
But fines are not the greatest risk. Non-compliant AI systems can be withdrawn from the EU market entirely. For UK businesses that depend on EU revenue — and that includes a significant proportion of the UK tech sector — losing market access could be existential.
The European AI Office has made clear that extraterritorial enforcement is a priority. It is coordinating with national authorities across all 27 member states, and the ICO has confirmed its willingness to cooperate on cross-border AI enforcement matters.
How Brain helps UK businesses achieve dual compliance
Brain is purpose-built for the AI competency challenge that sits at the heart of both EU and UK regulatory expectations. The platform delivers role-specific AI training modules, tracks competency across your organisation, and generates the documentation you need for compliance evidence.
For UK businesses navigating the dual regulatory landscape, Brain provides a single solution that covers EU Article 4 requirements, UK sector regulator guidance, and emerging AI governance standards — with training available in multiple languages for international teams.
Explore Brain’s plans to find the right approach for your organisation, or book a demo to see how AI competency training works in practice.
Related articles
EU AI Act and the UK: Does It Apply Post-Brexit? (2026)
Yes, the EU AI Act can apply to UK businesses post-Brexit. When it applies, what to do, and UK vs EU regulation compared.
AI for AML & KYC: Reduce False Positives by 70%+
How AI transforms AML and KYC — fewer false positives, better laundering detection and streamlined due diligence. Guide for compliance leaders.
AI Compliance Automation: Cut Costs + Reduce Risk
Automate regulatory compliance with AI — cut costs, reduce manual errors and lower risk. Tools, frameworks and implementation strategies.