dealrescueGuides › EU AI Act for UK vendors

Country guide

The EU AI Act for UK software vendors: what actually applies to you

UK vendors sit in a position no other market shares: data transfers from EU customers are easy — the UK holds a GDPR adequacy decision — yet the EU AI Act is not UK law, and the UK's own AI approach is guidance, not statute. That produces two opposite questionnaire mistakes: assuming the Act doesn't touch you, and assuming adequacy or "the UK framework" answers for it. The buyer's legal team is testing whether you can tell these apart.

Does the EU AI Act reach you?

Regulation (EU) 2024/1689 was never carried into UK law, so a UK vendor starts outside it — until one of Article 2(1)'s two extraterritorial triggers applies:

For most UK B2B SaaS selling into Europe, at least one fires. Both are unpacked with examples in the full non-EU vendor guide.

What you owe if it does

In scope does not mean the whole Regulation. Most B2B SaaS products are limited-risk systems outside Annex III, leaving the Article 50 transparency duties, applicable since 2 August 2026 — a date the Digital Omnibus did not postpone:

High-risk duties attach only to Annex III use cases and, after the Omnibus, apply from 2 December 2027. Article 50 fines reach up to €15,000,000 or 3% of worldwide turnover, whichever is higher (Art. 99(4)(g)); SMEs pay the lower of the two (Art. 99(6)). Unsure what lands on your product? The Article 50 checker takes two minutes.

What UK law adds (and what it doesn't)

Two genuinely helpful things — and one thing it doesn't do:

The questionnaire reality

Direct enforcement against a vendor with no EU establishment is not the near-term risk — the buyer's procurement process is. Your EU customers are in scope, so AI-CAIQ and SIG 2026 questionnaires push the question down to you — and for UK vendors it quietly tests exactly the distinction above. Answers that fail review: "the EU AI Act does not apply to UK companies" (ignores Art. 2), "we operate under the UK's AI framework" (doesn't answer the EU question), "we have adequacy" (transfers, not AI). An answer that survives scopes honestly via Art. 2(1)(a) or (c), classifies the system, names the Art. 50 duties with dates, and notes adequacy separately. If a questionnaire just landed, start with the first-24-hours playbook and the model answer to "Are you EU AI Act compliant?".

UK vendors and the EU AI Act: quick answers

Is the EU AI Act law in the UK?

No. It was never carried into UK law. A UK vendor is outside the Act unless Art. 2(1)(a) (EU market) or 2(1)(c) (output used in the Union) applies — for most UK SaaS selling into Europe, one does.

Does the UK's GDPR adequacy decision cover EU AI Act compliance?

No. Adequacy is a transfer matter. The AI Act applies through its own triggers regardless of how the data moves; conflating the two is a fast way to fail legal review.

Is there a UK equivalent act I comply with instead?

As of July 2026, no. The UK approach is pro-innovation guidance applied by existing regulators, not an equivalent statute. Where the triggers reach you, the Article 50 duties come from the EU Regulation itself.

Primary sources
  • Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 50, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
  • Digital Omnibus: European Parliament position 16 June 2026; Council adoption 29 June 2026 (consilium.europa.eu press releases)
  • European Commission — renewed UK adequacy decision under the GDPR, adopted 19 December 2025 (sunset 27 December 2031)
  • UK extension to the EU–US Data Privacy Framework ("UK–US Data Bridge"), in force 12 October 2023; certification list: dataprivacyframework.gov/list
  • Cloud Security Alliance — AI-CAIQ; Shared Assessments — SIG 2026 (AI domain)

A buyer just asked where you stand on the EU AI Act?

We draft every answer with this level of citation, in 48 hours, $490 flat — paid after delivery. Not sure yet? Send it anyway: the first 3 answers are free.

Send your questionnaire →