Does the EU AI Act apply to the UK?

The answer depends on where your AI systems, users and outputs reach, rather than where your company is registered.

A UK organisation with no EU customers, no EU users and no AI system outputs used in the EU is not bound by the EU AI Act today. A UK organisation can still fall within scope when it provides an AI system in the EU, deploys one there, or produces output that is used there. That reach beyond the EU's borders is part of the Act's scope rules (Article 2).

This makes the first question practical: where does the system operate, and where do its results go? A UK registered office does not settle the point. You need to look at each AI system, the role your organisation plays and the route by which the system or its output reaches people or operations in the EU.

How can a UK organisation come within scope?

The Act applies to providers that place AI systems on the EU market or put them into service in the EU, wherever the provider is established. If a UK company develops an AI system and offers it to EU customers under its own name, its location outside the EU does not by itself remove that system from scope (Articles 2 and 3).

It also applies to deployers that are established or located in the EU. A group with a UK parent and an EU operation should therefore examine how the EU operation uses AI systems under its authority. The same organisation can hold more than one role, because the Act separately recognises providers, deployers, importers, distributors and product manufacturers (Articles 2 and 3).

The third route is the extraterritorial output rule. The Act applies where the output of an AI system is used in the EU, even if the organisation operating the system is elsewhere. For a UK team, that means the review should follow outputs into decisions, services and workflows, rather than stopping at the location of the server or supplier (Article 2).

What already applies if there is EU exposure?

Four sets of obligations are already in force. Prohibited AI practices have applied since 2 February 2025, including the specific practices listed in Article 5. The AI literacy duty has applied from the same date and requires providers and deployers to ensure that staff dealing with AI have a sufficient level of AI literacy (Articles 4 and 5).

General-purpose AI model obligations have applied since 2 August 2025 (Chapter V). Transparency obligations have applied since 2 August 2026, covering matters such as telling people when they interact with an AI system, machine-readable marking of synthetic outputs, notices for people exposed to emotion recognition or biometric categorisation, and disclosure of deepfakes (Article 50).

These dates matter because an organisation can have work to do now even when its system is not in a deferred high-risk category. Our guide to the transparency requirements in force now explains the Article 50 duties, while the AI literacy guide covers the live staff duty.

Which high-risk dates were deferred?

The omnibus changed the timetable for high-risk obligations. Duties for Annex III stand-alone high-risk systems are deferred to 2 December 2027 under Regulation (EU) 2026/1744. The listed areas include biometrics, critical infrastructure, education, employment and worker management, access to essential services, law enforcement, migration and border control, and the administration of justice and democratic processes.

Obligations for Annex I product-embedded high-risk AI are deferred to 2 August 2028. This category concerns AI used as a safety component of products covered by EU harmonisation law, including machinery, medical devices, toys, lifts, radio equipment and in-vitro diagnostics. These obligations are deferred, not cancelled, under Regulation (EU) 2026/1744. The post-omnibus timeline sets the live and deferred dates out together.

What if the Act does not bind us today?

A genuinely UK-only organisation can reach the honest conclusion that the Act does not bind it today (Article 2). That conclusion should be based on current customers, users and output destinations, and revisited if the organisation enters the EU or an AI output starts being used there.

UK-facing rules may still emerge domestically. Governance work done now can transfer to that future position, but it should not be presented as a current EU legal obligation where Article 2 does not place the organisation in scope. Keeping the legal conclusion separate from a voluntary governance choice gives a board a clearer basis for deciding what to do next.

Checked against Regulation (EU) 2024/1689 as amended by Regulation (EU) 2026/1744. Last reviewed 11 August 2026.