What applies, what doesn't, and the one thing worth doing either way.
Yes, the UK left the EU. No, that doesn't make the EU AI Act someone else's problem. Like GDPR before it, the Act reaches any organisation whose AI touches the EU, and it has sharpened every insurer's and regulator's questions about AI, wherever you trade.
Broadly: it applies if you put an AI system on the EU market, or if the output of an AI system you use is used in the EU. A UK business with EU customers, EU offices or EU-facing services should assume some of it applies. A UK business with none of those is outside its direct reach, but see below before relaxing.
The Act sorts AI by risk, not by brand. A handful of uses are banned outright (social scoring, some biometric surveillance). "High-risk" uses, recruitment screening, credit decisions, critical infrastructure, carry heavy obligations: risk management, documentation, human oversight. Most everyday business use of AI (drafting, summarising, coding assistants) lands in the minimal-risk tier, where the main duty is transparency, people should know when they're talking to a machine.
General-purpose AI models (the ChatGPT and Gemini tier) carry their own obligations, but those fall on the providers. OpenAI, Google, Anthropic, not on the businesses using them.
Key dates (updated for the July 2026 "Digital Omnibus", which pushed the high-risk deadlines back):
The UK has no direct equivalent yet, the current approach leans on existing regulators rather than one AI law. But UK GDPR already covers personal data going into AI tools, and insurers and enterprise customers increasingly ask EU-AI-Act-shaped questions regardless of where you're based. The direction of travel is one-way.
Every obligation in the Act starts from the same place: knowing what AI is in use. Most organisations don't. 60% of AI and SaaS apps in use are unsanctioned or outside IT's control (Zylo's 2026 SaaS Management Index), you can't be transparent about, or accountable for, tools you can't see.
An AI inventory is step one for the Act, for UK GDPR, and for the insurance form. AI Exposure builds one continuously: which tools, which people, which actions, with the evidence exportable when someone official asks.
This guide is general information, not legal advice. For decisions about your obligations, talk to your counsel.
The AI risk check shows what you're exposed to. Nobody rings you.
Take the AI risk check →We use cookies to see how the site is used, and what you read before getting in touch. Privacy policy