The EU AI Act is the world's first comprehensive AI law. If you run or lead a UK business that uses AI in any form, you need to understand it. The rules have extraterritorial reach, the same way GDPR did, and the penalties for non-compliance are severe.
The most common mistake we see from UK SMEs is assuming this law doesn't apply to them because they're not based in the EU. That assumption is wrong.
Does the EU AI Act Apply to Your Business?
The Act applies based on where your AI system is used or has an effect, not where your company is registered.
You are in scope if you:
Sell an AI-powered product or feature to customers in the EU
Operate AI systems (your own or third-party) that run within the EU
Produce AI-generated outputs that are used or displayed in the EU
That third point catches most UK businesses off guard. A marketing agency using generative AI to produce content for an Irish client. A recruiter using an AI screening tool to assess candidates based in Germany. A SaaS platform with EU subscribers. If your products, services, or their outputs touch the EU market, you need to assess your position.
The Four Risk Tiers
The Act classifies AI systems into four categories. Your obligations depend on which category your systems fall into.
Banned systems are prohibited entirely: social scoring, real-time biometric surveillance in public spaces, AI designed to manipulate behaviour. Most SMEs won't be building these, but you need to check that third-party tools you use don't fall into this category.
High-risk systems carry the most significant compliance burden. An AI system is high-risk if it is used in:
Recruitment and HR: CV screening, candidate ranking, performance evaluation
Credit and insurance: creditworthiness assessment, pricing decisions
Education: admissions, student evaluation
Access to essential services: benefits, eligibility decisions
If your business uses AI in any of these areas, you face real obligations: risk management processes, data governance, technical documentation, human oversight, and a conformity assessment before deployment.
Limited-risk systems require transparency. If you use a chatbot, users must be told they are not talking to a human. AI-generated content must be labelled.
Minimal-risk systems such as spam filters, recommendation engines, and inventory tools carry no mandatory obligations, though voluntary codes of conduct are encouraged.
What Are the Penalties?
Up to €35 million or 7% of global annual turnover for using banned systems
Up to €15 million or 3% of turnover for breaching high-risk obligations
Up to €7.5 million or 1.5% of turnover for providing false information to regulators
For most SMEs, a fine at even the lower end of these ranges would be existential. The question is not whether compliance is worth the effort. It is whether you can afford to ignore it.
Note: Since this article was first published, the EU AI Act Omnibus (in force July 2026) postponed the high-risk obligations above from their original 2 August 2026 start date. Stand-alone Annex III systems (recruitment, credit scoring, education, access to services) now apply from 2 December 2027, and AI embedded in regulated products (Annex I, e.g. medical devices, machinery) from 2 August 2028. The Article 50 transparency and Article 4 AI literacy duties are unaffected and remain due from 2 August 2026. The banned-system rules and penalty framework above are unchanged.
What You Should Do Now
1. Build an AI inventory
You cannot govern what you have not mapped. List every AI system your business uses, including tools you have built yourself and AI features embedded in third-party software such as your CRM, HR platform, or finance tools. Most SMEs are surprised how long the list is.
2. Classify your risk
For each system, assess which tier it falls into. Document your reasoning. If any system touches recruitment, credit, access to services, or education, treat it as potentially high-risk until you have assessed it properly.
3. Review your supplier contracts
The Act distinguishes between providers (who build AI systems) and deployers (who use them). Your contracts should be clear about which party carries which compliance responsibilities, particularly around data governance and incident disclosure.
4. Put governance in place
This is where most SMEs stall. Governance sounds large and expensive, but the baseline requirement is straightforward: know what AI you are using, who is responsible for it, what decisions it influences, and what your process is when something goes wrong. The AI Assured Essential certification provides a structured way to get there. It is designed for SMEs to complete without specialist expertise, mapped to the EU AI Act, NIST AI RMF, and ISO 42001, and gives you a defensible governance baseline and a credential you can point to.
5. Start documenting
If any of your systems are potentially high-risk, begin assembling technical documentation now. What data does it use? What decisions does it influence? What testing has been done? It is substantially easier to document as you go than to reconstruct it under regulatory pressure.
What About UK Regulation?
The UK is not replicating the EU AI Act. Instead, it is asking existing regulators, including the ICO and FCA, to develop AI rules within their domains. The AI Safety Institute focuses on frontier model risk, not SME compliance.
For now, the EU AI Act is the most concrete and demanding AI regulation affecting UK businesses. Compliance with it will satisfy most of what the UK's evolving approach is likely to require.
The Practical Case for Acting Now
The businesses that will struggle most when enforcement deadlines arrive are those with no visibility of their AI use and no governance in place. That is a fixable problem, but it takes longer than most people expect to fix, and enforcement is not waiting.
The case for getting ahead of this is not primarily legal. It is commercial. Customers, procurement teams, and regulators are beginning to ask questions about AI governance. Having a clear, documented answer, ideally a recognised certification, is increasingly a condition of doing business, not a differentiator.
AI Assured is a structured self-certification for SMEs actively using AI. You can complete the certification yourself using the guidance and templates provided. The certification is mapped to the EU AI Act, NIST AI RMF, and ISO 42001.
Essential Takeaways
The EU AI Act applies to UK businesses if their AI systems are used in the EU market, regardless of the company's location.
It uses a risk-based approach, with the strictest rules for 'high-risk' AI in areas like recruitment, credit scoring, and critical infrastructure.
Penalties for non-compliance are severe, reaching up to €35 million or 7% of global turnover, making it a board-level concern.
Following the EU AI Act Omnibus (July 2026), high-risk obligations are now due 2 December 2027 (stand-alone) and 2 August 2028 (embedded); transparency and AI literacy duties are unaffected and remain due from August 2026.
SMEs should start by creating an inventory of all AI systems they use (both built and bought) to assess their risk level.
Scope
AI Assured is a governance programme, not an accredited certification body. It does not issue ISO/IEC 42001 certificates or statutory sign-off for the EU AI Act, FCA, FDA, NYC LL144 or other regulatory regimes. Articles are general information, not legal or regulatory advice.
Frequently asked questions
When does the EU AI Act come into force?
The EU AI Act is being implemented in phases. The ban on unacceptable-risk AI systems applied from late 2024, and GPAI transparency rules from early 2025. Following the EU AI Act Omnibus (in force July 2026), high-risk system obligations were postponed to 2 December 2027 (stand-alone systems) and 2 August 2028 (systems embedded in regulated products). Article 50 transparency and Article 4 AI literacy duties are unaffected and remain due from 2 August 2026.
Is there a UK version of the AI Act?
No, the UK has not passed a single, comprehensive 'AI Act'. Instead, it is pursuing a 'pro-innovation' approach, where existing regulators (like the ICO and FCA) will govern AI within their specific sectors based on a set of cross-sectoral principles.
What is a 'high-risk' AI system?
A high-risk AI system is one used in specific contexts that pose significant risks to health, safety, or fundamental rights. This includes AI for recruitment, credit scoring, medical devices, and critical infrastructure management. These systems face the most stringent compliance obligations under the Act.
Does the AI Act apply if I only use a third-party AI tool?
Yes. Under the Act, you are considered a 'deployer'. While the 'provider' (the developer) has the primary compliance burden for high-risk AI, deployers also have duties, such as using the system according to its instructions and ensuring appropriate human oversight.
Are there exemptions for SMEs in the EU AI Act?
The Act includes measures to support SMEs, such as regulatory sandboxes for testing and clearer guidance. However, there are no broad exemptions from the core compliance obligations for high-risk AI. The rules apply based on risk, not company size.
What is the difference between a 'provider' and a 'deployer'?
A 'provider' is an entity that develops an AI system and places it on the market or puts it into service. A 'deployer' is an entity that uses an AI system under its own authority. An SME could be a provider, a deployer, or both, and has different obligations in each role.
Sources
Harmeen Birk, AI Governance Advisor
Harmeen Birk is an ex-Citi senior AI strategist and executive advisor with over 20 years of experience leading large-scale data and AI programs within global financial institutions. As an IAPP-trained Artificial Intelligence Governance Professional (AIGP) she specialises in bridging the gap between rigorous compliance and practical innovation. Her expertise focuses on establishing robust AI governance frameworks and responsible AI practices for mid-market companies, boards, and emerging tech vendors.
Credentials: AI Governance Advisors, Institutions & Financial Services | Ex-Citi | HBS | AIGP | CGI

