Transparency When Using AI: The EU AI Act vs UK Businesses
On 2 August 2026, the latest provisions of the EU AI Act came into force. Businesses across many UK industries are potentially affected, and many may not yet realise it! Here is a simple breakdown of what the latest changes mean for UK businesses.
Why should the UK care about EU laws post-Brexit?
Two simple reasons:
The EU AI Act has ‘extraterritorial effect’. This means that UK companies will be caught by the legislation where: (a) they offer services to EU customers, or (b) they deploy AI services in the EU. This could be something as innocuous as a travel company marketing holidays to French customers using AI-generated images, or deploying AI chatbots within an app used by customers whilst travelling in Italy.
Fines. The potential fines for non-compliance with the EU AI Act are potentially huge, i.e. up to €35M or 7% of global turnover for the most serious infringements. Of course, those are the maximum penalties for the biggest earners and biggest offenders. A small company inadvertently committing a minor offence should not expect to be put into liquidation. But a large company that is deliberately flouting the rules can expect a proportionate response.
This is not, therefore, something that only tech providers need to worry about. Many UK businesses marketing to the EU, or deploying AI systems in connection with EU customers, will be affected.
New Rules: What are the key changes?
As of 2nd August 2026, much of the transparency requirements under Article 50 of the EU AI Act are now in force! Here are the key things to look out for:
Customer service chatbots. Users need to be informed when they are interacting with an AI system rather than a human (unless this is obvious from the context). This could be an automated system that responds to complaints, a live chatbot on a website or an AI voicebot deployed to ‘answer the phone’ in a modern customer service centre.
AI-generated content. Are your marketing/PR team using AI apps to create marketing images and videos? If so, you may be obliged in certain cases to identify this as “AI Generated Content” (or similar). If this content is potentially misleading to customers, that amplifies the risk considerably. Needless to say the use of “deepfakes”, e.g. an AI form of Michael Palin endorsing a train holiday on social media, might sound like ‘a bit of fun’, but could have serious consequences.
Emotion recognition. Are you using AI systems to infer a person’s emotional state from facial expressions, voice, writing, body language or the like? For example, a call centre might be monitoring for ‘angry customers’, your HR department might be using such tools during its recruitment process or you might be using these tools to monitor your own employees. If so, careful consideration should be given as to whether the system falls within the transparency requirements of the EU AI Act. If so, it will be necessary to disclose that ‘emotion recognition is taking place’.
Biometric categorisation. Are you using images of faces, voice samples or other data to place people into categories? For example, your marketing team may find it helpful to categorise customers by ‘age range’ based on facial analysis or voice recordings. Once again, when using such systems, those affected may need to be informed. This is, of course, in addition to any GDPR obligations in relation to the use and retention of that data to start with.
In short, the key word here is ‘transparency’. Are you using AI systems? Are you doing so in scenarios where your customers or employees might not even realise? If so, it would be wise to take stock and determine whether it is necessary to expressly identify and inform those affected.
Practical Steps
It might be sensible to adopt as many of the requirements needed to comply with the EU AI Act voluntarily in the anticipation that the UK and other countries may one day follow suit. If so, your operations are already “in place” and harmonised rather than fragmented over different markets. After all, the EU AI Act may well end up influencing other AI Regulations worldwide, comparable to the global impact of the EU’s GDPR regime.
For those that have not already done so, UK businesses should devise an action plan as below:
Identify all AI systems used across the business.
Identify which are being marketed to or used in the EU
Review all AI systems to check for compliance with the EU AI Act (for transparency, discrimination etc)
Review contracts with AI suppliers
Draft an AI governance policy to cover what AI systems you are using and how they are tested and monitored
Train all relevant departments on AI risks – HR/Recruitment, Marketing/PR, Customer Services etc
Monitor future AI Act developments in all jurisdictions you (or your customers) operate – EU, UK, USA… and beyond
Finally, although the new rules on transparency may have caught your attention, businesses should remember that AI literacy obligations and the prohibitions on certain AI practices have applied since February 2025. Examples include: restrictions on certain manipulative AI practices, the exploitation of vulnerable individuals, social scoring, and some forms of biometric categorisation.
If you want to discuss any of the issues above, feel free to contact us by phone, or by e-mail at info@techlaw.co.uk