The EU Artificial Intelligence Act (EU AI Act) creates a risk-based framework for the development, supply and use of artificial intelligence. Although it is an EU law, it may apply to UK businesses that develop or supply AI systems to EU customers, place AI systems on the EU market, or provide AI-powered services whose outputs are used in the EU. This article explains the EU AI Act’s rules on prohibited AI practices, transparency obligations, high-risk AI systems and copyright-related requirements for certain AI models, before considering the UK’s current regulatory approach and the practical implications for data protection, automated decision-making, consumer protection and commercial contracts.
Changes have been made to the UK’s data protection regime through the introduction of the Data (Use and Access) Act 2025 (DUAA). Whilst the provisions considered in this article are already in force, others will be introduced over time. The DUAA does not replace the UK’s existing data protection legislation (including the UK General Data Protection Regulation (UK GDPR), Data Protection Act 2018 (DPA 2018) and the Privacy and Electronic Communications (EC Directive) Regulations 2003 (PECR)) but will make some changes to that legislation in order to simplify the UK’s data protection regime.
Recent years have seen exponential growth in the adoption of artificial intelligence tools and systems across almost every industry. From predictive analytics to generative drafting tools, AI is no longer experimental for many businesses – it is becoming embedded in core commercial operations and those that fail to engage with it may risk losing competitive advantage.
The recent high-profile cyber breaches at Marks & Spencer, the Co-operative Group, and the Legal Aid Agency underscore the risks that even large, well-resourced organisations face in managing personal data. These incidents also demonstrate the importance of maintaining not only effective security measures, but also robust breach response plans, as required by the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.
In today’s fast-paced commercial environment, Supply Agreements are the backbone of many business operations. Whether you’re a manufacturer, distributor, or retailer, having a robust and legally sound supply contract is essential to mitigate risk, ensure continuity, and maintain strong commercial relationships.
A business’s terms and conditions can be a life saver if care is taken when drafting them. Of the many points which ought to be considered, addressing the fixed recoverable costs (FRC) regime introduced in the courts recently should be high on the list.
All businesses should have robust terms and conditions in place which set out the legal framework for the relationship between the business and its customers. This will help to ensure clarity and protection for both parties involved in commercial transactions.
Concern for the environment is at an all-time high. There is greater awareness, both on an individual and corporate level, of the impact of our daily activities and choices on the environment. ‘Sustainability’, ‘carbon footprint’ and ‘environmental impact’ are topics that now regularly appear on company websites and on their meeting agendas.