August 6, 2026

The Impact of the Enforcement of the EU AI Act on UK Companies

The transparency rules of the EU AI Act (the “AI Act”) became applicable on 2 August 2026. The AI Act’s transparency obligations (mainly Article 50) are now one of the key sets of rules that have become enforceable and apply broadly to businesses that use generative AI to produce content.

Article 50 of the AI Act introduces transparency obligations in four key situations:

  1. When AI interacts directly with people (the “Users”);
  2. When AI generates synthetic content;
  3. When AI is used for emotion recognition or biometric categorisation; and
  4. When AI creates deepfakes or text published on matters of public interest.

Who will be impacted from 2 August 2026?

The AI Act is applicable to UK businesses who:

  1. develop, supply or make available AI systems used in the EU market (e.g. chatbots and virtual assistants); and
  2. use AI systems in connection with EU customers, employees or markets (e.g. media businesses, financial services or AI customer interactions).

In other words, a UK company does not need to have a physical presence in the EU for the AI Act to be applicable; the focus is on where their AI systems are made available and where their customers and employees are.

Transparency obligations are not limited to companies who use systems that are classified as “high-risk” (i.e regulated) under the EU AI Act – in Article 6 and Annex I & III – but applies to any type of AI system used.

Note that each of the four obligations (listed below) do not apply to AI systems that are authorised by law to detect, prevent, investigate or prosecute criminal offences.

Obligation I: When AI interacts directly with Users (Article 50(1))

The first transparency obligation is that companies that operate as AI system providers (the “Provider”) should ensure that when their AI system interact with Users, those Users are informed that they are interacting with an AI system (which is obvious from the point of view of a natural person who is reasonably well-informed, observant and circumspect, taking into account the circumstances and the context of use).

Examples of such AI systems include chatbots and virtual assistants. Providers have to ensure that the design and development of any platform is performed in a way that users are informed once they begin interacting with the AI agent.

Obligation II: When AI generates synthetic content (Article 50(2))

The second transparency obligation is that when a Provider is generating AI content, whether that is audio, image, video or text, the output must be marked in a machine-readable format and detectable that it has been AI-generated. The EU has provided a code of practice to support compliance with marking and labelling AI-generated content.

This obligation does not apply where the AI system performs as an assistant to standard editing performances (for example, grammar correction) or where the AI system does not substantially edit the data held.

Obligation III: When AI is used for emotion recognition or biometric categorisation (Article 50(3))

When an AI system is used to recognise User’s emotions or categorise them biometrically (for example to assess stress or demographic characteristics), Providers must inform Users that are exposed to the AI system.

Any personal data retrieved by the AI system shall be processed and stored in compliance with applicable data protection legislation, including Regulations (EU) 2016/679 and (EU) 2018/1725 and Directive (EU) 2016/680.

Obligation IV: When AI creates deepfakes or text published on matters of public interest (Article 50(4))

Providers that generate or manipulate images, audio or video content which are ‘deep fake’ (defined in Article 3(60)), must disclose that the content has been artificially generated or manipulated.

Where the ‘deep fake’ content forms part of evidently artistic, creative, satirical, fictional or analogous work or programme, the transparency obligations are limited to disclosure of the existence of the generated content in an appropriate manner that does not hamper the display or enjoyment of the work.

Similarly, Providers that generate text which are published for public information on matters of public interest shall disclose that the text has been artificially generated. However, the caveat is where the AI-generated text has undergone a process of human review or editorial control and where a natural person holds editorial responsibility for the publication of the content.

It is important to note that Providers must notify Users at the first interaction or exposure that AI is in use, where it is clear and easily distinguishable to the User (Article 50(5)), and not hidden or faintly shown.

Penalties and Powers of the Act

For breaches of transparency obligations, the Commission may impose administrative fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher, depending on the category of infringement and the status of the company.

Although the AI Act includes reduced thresholds for SMEs and start-ups, substantial penalties may still apply. For the most serious infringements under the AI Act, penalties can rise to as much as €35 million or 7% of worldwide annual turnover.

How to ensure compliance with the new regulations

Providers should adopt a proactive AI governance framework within the company to minimise the risk of non-compliance of the AI Act rules, examples of practical steps include:-

  • Audit AI use: Maintain an inventory of all AI systems used across the business that interacts directly with Users (e.g. chatbots, virtual assistants or automated decision-making systems).
  • Assess risk: Classify each AI system under the AI Act’s risk framework: prohibited (Article 5), high risk (Article 6-49), or limited risk or minimal risk, to identify the applicable obligations.
  • Review market scope: Determine whether AI systems are used in, or made available to, the EU market so that the relevant AI Act requirements are understood.
  • Implement governance: Introduce AI policies, compliance procedures, and employee training to ensure understanding and requirements of the transparency obligations.
  • Appoint oversight: Designate an AI compliance officer to oversee AI deployments, monitor regulatory developments, and provide ongoing compliance guidance.

Taking these practical steps will help demonstrate a robust compliance framework, reduce regulatory risk and ensure they remain prepared as the AI Act continues to develop and become enforceable.

What happens if you breach the new regulations?

Under Article 99, Providers that fail to comply with the AI Act may face a tiered regime of administrative penalties, with the level of sanction depending on the seriousness of the infringement.

For Article 50, breach of the transparency obligation may result in fines of up to €15 million or 3% of worldwide annual turnover, whichever is higher (Article 99(4)(g)).

It is key to note, however, that in the case of start-ups and SMEs, fines shall be of either the lower percentage or lower amount.

When determining the appropriate penalty, the national competent authority of the EU Member State will consider relevant circumstances of the situation to ensure that the penalty is proportionate, factors include, but not limited to:

  • the intentionality of the Provider;
  • how cooperative the Provider is; and
  • the manner in which the infringement became known.

In summary, Providers should now have implemented and executed the necessary changes to their platforms, as these new obligations came into force on 2 August 2026.


Larry Owereh, a Trainee Solicitor in our Dispute Resolution team, was a contributor for this article.


For further information on the EU AI Act or advice on ensuring your organisation is compliant with the new transparency obligations, please contact a member of our team:

Contact us:

Read more about Cydney-Jane Ault
Read more about Carl Selby

Related articles from RWK Goodman:

View more articles related to Dispute Resolution and Intellectual Property