The EU AI Act: What UK SMEs Need to Know

Even if your SME is UK-based, the EU AI Act likely applies if you have any EU market presence; this guide explains the risks and how to prepare for compliance.

By Harmeen Birk, AI Governance Advisor · 2026-06-18 · 6 min read

The EU AI Act: What UK SMEs Need to Know


The EU AI Act is the world's first comprehensive AI law. If you run or lead a UK business that uses AI in any form, you need to understand it. The rules have extraterritorial reach, the same way GDPR did, and the penalties for non-compliance are severe.

The most common mistake we see from UK SMEs is assuming this law doesn't apply to them because they're not based in the EU. That assumption is wrong.



## Does the EU AI Act Apply to Your Business?

The Act applies based on where your AI system is used or has an effect, not where your company is registered.
You are in scope if you:

  1. Sell an AI-powered product or feature to customers in the EU
  2. Operate AI systems (your own or third-party) that run within the EU
  3. Produce AI-generated outputs that are used or displayed in the EU

That third point catches most UK businesses off guard. A marketing agency using generative AI to produce content for an Irish client. A recruiter using an AI screening tool to assess candidates based in Germany. A SaaS platform with EU subscribers. If your products, services, or their outputs touch the EU market, you need to assess your position.


## The Four Risk Tiers

The Act classifies AI systems into four categories. Your obligations depend on which category your systems fall into.

Banned systems are prohibited entirely: social scoring, real-time biometric surveillance in public spaces, AI designed to manipulate behaviour. Most SMEs won't be building these, but you need to check that third-party tools you use don't fall into this category.
High-risk systems carry the most significant compliance burden. An AI system is high-risk if it is used in:

  1. Recruitment and HR: CV screening, candidate ranking, performance evaluation
  2. Credit and insurance: creditworthiness assessment, pricing decisions
  3. Education: admissions, student evaluation
  4. Access to essential services: benefits, eligibility decisions
    If your business uses AI in any of these areas, you face real obligations: risk management processes, data governance, technical documentation, human oversight, and a conformity assessment before deployment.
    **Limited-risk systems** require transparency. If you use a chatbot, users must be told they are not talking to a human. AI-generated content must be labelled.
    **Minimal-risk systems** such as spam filters, recommendation engines, and inventory tools carry no mandatory obligations, though voluntary codes of conduct are encouraged.


## What Are the Penalties? 1. Up to €35 million or 7% of global annual turnover for using banned systems 2. Up to €15 million or 3% of turnover for breaching high-risk obligations 3. Up to €7.5 million or 1.5% of turnover for providing false information to regulators
For most SMEs, a fine at even the lower end of these ranges would be existential. The question is not whether compliance is worth the effort. It is whether you can afford to ignore it.
---

What You Should Do Now


**1. Build an AI inventory**

You cannot govern what you have not mapped. List every AI system your business uses, including tools you have built yourself and AI features embedded in third-party software such as your CRM, HR platform, or finance tools. Most SMEs are surprised how long the list is.
2. Classify your risk

For each system, assess which tier it falls into. Document your reasoning. If any system touches recruitment, credit, access to services, or education, treat it as potentially high-risk until you have assessed it properly.
3. Review your supplier contracts

The Act distinguishes between providers (who build AI systems) and deployers (who use them). Your contracts should be clear about which party carries which compliance responsibilities, particularly around data governance and incident disclosure.
4. Put governance in place

This is where most SMEs stall. Governance sounds large and expensive, but the baseline requirement is straightforward: know what AI you are using, who is responsible for it, what decisions it influences, and what your process is when something goes wrong. The AI Assured Essentials certification provides a structured way to get there. It is designed for SMEs to complete without specialist expertise, mapped to the EU AI Act, NIST AI RMF, and ISO 42001, and gives you a defensible governance baseline and a credential you can point to.
5. Start documenting

If any of your systems are potentially high-risk, begin assembling technical documentation now. What data does it use? What decisions does it influence? What testing has been done? It is substantially easier to document as you go than to reconstruct it under regulatory pressure.

::cta[Get AI Assured certified]{href=/selector variant=primary}

What About UK Regulation?

The UK is not replicating the EU AI Act. Instead, it is asking existing regulators, including the ICO and FCA, to develop AI rules within their domains. The AI Safety Institute focuses on frontier model risk, not SME compliance.
For now, the EU AI Act is the most concrete and demanding AI regulation affecting UK businesses. Compliance with it will satisfy most of what the UK's evolving approach is likely to require.


---
## The Practical Case for Acting Now

The businesses that will struggle most when enforcement deadlines arrive are those with no visibility of their AI use and no governance in place. That is a fixable problem, but it takes longer than most people expect to fix, and enforcement is not waiting.
The case for getting ahead of this is not primarily legal. It is commercial. Customers, procurement teams, and regulators are beginning to ask questions about AI governance. Having a clear, documented answer, ideally a recognised certification, is increasingly a condition of doing business, not a differentiator.


---
_**AI Essentials is a structured self-certification for SMEs actively using AI. You can complete the certification yourself using the guidance and templates provided. The ceritification is mapped to the EU AI Act, NIST AI RMF, and ISO 42001.**_

::cta[Start free assessment]{href=/assessment variant=primary}