The EU's AI Act is now being enforced, and it reaches UK firms too. Here's what it is, the five risk levels explained simply, and the practical steps UK businesses should take.
If you run a UK business and use AI (or you're thinking about it), you've probably heard of the EU AI Act. You may also have assumed that, since Brexit, it's not your problem.
For some businesses that's true. For a lot of others it isn't. The rules on chatbots and AI-generated content became enforceable in August 2026, so now is a good time to work out where you stand.
This guide cuts through the legal jargon. No article numbers, no acronyms you need to look up. Just what the law says, whether it affects you, and what to do about it.
What is the EU AI Act?
It's the world's first comprehensive law on artificial intelligence. It became law in August 2024 and is being switched on in stages up to 2028.
The idea is simple: the more harm an AI system could do to people, the stricter the rules. An AI spam filter has no new rules. An AI that decides who gets a job or a mortgage has a lot.
"But we're in the UK. Why should I care?"
Since Brexit, UK businesses count as "outside the EU". The Act was written to cover outside businesses whenever their AI touches the EU market. You can be caught if:
- you sell an AI product or service to EU customers, or
- the results your AI produces are used by people or businesses in the EU, even if your servers and staff are all in the UK.
That second point is the one that surprises people. Say a UK firm uses an AI tool to shortlist job applicants and some of those applicants are in Ireland or the Netherlands. The Act may apply.
If you genuinely only deal with UK customers, the EU AI Act doesn't apply to you directly. The UK has taken a lighter-touch approach, which we cover below.
The five risk levels, explained simply
1. Banned: "You can't do this, full stop"
Some uses of AI are illegal in the EU because they're too harmful. These include:
- scoring people on their behaviour and treating them differently because of it
- AI that secretly manipulates people or takes advantage of vulnerable people
- using AI to monitor your staff's emotions at work
- building facial recognition databases by scraping photos from the internet
That third one is the one an ordinary business is most likely to stumble into, for example through "sentiment monitoring" software on sales calls or video meetings. Check what your tools actually do.
2. High risk: "You can, but with serious safeguards"
This is AI that makes big decisions about people's lives, or that sits inside products where a mistake could hurt someone. For example:
- sifting CVs or ranking job candidates
- credit checks and lending decisions
- pricing health or life insurance
- marking exams or deciding on school or university places
- AI inside medical devices, machinery or vehicles
If you build these systems, there's a lot of paperwork: risk management, detailed technical records, testing for bias, and a human who can always step in and override the AI.
If you use one (an AI recruitment platform, say), your job is lighter but still real. Use it as the supplier intends, keep a human in charge of the final decision, keep an eye on whether it's producing fair results, and keep its records.
The deadline for most high-risk AI has been pushed back to December 2027 and to August 2028 for AI built into physical products. It's worth starting conversations with your suppliers now.
3. Limited risk: "Be honest that it's AI"
The risk here is people being fooled. The rule is about transparency:
- if a customer is chatting to an AI, it must tell them it's an AI, not a person
- AI-generated images, video, audio and text should be labelled as AI-generated
These rules have applied since 2 August 2026. If you have a chatbot on your website that EU visitors use, or you publish AI-generated content aimed at EU audiences, this applies to you now.
4. Minimal risk: "Carry on"
Most everyday business AI sits here: spam filters, product recommendations, stock management, smart search, AI that helps you draft emails or proposals. There are no new legal requirements. Good practice is encouraged, but it's voluntary.
5. General-purpose AI: "This one's for the tech giants"
The big AI models that power tools like ChatGPT, Gemini and Claude have their own rules about documentation, copyright and safety testing. These duties fall on the companies that build the models, not on the businesses that use them. If you're a typical UK business using these tools, this tier mostly matters because it means your supplier should be able to tell you how their model was built and tested.
Maker or user? It makes a big difference
The Act treats the people who make AI very differently from the people who use it.
- Makers ("providers") build an AI system and or sell it under their own name. They carry most of the burden.
- Users ("deployers") use AI tools in their business. That's almost every UK SME.
If you're using off-the-shelf AI tools, most of the heavy lifting sits with your suppliers. Your job is to use the tools sensibly, be open with customers, and keep people in control of important decisions.
What about businesses that only trade in the UK?
The UK chose not to copy the EU. There's no single AI law and no AI regulator. Instead, existing regulators apply five common-sense principles within their own areas:
1. Safety: AI should work reliably and securely.
2. Transparency: people should know when AI is being used and roughly how it reaches decisions.
3. Fairness: AI mustn't discriminate. The Equality Act still applies.
4. Accountability: someone in the business is clearly responsible for it.
5. The right to challenge: people should be able to question an AI-driven decision and get it put right.
In practice that means the rules you already follow still apply when AI is involved: UK GDPR (especially around decisions made purely by computer), the Equality Act, consumer protection law and guidance from your sector regulator, whether that's the ICO, FCA, CMA or another body.
One more thing: even if you're UK-only, the EU's standards are quietly becoming the norm. Big software suppliers build to them, and larger clients are starting to ask their suppliers whether they use AI responsibly. Getting your house in order now is good business as well as good compliance.
Six practical steps for UK businesses
You don't need a compliance department to get started:
1. Make a list of every AI tool you use. Include the AI hidden inside other software: your CRM, recruitment platform, marketing tools, phone system. Most businesses are surprised how long the list is.
2. Ask where it reaches.Does any of it touch customers, clients, candidates or staff in the EU? If not, focus on UK rules. If so, keep going.
3. Check nothing is on the banned list. Pay particular attention to anything that monitors staff emotions or behaviour.
4. Put each tool into a risk level. For most businesses this will be mostly "minimal", with a chatbot or two in "limited". Look carefully at anything to do with hiring, lending or insurance.
5. Be upfront. Make sure your chatbots say they're AI. Label AI-generated images and video. It's the law for EU audiences and simple good manners everywhere else.
6. Make sure your team understands the AI they use. What it's good at, where it gets things wrong, and when a human needs to check its work. Keep a simple record that you've done it.
If you build and sell AI products into the EU, especially anything high-risk, the list is longer. You'll need an official EU-based representative, detailed technical documentation and ongoing monitoring. It's worth looking at ISO 42001 the international standard for managing AI responsibly, because it satisfies both UK and EU expectations at once.
What happens if you get it wrong?
The headline fines are eye-watering: up to €35 million or 7% of worldwide turnover for using banned AI. For small and medium-sized businesses the law caps fines at the lower of the two figures. That's a relief, but not a free pass.
For most UK SMEs the bigger, more immediate risk is commercial: losing an EU contract because you can't answer your client's questions about how you use AI.
The bottom line
For most UK founder-led businesses, the EU AI Act is not a reason to stop using AI It's a reason to use it deliberately: know what tools you're running, be honest with the people they affect, and keep a human in charge of the decisions that really matter.
That's exactly how we think AI should be used anyway. At Amplifyy we help UK founder-led service firms put AI to work so the business can grow without the founder becoming the bottleneck, with clear oversight built in from the start.
Want to know where your business stands? Book a conversation with us (https://amplifyy.uk) and we'll help you make sense of the AI you already use, and the AI you could be using.