All posts
Modern Growth
Blog10 min read

Does the EU AI Act apply to your UK business?

Article 2 reaches UK companies with no EU entity at all. Deployer vs provider, what Article 50 actually requires, and what the July 2026 Digital Omnibus changed.

Modern GrowthPublished

Most people arrive at this question sideways. A client's procurement form asks whether your AI systems are AI Act compliant, or somebody on LinkedIn posts a screenshot of a €35m fine, and you go looking for the answer at half past ten on a Tuesday night.

The honest version is that the Act probably touches you, that what it asks of a small B2B firm is much shorter than the internet suggests, and that a fair amount of what you'll read about it describes a version of the law that changed in July 2026.

We're a growth consultancy, not a law firm. Nothing here is legal advice. It's written to help you work out whether you need to pay for some.

The short answer

If your business has EU customers, EU-based staff, EU prospects sitting in an outbound sequence, or an EU visitor who can open a chat widget on your website, you are probably in scope of Regulation (EU) 2024/1689. No EU entity is required. No office in Dublin, no VAT number, nothing.

What that scope means in practice, for a firm under about fifty people running ordinary commercial software, is a handful of transparency duties and a requirement to help your staff understand the tools you've given them. It is not the certification-and-conformity machinery you may have read about. That machinery is aimed at high-risk systems, which is a defined category, and a website chatbot is not in it.

Why Brexit doesn't settle this

Article 2(1) sets the territorial scope, and point (c) is the one that catches UK companies. It applies the Regulation to:

providers and deployers of AI systems that have their place of establishment or are located in a third country, where the output produced by the AI system is used in the Union

Read that twice, because the trigger is where the output lands, not where you are or where your server is. A UK consultancy running an AI tool that drafts personalised outbound emails, sent to a list that includes forty prospects in Amsterdam and Munich, is producing output used in the Union. The people receiving it are also "affected persons located within the Union" under Article 2(1)(g).

There's no de minimis threshold written into that test. Whether it bites on a handful of EU contacts is exactly the sort of question a qualified adviser should answer for your specific setup, and it's the first thing we'd send to one if you sell into Europe at all. What you shouldn't do is assume the answer is no because you left the single market.

Article 2(1)(c): the territorial test is where the output lands, not where you are A UK business with no EU entity, no EU office and no EU VAT number runs an AI tool. Its output — personalised emails — reaches recipients located in the Union. Under Article 2(1)(c) of Regulation (EU) 2024/1689 that puts the business in scope. Where the company is established and where its server sits are not the test. Article 2(1)(c) Where the output lands Not where you are. Not where your server is. You UK business, no EU entity No office in Dublin, no EU VAT number, server in London. Output personalised emails, a chat widget, generated copy Used in the Union 40 prospects in Amsterdam and Munich “affected persons located within the Union”, Art. 2(1)(g) In scope of Regulation (EU) 2024/1689 No EU entity required. No de minimis threshold in the test.
Article 2(1)(c) reaches providers and deployers established in a third country where the output produced by the AI system is used in the Union. No EU entity is required for that to bite. There is no de minimis threshold written into the test, which is exactly the question worth paying an adviser to answer for your setup.Regulation (EU) 2024/1689, Article 2(1)(c) and 2(1)(g). Not legal advice.

The dates that matter

Date What applied Status
1 Aug 2024 Regulation (EU) 2024/1689 entered into force Done
2 Feb 2025 Prohibited practices (Article 5), AI literacy duty (Article 4) In effect
2 Aug 2025 General-purpose AI model rules, governance, penalties In effect
2 Aug 2026 Transparency obligations (Article 50), general applicability In effect
2 Dec 2026 Grace period ends for machine-readable marking of generative systems already on the market before 2 Aug 2026 Coming
2 Dec 2027 Standalone high-risk systems (Annex III) Deferred
2 Aug 2028 High-risk AI embedded in regulated products (Annex I) Deferred

The last two rows moved. Both sets of high-risk obligations were originally due on 2 August 2026. They were pushed back by the Digital Omnibus on AI, Regulation (EU) 2026/1744, which was published in the Official Journal on 24 July 2026 and entered into force on 27 July 2026. Standalone high-risk systems listed in Annex III now have until 2 December 2027; AI built into products already covered by EU product safety law has until 2 August 2028.

Anything you read that was written before the summer will describe 2 August 2026 as the high-risk deadline. It was, and then it wasn't. Check the date on the article before you act on it.

AI Act timeline, showing which two deadlines the July 2026 Digital Omnibus moved In force 1 August 2024. Prohibited practices and the AI literacy duty applied from 2 February 2025. General-purpose AI model rules, governance and penalties from 2 August 2025. Article 50 transparency obligations and general applicability from 2 August 2026, which is the row that applies now. A grace period for machine-readable marking of generative systems already on the market runs to 2 December 2026. Standalone high-risk systems under Annex III and high-risk AI embedded in regulated products under Annex I were both originally due on 2 August 2026; the Digital Omnibus on AI, Regulation (EU) 2026/1744, moved them to 2 December 2027 and 2 August 2028. Regulation (EU) 2024/1689 Two dates moved Everything down to 2 August 2026 is already live. 1 Aug 2024 Entered into force Done 2 Feb 2025 Art. 5 prohibitions · Art. 4 AI literacy In effect 2 Aug 2025 GPAI models, governance, penalties In effect 2 Aug 2026 Art. 50 transparency · applicability In effect now 2 Dec 2026 Grace ends: machine-readable marking Coming Both were originally 2 August 2026. Moved by the Digital Omnibus, 27 July 2026. 2 Dec 2027 Annex III high-risk, standalone Deferred 2 Aug 2028 Annex I high-risk, inside products Deferred
Everything down to 2 August 2026 is live. The last two rows are the ones that moved: both sets of high-risk obligations were originally due on 2 August 2026 and were pushed back by the Digital Omnibus. Anything written before the summer of 2026 will describe the old dates.Regulation (EU) 2024/1689; Regulation (EU) 2026/1744, published 24 July 2026, in force 27 July 2026. Not legal advice.

Deployer vs provider: which one are you?

The Act splits duties between the person who builds and markets an AI system and the person who uses one. Most of the weight sits on the provider.

  • A provider develops an AI system, or has one developed, and places it on the market or puts it into service under its own name or trademark.
  • A deployer uses an AI system under its own authority, in the course of its own business.

Buy Intercom, switch on the AI agent, put it on your site: you're a deployer. Take a white-label conversational AI product, brand it as YourFirm Assist, and sell it on to your own clients as part of a retainer: you may have become a provider, with a materially heavier set of obligations, including the design duties in Article 50(1) and (2).

That second scenario is more common than it sounds among agencies and consultancies, because putting your name on somebody else's model is the standard way of packaging AI as a service right now. If any part of your offer involves reselling or rebranding an AI tool, get this classified properly rather than assuming you're on the light side of the line.

What Article 50 actually asks for

Article 50 has applied since 2 August 2026 and it's the part most small businesses are exposed to. Four obligations, and they don't all land on the same party:

Provision Applies to What it requires
50(1) Provider An AI system that interacts directly with people must be designed so those people are informed they're dealing with an AI system, unless that's obvious to a reasonably well-informed, observant and circumspect person
50(2) Provider Outputs of generative systems, including synthetic audio, image, video and text, marked in a machine-readable format and detectable as artificially generated
50(3) Deployer People exposed to emotion recognition or biometric categorisation must be told the system is operating
50(4) Deployer Disclose deep fakes, and disclose AI-generated text published to inform the public on matters of public interest

Two things worth pulling out of that table.

The first is the "unless this is obvious" carve-out in 50(1). It is not a loophole you can argue your way into after the fact. A widget in the corner of your site called Ava, which opens with "hi, what brings you here today", is not obviously software to a normal buyer, which is the entire reason it was named Ava. A line at the top of the chat costs you nothing and settles it.

The second is the editorial exemption in 50(4). The text disclosure duty is aimed at AI-generated text published to inform the public on matters of public interest, and it does not apply where the text has gone through human review and a person or company holds editorial responsibility for it. Your blog post, drafted by a model and edited by you before it went out, is not what that provision is chasing. If you publish machine-generated commentary on public affairs with nobody reading it first, it is.

Note also the four-month grace running to 2 December 2026, which covers only the machine-readable marking requirement, and only for generative systems that were already on the market before 2 August 2026. It is not a general extension.

The AI literacy duty got easier in July

This one is worth knowing because almost nothing written about it is current.

Article 4 has applied since February 2025. The original wording required providers and deployers to "ensure, to their best extent, a sufficient level of AI literacy" among staff and anybody operating the systems on their behalf. That is an obligation of result: you had to reach a level.

The Digital Omnibus rewrote it, with effect from 27 July 2026. Providers and deployers now "take measures to support the development of AI literacy", and the amended article says explicitly that this does not require anyone to guarantee any specific level of AI literacy of any individual. It became an obligation of effort.

It did not disappear. Every deployer still owes it, which includes you if there is a single AI tool in the business that a member of staff touches. What changed is that a documented hour of training plus a one-page policy on what may and may not be pasted into a model is now much closer to the shape of what the law asks for. Date it, minute it, keep it. For a team of eight, that is proportionate.

An AI Act compliance checklist for a small business

Skip the frameworks. Open a blank page and write down every AI system in the business that touches a person outside your company. Most founder-led firms find somewhere between four and nine, and are surprised by at least two of them, because the notetaker and the CV screener were bought by different people in different years.

For each one, three columns: what it is, whether you're the provider or the deployer, and whether the person on the other end is told it's software.

The list usually looks something like this.

System Typical role What it likely owes
Website chat widget Deployer Disclosure that it's an AI system
AI phone answering Deployer Disclosure in the greeting
Outbound sequencing tool that drafts and sends replies Deployer Disclosure once it holds a conversation
Meeting notetaker on client calls Deployer Consent and notice, mostly a GDPR question rather than an Article 50 one
Copy and image generation for marketing Deployer Little under 50(4) if a human edits and owns it
CV screening or applicant scoring Deployer, possibly high-risk Check this one properly; Annex III covers employment
A white-labelled AI product you resell Possibly provider Get advice before your next renewal

The row that catches people is the last one. The row that catches people legally is the one above it, because recruitment sits inside Annex III, and although the high-risk obligations are deferred to December 2027, deferred is not cancelled.

Then ask your vendors for their paperwork. Every AI tool you pay for should be able to tell you what it does, what it does with your data and how it addresses the Act. A supplier who can't answer that in the autumn of 2026 has told you something useful about the supplier.

What the fines actually are

Article 99 sets three tiers, and each is the higher of a fixed sum or a percentage of worldwide annual turnover:

  • Prohibited practices under Article 5: up to €35m or 7%
  • Most other operator obligations, including Article 50: up to €15m or 3%
  • Supplying incorrect or misleading information to authorities: up to €7.5m or 1%

The headline numbers on LinkedIn stop there, and they're the reason a lot of small businesses have quietly panicked about this. The next paragraph is the one that rarely gets screenshotted: for SMEs, including start-ups, each of those fines is capped at whichever of the percentage or the fixed amount is lower, not higher. Member states are also directed to take the economic viability of small companies into account when they set a penalty.

That is not permission to ignore the Act. It's context for deciding how much of your autumn to spend on it.

What you probably don't need to worry about

If you're a founder-led business with a chat widget, an outreach tool, a transcription service and something that helps write your copy, you are almost certainly a deployer of limited-risk systems rather than a provider of high-risk ones. The conformity assessments, the technical documentation, the registration in the EU database: none of that is pointed at you. Transparency is, and that's a much shorter list, and most of it is a sentence of copy in three places.

The letter version of this argument went out to our list on 6 August 2026, four days after the transparency rules started to apply, and it's in the archive if you want the ten-minute read rather than this one.

There's a commercial point hiding underneath the legal one, which is the reason we wrote about it at all. The disclosure question and the conversion question have the same answer. A buyer who works out on their own that they've been talking to software feels tricked and leaves; a buyer told up front feels nothing at all and carries on. We've written separately about why a high-intent lead should never be handed to your AI, and the compliant version of a chat widget is also the version that converts better.

Again: not legal advice. Dates and obligations here were checked against Regulation (EU) 2024/1689 and Regulation (EU) 2026/1744 as at 31 August 2026, and this page carries an updated date for a reason. If you're white-labelling AI, screening applicants with it, or selling into the EU at volume, pay a lawyer. It's cheaper than the alternative and it's a smaller bill than you think.

If you'd like a second pair of eyes on what your AI stack is doing to your leads, commercially rather than legally, there's a 30-minute call at links.moderngrowth.partners/book. No deck. Bring the list of nine things.

Sources

One letter a week

The same thinking, in your inbox on a Thursday. Nothing else.

Unsubscribe in one click.

All posts · The newsletter archive · Book a 30-minute call