Aug 2, 2026
Leadership
The EU AI Act

The EU AI Act: What UK Businesses Need to Know from August 2026
On 2 August 2026, another part of the EU AI Act came into effect.
For businesses, the most visible change is fairly straightforward:
people should know when they are dealing with certain types of AI.
That includes AI chatbots and phone assistants, along with new transparency requirements around AI-generated content.
For a UK business with no connection to the EU, the change may have little direct impact.
For a UK business selling into Europe, operating there, employing people there or producing AI outputs that are used there, the position can be very different.
The first job is therefore not rewriting every AI policy in the company.
It is working out whether the rules reach you at all.
What changed on 2 August 2026?
Article 50 of the EU AI Act introduces transparency obligations for certain AI systems.
There are four areas businesses should understand.
1. People interacting with AI need to know
If somebody is speaking to an AI assistant or using an AI chatbot, they generally need to be told that they are interacting with a machine.
That disclosure should happen at the beginning of the interaction.
It does not require a page of legal wording.
Something as simple as:
"AI assistant, here to help."
can make the position clear.
The same principle applies to AI answering a phone call.
Relying on the argument that "people will obviously realise" is increasingly weak as AI systems become more natural.
2. AI-generated content can require machine-readable marking
Providers of generative AI systems have responsibilities around marking AI-generated or manipulated content so that it can be identified electronically.
This is primarily a responsibility for the company providing the AI system, rather than every business using it.
That distinction matters.
Using an AI image generator for an ordinary marketing graphic does not automatically mean your business needs to place a large "AI generated" label across the image.
3. Deepfakes need visible disclosure
Different rules apply where AI has created or manipulated realistic content depicting a real person, object, place, entity or event in a way that could appear authentic.
Those situations can require visible disclosure.
The distinction is therefore not simply between "AI image" and "normal image".
It depends on what the content represents and whether somebody could reasonably mistake it for something real.
4. Some AI-written public-interest material needs disclosure
AI-generated or manipulated text published to inform the public on matters of public interest can also require disclosure where it has not been subject to genuine human review or editorial responsibility.
For ordinary businesses producing routine marketing copy, this is unlikely to be the first issue they encounter.
For publishers and organisations producing public-interest information, it matters considerably more.
UK businesses are not automatically outside the Act
One of the easiest assumptions to make is that the EU AI Act only applies to businesses registered inside the EU.
That is not how the scope works.
There are several ways a UK business can come into contact with the Act.
Selling into the EU
If you place an AI system or AI-powered product on the EU market, the rules can apply even though the company itself is British.
Operating in the EU
A UK company using AI through EU-based operations, employees, branches or subsidiaries may also fall within scope.
AI output being used in the EU
The system itself can be running entirely in the UK while its output is used inside the EU.
That can still matter.
Examples worth examining include an AI system used for applicants to a European role, AI software supplied to European customers or customer-facing AI operating across both UK and EU markets.
The location of the server alone does not settle the question.
The UK has rules too, just not one equivalent AI Act
The UK has taken a different approach.
There is currently no single UK law that mirrors the EU AI Act.
That does not mean businesses in the UK can use AI without restrictions.
Existing rules around data protection, consumer protection, employment, equality and sector-specific regulation still apply.
The difference is largely structural.
The EU has created a specific, risk-based AI framework.
The UK continues to regulate much of the same activity through laws and regulators that already existed.
For a UK-only business, that distinction is important.
You should not apply every EU requirement automatically.
You also should not assume that "the EU AI Act doesn't apply" means there are no obligations at all.
Are you the provider or the deployer?
The Act also distinguishes between businesses that provide AI systems and businesses that deploy them.
A deployer is generally using an AI system supplied by somebody else.
A provider develops a system, or has one developed, and places it on the market under its own name.
Providers carry significantly more responsibility.
For everyday businesses simply using recognised AI platforms, the distinction may be straightforward.
It becomes more important where companies develop their own products, substantially modify existing systems, repurpose them or offer AI to customers under their own branding.
There are additional rules around high-risk AI systems, where certain changes can cause a business to inherit provider responsibilities.
A supplier contract cannot simply remove a legal duty that belongs to your business.
What counts as high-risk AI?
The strictest rules are not aimed at every meeting summariser, writing assistant or spreadsheet tool.
They focus far more heavily on systems whose output can meaningfully determine what happens to a person.
For example:
Writing a job advert with AI is very different from using AI to rank applicants and recommend who should be rejected.
Rewording a mortgage letter is very different from using AI to decide who qualifies for the mortgage.
The technology could be similar.
The role it plays in the decision is not.
A useful question is:
Does a person's outcome change because of what the AI decided?
If the AI helps a person do their job and the person independently makes the decision, the risk profile is different from a system effectively making that decision itself.
The stricter high-risk regime is now scheduled to apply from 2 December 2027 for many of these uses.
That sounds some distance away, but systems involving hiring, lending, insurance or other significant decisions need more than a policy written at the end. Records, human oversight, data quality and monitoring need to be designed into the system itself.
What should a UK business do now?
For many companies, the practical response is fairly modest.
Start by listing the AI systems you currently use.
Then identify:
Which ones talk directly to customers or members of the public.
Which ones create content that is published externally.
Whether any of their outputs are used within the EU.
Whether AI is helping with decisions about employees, applicants, customers or access to services.
Whether staff using AI have received sensible guidance on how to use it.
For customer-facing AI that falls within Article 50, make the disclosure clear.
For realistic synthetic content or relevant public-interest material, check whether visible labelling is required.
And where AI is making or heavily influencing significant decisions about people, treat it as a separate piece of work rather than assuming the same rules apply as an internal writing assistant.
The main risk is either ignoring the Act or overreacting to it
Businesses can get this wrong in both directions.
Ignoring AI regulation altogether creates obvious problems.
Treating every use of AI as though it were a high-risk legal project causes a different one. It can stop useful, low-risk tools being adopted simply because nobody understands where the real boundaries sit.
The practical approach is to understand what the AI is doing, who is responsible for it, where its output is being used and how much its answer actually matters.
That usually makes the picture considerably clearer.
This article is intended as practical guidance, not legal advice. AI used in areas such as hiring, lending, insurance or public services deserves specialist legal and compliance review.
TUSTRA helps businesses understand where AI fits, what responsibilities come with it and how to adopt it without creating unnecessary risk or complexity.
FREE EMAIL BRIEFING
The Tustra Briefing
AI in plain English for UK business.
One considered briefing covering what changed, why it matters, how businesses are using it, what to be cautious about and one practical action worth considering.
Important developments without daily noise
Practical UK business context
Honest case studies, security and adoption guidance
Blog
Recent Articles
AI automation insights to help your business move faster and smarter.

