EU AI Act Exposure Check:
Scope, Readiness, and Cross-Border AI Risk
Many UK organisations assume the EU AI Act only applies to EU-headquartered businesses. That is often too simple. Brexit did not automatically remove EU-facing AI exposure.
If you serve EU clients, operate in the EU, or use AI in ways that affect people in the EU, you may have scope worth checking — before debating detailed obligations.
This free check starts with scope, then maps readiness across six control areas. Twelve questions · Yes / Partial / No / Unknown · about 3–4 minutes.
You receive an exposure band and a six-axis control-strength profile — a plain-English snapshot, not a compliance certificate. It scores exposure only. Obligations under the EU AI Act are phased and may evolve.

Start the self-audit
Twelve questions. Answer Yes / Partial / No / Unknown. Then unlock your exposure band and six-axis control-strength profile.
Also available: SRA audit · FCA audit · UK GDPR check
Scores exposure only. Not legal advice, not a compliance certificate, and not a funding eligibility check. Does not intercept a live prompt. EU AI Act obligations are phased and may evolve.
Also available: SRA GenAI Exposure Self-Audit · FCA GenAI Exposure Self-Audit · UK GDPR GenAI Exposure Check
What to do next
Your exposure band is a starting point. Keep the snapshot, share it with Legal / Compliance / Risk, then close gaps on paper — or move to a board-ready review and, where needed, runtime proof that AI use is tested, monitored, and proved.
EU AI Act scope, readiness, and cross-border AI risk
This pillar section gives search engines and human readers the plain-English context behind the audit above. It explains why UK organisations still need an EU AI Act exposure view, why scope comes before classification, and why policy alone is not proof.
Why UK organisations still need an EU AI Act exposure check
The EU AI Act is often discussed as an EU-only statute. For UK businesses, the practical question is territorial and operational: could your AI use touch EU clients, EU operations, or people in the EU — and if so, how ready are you?
Many firms pass an internal UK policy review and still have not mapped EU-facing AI exposure. That is a different diagnostic job from SRA or FCA sector audits, which is why this page is a standalone check.
This content is educational only. It is not legal advice and not a compliance certificate. Timelines under the Act are phased and may evolve.
Scope first — are you even in the conversation?
Before risk-tier debates, most organisations need four plain questions: do you have EU clients, offices, subsidiaries, partners, or counterparties; do AI outputs affect people in the EU; do you provide AI-enabled services to EU customers; and have you screened current use cases for more sensitive categories?
If the honest answers are largely No, you may sit outside obvious EU AI Act scope. That does not remove UK GDPR, SRA, or FCA exposure.
Provider vs deployer — where obligations can split
Teams often assume the model vendor carries everything. Under EU AI Act framing, responsibilities can split between providers of AI systems and organisations that deploy AI in their own operations or products.
You need clarity on which AI systems and suppliers you actually use, where vendor obligations end, and where your organisation's operating responsibilities begin.
High-risk categories and prohibited practices
This exposure check does not classify your systems as high-risk with legal certainty. It asks whether you have even started use-case classification and prohibited-practice screening.
Firms that skip classification tend to scale AI into sensitive workflows first and document later, or discover gaps only when a customer, partner, or auditor asks.
Transparency, human oversight, and documentation
Even where you are not building foundation models, deployer-style expectations often include knowing which AI systems are in use and for what purpose, documented human review for AI-assisted outputs, and records you can show if a client, regulator, or auditor asks.
A live AI register beats a static policy paragraph.
EU AI Act exposure often travels with UK GDPR risk
EU-facing AI workflows frequently involve personal data, special-category data, or cross-border transfers. Scope under the AI Act and exposure under UK GDPR often sit in the same prompts.
If your profile shows gaps on data and providers, complete the UK GDPR GenAI Exposure Check next.
Why dashboards and policies are not enough
An EU AI Act slide deck does not stop an inappropriate prompt or prove a control fired.
What firms prepare is often policy, vendor assurances, training, and timeline trackers. What is still missing is live visibility of systems and suppliers, clear deployer responsibilities, evidence of human oversight in practice, and runtime proof that bad uses were stopped.
The missing layer is often execution: what actually crossed the perimeter, whether policy survived run-time, and whether you can prove it afterwards.
What tested, monitored, and proved means here
For most organisations, it means controlled scenarios for inappropriate AI use or prompts, recurring review as usage and regulation change, and records of systems, ownership, and control outcomes.
A free exposure check is step zero: honesty about gaps. A board pack turns that into an accountable plan. Runtime controls are where proof becomes technical rather than aspirational.
How to use this free EU AI Act exposure check
Complete the 12-question self-audit above, unlock your exposure band and six-axis profile, and share the snapshot with compliance, legal, and IT.
If scope answers suggest you may be in scope, treat Evidence and Assurance scores as priorities. If you need something board-ready, the next step is a facilitated review, board pack, and one-hour consultation.
Frequently asked questions
Does Brexit mean the EU AI Act cannot apply to us?
Not automatically. EU clients, EU operations, or AI outputs affecting people in the EU can still create exposure worth checking.
Is this an official EU AI Act conformity assessment?
No. It is an educational scope and readiness exposure check. Not legal advice or a compliance certificate.
What if all scope answers are No?
You may sit outside obvious EU AI Act scope. Continue with UK GDPR and any sector audits that apply.
Related GenAI exposure checks
Also see SRA GenAI Exposure Self-Audit, FCA GenAI Exposure Self-Audit, and UK GDPR GenAI Exposure Check.
