Hael
Book a meeting
EU AI Act · United Kingdom

UK EU AI Act consultants

Hael · Published 7 August 2026 · Last reviewed 7 August 2026 · 9 min read
Key takeaways
  • Brexit did not remove the EU AI Act from UK companies. It applies where a system is placed on the EU market or its output is used in the EU.
  • The UK has no AI Act and no AI bill before Parliament. Regulation runs through existing regulators and existing law.
  • The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D, in force from 5 February 2026.
  • UK companies frequently need both: EU AI Act duties for EU-facing systems, and UK regulator expectations for the same systems at home.
  • Programme costs in the UK typically run £15,000 to £50,000, driven by system count.

Why a UK company ends up in scope

UK companies are caught by the EU AI Act more often than they expect. The Act applies to providers placing an AI system on the EU market wherever they are established, and to providers and deployers outside the EU where the output produced by the system is used in the EU. Neither test asks where the company is.

That second limb is the one that surprises people. A UK company with no EU entity, no EU office and no EU sales team can still be in scope if its system produces outputs used by people in the EU.

Selling software to EU customers. The most obvious route and the easiest to identify.

Selling to a UK or global customer whose own operations reach the EU, so your output is used there through them.

Employing or assessing people located in the EU using an AI system, which brings employment-related uses into view.

Providing a service where the output reaches EU consumers, even where the contract sits elsewhere.

Being named as the provider on a system you did not build. Putting your own brand on a third-party AI system, modifying it substantially, or using it for a purpose the original provider did not intend can make you the provider with the full set of duties attached.

What the UK requires separately

The UK has taken the opposite approach to Brussels. There is no UK AI Act, and no AI bill is before Parliament. Regulation runs through existing law applied by existing regulators.

LayerWhat it covers
UK GDPR and the Data (Use and Access) Act 2025Automated decision-making, replaced Article 22 with new Articles 22A to 22D in force from 5 February 2026, permitting solely automated decisions in more circumstances but only with documented safeguards: transparency, human review, and a right to contest
Sector regulatorsThe FCA for financial services, the MHRA for medical devices, Ofcom for online services, the CMA on competition, each applying its own rules to AI within its remit
The ICOAnything touching personal data, including the transparency and human involvement expectations around automated decisions
Five cross-sector principlesSafety and robustness, transparency and explainability, fairness, accountability and governance, contestability and redress, applied by regulators rather than as binding statutory duties

For a UK firm in a regulated sector, the practical rule is that your own regulator's AI expectations bind you sooner and more directly than any AI-specific statute will.

Doing both at once

Most UK companies with EU exposure end up running one governance programme that satisfies two sets of expectations, which is considerably cheaper than running two.

The overlap is substantial. Documented risk assessment, a record of what each system does and who owns it, human involvement in consequential decisions, transparency to the people affected, and evidence that the position is reviewed. Both regimes want those, described differently.

The differences that matter: the EU Act attaches specific documentation obligations per system with fixed dates, while the UK expects you to satisfy your own regulator on its own terms and timing. Building to the EU standard generally satisfies the UK expectation. The reverse is not reliably true.

Where the firm is regulated by the FCA, this is native ground for Buckingham Capital Consulting, the partner firm we work alongside on regulated engagements.

What a UK consultant should deliver

The same six workstreams as anywhere: inventory, classification, gap assessment, documentation, control build, monitoring. What a UK-based adviser should add is the second layer.

They should ask which UK regulator supervises you, and shape the evidence so it answers that regulator's questions as well as the EU file.

They should handle the Article 22A to 22D position on automated decisions alongside the AI Act classification, because for most UK companies the two land on the same systems.

They should be clear about which EU obligations bind you now. The Article 50 transparency duties took effect on 2 August 2026. Article 50(2) reaches systems already on the market on 2 December 2026, alongside the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material. High-risk obligations arrive on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products.

Cost in sterling

ComponentTypical UK range
Inventory and classification£5,000 to £15,000
Gap assessment£5,000 to £20,000
Full readiness and build£15,000 to £50,000
Annex IV technical file, per high-risk system£8,000 to £25,000
Day rate£700 to £1,600

Cost is driven by how many AI systems you have and how many are high risk, not by how many people you employ.

What to do next

Answer one question first: does any output from any of your AI systems reach people in the EU? If yes, you are likely in scope regardless of where your company sits, and the classification work should start now.

Our free AI impact assessment gives an immediate first view, and the EU AI Act service page sets out how we run the programme.

References

FAQ

Does the EU AI Act apply to UK companies?

Yes, where a system is placed on the EU market or its output is used in the EU. Company location is not the test.

Is there a UK AI Act?

No. There is no UK AI statute and no AI bill before Parliament. AI is regulated through existing law and existing sector regulators.

What changed for automated decisions in the UK?

The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D, in force from 5 February 2026, allowing solely automated decisions in more circumstances where documented safeguards are in place.

Do we need separate UK and EU programmes?

Usually not. One governance programme built to the EU standard generally satisfies UK regulator expectations as well, which is considerably cheaper than running two.

Which EU obligations bind us right now?

Prohibited practices, AI literacy, general purpose AI model duties, and the Article 50 transparency obligations since 2 August 2026.

About Hael

Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of UK and EU regulatory practice. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised UK payment and e-money firms on FCA authorisation and compliance since 2013.

This guide is general information and is not legal advice on your particular circumstances.

Free check

See where you stand on EU AI Act, free.

Answer a short set of questions and see what EU AI Act expects of your AI systems and where you stand today. No sign-up to see your result.

Applicability

Whether EU AI Act applies to how you use AI, and to which systems.

What is expected

Risk classification, governance, documentation and human oversight.

Where you stand

A banded result, pointed at the gaps that matter most.

What you get

On screen in about five minutes, pre-scoped to EU AI Act.

Or speak to us about your deadline. Book a meeting.