The EU AI Act is now in force, and the assumption that it only affects European businesses is wrong. The implications of the EU AI Act for businesses are broader than most organisations have accounted for. If you sell to EU customers, operate through EU subsidiaries, or deploy AI tools that process data about EU residents, parts of this regulation already apply to you, regardless of where your company is headquartered.
Why Brexit Did Not Create a Clean Separation
The EU AI Act works on a market and effect basis, not a territorial one. If your AI system produces outputs that reach EU users, or if you supply AI-enabled products and services into the EU market, the Act has scope to capture you. This is the same logic the GDPR used, and UK businesses learned that lesson the hard way. The AI Act follows the same pattern.
The UK government is pursuing its own lighter-touch framework, outlined in the pro-innovation white paper on AI regulation. But a domestic policy choice does not exempt UK organisations from EU law when they operate across the border. The two regimes will coexist, and compliance with one does not guarantee compliance with the other.
What High-Risk AI Classification Means in Practice
The Act places AI systems into risk tiers. Most of the real obligations land on what it calls high-risk AI. This covers systems used in recruitment, credit decisions, insurance underwriting, access to education, and critical infrastructure management, among others. If you use AI to screen CVs, score customers for credit, or assess claims, you are almost certainly working with high-risk AI under the Act’s definition.
For high-risk systems, the obligations are significant. You need conformity assessments, technical documentation, human oversight mechanisms, and registration in an EU database. These are not minor administrative additions. They require deliberate design choices and, in many cases, changes to how AI tools have already been deployed.
EU AI Act UK Businesses: Where the Real Exposure Sits
The most common exposure points for UK businesses are threefold. First, any UK company with an EU subsidiary where AI tools are in use. The subsidiary is directly subject to the Act, and the parent organisation typically controls the tooling. Second, UK-based AI developers and vendors selling into the EU market. The Act places obligations on providers, not just deployers. Third, UK businesses that process personal data about EU residents using AI, where that processing has automated decision-making components.
Many organisations have not mapped which of their AI tools fall into which category. Without that mapping, it is impossible to know where obligations begin. This is not a theoretical gap. Regulators are already building enforcement capability. The high-risk category obligations are live, and enforcement capacity is growing alongside them.
What Needs to Change in Your Governance Programme
If the Act applies to you in any of the ways described above, the governance implications are concrete. You need to know which AI systems you are operating, what decisions they influence, and whether any fall into high-risk categories under the Act. That requires an inventory. Most organisations discover, when they actually look, that their AI usage is broader than leadership was aware of. Assessing your organisation’s AI governance maturity is usually the clearest way to identify how far current practice falls short of what structured compliance demands.
Beyond the inventory, you need documented accountability. The Act requires clarity on who is responsible for a given AI system, what oversight is in place, and how incidents get reported. These are governance questions, not technical ones. Your legal, compliance, and operations teams need to be part of this conversation, not waiting for IT to hand them a report.
Compliance and Governance Are Not the Same Thing
One mistake organisations make is treating the EU AI Act purely as a compliance exercise. Tick the required boxes, file the documentation, move on. But compliance is a snapshot. Governance is what keeps that snapshot accurate over time. AI tools get updated, use cases expand, and staff find new applications that nobody originally approved. A compliance posture that was accurate in January can be materially wrong by March.
Understanding the difference between AI governance and AI compliance matters here. Compliance tells you whether you meet the standard today. Governance is the mechanism that ensures you keep meeting it, and that you catch problems before they become regulatory events.
A Practical Starting Point for UK Organisations
The organisations that will handle this well are not necessarily the largest or most technically sophisticated. They are the ones that start with an honest inventory of what AI they are actually using, where it touches EU operations or customers, and what oversight currently exists. From that baseline, the gaps become manageable rather than overwhelming.
Most UK businesses with any EU exposure have at least some work to do here. The question is whether that work happens proactively, with time to address findings properly, or reactively, after a regulator asks a question you cannot answer.
If you are unsure where your EU AI Act obligations begin, the AI Governance Gap Assessment gives you a clear picture of what applies to your organisation and what needs to change.