Plenty of UK founders assumed the EU AI Act was a European problem. It is not.

If you sell into the EU, if your product is used by customers based there, or if the output of your AI system reaches EU users, the Act can apply to you. Location of your company is not the deciding factor. Where the system is used and who it affects usually is.

For a scaling UK tech business, that changes the question. It is no longer whether the rules apply. It is where your product sits in the risk tiers, and what that costs you to comply with.

How the Act classifies AI systems

The Act works on risk. The higher the risk your system carries, the heavier the obligations. There are four broad levels.

  • Unacceptable risk. A small set of uses are banned outright, such as social scoring and certain forms of biometric categorisation.
  • High risk. Systems used in areas like recruitment, credit, education, essential services and safety components. These carry the most demanding obligations.
  • Limited risk. Systems that interact with people, such as chatbots, where users must be told they are dealing with AI.
  • Minimal risk. Most everyday tools, with little or no specific obligation.


The commercial catch is simple. Many founders assume their product is low risk because it feels harmless. The Act does not classify by how a tool feels. It classifies by where it is used. An AI feature that screens job applicants or helps decide who gets a loan can land in the high risk tier even if it started life as a helpful add-on.

What high risk actually demands

If your system is high risk, the obligations are real and ongoing. They include risk management processes, data governance, technical documentation, human oversight, accuracy and security standards, and registration in an EU database.

This is not a one-off form. It is a set of controls you have to build, evidence and maintain. For a company shipping features every few weeks, that has a direct effect on how you develop, test and release. It is a product and engineering issue as much as a legal one.

The obligations that catch general AI use

Even if you never build a high risk system, the Act still reaches you in two common ways.

First, transparency. If your product uses AI to talk to people, generate content or produce deepfakes, you generally have to make that clear. Users should know when they are dealing with a machine or with synthetic content.

Second, general purpose AI. If you build on top of large models, obligations flow through the supply chain. The model provider has duties, and so do you as the business deploying it. You cannot assume the provider has handled everything on your behalf.

Why this is a board level issue, not a compliance afterthought

The penalties are set high on purpose. Breaches of the banned uses can reach the tens of millions of euros or a percentage of global turnover, whichever is greater. Even lesser breaches carry serious figures.

For a business in the five to thirty million range, a penalty on that scale is not a line item. It is an existential risk. That is why this belongs on the board agenda and not buried in a product backlog.

There is a commercial upside too. Enterprise customers are already asking suppliers how they handle AI risk. Being able to answer clearly is becoming a condition of winning larger deals. Getting ahead of this is a sales advantage, not just a defensive move.

What to check now

You do not need a full compliance programme overnight. You need to know where you stand. Start here.

  • Map your AI. List every AI system and feature in your product and your operations, including tools bought from suppliers.
  • Classify the risk. Work out which tier each one sits in, based on how and where it is used.
  • Check your reach. Confirm whether any of your systems touch EU users or markets, directly or through your customers.
  • Review your supplier chain. Understand what obligations your model and tool providers carry, and what they push back onto you.
  • Fix your transparency. Make sure users are told when they are interacting with AI or AI generated content.


The bottom line

The EU AI Act is not a distant European rulebook. For UK tech companies selling across borders, it is a live commercial issue that affects product design, supplier contracts and the way you sell to larger customers.

The businesses that treat it as a structured risk to manage will move faster and win bigger deals. The ones that ignore it until a customer or regulator forces the question will be reacting under pressure, which is the most expensive way to deal with anything.

If you are not sure where your AI systems sit under the Act, or what your supplier contracts actually commit you to, get the position checked before it becomes the problem. Book a call with the Ethiqs team.

Book a free 20min Chat

Feel free to ask for details, don't save any questions!

Our Office

Business Hours

  • Monday - Friday - 9am to 5pm

Get in Touch

Ethiqs is committed to providing our clients with accessible, transparent and affordable legal services and this starts all the way from the initial consultation.