Every week, somewhere in a UK boardroom, someone says it: "We left the EU, so the AI Act doesn't apply to us."

It's a reasonable assumption. It's also wrong — and betting your compliance posture on it is a poor use of optimism. The EU AI Act doesn't care where your company is registered. It cares where your AI reaches. This article explains what that means in plain English, which UK businesses are caught, and what to do about it. (We work alongside your legal counsel — this is practical guidance, not legal advice.) For the full picture, see our guide to the EU AI Act for UK and Irish businesses.

Why Brexit doesn't exempt you

The AI Act was written with deliberately extraterritorial scope. Article 2 extends it beyond companies based in the EU. Three things pull a UK business into scope:

  • Placing AI on the EU market — offering an AI system (or a product containing one) to EU customers or users.
  • Output used in the EU — AI-generated results, decisions or content that are used inside the EU, even if the system itself runs from Reading or Manchester.
  • EU establishment or users — having staff, an office, or users in the EU who interact with your AI tools.

Notice what's missing: company domicile. The Act follows the market, not the paperwork. The same logic already applies to GDPR — plenty of UK firms comply with EU data protection law for exactly this reason. If you've written a privacy notice that mentions EU residents, you've already accepted this territorial model once. The AI Act borrows the same thinking and applies it to AI systems instead of personal data.

Concrete examples for UK businesses:

  • A British B2B SaaS firm whose AI features are used by customers in Germany and France.
  • A marketing team using AI to personalise a website for visitors from EU member states.
  • A London company with a salesperson in Paris who uses an AI copilot daily.

All three are in scope. None of them is registered in the EU.

One distinction worth knowing: the Act treats providers (those who develop or brand an AI system) differently from deployers (those who use it in their own operations). Most UK SMEs are deployers — you use Copilot, ChatGPT, or a vendor's AI features rather than building models. That's generally the lighter side of the obligation stack, but it's not zero: deployers owe duties around intended use, human oversight, data protection, and AI literacy. If you white-label an AI feature into your own product, you may become a provider for those purposes — with everything that follows.

Three tests: does the Act reach your business?

Run these against your own setup — honestly. Be generous with the word "user": contractors, trial accounts, and the Frankfurt office of your UK client all count. If any test returns a yes, the AI Act's obligations apply to you:

  • Test 1 — EU customers or users: do you sell to, or serve, people or companies in the EU? Include free users and trial accounts.
  • Test 2 — AI output entering the EU: does anything your AI produces — reports, scores, recommendations, content, decisions — get used in the EU market?
  • Test 3 — EU establishment or staff: does anyone in the EU use your AI tools on your behalf, as an employee, contractor or agent?

Test 3 is the one firms forget. A UK company with no EU sales can still be caught by a single remote hire in Amsterdam or an agency in Dublin running AI tools on its behalf. Footprint, not revenue, is what counts.

The question isn't "where are we registered?" It's "where does our AI land?" If the answer touches the EU, you have obligations.

If you're unsure how your AI use maps onto these tests, take the AI Act quiz — two minutes, six questions, and it flags the exposure patterns that matter.

What it means in practice for a UK SME

Being in scope doesn't mean catastrophe. It means four practical workstreams:

1. AI literacy (Article 4). Already in force since February 2025: providers and deployers must ensure staff have sufficient AI literacy for the tools they use. For most SMEs this is the cheapest obligation to meet — and the one most often ignored. A documented training baseline usually suffices.

2. Know what you run. You cannot classify what you haven't inventoried. Most businesses discover, during a first inventory, AI use they didn't know existed — browser extensions, CRM features, "shadow" ChatGPT use. Build the register before anything else.

3. Risk classification basics. The Act sorts AI uses into tiers: prohibited, high-risk, limited-risk (transparency duties), and minimal risk. Most everyday B2B tools — drafting, summarising, searching — sit in the minimal tier. But watch for uses that touch employment decisions, credit scoring, or biometric data: those can be high-risk, with heavier obligations around documentation, monitoring and human oversight.

4. Transparency duties. The limited-risk tier is easy to trip over without noticing. If customers interact with a chatbot, they must be told it's AI. AI-generated content that resembles real people, places or events needs labelling. If your marketing team publishes synthetic imagery or your support flow uses an AI agent, disclosure is part of compliance — not an optional courtesy.

You don't have to work this out alone, but you do need a legal view and a technical view working together. Our approach — AI Act Readiness — sits deliberately alongside your legal counsel: they interpret the regulation, we map your systems, data flows and obligations against it.

What the fines look like (briefly)

Penalties scale with the risk class of the system involved — the most serious breaches reach up to €35m or 7% of global turnover. That number gets the headlines, but it's the wrong thing to focus on. Enforcement typically begins with information requests, not fines. The realistic cost of ignoring the Act isn't a single penalty; it's scrambling to comply on a regulator's deadline, mid-contract, with a customer asking questions you can't answer. We cover the penalty structure in detail in our AI Act fines article.

What to do next

If you've read this far and recognised your own business in the examples, work the ladder — in this order. Nothing here requires panic, but the order matters: each step feeds the next, and skipping straight to a full diagnostic before you know your exposure is paying for detail you may not need.

  • Step 1 — Take the AI Act quiz (2 minutes). Six questions, instant read on your exposure patterns.
  • Step 2 — Exposure Assessment. A structured pass over your customer base, AI output and users to confirm which of the three tests you fail, and how badly.
  • Step 3 — AI Readiness Diagnostic. For firms that need the full map: every tool, every data flow, every obligation, prioritised. 2–3 weeks, fixed price.

A reasonable cadence: quiz this week, exposure assessment this month, diagnostic when you know you need the depth. Compliance work compounds — an inventory built now serves every future obligation, from customer due-diligence questions to procurement forms that increasingly ask about AI governance.

The myth that Brexit exempts UK businesses is convenient, widely repeated, and incorrect. The Act follows your market. Find out where you stand — start with the quiz.