The EU AI Act: are UK financial services firms really out of scope?
The EU AI Act is now being enforced. For a financial services firm headquartered in London, it would be easy to see that as an EU compliance issue and move on.
That could be a mistake.
Being based in the UK does not, by itself, put a firm outside the Act.
This is not a case of EU law simply being replicated in the UK. The UK has taken a different regulatory approach to AI. But for financial services firms with European customers, operations, suppliers or group entities, the practical effect is that the EU AI Act can still reach into the UK operating model.
What can bring a UK firm into scope?
Under Article 2 of the EU AI Act, the rules can apply where:
- a UK provider places an AI system or general-purpose AI model on the EU market;
- an AI system is deployed through an EU branch, subsidiary or other establishment; or
- a provider or deployer outside the EU produces AI output that is used in the EU.
The third point is particularly easy to underestimate.
Imagine a model developed in London, hosted by a US technology provider and used by a team in Paris. Its output feeds into a decision concerning an EU customer. In that situation, saying that the model is “UK-hosted” does not really answer the scope question.
The same issue can arise where a London fintech supplies technology to an EU bank, a group credit model supports decisions in Dublin, or a shared HR platform screens candidates in both London and Frankfurt.
There is still limited enforcement history around the test for where AI output is used. That makes documentation more important, not less. Firms should be able to explain why they consider a system to be in or out of scope rather than relying on the location of the development team or server.
Which financial services use cases matter most?
One point is worth clearing up early: not every important AI system used by a bank or insurer is automatically “high-risk”.
High-risk is a legal classification, and it matters because systems in this category are subject to a detailed compliance regime. Depending on whether the firm is acting as provider or deployer, requirements can include risk management, data governance, logging, technical documentation, information for deployers, human oversight, accuracy, robustness, cybersecurity and ongoing monitoring.
The classification is driven mainly by the system’s intended purpose rather than by how advanced, expensive or business-critical the technology happens to be. For most standalone financial-services systems, the key question is whether the intended use falls within one of the use cases listed in Annex III.
For financial services, two of the most relevant sector-specific categories are:
- AI used to assess a natural person’s creditworthiness or establish their credit score, excluding systems used to detect financial fraud; and
- AI used for individual risk assessment and pricing in life and health insurance.
Employment-related systems also deserve attention. AI used in recruitment, candidate screening, work allocation, performance monitoring or termination decisions may fall within the high-risk regime. Emotion recognition in the workplace is prohibited, subject to narrow medical and safety exceptions.
By contrast, trading models, corporate-lending tools and systems used for AML or fraud detection are not automatically high-risk simply because they are important to the firm. Their purpose and the other rules applying to them still need to be assessed.
There is another distinction that can get lost in vendor discussions: provider versus deployer.
Buying a system from a third party does not end the analysis. If a firm rebrands a system, substantially modifies it or changes its intended purpose, it may take on additional responsibilities. Procurement therefore cannot be the only team asking questions about AI classification.
The clock has already started
Some parts of the Act have applied for a while.
Prohibited AI practices and requirements to support staff AI literacy have applied since February 2025. Obligations for providers of general-purpose AI models followed in August 2025.
On 2 August 2026, further provisions began to be enforced and the Article 50 transparency requirements took effect. These include requirements, in certain circumstances, to tell people when they are interacting directly with an AI system rather than a human.
Following the July 2026 AI Omnibus, the Annex III high-risk requirements will apply from 2 December 2027.
December 2027 may still look comfortably distant on a project plan. In practice, it isn’t.
A firm first has to identify the systems it is actually using. It then needs to determine scope, establish ownership, obtain enough information from suppliers, assess its controls, close gaps and test whether arrangements such as human oversight work in reality.
None of that happens particularly quickly in a large financial institution.
The firms under the most pressure in late 2027 are likely to be those that treated the Act as a future legal interpretation exercise rather than a current governance and operating-model issue.
What does this mean for UK-regulated firms?
The FCA has said that it does not currently plan to introduce a separate set of AI-specific rules. Instead, it intends to rely on existing frameworks, including the Consumer Duty, SM&CR and its wider expectations around governance and controls.
That should not be read as meaning AI is unregulated in the UK.
Depending on the use case, firms still need to consider customer outcomes, accountability, operational resilience, outsourcing, data protection and equality law. For firms within scope, the PRA’s model-risk principles also set expectations around areas such as model inventories, ownership, development, validation and risk mitigation.
The Bank of England and FCA’s 2024 survey gives some indication of the scale of the issue. 75% of responding firms said they were already using AI. One-third of use cases were third-party implementations, while 46% of firms said they had only a partial understanding of the AI technologies they used.
That combination should get management’s attention.
AI adoption is increasing at the same time as supplier concentration, model complexity and embedded or “hidden” AI make it harder to know exactly what is running inside an organisation.
The EU and UK regimes may take different legal routes, but the underlying management questions are surprisingly similar:
Can the firm identify the system? Can it explain what the system is used for? Is there an accountable owner? And can the firm produce evidence that the relevant controls actually work?
A useful test for senior management
There is a fairly simple way to test the maturity of the current approach.
If someone asked for an explanation of the firm’s five most material AI systems today, could management readily show:
- what each system does;
- which customers, employees or decisions it affects;
- where its users and outputs are located;
- whether the firm is acting as provider or deployer;
- who owns the system and its outcomes; and
- what evidence supports the firm’s assessment?
More importantly, how long would it take to assemble that information?
If the answer is several days, or requires a chain of emails across Technology, Risk, Legal, Procurement and the business, the problem is not simply documentation. It is a sign that the underlying governance may not yet be sufficiently joined up.
What should firms be doing now?
For most firms, the sensible starting point is not another lengthy AI policy. It is a clear-eyed assessment of exposure and control maturity.
That means mapping the firm’s material AI systems alongside the suppliers, legal entities, users, output locations and decisions they affect. It also means separating direct EU legal exposure from obligations that may arise through group standards or customer contracts.
Once that picture exists, firms can classify individual use cases, confirm whether they are acting as provider or deployer, and compare the controls already in place with the relevant EU and UK requirements.
The useful output is not a polished presentation. It is a prioritised list of gaps, with owners and deadlines.
Existing work on model risk, data protection, operational resilience and Consumer Duty can provide a strong starting point. But policies and frameworks only get you so far. Firms will need evidence: testing results, human-oversight arrangements, monitoring records, incident processes and contractual rights to obtain the necessary information from suppliers.
There is also a risk in treating EU and UK requirements as two entirely separate compliance programmes.
EU conformity does not demonstrate good UK customer outcomes. Equally, strong UK governance does not automatically satisfy the EU AI Act. For firms operating across both markets, a more practical approach is to build one common control base and add targeted jurisdiction-specific requirements where they are genuinely needed.
How Be UK can help
Assess exposure and readiness
Be UK can support financial services firms with a focused assessment of their EU AI Act exposure and readiness across UK and European operating models.
The aim is to answer the questions management actually needs answered: which systems may be in scope, where the firm is acting as provider or deployer, which use cases need attention first, and where governance, supplier management or control evidence is not yet strong enough.
Prioritise and plan
We turn the findings into a prioritised roadmap, showing which systems and use cases need attention first and setting practical actions, owners and deadlines.
Remediate and evidence
We then support remediation in practical areas such as strengthening the AI inventory, clarifying ownership, designing proportionate controls, improving testing and monitoring, and building the documentation needed to support both EU requirements and UK regulatory outcomes.
As part of a pan-European financial services consultancy, Be UK combines knowledge of the London market with experience and reach across Europe. That matters because, for many firms, the difficult part will not be interpreting one regulation in isolation. It will be creating an approach that works across borders without building two disconnected compliance infrastructures.
The question, then, is not whether the EU AI Act is UK law. It isn’t.
The more useful question is whether your AI operating model crosses the boundary.
For many London financial services firms, it already does.




