MICKAI®ArticlesDoes the EU AI Act apply to UK co…
Article · 21 July 2026

Does the EU AI Act apply to UK companies selling into the EU?

Yes. The Act is extraterritorial: UK providers placing AI on the EU market, or whose output is used in the EU, are in scope.

Author
Micky Irons
Published
21 July 2026
Follow Micky Irons
LinkedInX
sovereign aieu ai actregulated aiai readinessdata sovereignty

Yes. The EU AI Act is extraterritorial: it applies to providers placing AI systems on the EU market wherever they are established, and to providers and deployers located outside the EU where the output produced by the system is used in the EU. A UK company with EU clients is therefore in scope regardless of Brexit. Only firms serving the UK market alone sit outside the Act, and even they will feel it through the contracts of EU-facing clients.

The question matters in 2026 because the Act's obligations are arriving in stages, the high-risk timeline has moved, and UK boards are discovering that leaving the EU did not remove them from the reach of EU law that follows the output rather than the office.

What does the Act say about who it covers?

The territorial scope provisions are explicit. The Act covers providers placing AI systems or general-purpose AI models on the EU market, irrespective of where the provider is established; deployers located in the EU; and providers and deployers in third countries where the output produced by the AI system is used in the EU. That last limb is the one UK firms underestimate. A UK company running a model in London whose outputs are consumed by a client in Frankfurt is inside the Act's scope without ever placing a system on the EU market in the conventional sense.

Which deadlines are actually live in 2026?

The Act applies in stages. The prohibitions on unacceptable-risk practices have applied since 2 February 2025. Obligations for general-purpose AI models have applied since August 2025. The high-risk obligations under Annex III, originally due on 2 August 2026, were deferred by the Digital Omnibus to 2 December 2027, and high-risk AI embedded in products regulated under Annex I moved to 2 August 2028. Article 50 transparency obligations are largely unchanged. Any compliance plan still anchored to 2 August 2026 as the high-risk deadline is working from a superseded timeline.

Is the 2 August 2026 high-risk deadline still real?

No. The Digital Omnibus deferred the Annex III high-risk obligations to 2 December 2027, with Annex I embedded systems following on 2 August 2028. The obligations themselves did not shrink: risk management, data governance, logging, human oversight, accuracy and robustness all remain. Only the date moved. Firms that use the window to build evidence-generating architecture will meet December 2027 with proof in hand. Firms that treat it as extra runway will meet it with a gap analysis and a procurement scramble.

The deferral to December 2027 is a build window, not a reprieve.

What if we only sell in the UK?

A UK firm whose AI systems serve the UK market alone, with no EU clients and no output used in the EU, is outside the Act's scope. The practical caveat is contractual: EU-facing clients and partners will pass their own obligations down the supply chain, asking UK suppliers for the documentation, logging and transparency evidence they need for their own compliance. Scope in law and exposure in practice are different questions, and most UK firms of any size will encounter the second even if they escape the first.

What will EU clients demand in contracts?

The pattern is already visible in procurement. We see recurring demands for:

  • Technical documentation and instructions for use aligned to the Act's high-risk requirements.
  • Logging and record-keeping sufficient for the client's own oversight duties.
  • Evidence of data governance over training and input data.
  • Human oversight mechanisms the client can operate and demonstrate.
  • Cooperation clauses for regulator requests and incident investigation.

A UK supplier that can generate this evidence from its own infrastructure answers in days. One that must assemble it retrospectively answers slowly, and every slow answer weakens its position on the next tender.

How should UK firms use the window to December 2027?

Build the evidence layer first, because every high-risk obligation converges on proof. Mickai approaches this as an architecture question: a Sovereign Intelligence Operating System, a SIOS, runs offline on operator-owned hardware, records every action in an audit ledger signed under FIPS 204 (ML-DSA), binds each entry to hardware-attested identity, and keeps data inside a zero-egress inbound perimeter. Logging, traceability and human oversight then exist as properties of the system rather than documents about it. A firm that can show a sealed, verifiable record of what its AI did will be in a defensible position under any final enforcement practice; a firm relying on vendor attestations holds a promise, and a contractual promise is not a technical guarantee.

How the whole system fits together is set out at /sovereign-ai, and the film at /film shows the interface in operation.

Frequently asked questions

Does the EU AI Act apply to my UK company after Brexit?

Yes, if the company places AI systems on the EU market or the output of its systems is used in the EU. The Act's scope follows the market and the output, not the company's registered office. Brexit removed the UK from EU lawmaking, not from the reach of extraterritorial EU law.

Is the EU AI Act high-risk deadline still 2 August 2026?

No. The Digital Omnibus deferred the Annex III high-risk obligations to 2 December 2027, and high-risk AI embedded in products regulated under Annex I to 2 August 2028. The prohibitions have applied since 2 February 2025 and general-purpose AI obligations since August 2025. Article 50 transparency obligations are largely unchanged.

Which parts of the EU AI Act already apply in 2026?

The prohibitions on unacceptable-risk practices, applying since 2 February 2025, and the general-purpose AI model obligations, applying since August 2025. Transparency duties under Article 50 continue on their original path. The deferred elements are the high-risk obligations, now due on 2 December 2027 for Annex III and 2 August 2028 for Annex I embedded systems.

My company only sells in the UK, can we ignore the EU AI Act?

Legally, a UK-only firm with no EU market presence and no output used in the EU is outside scope. Commercially, EU-facing clients will pass their obligations down through contracts, so documentation, logging and transparency requests will still arrive. Building the evidence base once is far more efficient than answering each contract from scratch.

What should a UK provider do before December 2027?

Classify systems against the Act's risk categories, identify which sales or outputs touch the EU, and build the logging, data governance and human oversight evidence the high-risk obligations require. We recommend treating the deferral as a build window: architecture that generates verifiable records as it runs turns the December 2027 deadline into a formality rather than a scramble.

Subscribe
Get every new Mickai article by email.

Long-form essays on sovereign AI from Micky Irons. One email per article. No tracking, no marketing, no third parties. Every email includes a one-click unsubscribe link.

Prefer RSS? Subscribe at /articles/feed.xml.

Originally published at https://mickai.co.uk/articles/does-the-eu-ai-act-apply-to-uk-companies-selling-into-the-eu. If you operate in a regulated sector or want sovereign AI on your own hardware, the audit form on mickai.co.uk is the entry point.
More articles