Liverpool: 0151 224 0500   |   Manchester: 0161 827 4600   |   Email: info@bermans.co.uk   |   Twitter Icon  |  Linkedin Icon
bermans_logo

Does the EU AI Act Apply to UK Businesses? Key Compliance Rules, Risks and Practical Steps for 2026

Rob Eakins

The EU Artificial Intelligence Act (EU AI Act) creates a risk-based framework for the development, supply and use of artificial intelligence. Although it is an EU law, it may apply to UK businesses that develop or supply AI systems to EU customers, place AI systems on the EU market, or provide AI-powered services whose outputs are used in the EU. This article explains the EU AI Act’s rules on prohibited AI practices, transparency obligations, high-risk AI systems and copyright-related requirements for certain AI models, before considering the UK’s current regulatory approach and the practical implications for data protection, automated decision-making, consumer protection and commercial contracts.

The EU AI Act came into force on 1 August 2024 and its provisions are taking effect in phases. While certain provisions had already become applicable, from 2 August 2026, the European Commission’s AI Office, working alongside national authorities, began enforcing key elements, including rules for general-purpose AI models and certain transparency obligations. The legislation is intended to support trustworthy AI and protect fundamental rights while allowing responsible innovation.

Which AI practices are prohibited under the EU AI Act? 

The EU AI Act prohibits AI systems that pose an unacceptable risk to people’s rights and safety. Those concerned about the ability of AI to distort behaviour will be pleased to read that AI systems using subliminal, manipulative or deceptive techniques in order to impair a person’s ability to make an informed decision are banned. The intention is to protect individuals from making choices they would not otherwise have made were it not for such systems.

Of course, many AI products, such as recommendation engines, are designed to influence user behaviour, and such influence is not, in itself, prohibited. For an AI system to fall within the scope of the prohibition, it must operate outside a person’s conscious awareness or use deliberately manipulative or deceptive techniques, materially distort that person’s behaviour, and cause, or be reasonably likely to cause, significant harm. The prohibition is therefore aimed at particularly harmful forms of AI-enabled manipulation, rather than ordinary personalisation, recommendations or marketing activities.

When must businesses disclose the use of AI and AI-generated content? 

Another key element of the EU AI Act is the requirement for individuals to be informed when they are interacting with AI systems. Where content has been generated or altered by AI, this should also be made clear to the user. This allows users to make informed decisions about the content they interact with including assessing its reliability and credibility.

Whilst transparency regarding AI-generated content may assist users to act autonomously and make informed decisions, it also raises a number of practical concerns. Although there have been numerous reported examples of AI systems generating plausible-sounding but inaccurate or even fictitious information, AI-generated content can be highly accurate, whilst human-generated content may itself be inaccurate or misleading. There is also the concern that using AI to make minor modifications to content may lead to the entire content being flagged as AI-generated, which is itself misleading and obscures the essential role played by the original, human creator.

How does the EU AI Act address copyright and AI training data? 

Those in the creative industries will be interested to learn that the EU AI Act requires providers of general-purpose AI models to put in place a policy to comply with copyright laws and make publicly available a detailed summary of the content used for training the AI model. It is not yet clear how this will play out but these requirements acknowledge the importance of protecting the rights of authors, musicians and other creatives as the sector develops.

Which AI systems are classed as high risk under the EU AI Act?

The EU AI Act introduces classification rules for high-risk AI systems, with those systems deemed to be high risk being subject to the EU AI Act’s strictest requirements, including risk management procedures, data governance controls, technical documentation obligations, human oversight measures and requirements relating to accuracy, robustness and cybersecurity. This may include systems used in particularly sensitive areas, including biometrics, critical infrastructure, education and the administration of justice. Although the EU AI Act’s classification rules have been in place since 2 February 2025, the principal compliance obligations applicable to high-risk systems will be phased in during 2027 and 2028.

When does the EU AI Act apply to UK businesses? 

The EU AI Act has extraterritorial effect, so even if your business is based in the UK, if you develop or supply AI systems to customers in the EU, place AI systems on the EU market, or provide AI-powered services that generate outputs used in the EU, you are likely to be caught by the EU AI Act.

How is artificial intelligence currently regulated in the UK? 

Although the UK does not currently have an overarching piece of legislation equivalent to the EU’s AI Act, that does not mean that the development and deployment of AI models and services in the UK is free from regulation, as various existing laws already apply to AI.

In terms of policy, the UK Government has adopted a “pro-innovation” approach to AI regulation, under which it expects existing regulators to apply five AI principles.  These principles are:

  • Safety – Ensuring AI systems work safely and securely and protect individuals and businesses from harm
  • Transparency – Ensuring that users are able to understand when and in what way they are interacting with AI systems and content
  • Fairness – Ensuring AI systems do not discriminate against users unlawfully or prejudice a user’s legal rights
  • Accountability – Identifying those responsible for the development, deployment and operation of an organisation’s AI systems so that accountability for their use and outcomes is clear
  • Redress – Providing appropriate mechanisms for individuals who are adversely affected by the use of AI to raise concerns, challenge decisions and seek remedies where appropriate

Although not currently directly binding on businesses, they are expected to influence the approach of regulators in their own sector. Below we explore some examples of how existing laws and the approach of regulators may apply in practice.

How do UK data protection laws apply to AI systems? 

Existing UK data protection legislation sets out seven key principles that lie at the heart of handling personal data: lawfulness, fairness and transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity and confidentiality and accountability. These principles will apply to AI systems and services as they do to any other digital systems and services. The Information Commissioner’s Office has set out detailed guidance to help organisations apply the principles to the use of information in AI systems.

For example, the principle of accountability requires a controller of personal data to be able to demonstrate compliance with the other principles. Organisations using AI systems may be required to implement human oversight, monitoring and governance measures appropriate to the nature and risks of the AI system being used. Organisations should be able to explain how their AI systems operate, demonstrate regulatory compliance and take corrective action where necessary.

The Data (Use and Access) Act 2025 (DUAA) amended the UK’s data protection framework and introduced new provisions in relation to automated decision-making. It clarified that a decision is based solely on automated processing if there is no meaningful human involvement in the taking of the decision, and defined what is meant by a “significant decision”.

The DUAA requires controllers to implement safeguards where solely automated significant decisions are made. These safeguards include providing information about the decision, enabling the individual to make representations about the decision and obtain human intervention, and contest the decision where the individual wishes to do so. Organisations using AI to make decisions about individuals will therefore need to consider these requirements as they apply to their systems and implement the necessary safeguards and processes.

What consumer protection risks arise when businesses use AI? 

Online retailers are frequently using AI chatbots on their websites to provide information to their customers and close sales. Care must be taken, as the retailer will be responsible for the comments made by the chatbot, just as they would if the comments were made by an employee. If statements made are inaccurate and cause the customer to purchase a product they would not otherwise have bought, the retailer could face liability under consumer protection legislation.

More generally, the fact that a decision was made or an action undertaken by an AI system is unlikely to provide a defence for the business using the AI system. Businesses using AI should ensure that appropriate safeguards, testing and human oversight are in place, as they are likely to remain responsible for the consequences of how those systems are used. Where a business accesses AI through a third-party provider, it should carefully review the contract with the third-party provider in order to establish the scope and specification of the system provided and how the risks associated with the operation of that system are allocated between the parties.

How Bermans can help

Bermans Commercial team can support organisations supplying AI systems and those using such systems in their business operations. The team advises on all aspects of commercial contracts, consumer rights and data protection. We review and draft the commercial contracts that support your business activities, helping ensure your agreements reflect your rights and obligations and manage risk effectively.

Contact Rob Eakins, Associate in our Commercial team.