AI23 min read12 June 2026

The EU AI Act & UK AI Policy: A Full Briefing for Marketing Teams

Prepared by: David Chadderton, The STAR Framework Date: June 2026 Version: 1.0

Prepared by: David Chadderton, The STAR Framework Date: June 2026 Version: 1.0


Executive Summary

The regulatory landscape for artificial intelligence is shifting beneath the feet of every marketing team in Europe. The EU AI Act, the world’s first comprehensive legal framework for AI, entered into force on 1 August 2024 and is now rolling out in phases, with the most significant enforcement deadline arriving on 2 August 2026. On that date, transparency obligations under Article 50 take effect, and the rules governing high-risk AI systems come into force.

The UK, meanwhile, has chosen a fundamentally different path: no single AI Act, no centralised risk classification, and no prescriptive legislative framework. Instead, existing regulators — the ICO, ASA, Ofcom, and others — are applying their existing mandates to AI within their respective domains, guided by five cross-cutting principles.

For marketing teams operating across both jurisdictions, or targeting audiences in both markets, the practical reality is this: you are likely subject to both frameworks simultaneously, and the compliance burden is about to increase sharply.

This briefing covers what you need to know, what you need to do, and what to watch for next.


Part One: The EU AI Act

1.1 What Is It?

The EU AI Act (Regulation (EU) 2024/1689) is a horizontal, legally binding regulation that establishes a comprehensive framework for the development, placement on the market, putting into service, and use of AI systems within the European Union. It applies to:

The key point for UK-based marketing teams: if your AI systems affect people in the EU, the Act applies to you regardless of where you are based.

1.2 Risk Classification: The Four Tiers

The EU AI Act classifies all AI systems into four risk categories, each with escalating obligations:

Tier 1: Unacceptable Risk (Prohibited)

These AI practices are banned outright. They include:

Marketing relevance: If your targeting strategies involve profiling individuals based on sensitive attributes, or your AI systems use techniques that could be characterised as manipulative or exploitative, you are operating in prohibited territory. This includes certain forms of behavioural micro-targeting that exploit cognitive vulnerabilities.

Tier 2: High Risk

High-risk AI systems are not banned but are subject to stringent requirements before they can be placed on the market. They typically fall into two groups:

  1. AI systems as safety components of regulated products (medical devices, aviation, vehicles, etc.)
  2. AI systems used in specific domains listed in Annex III, including:
    • Biometric identification and categorisation
    • Critical infrastructure management
    • Education and vocational training
    • Employment, worker management, and recruitment
    • Access to essential services (credit scoring, insurance, healthcare)
    • Law enforcement and criminal justice
    • Migration and border control
    • Administration of justice and democratic processes

Marketing relevance: Most marketing AI systems will not fall into the high-risk category directly. However, if your organisation uses AI for recruitment, credit assessment, or customer profiling that determines access to essential services, those systems may be classified as high-risk. The obligations include:

Important note: The “AI Act Omnibus” agreement (May 2026) has proposed extending compliance deadlines for high-risk systems in Annex III to 2 December 2027, and for high-risk systems embedded in regulated products (Annex I) to 2 August 2028. This proposal needs formal adoption before 2 August 2026 to take legal effect.

Tier 3: Limited Risk

These systems present lower levels of risk but are subject to specific transparency requirements. This is where most marketing AI systems will sit. Examples include:

Obligations: Providers must ensure that humans are informed when they are interacting with an AI or viewing AI-generated content.

Tier 4: Minimal or No Risk

The vast majority of AI systems, including spam filters, AI-enabled video games, and basic product recommendation engines. No mandatory obligations apply, though voluntary codes of conduct are encouraged.

1.3 The August 2026 Deadline: Article 50 Transparency Obligations

This is the deadline that matters most for marketing teams. On 2 August 2026, the transparency obligations under Article 50 of the EU AI Act come into force. These requirements apply to all deployers of AI systems that generate or manipulate content, not just those classified as high-risk.

What Article 50 requires:

  1. AI-Generated Content Disclosure: Any content that has been generated or substantially manipulated by AI must be clearly and prominently disclosed to the person encountering it. This applies to:

    • Synthetic images (including AI-generated product imagery, lifestyle scenes, virtual models)
    • AI-generated or AI-edited video content
    • AI-generated text (where it could be mistaken for human-authored content)
    • AI-generated or AI-manipulated audio
    • Deepfakes
  2. Deepfake Labelling: The Act defines deepfakes as AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or events and would falsely appear authentic. Content that is clearly fantastical (e.g., dragons, impossible scenarios) is generally excluded. Deepfakes must be clearly labelled as AI-generated or manipulated.

  3. Chatbot Disclosure: If an AI system directly interacts with a user, it must clearly inform the user that they are interacting with an AI, unless this is obvious to a reasonably well-informed person.

  4. Machine-Readable Marking: Providers of AI systems that generate synthetic content (images, audio, video) are required to mark their outputs in a machine-readable format to ensure detectability. This includes watermarking and metadata tagging.

  5. Method of Disclosure: The disclosure must be:

    • Clear and prominent
    • Presented at the time the person encounters the content
    • Not buried in terms and conditions or general AI notices
    • Acceptable methods include persistent visual labels, opening disclaimers for videos, and audible warnings for audio
  6. Artistic Exception: For deepfakes that are part of evidently artistic, creative, satirical, fictional, or analogous works, the transparency obligation is limited to disclosure in a manner that does not hinder the display or enjoyment of the work.

What this means in practice for marketing teams:

1.4 Penalties and Fines

The EU AI Act establishes a three-tiered penalty structure:

Violation Type Maximum Fine
Non-compliance with prohibited AI practices (Article 5) €35 million or 7% of global annual turnover (whichever is higher)
Non-compliance with high-risk obligations or GPAI model requirements €15 million or 3% of global annual turnover
Supply of incorrect or misleading information to authorities €7.5 million or 1% of global annual turnover

For SMEs, fines are capped at the lower of the fixed amount or the percentage of turnover.

1.5 Implementation Timeline

Date What Comes Into Force
1 August 2024 AI Act enters into force
2 February 2025 Prohibited AI practices and AI literacy obligations
2 August 2025 Rules for general-purpose AI (GPAI) models and governance
2 August 2026 High-risk AI systems (Annex III) and transparency obligations (Article 50)
2 December 2026 New prohibitions on CSAM/non-consensual imagery generators; watermarking obligations
2 December 2027 Proposed extended deadline for Annex III high-risk systems (pending Omnibus adoption)
2 August 2028 Proposed extended deadline for Annex I high-risk systems (pending Omnibus adoption)

1.6 How the EU AI Act Applies to Specific Marketing Channels

Organic Social


Part Two: UK AI Policy

2.1 The UK Approach: Principles Over Prescriptions

The UK has deliberately chosen not to create an EU AI Act equivalent. Instead, the government’s March 2023 White Paper, “A Pro-Innovation Approach to AI Regulation,” established a framework built on five cross-cutting principles, to be applied by existing sector-specific regulators:

  1. Safety, security, and robustness
  2. Transparency and explainability
  3. Fairness
  4. Accountability and governance
  5. Contestability and redress

These are not legally binding in themselves. They are implemented through guidance issued by regulators within their existing mandates, not through new AI-specific legislation.

The critical distinction: Where the EU has a single Act with a centralised risk classification, the UK has a decentralised system where each regulator interprets and applies the five principles within their domain.

2.2 The Key Regulators for Marketing Teams

Information Commissioner’s Office (ICO)

The ICO is the primary regulator for AI concerning personal data, operating under the UK GDPR and the Data Protection Act 2018, as amended by the Data (Use and Access) Act 2025.

Current status (June 2026):

Marketing relevance: The ICO’s focus on automated decision-making, profiling, and targeted advertising means that AI-powered marketing systems that process personal data are firmly within scope. The emerging Code of Practice will likely impose transparency and governance obligations that parallel elements of the EU AI Act, but through the lens of data protection law.

Advertising Standards Authority (ASA)

The ASA regulates AI in advertising through its existing, media-neutral codes: the CAP Code (non-broadcast) and the BCAP Code (broadcast). These codes apply regardless of whether content is human-generated or AI-generated.

Current status (June 2026):

Marketing relevance: The ASA’s approach is straightforward: advertisers are responsible for all AI-generated content, and it must not be misleading, harmful, offensive, or socially irresponsible. There is no separate AI-specific code, but the existing codes are being applied to AI content with increasing vigour.

Ofcom

Ofcom’s AI role stems from its oversight of telecoms networks (Telecoms Security Act 2021) and online services (Online Safety Act 2023).

Current status (June 2026):

Marketing relevance: Ofcom’s focus is primarily on the infrastructure and online safety dimensions rather than direct advertising regulation. However, the Fraudulent Advertising Code of Practice could have implications for AI-generated advertising that appears on Ofcom-regulated platforms.

Digital Regulation Cooperation Forum (DRCF)

The DRCF coordinates cross-regulatory AI activities between the ICO, CMA (Competition and Markets Authority), Ofcom, and FCA. This is the closest the UK gets to a unified AI governance body, though it coordinates rather than regulates directly.

2.3 The UK Regulatory Gap: What Is Missing

The UK’s approach has notable gaps compared to the EU AI Act:

  1. No risk classification system: There is no UK equivalent of the four-tier risk hierarchy. Regulators assess AI risk within their existing mandates, which means there is no unified standard for what constitutes “high-risk” AI across sectors.

  2. No comprehensive transparency obligations: While the ICO and ASA both address transparency in their respective domains, there is no single, legally binding requirement equivalent to Article 50 of the EU AI Act.

  3. No prohibited practices list: The UK has not legislated specific AI practices as prohibited. Harmful uses of AI are addressed through existing law (data protection, consumer protection, equality law) rather than a dedicated AI framework.

  4. No centralised enforcement: Enforcement is fragmented across multiple regulators, each with different powers, penalties, and approaches.

  5. No mandatory AI literacy obligations: The EU AI Act requires organisations to ensure a sufficient level of AI literacy among their staff. The UK has no equivalent requirement.

  6. Uncertain legislative future: The government has signalled intent to introduce AI legislation, with a decision expected by autumn 2026. An anticipated AI Bill has not materialised, and the legislative timetable remains unclear.

2.4 Existing UK Law That Already Applies to AI in Marketing

Even without a dedicated AI Act, UK marketing teams are already subject to:


Part Three: EU vs UK — Similarities, Differences, and Practical Implications

3.1 Where They Align

Area EU AI Act UK Approach
Transparency Article 50 mandates disclosure of AI-generated content ICO and ASA both require transparency, though through different mechanisms
Accountability Deployers carry disclosure obligations Advertisers responsible for all AI-generated content (ASA)
Consumer Protection Prohibited practices include manipulation and exploitation Consumer protection law prohibits misleading and aggressive practices
Data Protection GDPR applies alongside the AI Act UK GDPR and DPA 2018 apply
Deepfake Disclosure Explicit labelling requirements ASA guidance requires disclosure where omission would mislead
Chatbot Disclosure Mandatory under Article 50 ICO and ASA guidance both address this

3.2 Where They Diverge

Area EU AI Act UK Approach
Legislative Framework Single, comprehensive, legally binding Act No dedicated AI legislation; principles-based, regulator-led
Risk Classification Four-tier system (unacceptable, high, limited, minimal) No unified risk classification
Prohibited Practices Explicit list of banned AI practices No dedicated prohibited practices list; addressed through existing law
Enforcement Centralised under national AI authorities with EU coordination Fragmented across ICO, ASA, Ofcom, CMA, FCA
Penalties Defined fine structure (up to €35m / 7% turnover) Varies by regulator; ICO fines up to £17.5m / 4% turnover under UK GDPR
Transparency Obligations Legally binding, specific, and detailed (Article 50) Guidance-based, interpreted by each regulator
AI Literacy Mandatory for all organisations deploying AI No equivalent requirement
Registration High-risk systems must be registered in EU database No centralised registration requirement
Scope Applies to anyone affecting EU individuals Applies to UK-regulated activities

3.3 The Extraterritorial Problem

This is the practical reality that many UK marketing teams have not yet absorbed: the EU AI Act applies extraterritorially. If your AI systems affect individuals in the EU, you are subject to the Act regardless of where you are based.

This means:

You do not need an EU office to be caught by this. The Act follows the individual, not the company’s jurisdiction.

3.4 Compliance Matrix: What Applies Where

Scenario EU AI Act UK Regulations
UK company, UK audience only ❌ Not directly applicable ✅ UK GDPR, ASA codes, PECR, Consumer Rights Act
UK company, EU audience ✅ Full EU AI Act applies ✅ UK regulations also apply
UK company, UK + EU audiences ✅ Full EU AI Act for EU portion ✅ Full UK regulations
EU-based company, UK audience ❌ EU AI Act applies to EU operations ✅ UK regulations apply to UK targeting
AI tool provider (UK), used by EU deployers ✅ Provider obligations apply ✅ UK regulations for UK operations

Part Four: Do’s and Don’ts for Marketing Teams

4.1 Do’s

  1. Audit your AI stack now. Identify every AI tool in your marketing workflow: creative generation, copywriting, targeting, personalisation, chatbots, analytics, A/B testing. Document what each does, what data it processes, and where it operates.

  2. Disclose AI-generated content proactively. If in doubt, disclose. The cost of disclosure is minimal; the cost of non-compliance is not. For EU-facing content, assume Article 50 applies.

  3. Implement AI content labelling. Develop a standardised approach to labelling AI-generated or AI-assisted content across all channels. This should be visible, prominent, and consistent.

  4. Review your targeting strategies. Ensure your AI-powered targeting does not rely on prohibited practices: social scoring, exploitation of vulnerabilities, inference of sensitive attributes, or subliminal manipulation.

  5. Train your team on AI literacy. While the UK does not mandate this, the EU does for organisations operating in EU markets. Build AI literacy into your team development regardless of jurisdiction.

  6. Document your AI decision-making. Maintain records of how AI tools are used in your marketing processes, what data they access, and what decisions they influence. This supports accountability under both frameworks.

  7. Review vendor contracts. Ensure your AI tool providers are meeting their obligations under the EU AI Act (provider responsibilities) and that your contracts clearly allocate compliance responsibilities.

  8. Prepare for the ICO Code of Practice. The ICO’s Code on AI and automated decision-making is expected in 2027. Start aligning with the draft guidance now rather than waiting for final publication.

  9. Monitor the UK legislative timetable. A decision on UK AI legislation is expected by autumn 2026. Be prepared for the possibility that the UK introduces more prescriptive requirements.

  10. Build compliance into your creative workflow. AI disclosure should not be an afterthought added at the end of the creative process. It should be a standard step in content production.

4.2 Don’ts

  1. Don’t assume the UK is exempt from the EU AI Act. If you touch EU audiences, you are in scope. Full stop.

  2. Don’t bury AI disclosures. A disclaimer hidden in terms and conditions does not satisfy Article 50. Disclosure must be clear, prominent, and presented at the point of encounter.

  3. Don’t use AI to generate fake reviews or testimonials. This is explicitly prohibited under the EU AI Act and is likely to be addressed by UK regulators as well.

  4. Don’t rely on platform tools to handle compliance for you. Google, Meta, and other platforms are updating their terms, but the disclosure obligation sits with you, the deployer. Platforms provide tools; you provide compliance.

  5. Don’t assume AI-generated content is “obviously” AI-generated. If it could be mistaken for authentic by a reasonable person, it requires disclosure.

  6. Don’t ignore the ASA. The ASA’s Active Ad Monitoring System is reviewing 40 million ads in 2026. AI-generated content that is misleading, harmful, or socially irresponsible will be caught and ruled against.

  7. Don’t conflate “principles-based” with “optional.” The UK’s approach may be less prescriptive than the EU AI Act, but the existing regulations carry real enforcement powers. ICO fines can reach £17.5 million or 4% of global turnover.

  8. Don’t wait for final guidance before acting. The direction of travel is clear in both jurisdictions. Compliance costs are lower when built in early rather than retrofitted.

  9. Don’t assume minimal-risk AI systems are entirely unregulated. While the EU AI Act does not impose specific obligations on minimal-risk systems, they remain subject to existing consumer protection, data protection, and advertising law in both jurisdictions.

  10. Don’t forget your supply chain. If you use third-party AI tools, your compliance depends on theirs. Vet your providers.


Part Five: Things to Think About

5.1 The Trust Deficit

The regulatory response to AI in marketing is not happening in a vacuum. Consumer trust in advertising is already low, and the proliferation of AI-generated content is accelerating the erosion. The ASA’s proactive monitoring and the EU’s transparency requirements are both responses to a consumer protection problem that the market has not self-corrected.

For marketing teams, this is not just a compliance question. It is a strategic one. Brands that embrace transparency and build trust through honest disclosure will outperform those that treat AI disclosure as a box-ticking exercise.

5.2 The Competitive Implications

The EU AI Act creates a competitive asymmetry. Companies that comply early will build consumer trust and regulatory goodwill. Those that delay face both legal risk and reputational damage. The ASA’s willingness to name and rule against brands, combined with the EU’s substantial fine structure, means the cost of non-compliance is both financial and public.

5.3 The UK Legislative Horizon

The UK government’s autumn 2026 decision on AI legislation will be the defining moment for UK AI policy. If the UK introduces a more prescriptive framework, the current regulatory patchwork could be consolidated into something closer to the EU model. If it does not, the fragmented approach will continue, and UK businesses operating in EU markets will continue to be caught by both systems.

5.4 The Generative AI Supply Chain

Most marketing teams do not build their own AI systems. They use tools provided by third parties: Google’s Performance Max, Meta’s Advantage+, ChatGPT, Midjourney, and others. This creates a complex supply chain of obligations:

5.5 The Intersection with Data Protection

AI regulation does not exist in isolation. It intersects with GDPR/UK GDPR in critical ways:


Part Six: Key Dates to Watch

Date Event Relevance
Now ASA Active Ad Monitoring at full capacity AI-generated ads being reviewed at scale
19 June 2026 New ICO complaint handling rules Data protection complaint obligations for AI-related data processing
1 July 2026 Google Ads updated terms Authorises automation; advertiser disclosure obligations unchanged
2 August 2026 EU AI Act Article 50 enforcement Transparency obligations for AI-generated content become enforceable
Summer 2026 ICO draft automated decision-making guidance (final) Expected to set direction for UK AI regulation
Summer 2026 Ofcom Fraudulent Advertising Code (draft) Implications for AI-generated advertising on regulated platforms
Autumn 2026 UK government decision on AI legislation Could fundamentally reshape UK AI regulatory landscape
2 December 2026 New EU prohibitions + watermarking obligations CSAM/non-consensual imagery bans; enhanced marking requirements
2027 ICO Code of Practice on AI Comprehensive UK AI governance framework
2 December 2027 Proposed extended Annex III deadline (pending Omnibus) High-risk AI system compliance deadline (if adopted)

Appendix: Glossary of Key Terms

Term Definition
AI System A machine-based system designed to operate with varying levels of autonomy, that may exhibit adaptiveness after deployment and that, for explicit or implicit objectives, infers from the input it receives how to generate outputs such as predictions, content, recommendations, or decisions that can influence physical or virtual environments
Deployer Any natural or legal person, including a public authority, agency or other body, using an AI system under its authority (i.e., you, the marketing team using the tool)
Provider Any natural or legal person that develops an AI system or has it developed and places it on the market or puts it into service under its own name or trademark (i.e., the tool vendor)
Deepfake AI-generated or manipulated image, audio, or video content that resembles existing persons, objects, places, or events and would falsely appear authentic or truthful
General-Purpose AI (GPAI) AI systems that can be used for a wide range of purposes, including large language models and image generators
High-Risk AI System An AI system classified under the Act’s Annex III categories or as a safety component of regulated products, subject to stringent obligations
Machine-Readable Marking Technical measures (watermarking, metadata, cryptographic signatures) that enable the identification of AI-generated content by automated systems
Article 50 The section of the EU AI Act establishing transparency obligations for AI-generated content, chatbots, deepfakes, and emotion recognition systems
Omnibus The proposed amendments to the AI Act (May 2026) extending compliance deadlines for high-risk systems

This briefing is current as of June 2026. The regulatory landscape is evolving rapidly. This document should be reviewed and updated as new guidance, legislation, and enforcement actions emerge.


David Chadderton is the creator of the STAR Framework and the author of three books: The STAR Framework: Rewriting the Rules of Consumer Engagement (NYC Big Book Award 2025), The STAR Operating System: Decode Mindset, Understand Motivation, Transform Human Behaviour, and Dear Algorithm, It’s Not Me, It’s You. He spent his twenties and thirties teaching people how to make life-or-death decisions at forty thousand feet. He now applies the same principles to consumer psychology, which, depending on the brief, can feel equally high-stakes. By day, a Chief Marketing Officer. By night, a behavioural science obsessive who writes The Unoptimised Human because he can’t stop thinking about why people do what they does.

The STAR Framework

If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.