9 September 2026

The European Union Artificial Intelligence (EU AI) Act, the General Data Protection Regulation (GDPR) and data protection rights: what UK organisations need to know

By Clare Chatfield, Information Governance Manager

A practical guide to when the EU AI Act may affect UK organisations.

This post explains when the European Union Artificial Intelligence Act[1] (EU AI Act) may matter for UK organisations, especially where artificial intelligence (AI) involves personal data, EU users, EU customers or EU-facing services.  It focuses on the overlap between AI governance, the United Kingdom General Data Protection Regulation (UK GDPR), the European Union General Data Protection Regulation (EU GDPR) and data protection rights.

Introduction

The UK has not adopted the EU AI Act, which entered into force in the EU in 2024. For organisations operating solely in the UK, it has not been transposed into domestic UK law because the UK is no longer part of the EU.  They remain subject to UK legal and regulatory requirements, including UK GDPR, the Data Protection Act 2018, information security, equality, consumer protection, employment and sector-specific regulation.

This is especially relevant for cultural, heritage, education, charity, public and information-management organisations using AI for collections access, rights management, research, audience engagement, recruitment, customer support, transcription, translation or content generation.

Even though the UK has not implemented the EU AI Act, the key issue here is the scope of the Act.  In fact, the EU AI Act may affect a UK organisation where it conducts business in the EU, places AI systems on the EU market, puts AI systems into service in the EU, serves EU customers or users, or produces AI outputs used in the EU.

For example, a UK heritage organisation using AI only to transcribe internal archive notes for UK staff may remain mainly within UK GDPR and UK governance requirements. If it offers an AI-powered search tool to EU users or uses AI-generated outputs in services for EU clients, EU GDPR and the EU AI Act may also need to be considered.

In practice, the question is whether the AI system, service, user base, customer relationship or output has an EU connection.  If use is genuinely limited to UK operations, UK users and UK customers, the EU AI Act will usually not apply directly. If the activity is EU-facing, it may need to be considered alongside UK law and, where personal data is involved, EU GDPR.

So, at this stage, UK organisations would be advised to undertake a scoping exercise rather than a complete compliance assessment. Doing this will help them identify which legal frameworks are likely to apply before more detailed legal, technical or contractual checks are carried out.

Organisations should start with a UK and EU scope assessment for each AI use case.  An AI register should record the purpose, supplier, affected individuals or markets, whether outputs are used in the EU, what personal data is processed, the lawful basis, retention, transfers and contractual controls.

Where AI involves personal data, organisations should check whether individuals have been clearly told how AI is used, whether the lawful basis is appropriate, whether only necessary data is processed, whether outputs may have unfair or discriminatory effects, whether individuals can exercise their information rights, and whether human review is available for decisions with significant effects.

Practical steps include maintaining an AI register, confirming whether UK GDPR, EU GDPR or the EU AI Act applies, updating privacy notices and AI notices, checking supplier contracts and data processing arrangements, reviewing Data Protection Impact Assessments (DPIAs) where needed, and monitoring UK and EU regulatory developments.  Organisations should also monitor guidance from the Information Commissioner’s Office (ICO), UK regulators and EU bodies.

The priority is to identify whether there is an EU connection.  If there is, EU AI Act compliance should be planned alongside UK governance and data protection obligations. If there is not, organisations should focus on UK law, regulator expectations and proportionate internal controls.

How we can help

We can help organisations assess AI-related data protection and governance risks, map AI use cases, review documentation, update policies, strengthen supplier due diligence and develop proportionate compliance roadmaps.  Where specialist EU AI Act classification or technical assurance is required, we can help identify the right next steps.


[1] The Act Texts | EU Artificial Intelligence Act

Recent News

Back to News

Discover more from Naomi Korn Associates

Subscribe now to keep reading and get access to the full archive.

Continue reading