Article
EU AI Act transparency rules: what UK businesses need to know

Today, 2 August 2026, is a significant date for the EU AI Act. It is a reason to get clear about where AI sits in your work, who is accountable for it and what people need to know.
Over the past few weeks, the same question has come up repeatedly: "We are a UK business, but we have customers in Europe. Does the EU AI Act apply to us?"
You may have seen headlines saying that Europe's AI rules are now "fully in force". A meaningful new part of the Act takes effect today, while the most demanding requirements follow later.
The Act is risk-based. The rules are tougher where AI can materially affect someone's rights, safety or access to opportunity. The most demanding requirements for high-risk systems, such as AI used in recruitment, education, credit decisions or certain public services, have moved to 2 December 2027. Rules for AI built into regulated products, such as medical devices, follow on 2 August 2028. These are settled dates. The Digital Omnibus that delays them, Regulation (EU) 2026/1744, was published in the Official Journal on 24 July and has been in force since 27 July.
What changes today is particularly relevant to businesses that provide AI-enabled products or services to people in the EU: transparency.
The simplest version is this:
If people are talking to AI, or looking at AI-made content, they should know it.
What is the EU AI Act?
The EU AI Act is a law governing how AI systems are developed, sold and used in the European Union. It treats different uses differently.
It prohibits a small number of harmful uses. It introduces transparency rules for certain AI interactions and AI-generated content. It sets more substantial obligations for systems used in high-risk contexts. It also places duties on the companies behind general-purpose AI models.
It applies to organisations inside and outside the EU where they place an AI system on the EU market, use it in the EU, or, for providers outside the EU, where the output of their system is used in the EU.
That last point matters for UK businesses. A British address alone does not determine whether the Act applies. The route to market and use in Europe do.
If you have European customers, users, staff or audiences, it is sensible to understand the Act and check where your work sits.
What changed on 2 August 2026?
The new rules that matter most to many organisations are the transparency obligations in Article 50.
In practical terms, they cover four main things:
- AI systems that interact directly with people, such as chatbots, AI agents and avatars
- Generative AI systems that create or alter content
- Deepfakes, including realistic AI-generated or manipulated image, video or audio
- Emotion recognition and biometric categorisation systems
Providers of AI systems that interact directly with people must make sure users know they are interacting with AI.
Providers of generative AI systems must make their output detectable as AI-generated or manipulated where technically feasible. For most organisations, that particular duty sits with the company providing the system.
Businesses using these systems have more direct obligations in particular cases. For example, they must disclose deepfakes, and must disclose AI-generated text published to inform the public on matters of public interest where it has not had human review or editorial control.
If you use AI to help structure an article, sharpen a piece of copy or turn notes into a first draft, meaningful human judgement remains central before publication. Article 50 is aimed at deception.
EU AI Act implementation timeline
The dates that matter for organisations using AI in Europe
When should a UK business pay attention?
You should pay close attention if you:
- sell an AI-enabled product or service to European customers
- run an AI chatbot, assistant or avatar that EU users can access
- create or commission realistic AI-generated video, images or audio that could mislead people
- use AI in recruitment, education, lending, insurance, healthcare, public services or other decisions that affect people's lives
- use emotion recognition or biometric categorisation
- publish automated public-interest content without meaningful human editorial oversight
You should also pay attention if your clients operate in Europe. European clients will often need better answers about the tools, data, safeguards and decision-making behind the work you deliver.
That is already happening.
What should smaller businesses do?
Most smaller businesses do not need a legal department or a 90-page policy. They do need to stop treating AI as a collection of disconnected tools.
A proportionate starting point is:
1. Know where AI is being used
Make a simple list.
Include the tool, what it does, who uses it, what data goes into it, whether it creates anything customer-facing and who checks the output.
You cannot govern what you have not noticed.
2. Separate low-risk assistance from high-impact decisions
Using AI to draft a meeting agenda carries a different weight to using it to score job applicants.
Be especially cautious where AI influences employment, access to services, pricing, assessment, eligibility or decisions about individuals. These uses need clearer controls, better evidence and meaningful human oversight.
3. Be honest about AI in customer-facing work
If someone is speaking to a chatbot, tell them.
If an image, voice or video could reasonably be mistaken for a real person or event, disclose that it has been generated or manipulated.
If AI helps create public-facing content, make sure a named person is responsible for its accuracy, context and publication.
4. Train the people using it
Since February 2025, organisations within scope have needed to take measures to support AI literacy among the people using AI on their behalf. The Digital Omnibus makes clear that this does not require them to guarantee any particular level of understanding.
In plain English, people need to understand the tools they use well enough to use them safely. That includes their limits, data handling, likely errors, bias, copyright and confidentiality risks and when to escalate a problem.
A one-hour session is a start. The useful work happens when guidance is connected to the real workflows people use every day.
5. Put data and security before convenience
Do not put personal, commercially sensitive or client-confidential material into a tool without knowing how that tool handles it.
Check whether data is retained, used for training, processed outside the UK or EU, or shared with subcontractors. Set clear rules for what can and cannot be entered into each tool.
Data and security are central to responsible AI.
6. Keep a human responsible
Human oversight means someone has the authority, context and confidence to question the result, correct it, reject it and take responsibility for what happens next. It is more than a glance at the output before pressing send.
That applies to copywriting, client preparation, transcripts and internal workflows just as much as it does to customer-facing products.
Why do this if UK law is different?
The UK takes a different regulatory route from the EU, and the eventual shape of further AI rules remains unsettled.
UK businesses already have obligations under data protection, equality, consumer protection, copyright, employment and sector-specific rules. Those duties continue when AI is involved.
More importantly, the habits behind the EU AI Act are useful regardless of the legal route the UK takes:
- know where AI is used
- use it for a clear purpose
- protect people's data
- be transparent where it matters
- test higher-risk uses properly
- keep people accountable
Those habits make the work more reliable, easier to explain to clients and less likely to create a problem you have to untangle later.
The businesses most likely to struggle are those that cannot explain what their AI is doing, where their data has gone, or who made the final decision.
Build good working habits now. They will stand up whether the next pressure comes from regulation, a client questionnaire, a procurement process, an insurer, a staff concern or a customer asking a perfectly fair question:
"Was this made or decided by AI, and who is responsible for it?"
This article is general information, not legal advice. The EU AI Act has a detailed scope and specific exceptions. If you are developing or deploying AI in a higher-risk area, take specialist legal advice.
If you want to work through where your own AI use sits against this, that is exactly what Groundwork was built for.
Further reading: European Commission, navigating the AI Act and Article 50 transparency guidance.
A note on how this was made: Claude and ChatGPT were used for research, fact-checking against primary EU sources and drafting support. The framing, the reading of what UK businesses actually need to do and every significant decision along the way were mine.
More thinking
Have a project in mind?
Book a call and tell me what you're working on.
Book an intro call

