The EU AI Act Explained for UK Businesses
The EU AI Act is the world's first comprehensive law on artificial intelligence, and it reaches well beyond the EU's borders. If your business builds, sells or uses AI systems whose output is relied on inside the European Union, the rules apply to you even though the UK has left the bloc. This guide explains what the EU AI Act is, how its risk tiers work, the timeline that matters, and the practical steps a UK business should take now.
What the EU AI Act is
The Act (Regulation 2024/1689) was published in the EU's Official Journal and entered into force on 1 August 2024. It sets harmonised rules for placing AI systems on the EU market and putting them into use, with obligations that scale according to the risk a system poses to health, safety and fundamental rights. It sits alongside existing EU law such as the GDPR rather than replacing it.
Crucially, it is extraterritorial. It applies not only to providers and deployers established in the EU, but also to those based outside the EU where the system's output is used within the Union. A UK software firm selling an AI recruitment tool to a German employer, or a UK bank using an AI model to score EU customers, is caught.
The four risk tiers
The Act classifies AI by risk, and your obligations follow from where a system sits.
- Unacceptable risk: a short list of banned practices, including social scoring by public authorities, untargeted scraping of facial images to build recognition databases, and certain manipulative or exploitative systems. These are prohibited outright.
- High risk: systems used in areas such as recruitment, credit scoring, education, essential services, medical devices and critical infrastructure. These are permitted but carry the heaviest duties: risk management, data governance, technical documentation, human oversight, transparency and conformity assessment.
- Limited risk: systems such as chatbots and generative tools that mainly trigger transparency duties. Users must be told they are interacting with AI, and synthetic or manipulated content should be labelled.
- Minimal risk: the vast majority of AI, from spam filters to recommendation engines, which face no new obligations under the Act.
The timeline UK businesses should watch
The Act applies in phases rather than all at once:
- 2 February 2025: the bans on unacceptable-risk systems took effect, along with AI literacy duties for staff who work with these tools.
- 2 August 2025: obligations for general-purpose AI (GPAI) models, such as large language models, began to apply, covering technical documentation, copyright policy and, for the most capable models, systemic-risk controls.
- 2 August 2026: the bulk of the high-risk system rules apply.
- 2 August 2027: the remaining high-risk rules for AI embedded in regulated products take effect.
Penalties are significant: up to 35 million euros or 7 percent of worldwide annual turnover for breaching the prohibitions, whichever is higher, with lower ceilings for other breaches.
How this sits with UK rules
The UK has taken a different route. Rather than a single AI statute, it has so far favoured a principles-based, pro-innovation approach that asks existing regulators to apply cross-cutting principles within their own remits, with legislation under discussion. That means a UK business can face two regimes at once: light-touch expectations at home and the full weight of the EU AI Act on anything it sells into or uses within the EU. Plan for the stricter of the two.
What to do now
- Build an inventory of every AI system you develop or use, and note where its outputs are relied on. Anything touching the EU needs closer attention.
- Classify each system against the risk tiers so you know which duties bite.
- Tighten documentation, data governance and human-oversight arrangements for anything high risk, and start now rather than close to the 2026 deadline.
- Add clear AI-use transparency to customer-facing tools, and train staff so they understand the systems they operate.
- Fold all of this into a wider governance framework rather than treating it as a one-off compliance task.
For the bigger picture on responsible AI, read our guide to AI ethics in business, and see the rest of the E-Business Ethics library for governance and compliance. The full legal text is available on the EU's EUR-Lex portal.
Frequently asked questions
Does the EU AI Act apply to UK businesses after Brexit?
Yes, where it has an EU nexus. The Act applies to providers and deployers outside the EU if their AI system is placed on the EU market or its output is used within the Union. A UK firm selling or operating AI that affects EU users is in scope.
When does the EU AI Act come into force?
It entered into force on 1 August 2024 and applies in stages: the bans from February 2025, general-purpose AI rules from August 2025, most high-risk rules from August 2026, and the final high-risk product rules from August 2027.
What counts as a high-risk AI system?
Systems used in areas such as recruitment, credit scoring, education, medical devices, critical infrastructure and essential services. They are allowed but must meet duties on risk management, data quality, documentation, human oversight and conformity assessment.
What are the penalties for breaching the EU AI Act?
Up to 35 million euros or 7 percent of worldwide annual turnover, whichever is higher, for using banned systems, with lower maximum fines for other breaches such as failing high-risk obligations or providing misleading information.
How is the UK's approach to AI different?
The UK has so far avoided a single AI law, instead asking existing regulators to apply shared principles within their sectors, with further legislation under discussion. UK businesses trading into the EU should plan around the stricter EU regime.