CAIS Background Watermark
SOVEREIGN AI · EU AI ACT EXPOSURE

EU AI Act Exposure Check:
Scope, Readiness, and Cross-Border AI Risk

Many UK organisations assume the EU AI Act only applies to EU-headquartered businesses. That is often too simple. Brexit did not automatically remove EU-facing AI exposure.

If you serve EU clients, operate in the EU, or use AI in ways that affect people in the EU, you may have scope worth checking — before debating detailed obligations.

This free check starts with scope, then maps readiness across six control areas. Twelve questions · Yes / Partial / No / Unknown · about 3–4 minutes.

You receive an exposure band and a six-axis control-strength profile — a plain-English snapshot, not a compliance certificate. It scores exposure only. Obligations under the EU AI Act are phased and may evolve.

Compliance AI Shield
EU AI Act · scope and readiness
Compliance AI Shield
Compliance AI Shield
complianceaishield.co.uk
Self-auditSovereign AI12 questions~3–4 minutes

Start the self-audit

Twelve questions. Answer Yes / Partial / No / Unknown. Then unlock your exposure band and six-axis control-strength profile.

This scores exposure, not eligibility for any government funding scheme. It does not intercept a live prompt, block a model call, or produce a cryptographic audit receipt. Paper policies catalogue risk — they do not eliminate runtime leakage.
Educational self-assessment only. Not legal advice or compliance certification. Obligations under the EU AI Act are phased and may evolve.
Also available: SRA audit · FCA audit · UK GDPR check

Scores exposure only. Not legal advice, not a compliance certificate, and not a funding eligibility check. Does not intercept a live prompt. EU AI Act obligations are phased and may evolve.

Also available: SRA GenAI Exposure Self-Audit · FCA GenAI Exposure Self-Audit · UK GDPR GenAI Exposure Check

What to do next

Your exposure band is a starting point. Keep the snapshot, share it with Legal / Compliance / Risk, then close gaps on paper — or move to a board-ready review and, where needed, runtime proof that AI use is tested, monitored, and proved.

EU AI Act scope, readiness, and cross-border AI risk

This pillar section gives search engines and human readers the plain-English context behind the audit above. It explains why UK organisations still need an EU AI Act exposure view, why scope comes before classification, and why policy alone is not proof.

Why UK organisations still need an EU AI Act exposure check

The EU AI Act is often discussed as an EU-only statute. For UK businesses, the practical question is territorial and operational: could your AI use touch EU clients, EU operations, or people in the EU — and if so, how ready are you?

Many firms pass an internal UK policy review and still have not mapped EU-facing AI exposure. That is a different diagnostic job from SRA or FCA sector audits, which is why this page is a standalone check.

This content is educational only. It is not legal advice and not a compliance certificate. Timelines under the Act are phased and may evolve.

Scope first — are you even in the conversation?

Before risk-tier debates, most organisations need four plain questions: do you have EU clients, offices, subsidiaries, partners, or counterparties; do AI outputs affect people in the EU; do you provide AI-enabled services to EU customers; and have you screened current use cases for more sensitive categories?

If the honest answers are largely No, you may sit outside obvious EU AI Act scope. That does not remove UK GDPR, SRA, or FCA exposure.

Provider vs deployer — where obligations can split

Teams often assume the model vendor carries everything. Under EU AI Act framing, responsibilities can split between providers of AI systems and organisations that deploy AI in their own operations or products.

You need clarity on which AI systems and suppliers you actually use, where vendor obligations end, and where your organisation's operating responsibilities begin.

High-risk categories and prohibited practices

This exposure check does not classify your systems as high-risk with legal certainty. It asks whether you have even started use-case classification and prohibited-practice screening.

Firms that skip classification tend to scale AI into sensitive workflows first and document later, or discover gaps only when a customer, partner, or auditor asks.

Transparency, human oversight, and documentation

Even where you are not building foundation models, deployer-style expectations often include knowing which AI systems are in use and for what purpose, documented human review for AI-assisted outputs, and records you can show if a client, regulator, or auditor asks.

A live AI register beats a static policy paragraph.

EU AI Act exposure often travels with UK GDPR risk

EU-facing AI workflows frequently involve personal data, special-category data, or cross-border transfers. Scope under the AI Act and exposure under UK GDPR often sit in the same prompts.

If your profile shows gaps on data and providers, complete the UK GDPR GenAI Exposure Check next.

Why dashboards and policies are not enough

An EU AI Act slide deck does not stop an inappropriate prompt or prove a control fired.

What firms prepare is often policy, vendor assurances, training, and timeline trackers. What is still missing is live visibility of systems and suppliers, clear deployer responsibilities, evidence of human oversight in practice, and runtime proof that bad uses were stopped.

The missing layer is often execution: what actually crossed the perimeter, whether policy survived run-time, and whether you can prove it afterwards.

What tested, monitored, and proved means here

For most organisations, it means controlled scenarios for inappropriate AI use or prompts, recurring review as usage and regulation change, and records of systems, ownership, and control outcomes.

A free exposure check is step zero: honesty about gaps. A board pack turns that into an accountable plan. Runtime controls are where proof becomes technical rather than aspirational.

How to use this free EU AI Act exposure check

Complete the 12-question self-audit above, unlock your exposure band and six-axis profile, and share the snapshot with compliance, legal, and IT.

If scope answers suggest you may be in scope, treat Evidence and Assurance scores as priorities. If you need something board-ready, the next step is a facilitated review, board pack, and one-hour consultation.

Frequently asked questions

Does Brexit mean the EU AI Act cannot apply to us?

Not automatically. EU clients, EU operations, or AI outputs affecting people in the EU can still create exposure worth checking.

Is this an official EU AI Act conformity assessment?

No. It is an educational scope and readiness exposure check. Not legal advice or a compliance certificate.

What if all scope answers are No?

You may sit outside obvious EU AI Act scope. Continue with UK GDPR and any sector audits that apply.