The EU AI Act: What Effect Does This Have on UK Companies?

The EU AI Act (the “Act”) was approved by the EU Council on 21 May 2024 and came into force on 1 August 2024. The legislation aims to establish a consistent legal framework for AI systems across the EU, ensuring that human welfare, reliability, and European principles are prioritised.

The Act categorises AI systems into four risk levels:

  • Prohibited. Systems with an unacceptable risk rating. For example, social scoring or manipulative AI.
  • High-risk. Systems requiring strict regulation and must undergo a conformity assessment.
  • Limited-risk. Systems will face lighter transparency requirements whereby they do not pose the risk of the above two levels, but still present some level of risk that requires regulation. An example referenced is chatbot systems.
  • Minimal-risk. For systems which do not pose a threat and remain unregulated, for example, filters or games.

How does this affect the UK?

Although the Act’s jurisdiction is limited to the EU itself, it’s impact is still felt within the UK regulation and system due to its extraterritorial reach. Similar to the GDPR, the Act applies to companies whose AI systems are used within the EU, regardless of where the company is based. Businesses in the UK that develop or deploy an AI system that is used in the EU will need to comply with the Act. As the UK is still in the process of shaping its own AI regulations, the legislation may well create pressure for the UK to align with the EU’s approach.

UK based entities should pay particular attention to AI systems that could be flagged as high-risk by the Act. These systems, which include those already implemented into critical sectors like healthcare, policing, and employment, will now be subject to strict regulatory requirements. Businesses making use of such AI will need to implement thorough risk management processes, maintain quality management systems, and ensure proper data governance and cybersecurity measures are in place. Additionally, they will need to undergo assessments to prove compliance before their AI systems can be used in the EU market. For companies providing general-purpose AI models, evidence of training data, testing processes, and potential biases will be required to maintain transparency and accountability.

The financial risks associated with noncompliance are also a factor that UK companies should consider. The Act imposes heavy fines for violations, with the potential financial penalty reaching up to €35 million, or, 7% of global turnover, whichever is higher. Therefore, it is vital that businesses are proactive in reviewing their AI systems and ensuring they meet the EU’s regulatory standards.

Notably, there is a clear overlap between the Act and the GDPR. As many AI systems rely on personal data, UK businesses must ensure that their AI use complies with both sets of regulations. This could increase the regulatory burden on companies that handle personal data, particularly as transparency and responsible data use are central to both the AI Act and GDPR.

In the meantime, UK companies interacting with the EU market need to carefully navigate the requirements of the AI Act and the GDPR to ensure continued access to the market and to mitigate potential legal risks.

Dates to be aware of

There is little time to ensure firms themselves are compliant with the regulation, as the ban on prohibited systems will be enforced from 2 February 2025.

To check whether a business is compliant under the new legislation, the EU have provided a website dedicated to the Act, with its own compliance checker: https://artificialintelligenceact.eu/assessment/eu-ai-act-compliance-checker/

In the future, the EU will be providing a “Code of Practice” to assist firms in ensuring their compliance. This is expected to be released in May 2025.

Scroll to Top

Quick Contact