The EU AI Act can apply to a Sussex SME even if it has no EU office. Your client work, recruitment software or staff’s AI use may be enough.
That will come as an unwelcome surprise to plenty of business owners. Brexit may have changed our relationship with European regulation, but it didn’t build a legal force field around Brighton and Hove.
Forget the futuristic supercomputer making sinister decisions in the server cupboard. The risk sits in the ordinary software already helping your team write proposals, screen applicants, create images or complete work for an overseas client.
AI is no longer niche, either. In June 2026, 29% of UK businesses were using at least one type of AI technology. Text generation was the most commonly adopted type, used by 17% of businesses, followed by visual content creation at 14%.
For many Sussex SMEs, the question has moved on from whether the EU AI Act matters to whether anyone has actually checked.
The EU AI Act follows what an AI system does and where its output is used. It doesn’t only follow the postcode of the business operating it.
A UK company may come within scope if it puts an AI system on the EU market, makes one available for use there or produces AI output that is used in the EU. Guidance for businesses outside the bloc also confirms that the Act has extraterritorial scope.
That creates several perfectly ordinary routes into the regulation.
A Brighton marketing agency might use generative AI to produce campaign material for a French client. A Shoreham consultancy could use an AI-assisted forecasting tool and send its analysis to a customer in Belgium. A software business might provide an AI-enabled product to European users. A recruitment firm could process applicants for roles based in the EU.
None of those businesses needs an office in Paris, Berlin or Brussels for the issue to arise.
The details will depend on whether you provide an AI system, deploy one in your own operations or simply use its output. Your obligations will also depend on the system’s risk classification. What you shouldn’t do is assume that being based exclusively in Sussex settles the question.
Start with a practical test: do you sell to EU customers, support EU users, recruit within the EU or deliver work there that has been produced or influenced by AI? If the answer is yes, your exposure deserves a closer look.

There’s another comforting assumption doing the rounds: this is a future problem.
It isn’t.
The EU AI Act entered into force on 1st August 2024 and became applicable on 2nd August 2026. From the latter date, the AI Office and national authorities became responsible for implementing, supervising and enforcing it. The Act’s transparency rules also took effect that same month.
Those transparency obligations matter when people interact with certain AI systems or encounter AI-generated content. Depending on the use, organisations may need to ensure people know they’re dealing with AI or that content has been artificially generated or manipulated.
Some high-risk requirements have more time attached to them. Rules covering high-risk systems in areas such as employment, education and critical infrastructure apply from 2nd December 2027. Requirements for certain AI systems embedded in regulated products, including lifts and toys, apply from 2nd August 2028.
That extra time is useful, particularly for employers using recruitment or workforce technology. Treating it as a reason to leave the job until the final month would be a mistake. You need time to discover what your software actually does, collect information from suppliers, change contracts and introduce proper human oversight.
If your first audit happens when a client sends you a compliance questionnaire, you’re already doing it under pressure.
The most obvious AI company is one that builds AI products but a much less obvious one is the ordinary SME that has simply acquired AI through subscriptions, software upgrades and employees experimenting with free tools.
That’s where two common risks emerge.
AI used for employment decisions sits among the Act’s high-risk categories. That includes tools involved in recruitment, candidate selection, performance evaluation, task allocation, worker monitoring and decisions about promotion or dismissal. Even CV-sorting software is listed as an example of high-risk employment AI.
You don’t need to own a sophisticated HR platform to be affected. AI functionality can appear inside applicant tracking systems, job advertising platforms, online assessments, video interview products and outsourced recruitment services.
The tempting response is: “Our supplier handles that.” Unfortunately, buying the software doesn’t make your own responsibilities disappear. A business using an AI system may be treated as a deployer, with obligations connected to human oversight and monitoring and to how that system is incorporated into decisions.
UK data protection law creates a related risk. After examining automated recruitment practices, the ICO found that many employers were likely relying on solely automated decisions. It warned that more safeguards may be required than employers currently have in place.
Ask your recruitment provider some blunt questions. Does its system rank, filter or reject candidates? Can a person meaningfully challenge its recommendation? What data was it trained on? Does it infer sensitive information? Can your hiring manager override the result and record why?
“We thought the software was only helping” won’t be a particularly strong governance policy.

Shadow AI is the use of AI tools that haven’t been approved or managed by the employer. It might be a team member pasting a client email into a public chatbot, uploading a CV for summarisation or feeding commercial figures into an online presentation generator. Let’s be honest, this is going on everywhere and short of blocking companywide access to online chatbots it’s very difficult to prevent.
Research involving UK employees found that 71% had used unapproved consumer AI tools at work, while 51% were doing so weekly. Only 32% were concerned about the privacy of company or customer data.
This is a security and data protection problem before you even reach the EU AI Act. It can also make Act compliance much harder because you can’t assess, document or control a system nobody has declared.
Banning everything is unlikely to work. Staff generally reach for these tools because they save time, and 28% said their employer didn’t provide an approved option. A better response is to offer clear boundaries and suitable tools for legitimate work.
Your policy should explain what can’t be entered into a public AI service, including personal data, confidential client material, credentials, unpublished financial information and protected intellectual property. It should also say which tools are approved, what human review is expected and who to ask when a new use case appears.
The largest EU AI Act fines make dramatic headlines, but they need context.
Breaches involving prohibited AI practices can attract a fine of up to €35 million or 7% of worldwide annual turnover, depending on the organisation and the applicable calculation. That highest tier is aimed at prohibited uses, not every mistake involving a chatbot.
Other failures under the Act may carry penalties of up to €15 million or 3% of worldwide annual turnover. Providing incorrect or misleading information to authorities can lead to penalties of up to €7.5 million or 1%.
For SMEs, the framework requires penalties to take account of their interests and economic viability. The statutory rules also provide that SMEs, including start-ups, are subject to the lower applicable maximum rather than the higher one.
That proportionality is important. It doesn’t make non-compliance harmless.
The more immediate cost for a small firm could be losing an EU client, delaying a contract, conducting an urgent legal review or discovering that a recruitment process can’t be properly explained. There’s also reputational damage if confidential customer information has been entered into an unapproved system.
So good compliance protects your commercial relationships. Avoiding the maximum fine on a regulator’s tariff sheet is the smaller prize.

You don’t need to classify every piece of technology perfectly before taking action. Begin by locating the obvious exposure.
Your team uses little or no AI, doesn’t sell AI-enabled products and doesn’t provide AI-assisted work to EU customers. Any use is limited to low-stakes internal tasks, with no personal, confidential or commercially sensitive data involved.
You still need basic controls. Software changes quickly, and AI features have a habit of arriving inside products you already pay for.
Staff use generative AI for client work, administration, content or analysis. Your business has EU customers or users, but AI isn’t making consequential decisions about people.
Focus on transparency, data handling, supplier terms and where outputs are ultimately used. Check whether your client contracts contain restrictions or warranties concerning AI.
Your business supplies an AI-enabled service to the EU or uses AI in recruitment, employee management, credit assessment or another consequential process. The system ranks people, recommends outcomes or makes decisions with limited human intervention.
This needs a more formal assessment. Identify your legal role, document oversight and seek specialist advice where the answer isn’t clear.
A useful first pass doesn’t need to swallow six months of your year. Give one person ownership and work through these steps.
Whether you’re managing a consultancy from central Brighton or a growing team in Worthing, the obligations don’t shrink to match your headcount. Smaller firms simply have fewer people available to handle them.
A workspace where teams can talk openly helps. Someone needs to be able to say, “I’ve found a useful tool, can we check it?” before customer data disappears into an unapproved account. Admittedly, we at JetSpace might be a little biased, but good compliance often begins with people sharing what they’re doing rather than quietly improvising from separate kitchen tables.
Nobody is asking you to stop using AI. The aim is to know where it sits in your business, what it touches and when a convenient shortcut becomes a regulated decision.
If you found this useful, you might also enjoy our guides to practical AI for small businesses, SME cybersecurity and what Sussex SMEs need to do about employment law changes.
Looking for new serviced office space in Brighton & Shoreham?
Call on 01273 917977 or complete our enquiry form.
Call on 01273 917977 or complete our enquiry form
enquire book a viewing