TrustLayer
Book a demo
Guide

The EU AI Act for UK SMEs

What applies, what doesn't, and the one thing worth doing either way.

Yes, the UK left the EU. No, that doesn't make the EU AI Act someone else's problem. Like GDPR before it, the Act reaches any organisation whose AI touches the EU, and it has sharpened every insurer's and regulator's questions about AI, wherever you trade.

Does it apply to you?

Broadly: it applies if you put an AI system on the EU market, or if the output of an AI system you use is used in the EU. A UK business with EU customers, EU offices or EU-facing services should assume some of it applies. A UK business with none of those is outside its direct reach, but see below before relaxing.

What it actually does

The Act sorts AI by risk, not by brand. A handful of uses are banned outright (social scoring, some biometric surveillance). "High-risk" uses, recruitment screening, credit decisions, critical infrastructure, carry heavy obligations: risk management, documentation, human oversight. Most everyday business use of AI (drafting, summarising, coding assistants) lands in the minimal-risk tier, where the main duty is transparency, people should know when they're talking to a machine.

General-purpose AI models (the ChatGPT and Gemini tier) carry their own obligations, but those fall on the providers. OpenAI, Google, Anthropic, not on the businesses using them.

Key dates (updated for the July 2026 "Digital Omnibus", which pushed the high-risk deadlines back):

  • February 2025, bans on prohibited uses took effect
  • August 2025, obligations for general-purpose AI providers
  • August 2026, transparency obligations, people must be told when they're dealing with AI
  • December 2027, high-risk systems such as recruitment screening and credit decisions
  • August 2028, high-risk AI embedded in regulated products

The UK angle

The UK has no direct equivalent yet, the current approach leans on existing regulators rather than one AI law. But UK GDPR already covers personal data going into AI tools, and insurers and enterprise customers increasingly ask EU-AI-Act-shaped questions regardless of where you're based. The direction of travel is one-way.

The one thing worth doing either way

Every obligation in the Act starts from the same place: knowing what AI is in use. Most organisations don't. 60% of AI and SaaS apps in use are unsanctioned or outside IT's control (Zylo's 2026 SaaS Management Index), you can't be transparent about, or accountable for, tools you can't see.

An AI inventory is step one for the Act, for UK GDPR, and for the insurance form. AI Exposure builds one continuously: which tools, which people, which actions, with the evidence exportable when someone official asks.

This guide is general information, not legal advice. For decisions about your obligations, talk to your counsel.

Two minutes, ten questions

The AI risk check shows what you're exposed to. Nobody rings you.

Take the AI risk check →

An AI inventory,
by Friday.

See which AI tools are in use across your organisation, with the evidence ready for whoever asks next.

Book a demo
Live platform, your questions.
Book a demo
Take the AI risk check
Ten questions. Two minutes. Nobody rings you.
Start →