UK EU AI Act consultants
- Brexit did not remove the EU AI Act from UK companies. It applies where a system is placed on the EU market or its output is used in the EU.
- The UK has no AI Act and no AI bill before Parliament. Regulation runs through existing regulators and existing law.
- The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D, in force from 5 February 2026.
- UK companies frequently need both: EU AI Act duties for EU-facing systems, and UK regulator expectations for the same systems at home.
- Programme costs in the UK typically run £15,000 to £50,000, driven by system count.
Why a UK company ends up in scope
UK companies are caught by the EU AI Act more often than they expect. The Act applies to providers placing an AI system on the EU market wherever they are established, and to providers and deployers outside the EU where the output produced by the system is used in the EU. Neither test asks where the company is.
That second limb is the one that surprises people. A UK company with no EU entity, no EU office and no EU sales team can still be in scope if its system produces outputs used by people in the EU.
Selling software to EU customers. The most obvious route and the easiest to identify.
Selling to a UK or global customer whose own operations reach the EU, so your output is used there through them.
Employing or assessing people located in the EU using an AI system, which brings employment-related uses into view.
Providing a service where the output reaches EU consumers, even where the contract sits elsewhere.
Being named as the provider on a system you did not build. Putting your own brand on a third-party AI system, modifying it substantially, or using it for a purpose the original provider did not intend can make you the provider with the full set of duties attached.
What the UK requires separately
The UK has taken the opposite approach to Brussels. There is no UK AI Act, and no AI bill is before Parliament. Regulation runs through existing law applied by existing regulators.
| Layer | What it covers |
|---|---|
| UK GDPR and the Data (Use and Access) Act 2025 | Automated decision-making, replaced Article 22 with new Articles 22A to 22D in force from 5 February 2026, permitting solely automated decisions in more circumstances but only with documented safeguards: transparency, human review, and a right to contest |
| Sector regulators | The FCA for financial services, the MHRA for medical devices, Ofcom for online services, the CMA on competition, each applying its own rules to AI within its remit |
| The ICO | Anything touching personal data, including the transparency and human involvement expectations around automated decisions |
| Five cross-sector principles | Safety and robustness, transparency and explainability, fairness, accountability and governance, contestability and redress, applied by regulators rather than as binding statutory duties |
For a UK firm in a regulated sector, the practical rule is that your own regulator's AI expectations bind you sooner and more directly than any AI-specific statute will.
Doing both at once
Most UK companies with EU exposure end up running one governance programme that satisfies two sets of expectations, which is considerably cheaper than running two.
The overlap is substantial. Documented risk assessment, a record of what each system does and who owns it, human involvement in consequential decisions, transparency to the people affected, and evidence that the position is reviewed. Both regimes want those, described differently.
The differences that matter: the EU Act attaches specific documentation obligations per system with fixed dates, while the UK expects you to satisfy your own regulator on its own terms and timing. Building to the EU standard generally satisfies the UK expectation. The reverse is not reliably true.
Where the firm is regulated by the FCA, this is native ground for Buckingham Capital Consulting, the partner firm we work alongside on regulated engagements.
What a UK consultant should deliver
The same six workstreams as anywhere: inventory, classification, gap assessment, documentation, control build, monitoring. What a UK-based adviser should add is the second layer.
They should ask which UK regulator supervises you, and shape the evidence so it answers that regulator's questions as well as the EU file.
They should handle the Article 22A to 22D position on automated decisions alongside the AI Act classification, because for most UK companies the two land on the same systems.
They should be clear about which EU obligations bind you now. The Article 50 transparency duties took effect on 2 August 2026. Article 50(2) reaches systems already on the market on 2 December 2026, alongside the new prohibitions on AI generating non-consensual intimate imagery and child sexual abuse material. High-risk obligations arrive on 2 December 2027 for stand-alone Annex III systems and 2 August 2028 for AI embedded in regulated products.
Cost in sterling
| Component | Typical UK range |
|---|---|
| Inventory and classification | £5,000 to £15,000 |
| Gap assessment | £5,000 to £20,000 |
| Full readiness and build | £15,000 to £50,000 |
| Annex IV technical file, per high-risk system | £8,000 to £25,000 |
| Day rate | £700 to £1,600 |
Cost is driven by how many AI systems you have and how many are high risk, not by how many people you employ.
What to do next
Answer one question first: does any output from any of your AI systems reach people in the EU? If yes, you are likely in scope regardless of where your company sits, and the classification work should start now.
Our free AI impact assessment gives an immediate first view, and the EU AI Act service page sets out how we run the programme.
References
FAQ
Does the EU AI Act apply to UK companies?
Yes, where a system is placed on the EU market or its output is used in the EU. Company location is not the test.
Is there a UK AI Act?
No. There is no UK AI statute and no AI bill before Parliament. AI is regulated through existing law and existing sector regulators.
What changed for automated decisions in the UK?
The Data (Use and Access) Act 2025 replaced UK GDPR Article 22 with Articles 22A to 22D, in force from 5 February 2026, allowing solely automated decisions in more circumstances where documented safeguards are in place.
Do we need separate UK and EU programmes?
Usually not. One governance programme built to the EU standard generally satisfies UK regulator expectations as well, which is considerably cheaper than running two.
Which EU obligations bind us right now?
Prohibited practices, AI literacy, general purpose AI model duties, and the Article 50 transparency obligations since 2 August 2026.
About Hael
Hael is an advisory firm specialising in AI governance and security compliance, built on fifteen years of UK and EU regulatory practice. We take companies through the EU AI Act, ISO/IEC 42001, SOC 2 and ISO 27001, and maintain the position afterwards. On engagements involving regulated financial services firms we work alongside Buckingham Capital Consulting, the partner firm that has advised UK payment and e-money firms on FCA authorisation and compliance since 2013.
This guide is general information and is not legal advice on your particular circumstances.