Short answer: Yes, in defined circumstances. The EU AI Act applies to businesses outside the EU where they place an AI system on the EU market, or where the output produced by their AI system is used within the EU. A UK consultancy using AI to produce work for EU clients is likely in scope. A UK business serving only UK customers with internal AI tools generally is not.
General information, not legal advice. Take advice on your specific position.
Trigger one: placing on the EU market. If you make an AI system or a product containing one available in the EU — selling software with AI features to EU customers, offering an AI-powered service into the EU — you're in scope as a provider, with the obligations that attach to whatever risk category it falls into.
Trigger two: output used in the EU. The broader and more commonly overlooked one. If you're a deployer of an AI system and the output it produces is used within the EU, the Act reaches you regardless of where you sit.
The practical implication: a Cardiff consultancy using AI to help produce analysis delivered to a client in Dublin is producing output used in the EU. That's the trigger.
If that's you, the EU AI Act isn't your concern. UK data protection law still is, wherever AI touches personal data.
For the great majority — deployers using off-the-shelf AI tools — the obligations are modest:
The high-risk regime — conformity assessments, technical files, notified bodies — only engages if you deploy AI in a listed high-risk domain such as recruitment decisions, credit scoring or education access. Its deadlines have also been pushed back into 2027 and 2028.
The UK has taken a sector-led approach rather than passing an equivalent horizontal AI statute. What binds UK businesses today:
For most UK SMEs, UK GDPR is the more immediate and more likely enforcement risk.
Rather than agonising over jurisdiction, build the register. List your AI tools, what they're used for, and whether any output reaches EU clients. That single document answers the scope question and forms the basis of every other obligation. Businesses that skip it end up either over-complying expensively or discovering a gap during a client's due diligence process.
If AI output forms part of what you deliver to them, likely yes as a deployer. The obligations at that level are proportionate — policy, training, transparency.
No. Extraterritorial reach was designed exactly to prevent that, in the same way UK GDPR reaches EU businesses serving UK data subjects.
Position has shifted several times. As of mid-2026 the approach remains sector regulators applying existing powers, with proposals under discussion. Watch for changes rather than assuming stability.
Not sure which side of the line you're on? Take our free AI compliance assessment.