The EU AI Act for UK software vendors: what actually applies to you
UK vendors sit in a position no other market shares: data transfers from EU customers are easy — the UK holds a GDPR adequacy decision — yet the EU AI Act is not UK law, and the UK's own AI approach is guidance, not statute. That produces two opposite questionnaire mistakes: assuming the Act doesn't touch you, and assuming adequacy or "the UK framework" answers for it. The buyer's legal team is testing whether you can tell these apart.
Does the EU AI Act reach you?
Regulation (EU) 2024/1689 was never carried into UK law, so a UK vendor starts outside it — until one of Article 2(1)'s two extraterritorial triggers applies:
- Art. 2(1)(a) — the market trigger. Providers placing AI systems on the market or putting them into service in the Union are in scope irrespective of establishment in a third country — which, since Brexit, is what the UK is. A London SaaS with a paying customer in Dublin or Amsterdam is on the EU market as provider.
- Art. 2(1)(c) — the output trigger. Providers and deployers established in a third country are in scope where the output produced by the AI system is used in the Union. Selling only to UK enterprises does not keep you out if their EU branches consume your AI's reports, scores or content.
For most UK B2B SaaS selling into Europe, at least one fires. Both are unpacked with examples in the full non-EU vendor guide.
What you owe if it does
In scope does not mean the whole Regulation. Most B2B SaaS products are limited-risk systems outside Annex III, leaving the Article 50 transparency duties, applicable since 2 August 2026 — a date the Digital Omnibus did not postpone:
- Art. 50(1) — AI that interacts directly with people must disclose it is a machine. Mind the rebranding rule: whoever ships the system under their own brand, or substantially modifies it, is the provider: a UK vendor wrapping GPT or Claude under its own brand owns this duty, not its model supplier.
- Art. 50(2) — synthetic audio, image, video or text must carry machine-readable marking; systems already on the market have until 2 December 2026.
High-risk duties attach only to Annex III use cases and, after the Omnibus, apply from 2 December 2027. Article 50 fines reach up to €15,000,000 or 3% of worldwide turnover, whichever is higher (Art. 99(4)(g)); SMEs pay the lower of the two (Art. 99(6)). Unsure what lands on your product? The Article 50 checker takes two minutes.
What UK law adds (and what it doesn't)
Two genuinely helpful things — and one thing it doesn't do:
- Transfers into the UK are easy. The UK holds a European Commission adequacy decision under the GDPR — renewed on 19 December 2025 after the 2021 decision's sunset, now running to 27 December 2031 unless revisited — in force as of this guide's last update (28 July 2026): personal data flows from EU customers to your UK infrastructure without Standard Contractual Clauses. Unlike a US vendor, you normally face no transfer interrogation for the EU→UK leg.
- The onward leg to US model APIs has its own bridge. Transfers from the UK to US-processed model APIs are covered by the UK extension to the EU–US Data Privacy Framework (the "UK–US Data Bridge", in force since 12 October 2023) — but only where the US provider's DPF certification includes the UK extension, not base DPF alone — otherwise by the safeguards in the provider's DPA. Verify the certification before asserting it.
- But there is no UK "AI Act" to comply with instead. As of July 2026, the UK's domestic approach remains principles-based, pro-innovation guidance applied by existing regulators — not a statute equivalent to the EU Act. Adequacy covers transfers, not AI duties; UK principles do not discharge Article 50 — those duties come from the EU Regulation directly.
The questionnaire reality
Direct enforcement against a vendor with no EU establishment is not the near-term risk — the buyer's procurement process is. Your EU customers are in scope, so AI-CAIQ and SIG 2026 questionnaires push the question down to you — and for UK vendors it quietly tests exactly the distinction above. Answers that fail review: "the EU AI Act does not apply to UK companies" (ignores Art. 2), "we operate under the UK's AI framework" (doesn't answer the EU question), "we have adequacy" (transfers, not AI). An answer that survives scopes honestly via Art. 2(1)(a) or (c), classifies the system, names the Art. 50 duties with dates, and notes adequacy separately. If a questionnaire just landed, start with the first-24-hours playbook and the model answer to "Are you EU AI Act compliant?".
UK vendors and the EU AI Act: quick answers
Is the EU AI Act law in the UK?
No. It was never carried into UK law. A UK vendor is outside the Act unless Art. 2(1)(a) (EU market) or 2(1)(c) (output used in the Union) applies — for most UK SaaS selling into Europe, one does.
Does the UK's GDPR adequacy decision cover EU AI Act compliance?
No. Adequacy is a transfer matter. The AI Act applies through its own triggers regardless of how the data moves; conflating the two is a fast way to fail legal review.
Is there a UK equivalent act I comply with instead?
As of July 2026, no. The UK approach is pro-innovation guidance applied by existing regulators, not an equivalent statute. Where the triggers reach you, the Article 50 duties come from the EU Regulation itself.
- Regulation (EU) 2024/1689, Official Journal — Art. 2(1)(a), 2(1)(c), Art. 50, Art. 99, Art. 113 (ELI: data.europa.eu/eli/reg/2024/1689/oj)
- Digital Omnibus: European Parliament position 16 June 2026; Council adoption 29 June 2026 (consilium.europa.eu press releases)
- European Commission — renewed UK adequacy decision under the GDPR, adopted 19 December 2025 (sunset 27 December 2031)
- UK extension to the EU–US Data Privacy Framework ("UK–US Data Bridge"), in force 12 October 2023; certification list: dataprivacyframework.gov/list
- Cloud Security Alliance — AI-CAIQ; Shared Assessments — SIG 2026 (AI domain)