The EU AI Act and UK AI Policy: A Marketing Team Briefing
A practical guide for marketing teams and businesses navigating AI regulation in Europe
A practical guide for marketing teams and businesses navigating AI regulation in Europe
June 2026
Executive Summary
If your business uses AI in any capacity, and if you market to consumers in the EU or UK, two regulatory landscapes now matter to you. The EU has the world’s first comprehensive AI law, with binding obligations already rolling out and the bulk of enforcement arriving on 2 August 2026. The UK has deliberately taken a different path, relying on existing regulators and five cross-sector principles rather than a single statute, though a formal AI Bill may arrive before the end of 2026.
This briefing covers both frameworks in full, maps the similarities and differences, and translates the legal language into what your marketing team actually needs to do.
Part One: The EU AI Act
What It Is
The EU AI Act (Regulation 2024/1689) is the world’s first comprehensive legal framework for artificial intelligence. It was published in the Official Journal of the European Union on 12 July 2024 and entered into force on 1 August 2024. Provisions are rolling out on a staggered timeline through 2027.
It applies to any organisation that places AI systems on the EU market, or whose AI outputs affect people in the EU, regardless of where the organisation is based. If you market to EU consumers, you are in scope.
The Risk-Based Framework
The Act classifies all AI systems into four risk tiers. The higher the risk, the heavier the compliance burden.
1. Unacceptable Risk (Banned)
These AI practices are prohibited outright:
- Subliminal manipulation: AI that uses covert techniques to distort behaviour in ways that cause harm
- Exploitation of vulnerabilities: AI that targets people due to age, disability, or social and economic situation
- Social scoring: Government-run AI systems that evaluate or classify citizens based on social behaviour
- Real-time remote biometric identification in public spaces by law enforcement (with narrow exceptions)
- Biometric categorisation that deduces sensitive characteristics (political opinions, religion, race, sexual orientation)
- Untargeted scraping of the internet or CCTV to build facial recognition databases
- Emotion recognition in workplaces and educational institutions
- Individual criminal risk prediction
- AI-generated fake reviews and testimonials (from December 2026)
Marketing relevance: If you use AI to generate fake reviews, fabricate testimonials, or deploy subliminal persuasion techniques, you are operating in banned territory. Full stop.
2. High Risk
AI systems that pose serious risks to health, safety, or fundamental rights. These require robust compliance infrastructure: risk management systems, data governance, human oversight, transparency obligations, and conformity assessments.
High-risk use cases include:
- Biometric identification and categorisation (non-banned uses)
- Critical infrastructure safety components
- Education and vocational training (admissions, assessment, cheating detection)
- Employment and recruitment (CV sorting, performance evaluation, worker management)
- Access to essential services (credit scoring, eligibility for public benefits, housing, healthcare)
- Law enforcement (evidence evaluation, recidivism risk, polygraphs)
- Medical devices and healthcare (diagnostics, robot-assisted surgery)
- Administration of justice and democratic processes
Marketing relevance: If your AI systems profile consumers for credit, insurance, or housing decisions, or if you use AI-driven recruitment tools, you are in high-risk territory. Full compliance required by December 2027.
3. Limited Risk
Systems with specific transparency obligations. Users must know they are interacting with AI.
- Chatbots and virtual assistants: Must disclose that the user is communicating with AI
- Deepfakes and AI-generated content: Must be labelled as artificially generated or manipulated
- Emotion recognition systems (in contexts outside the banned category)
Marketing relevance: This is where most marketing teams will feel the impact. If you use chatbots, AI-generated imagery, AI-generated video, or deepfake technology in campaigns, disclosure is mandatory.
4. Minimal or No Risk
The vast majority of AI systems. No mandatory obligations, though voluntary codes of conduct are encouraged.
Examples: spam filters, grammar assistants, autocomplete, search tools, inventory management, predictive maintenance.
General Purpose AI (GPAI) Models
The Act creates a specific regime for GPAI models, which is relevant to any marketing team using large language models, image generators, or other foundation models.
All GPAI providers must:
- Maintain technical documentation of the model (training process, testing, capabilities)
- Provide information and documentation to downstream deployers
- Comply with EU copyright law and publish a summary of training data
- Cooperate with the European Commission and national authorities
GPAI models with systemic risk (those trained with more than 10^25 FLOPS) face additional obligations:
- Notify the European Commission within two weeks of meeting the threshold
- Conduct model evaluations including adversarial testing
- Assess and mitigate systemic risks at EU level
- Report serious incidents to the AI Office
- Adopt a Safety and Security Framework
Timeline:
- 2 August 2025: GPAI obligations applicable for new models
- 2 August 2026: Full enforcement powers and transparency obligations
- 2 August 2027: Extended grace period for models already on market before August 2025
Marketing relevance: If your team uses ChatGPT, Claude, Gemini, Midjourney, or any other GPAI tool for content creation, the providers of those tools have obligations to you as a downstream deployer. You, in turn, have obligations around how you use and disclose their outputs.
The Implementation Timeline
| Date | What Happens |
|---|---|
| 1 August 2024 | EU AI Act enters into force |
| 2 February 2025 | Prohibited practices and AI literacy obligations applicable |
| 2 May 2025 | Codes of practice finalised |
| 2 August 2025 | GPAI model obligations applicable; governance and sanctions provisions active |
| 2 August 2026 | Full compliance framework for high-risk AI (Annex III); transparency obligations for AI-generated content; Commission enforcement powers |
| 2 December 2026 | Prohibition on AI-generated CSAM and non-consensual intimate imagery; watermarking obligations |
| 2 December 2027 | Full compliance for remaining high-risk AI systems |
| 2 August 2028 | Extended transition for certain high-risk AI systems in existing products |
The critical date for most businesses is 2 August 2026. That is when transparency obligations, high-risk system requirements, and enforcement powers all activate.
Penalties
- Prohibited practices violations: Up to €35 million or 7% of global annual turnover (whichever is higher)
- High-risk system violations: Up to €15 million or 3% of global annual turnover
- Providing incorrect information: Up to €7.5 million or 1% of global annual turnover
- Proportionate caps apply to SMEs and startups
What Marketing Teams Must Do Now
Immediate (before August 2026):
- Audit your AI stack. Every AI tool your team uses, from chatbots to content generators to analytics platforms, needs to be mapped against the risk classification
- Label AI-generated content. Any AI-generated images, video, audio, or text published to inform the public on matters of public interest must be disclosed. Advertising copy with human editorial oversight is generally exempt, but the boundary is narrow
- Disclose chatbot interactions. If you use AI chatbots for customer engagement, users must be informed they are talking to AI
- Implement AI literacy. Your team must understand the AI systems they use and the regulatory framework. This is not optional; it has been applicable since February 2025
- Review deepfake usage. Any AI-generated or manipulated content that depicts real persons doing things they did not do must be explicitly disclosed
- Check your review and testimonial practices. AI-generated fake reviews are banned. Full stop
Strategic (ongoing):
- Appoint or designate AI governance responsibility. Someone on your team or in your organisation needs to own this
- Build human oversight into workflows. AI-generated content should be reviewed by a competent human before publication
- Review targeting and profiling. AI-driven consumer profiling for credit, insurance, or housing triggers high-risk obligations. AI targeting based on sensitive personal characteristics (race, religion, etc.) is prohibited
- Document everything. Risk assessments, AI system inventories, compliance decisions. If the regulator asks, you need to show your work
Part Two: UK AI Policy
The UK Approach: Principles, Not a Single Law
The UK has deliberately chosen a different path from the EU. Rather than a single comprehensive AI statute, the UK published “A Pro-Innovation Approach to AI Regulation” (March 2023 White Paper), which established a principles-based, sector-led framework.
There is no UK AI Act. Instead, five cross-sector principles are applied by existing regulators within their own domains.
The Five Principles
- Safety, security, and robustness
- Appropriate transparency and explainability
- Fairness
- Accountability and governance
- Contestability and redress
These are not legally binding in themselves. They are implemented by regulators including:
- ICO (data protection and privacy)
- Ofcom (communications and media)
- CMA (competition and markets)
- FCA (financial services)
- EHRC (equality and human rights)
Each regulator interprets and applies the principles using their existing statutory powers and new guidance.
Key UK Developments (2025-2026)
AI Opportunities Action Plan (January 2025) The government accepted 50 recommendations to boost AI adoption, including AI growth zones, new infrastructure investment, and a National Data Library.
Data (Use and Access) Act (mid-2025) The UK’s first statutory step toward AI-relevant obligations. Updates data governance rules and introduces provisions affecting AI training datasets, copyrighted material use, and algorithmic accountability.
AI Security Institute (rebranded February 2025) Formerly the AI Safety Institute. The rebranding signals a stronger focus on national security and misuse risks. The institute evaluates AI models to ensure foundational safety.
AI for Science Strategy (November 2025) Backed by up to £137 million from a broader £2 billion AI investment (2026-2030), focused on AI-ready data landscapes, compute access, and interdisciplinary research.
UKRI AI Strategy (February 2026) A record £1.6 billion committed directly to the AI sector from 2026 to 2030. UKRI’s biggest single investment area. Focus on explainable AI, edge computing, human-in-the-loop systems, agentic AI, and sustainable AI.
Regulating for Growth Bill (May 2026) Announced in the King’s Speech. Creates “sandbox powers” for temporary relaxation of existing rules under strict controls, testing new products and technologies. Reinforces regulators’ focus on growth and AI innovation.
AI Adoption Summit (June 2026) Over £200 million announced to help British companies adopt AI, with the goal of making the UK the fastest AI-adopting country in the G7.
Is a UK AI Law Coming?
There is growing momentum. A comprehensive AI Bill could be introduced in 2026, drawing on lessons from the EU AI Act and international AI summits. The aim would be to balance innovation with security and governance, particularly around generative and frontier AI.
But as of June 2026, the UK remains principles-led, regulator-enforced, and statute-light.
What Marketing Teams in the UK Must Do Now
- Follow the five principles. They are not law, but regulators are applying them. If your AI use violates fairness, transparency, or accountability principles, the relevant regulator can act under existing powers (Data Protection Act 2018, Consumer Rights Act 2015, Equality Act 2010, etc.)
- Comply with the Data (Use and Access) Act. This is now statute. It affects AI training data, copyright, and algorithmic accountability
- Monitor ICO guidance. The ICO is the most relevant regulator for marketing teams. Its AI and data protection guidance is effectively the UK’s marketing-specific AI rulebook
- Prepare for a potential AI Bill. If legislation arrives in 2026, organisations already operating within the five principles will be best positioned
- If you also operate in the EU, comply with the EU AI Act. The UK framework does not exempt you from EU obligations if you serve EU consumers
Part Three: EU vs UK, Similarities and Differences
Where They Align
| Area | EU | UK |
|---|---|---|
| Core principles | Safety, transparency, fairness, accountability, human oversight | Safety, transparency, fairness, accountability, contestability |
| Risk-based thinking | Formal risk classification (4 tiers) | Principles applied proportionately by sector regulators |
| AI literacy | Mandatory (applicable Feb 2025) | Expected but not yet mandated by statute |
| Consumer protection | Banned practices (fake reviews, manipulation) | Existing consumer protection law applies (CMA, Trading Standards) |
| Transparency | Specific obligations for AI content labelling | Principle of “appropriate transparency and explainability” |
| Copyright and training data | GPAI providers must comply with EU copyright law and publish training data summaries | Data (Use and Access) Act addresses copyright and AI training |
| High-risk focus | Defined high-risk categories with specific obligations | Regulators prioritise based on sector-specific risk assessments |
Where They Diverge
| Dimension | EU | UK |
|---|---|---|
| Legal structure | Single comprehensive regulation (binding across all member states) | Principles-based, enforced through existing regulators and statutes |
| Specificity | Detailed risk tiers, defined obligations, prescribed penalties | High-level principles, regulator discretion, sector-specific interpretation |
| AI system classification | Four formal risk tiers (unacceptable, high, limited, minimal) | No formal classification system; risk assessed per regulator |
| Prohibited practices | Explicitly defined list of banned AI uses | No specific banned list; prohibited through application of existing law |
| Enforcement | Dedicated AI Office; penalties up to 7% of global turnover | Existing regulators using existing powers; no AI-specific penalty regime (yet) |
| GPAI regulation | Dedicated regime with specific obligations for providers | No equivalent; relied upon through general principles and copyright law |
| Extraterritorial reach | Applies to anyone affecting EU consumers, regardless of location | Applies primarily to UK-based organisations and those serving UK consumers |
| Legislation timeline | Fully applicable by August 2026 (most provisions) | Potential AI Bill in 2026; no confirmed date |
| Regulatory philosophy | Precautionary: regulate before harm occurs | Pro-innovation: enable first, regulate if harm emerges |
The Practical Difference
The EU tells you exactly what you can and cannot do, and punishes you for getting it wrong. The UK tells you the principles it expects you to follow, asks sector regulators to interpret those principles, and intervenes under existing law when things go wrong.
For a marketing team operating in both markets, the EU AI Act is the harder compliance challenge because it is specific, prescriptive, and carries significant financial penalties. The UK is lighter-touch today, but the regulatory floor is rising, and an AI Bill could change the landscape quickly.
Part Four: What This Means for Your Marketing Team
The Compliance Overlap
If you comply with the EU AI Act’s transparency obligations, you will almost certainly satisfy UK principles on transparency and fairness. The EU framework is more prescriptive, so meeting it puts you ahead in both jurisdictions.
Priority Actions (Ranked)
1. AI Inventory and Risk Assessment (Now) Map every AI tool in your marketing stack. Classify each against the EU risk tiers. Identify any tools that fall into high-risk or banned categories.
2. Content Labelling and Disclosure (Before August 2026) Implement workflows that ensure AI-generated content is labelled. Build disclosure into your chatbot interfaces. Review any deepfake or synthetic media usage.
3. AI Literacy Training (Overdue) Your team should understand how the AI tools they use work, what the regulations require, and where the boundaries are. This has been applicable in the EU since February 2025.
4. Human Oversight Protocols (Now) Ensure AI-generated content passes through human review before publication. Document the review process.
5. Review and Testimonial Audit (Now) Eliminate any AI-generated fake reviews or testimonials. This is banned under the EU AI Act and likely violates existing UK consumer protection law.
6. Consumer Profiling Review (Now) If you use AI for consumer profiling that could affect access to credit, insurance, housing, or similar, you are in high-risk territory under the EU Act.
7. GPAI Provider Due Diligence (Ongoing) Understand what obligations your GPAI providers (OpenAI, Anthropic, Google, etc.) have to you as a downstream deployer. Ensure you have access to the documentation and information you need.
8. Governance Structure (Before August 2026) Assign clear responsibility for AI compliance. Someone in your organisation needs to own this, and it needs board-level visibility.
The STAR Angle
This is where behavioural science meets regulatory compliance. The EU AI Act’s transparency requirements align with what STAR already teaches us about consumer trust: people respond differently to AI interactions depending on their type.
- Thinkers want to know the AI’s logic and data sources. Transparency builds their confidence.
- Adventurers will push the boundaries. They need clear guardrails, not vague principles.
- Socialisers care about the human element. Disclosure that AI is involved does not reduce engagement; it builds trust.
- Realists want certainty. Clear labelling and predictable rules reduce their friction.
A disclosure-first approach to AI-generated content is not just a compliance strategy. It is a trust strategy, and it maps directly to how your consumers are wired.
Quick Reference: Key Dates
| Date | Jurisdiction | Event |
|---|---|---|
| 2 February 2025 | EU | Prohibited practices and AI literacy applicable |
| 2 August 2025 | EU | GPAI obligations applicable |
| Mid-2025 | UK | Data (Use and Access) Act becomes law |
| 2 August 2026 | EU | Full compliance: high-risk systems, transparency, enforcement |
| 2 December 2026 | EU | CSAM/intimate imagery prohibition; watermarking |
| 2026 (TBC) | UK | Potential AI Bill introduction |
| 2 December 2027 | EU | Remaining high-risk AI compliance |
| 2 August 2028 | EU | Extended transition for certain high-risk systems |
Sources
- EU AI Act: Regulation (EU) 2024/1689, Official Journal of the European Union
- European Commission: AI Act enters into force (August 2024)
- European Commission: Guidelines on GPAI obligations and Codes of Practice (2025-2026)
- UK Government: “A Pro-Innovation Approach to AI Regulation” White Paper (March 2023)
- UK Government: AI Opportunities Action Plan (January 2025)
- UK Government: Data (Use and Access) Act 2025
- UK Government: Regulating for Growth Bill, King’s Speech Background Briefing Notes (May 2026)
- UKRI: AI Strategy 2026-2030 (February 2026)
- UK Government: AI Adoption Summit announcements (June 2026)
This briefing is current as of 13 June 2026. The regulatory landscape is evolving rapidly. Consult legal counsel for compliance decisions specific to your organisation.
The STAR Framework
If you enjoyed this essay, you'll find the full argument — and the framework behind it — in the book.