Usually not — merely using ChatGPT in a UK office does not bring a UK firm under the EU AI Act. The Act (Regulation (EU) 2024/1689, in force since August 2024) reaches beyond the EU in two main ways: if you place an AI system on the EU market as a provider, or if the output of your AI use is used in the EU. A UK firm serving EU clients with AI-produced work can be caught by that second trigger. What binds UK firms day to day is UK law: DUAA-amended UK GDPR and sector regulators, not the AI Act.
The territorial rules, plainly
Article 2 of the AI Act sets three main hooks. First: providers placing AI systems or general-purpose models on the EU market are covered regardless of where they are established — that catches a UK company selling an AI product into the EU, not a firm merely using someone else’s tool. Second: deployers established in the EU. Third — the one UK professional firms should actually check — providers and deployers in third countries where the output produced by the AI system is used in the EU.
For a UK law or accounting firm, that means the ordinary use of ChatGPT for internal work is out of scope. The analysis changes if AI-produced output is delivered for use in the EU — for example, work product for an EU client engagement — or if the firm ships its own AI-powered tool to EU customers.
The timeline keeps moving — check before you rely on it
The Act entered into force on 1 August 2024 with staged application: prohibited practices and AI-literacy duties from 2 February 2025, general-purpose AI obligations and governance from 2 August 2025, and general application from 2 August 2026.
In June 2026 the European Parliament approved the "Digital Omnibus on AI" amendments, which postpone the high-risk system obligations — the widely reported new targets are December 2027 for Annex III high-risk systems and August 2028 for Annex I product-safety systems. If your exposure analysis turns on high-risk classification, verify the current dates on the Commission’s official pages before relying on them.
What governs UK firms instead
The UK has no general AI statute. The framework is the March 2023 pro-innovation approach (existing regulators apply cross-sector principles) plus the Data (Use and Access) Act 2025, which amends UK GDPR — including the automated decision-making rules in force since February 2026. For a UK firm putting personal data into AI tools, that is the live compliance surface: data protection law, sector guidance, and confidentiality duties — the things our compliance hub maps to controls.
The short version
- Using ChatGPT internally does not, by itself, put a UK firm in AI Act scope.
- Two triggers to check: providing AI into the EU market, and AI output used in the EU.
- High-risk obligation dates were postponed by the June 2026 omnibus amendments — verify current dates before relying.
- Day to day, UK firms answer to DUAA-amended UK GDPR and their sector regulators.
Related questions
We have EU clients — are we caught?
Possibly, under the output-used-in-the-EU hook (Article 2). It depends on whether AI-produced output is actually used in the EU and in what role you act (provider vs deployer). This is exactly the kind of fact-specific question to take to counsel — the safe engineering posture meanwhile is to minimise the personal data entering AI workflows.
Is there a UK version of the AI Act coming?
Nothing equivalent is in force. The UK approach relies on existing regulators plus the DUAA’s data protection reforms, with an ICO statutory code on AI and automated decision-making in development. Watch that code — it will set the evidence expectations for UK AI use.
Does masking PII help with AI Act exposure?
It is not an AI Act compliance mechanism, but it shrinks the data protection surface that both regimes care about: less personal data in prompts means less exposure under UK GDPR today and simpler answers in any future scope analysis.
This page is general information, not legal advice. Where third-party guidance or law is summarised, read the originals via the source links before relying on them. Last reviewed: 17 July 2026.
This is the control in action
Identifiable data is masked in the browser before the prompt ever leaves — try it yourself with a sample prompt, or bring one low-risk workflow to a 20-minute review.
Advise Sarah Thompson, NI AB123456C, on the settlement offer.
Advise <PERSON_7K9X>, NI <NI_8W1R>, on the settlement offer.